ETSI EN 304 620 V1.0.0 (2026-08)
Cyber Security (CYBER); CRA; Cybersecurity requirements for Virtual Private Networks (VPNs)
General Information
- Abstract
DEN/CYBER-EUS-005
- Status
- Not Published
- Technical Committee
- CYBER EUSR - European Union Standardization Request
- Current Stage
- 7 - Dispatch to NSOs / TC
- Due Date
- 31-Oct-2026
Frequently Asked Questions
ETSI EN 304 620 V1.0.0 (2026-08) is a standard published by the European Telecommunications Standards Institute (ETSI). Its full title is "Cyber Security (CYBER); CRA; Cybersecurity requirements for Virtual Private Networks (VPNs)". This standard covers: DEN/CYBER-EUS-005
DEN/CYBER-EUS-005
ETSI EN 304 620 V1.0.0 (2026-08) is available in PDF format for immediate download after purchase. The document can be added to your cart and obtained through the secure checkout process. Digital delivery ensures instant access to the complete standard document.
Standards Content (Sample)
Draft ETSI EN 304 620 V1.0.0 (2026-08)
HARMONISED EUROPEAN STANDARD
Cyber Security (CYBER);
CRA;
Cybersecurity requirements for
Virtual Private Networks (VPNs)
2 Draft ETSI EN 304 620 V1.0.0 (2026-08)
Reference
DEN/CYBER-EUS-005
Keywords
CRA, cybersecurity, VPN
ETSI
650 Route des Lucioles
F-06921 Sophia Antipolis Cedex - FRANCE
Tel.: +33 4 92 94 42 00 Fax: +33 4 93 65 47 16
Siret N° 348 623 562 00017 - APE 7112B
Association à but non lucratif enregistrée à la
Sous-Préfecture de Grasse (06) N° w061004871
Important notice
The present document can be downloaded from the
ETSI Search & Browse Standards application.
The present document may be made available in electronic versions and/or in print. The content of any electronic and/or
print versions of the present document shall not be modified without the prior written authorization of ETSI. In case of any
existing or perceived difference in contents between such versions and/or in print, the prevailing version of an ETSI
deliverable is the one made publicly available in PDF format on ETSI deliver repository.
Users should be aware that the present document may be revised or have its status changed,
this information is available in the Milestones listing.
If you find errors in the present document, please send your comments to
the relevant service listed under Committee Support Staff.
If you find a security vulnerability in the present document, please report it through our
Coordinated Vulnerability Disclosure (CVD) program.
Notice of disclaimer & limitation of liability
The information provided in the present deliverable is directed solely to professionals who have the appropriate degree of
experience to understand and interpret its content in accordance with generally accepted engineering or
other professional standard and applicable regulations.
No recommendation as to products and services or vendors is made or should be implied.
In no event shall ETSI be held liable for loss of profits or any other incidental or consequential damages.
Any software contained in this deliverable is provided "AS IS" with no warranties, express or implied, including but not
limited to, the warranties of merchantability, fitness for a particular purpose and non-infringement of intellectual property
rights and ETSI shall not be held liable in any event for any damages whatsoever (including, without limitation, damages
for loss of profits, business interruption, loss of information, or any other pecuniary loss) arising out of or related to the use
of or inability to use the software.
Copyright Notification
No part of this document may be reproduced in any form, by any means and in any media, without the prior written
authorization of ETSI and except as expressly permitted below.
By way of exception and when the document is a normative deliverable (European Standard (EN),
Technical Specification (TS), Group Specification (GS) or ETSI Standard (ES)), ETSI authorizes to reproduce
and incorporate into products, services and technical documentation only those extracts (e.g. templates) that are strictly
necessary for the technical implementation of the normative deliverable, to ensure compliance with the latter.
Nothing in this notice shall be construed as limiting any mandatory exceptions to copyright provided by applicable law.
© ETSI 2026.
All rights reserved.
