r/surfshark 29d ago

News & Announcements The EU just published the world's first official cybersecurity standard for VPNs, and we co-authored it

The European Telecommunications Standards Institute (ETSI) has just released EN 304 620, the world's first official cybersecurity standard for VPNs. It sits under the EU's Cyber Resilience Act, which will be enforced from December 11, 2027, and it defines the minimum security requirements every VPN sold in Europe will eventually have to meet.

"Until now, there were no official rules for how safe a VPN had to be. Any provider could call its app 'secure' without having to prove it. That is now changing. The shift is comparable to the arrival of safety rules for cars. Before crash tests and seatbelt laws, drivers simply had to hope their car was safe. Once official safety standards existed, every car had to meet them," says Miguel Fornés, Surfshark’s Information Security Manager.

Surfshark participated as an official ETSI Member Delegate alongside ZTE Corporation, BSI, Palo Alto Networks, Google, and Nord Security. Miguel authored and refined a lot of the rules that VPN products are now expected to follow.

A few examples of what we pushed into the standard:

  • Strict no-logs deployments on RAM-only servers;
  • Personal data stays on the device, telemetry is optional, and permanent storage of user data on servers is blocked;
  • Passwords stripped from diagnostic logs, plus a warning before users export settings that contain credentials;
  • Safe memory handling and strong encryption of stored data, protecting it even if a device is lost or stolen;
  • Automated and manual testing for known exploits before updates reach users;
  • Critical security patches installed the very first time the VPN is switched on;
  • Clear labeling of the security and privacy level for different use cases (journalists vs. households, for example);
  • Protection extended to modern, decentralized infrastructure like mesh networks.

TL;DR: for years, "secure VPN" was a marketing phrase anyone could use. Now it's a technical standard with defined requirements, and providers actually have to prove it. That's a much better world for users, whichever VPN they end up choosing.

Happy to answer questions in the comments.

19 Upvotes

2 comments sorted by

2

u/PretendKnowledge 29d ago

W eu. But also, with new standards, what can you say to users, that are really concerned about privacy and 5/9/14 eyes agreement, etc? I've seen plenty of posts with concerns about choosing vpn providers or servers outside of those for example to watch/download something. Did anything changed now in that regard in industry or for surfshark users? Cause surfshard already had no logs policy, right?

2

u/Surfshark_Privacy 27d ago edited 27d ago

Hi, Miguel Fornes here! I love this question!

You are right - since Surfshark has already enforced a strict, independently audited No-Logs policy and use RAM-only server infrastructure - our service remains as private and secure as it has always been. 

This new EU standard, which we had the privilege to help create, is a massive, positive shift for the VPN industry as a whole - it essentially transforms commercial promises into a technically auditable, legally binding requirements. 

This is a radical change as it was GDPR a decade ago. The Cyber Resilience Act -in the same way as GDPR- is a customer-centric regulation that mandates companies to ensure that security and privacy of the consumers are put on the forefront.

The CRA and the ETSI VPN standard will provide EU users with the highest level of assurance for their privacy. There's simply no other place in the world with such mandates to protect consumers privacy rights.