ETSI
3 Draft ETSI EN 304 620 V1.0.0 (2026-08)
Contents
Intellectual Property Rights . 19
Foreword. 19
Modal verbs terminology . 20
Introduction . 20
1 Scope . 21
2 References . 21
2.1 Normative references . 21
2.2 Informative references . 21
3 Definition of terms, symbols, abbreviations and naming conventions . 23
3.1 Terms . 23
3.2 Symbols . 24
3.3 Abbreviations . 24
3.4 Naming conventions . 25
4 Product context . 25
4.1 Product Functions . 25
4.1.1 Overview . 25
4.1.2 Potential functions of a node . 26
4.1.2.1 Authentication . 26
4.1.2.2 Access control . 26
4.1.2.3 Traffic encryption . 26
4.1.2.4 Routing . 26
4.1.2.5 Filtering . 26
4.1.3 Potential roles of nodes . 26
4.1.4 Capabilities of nodes . 26
4.2 Product Architecture . 27
4.2.1 Product overview . 27
4.2.2 Network topology and relationship between nodes . 27
4.2.3 VPN client . 28
4.2.4 VPN server, VPN gateway . 29
4.2.4.1 Server & gateway responsibilities . 29
4.2.4.2 Server & gateway remote data processing . 29
4.2.5 Management server . 29
4.3 Operational Environment . 29
4.3.1 General description . 29
4.3.2 Hardware environment . 29
4.3.3 Software environment . 30
4.3.4 Connectivity aspects . 31
4.4 Distribution of Security Functions . 31
4.4.1 Cybersecurity function distribution overview . 31
4.4.2 Cybersecurity Functionalities Offered to Integrated Components . 32
4.4.3 Cybersecurity functions required from the environment . 32
4.5 Users . 32
4.6 Use Cases . 33
4.6.1 Introduction to Use Cases . 33
4.6.2 UC-1 Individual consumer . 33
4.6.3 UC-2 Privacy conscious household . 33
4.6.4 UC-3 Journalist, activist, legal professionals . 33
4.6.5 UC-4 Small enterprise, small not-for-profit organization . 34
4.6.6 UC-5 Large enterprise . 34
4.6.7 UC-6 Enterprise with independent VPN infrastructure . 34
4.6.8 UC-7 Mesh Network . 34
5 Technical requirements for products . 35
ETSI
4 Draft ETSI EN 304 620 V1.0.0 (2026-08)
5.1 Introduction - Applicability of the requirements . 35
5.2 Appropriate level of cybersecurity . 37
5.2.1 Overview . 37
5.2.1.1 CRA Relevance . 37
5.2.1.2 Secure software design and development . 37
5.2.2 REQ-SSD-01 Memory access error prevention . 37
5.2.2.1 Requirement . 37
5.2.2.2 Applicability . 37
5.2.3 REQ-SSD-02 Resilience against potentially untrusted inputs . 38
5.2.3.1 Requirement . 38
5.2.3.2 Applicability . 38
5.2.4 REQ-SSD-03 Applicability of Annex R . 38
5.2.4.1 Requirement . 38
5.2.4.2 Applicability . 38
5.2.4.3 Guidance . 39
5.2.5 Mapping of requirements to use cases. 39
5.3 No known exploitable vulnerabilities . 39
5.3.1 Overview . 39
5.3.2 REQ-KEV-01 Testing for known exploitable vulnerabilities . 39
5.3.2.1 Requirement . 39
5.3.2.2 Applicability . 39
5.3.2.3 Guidance . 40
5.3.3 Mapping of requirements to use cases. 40
5.4 Secure by default configuration . 40
5.4.1 Overview . 40
5.4.2 REQ-SBD-01 Unintentional disabling of cybersecurity features . 40
5.4.2.1 Requirement . 40
5.4.2.2 Applicability . 40
5.4.3 Mapping of requirements to use cases. 41
5.5 Security updates . 41
5.5.1 Overview . 41
5.5.2 REQ-SU-01 Automatic secure update before or during first use . 41
5.5.2.1 Requirement . 41
5.5.2.2 Applicability . 41
5.5.3 REQ-SU-02 Automatic secure update via operational environment before or during first use . 41
5.5.3.1 Requirement . 41
5.5.3.2 Applicability . 41
5.5.4 REQ-SU-03 Secure update via product . 42
5.5.4.1 Requirement . 42
5.5.4.2 Applicability . 42
5.5.5 REQ-SU-04 Automatic secure update via product . 42
5.5.5.1 Requirement . 42
5.5.5.2 Applicability . 42
5.5.6 REQ-SU-05 Secure update provided by operational environment . 43
5.5.6.1 Requirement . 43
5.5.6.2 Applicability . 43
5.5.7 REQ-SU-06 Automatic secure update provided by operational environment . 43
5.5.7.1 Requirement . 43
5.5.7.2 Applicability . 43
5.5.8 REQ-SU-07 Updates are signed and verified before installation . 44
5.5.8.1 Requirement . 44
5.5.8.2 Applicability . 44
5.5.9 REQ-SU-08 Only authorized software updates. 44
5.5.9.1 Requirement . 44
5.5.9.2 Applicability . 44
5.5.10 REQ-SU-09 Secure update has validly signed hash . 44
5.5.10.1 Requirement . 44
5.5.10.2 Applicability . 44
5.5.10.3 Guidance . 45
5.5.11 REQ-SU-10 Invalidated update is rejected . 45
5.5.11.1 Requirement . 45
5.5.11.2 Applicability . 45
ETSI
5 Draft ETSI EN 304 620 V1.0.0 (2026-08)
5.5.11.3 Guidance . 45
5.5.12 REQ-SU-11 Signing keys have strictly scoped usage . 46
5.5.12.1 Requirement . 46
5.5.12.2 Applicability . 46
5.5.12.3 Guidance . 46
5.5.13 REQ-SU-12 Signing keys have not been revoked or otherwise marked untrusted . 46
5.5.13.1 Requirement . 46
5.5.13.2 Applicability . 46
5.5.13.3 Guidance . 47
5.5.14 REQ-SU-13 Reject update to current or previous version . 47
5.5.14.1 Requirement . 47
5.5.14.2 Applicability . 47
5.5.15 REQ-SU-14 Updates not applied from expired sources . 48
5.5.15.1 Requirement . 48
5.5.15.2 Applicability . 48
5.5.16 Mapping of requirements to use cases. 48
5.6 Authentication and access control . 48
5.6.1 Overview . 48
5.6.2 REQ-AAC-01 Authentication of cybersecurity-relevant nodes . 49
5.6.2.1 Requirement . 49
5.6.2.2 Applicability . 49
5.6.2.3 Guidance . 49
5.6.3 REQ-AAC-02 Encryption of transmitted credentials . 49
5.6.3.1 Requirement . 49
5.6.3.2 Applicability . 49
5.6.4 REQ-AAC-03 Authentication timeout . 49
5.6.4.1 Requirement . 49
5.6.4.2 Applicability . 50
5.6.5 REQ-AAC-04 Cloned credentials detection . 50
5.6.5.1 Requirement . 50
5.6.5.2 Applicability . 50
5.6.6 REQ-AAC-05 Forced revocation of authorization of endpoints . 50
5.6.6.1 Requirement . 50
5.6.6.2 Applicability . 51
5.6.7 REQ-AAC-06 Brute force protection . 51
5.6.7.1 Requirement . 51
5.6.7.2 Applicability . 51
5.6.8 REQ-AAC-07 Authorization of endpoints . 51
5.6.8.1 Requirement . 51
5.6.8.2 Applicability . 52
5.6.9 REQ-AAC-08 Fine-grain access control . 52
5.6.9.1 Requirement . 52
5.6.9.2 Applicability . 52
5.6.10 Mapping of requirements to use cases. 52
5.7 Confidentiality protection . 53
5.7.1 Overview . 53
5.7.1.1 CRA relevance . 53
5.7.1.2 Confidentiality of DNS queries . 53
5.7.2 REQ-CON-01 VPN routing stays in effect until VPN connection deactivated . 53
5.7.2.1 Requirement . 53
5.7.2.2 Applicability . 53
5.7.3 REQ-CON-02 VPN routing stays in effect during network-level tunnel failure . 54
5.7.3.1 Requirement . 54
5.7.3.2 Applicability . 54
5.7.4 REQ-CON-03 Tunnel all traffic by default . 54
5.7.4.1 Requirement . 54
5.7.4.2 Applicability . 54
5.7.5 REQ-CON-04 Endpoint to endpoint encryption . 54
5.7.5.1 Requirement . 54
5.7.5.2 Applicability . 55
5.7.6 REQ-CON-05 Inform user of visibility of DNS queries . 55
5.7.6.1 Requirement . 55
ETSI
6 Draft ETSI EN 304 620 V1.0.0 (2026-08)
5.7.6.2 Applicability . 55
5.7.7 REQ-CON-06 Configurable exclusive DNS routing . 55
5.7.7.1 Requirement . 55
5.7.7.2 Applicability . 56
5.7.8 REQ-CON-07 Exclusive DNS routing by default . 56
5.7.8.1 Requirement . 56
5.7.8.2 Applicability . 56
5.7.9 REQ-CON-08 DNS configuration consistency . 56
5.7.9.1 Requirement . 56
5.7.9.2 Applicability . 56
5.7.10 REQ-CON-09 Secure DNS protocols . 57
5.7.10.1 Requirement . 57
5.7.10.2 Applicability . 57
5.7.11 REQ-CON-10 No DNS leaks during network-level tunnel failure . 57
5.7.11.1 Requirement . 57
5.7.11.2 Applicability . 57
5.7.12 REQ-CON-11 Block IPv6 if Unsupported . 57
5.7.12.1 Requirement . 57
5.7.12.2 Applicability . 58
5.7.13 REQ-CON-12 Full Support if Claimed . 58
5.7.13.1 Requirement . 58
5.7.13.2 Applicability . 58
5.7.14 REQ-CON-13 Use conformant cryptography . 58
5.7.14.1 Requirement . 58
5.7.14.2 Applicability . 58
5.7.15 REQ-CON-14 Protect confidentiality of data stored on the product . 59
5.7.15.1 Requirement . 59
5.7.15.2 Applicability . 59
5.7.16 REQ-CON-15 Inform user of limits of privacy protection . 59
5.7.16.1 Requirement . 59
5.7.16.2 Applicability . 60
5.7.17 Mapping of requirements to use cases. 60
5.8 Integrity protection . 60
5.8.1 Overview . 60
5.8.2 REQ-INT-01 VPN client restores any system configuration it changes to its previous state after the
VPN connection ends . 60
5.8.2.1 Requirement . 60
5.8.2.2 Applicability . 61
5.8.3 REQ-INT-02 VPN client provides a method to restore any system configuration it changes to its
previous state . 61
5.8.3.1 Requirement . 61
5.8.3.2 Applicability . 61
5.8.4 REQ-INT-03 VPN client does not degrade system security . 61
5.8.4.1 Requirement . 61
5.8.4.2 Applicability . 61
5.8.5 REQ-INT-04 Application protocol validity checks. 62
5.8.5.1 Requirement . 62
5.8.5.2 Applicability . 62
5.8.6 REQ-INT-05 Application protocol validity checks by operational environment . 62
5.8.6.1 Requirement . 62
5.8.6.2 Applicability . 62
5.8.7 Mapping of requirements to use cases. 63
5.9 Data minimisation . 63
5.9.1 Overview . 63
5.9.2 REQ-DM-01 Data minimisation across the product . 63
5.9.2.1 Requirement . 63
5.9.2.2 Applicability . 63
5.9.3 REQ-DM-02 No Personal Data sent outside endpoint . 63
5.9.3.1 Requirement . 63
5.9.3.2 Applicability . 64
5.9.4 REQ-DM-03 Minimise Personal Data required for service provisioning and payment . 64
5.9.4.1 Requirement . 64
ETSI
7 Draft ETSI EN 304 620 V1.0.0 (2026-08)
5.9.4.2 Applicability . 64
5.9.5 REQ-DM-04 Minimise Personal Data stored . 64
5.9.5.1 Requirement . 64
5.9.5.2 Applicability . 64
5.9.6 REQ-DM-05 No data persistence or storage enabled on exit nodes . 65
5.9.6.1 Requirement . 65
5.9.6.2 Applicability . 65
5.9.7 Mapping of requirements to use cases. 65
5.10 Availability protection . 65
5.10.1 Overview . 65
5.10.2 REQ-AP-01 Fast packet drop . 65
5.10.2.1 Requirement . 65
5.10.2.2 Applicability . 66
5.10.3 REQ-AP-02 Limit memory usage . 66
5.10.3.1 Requirement . 66
5.10.3.2 Applicability . 66
5.10.4 REQ-AP-03 Availability protection provided by operational environment . 66
5.10.4.1 Requirement . 66
5.10.4.2 Applicability . 66
5.10.5 REQ-AP-04 Rate limit unauthenticated traffic . 67
5.10.5.1 Requirement . 67
5.10.5.2 Applicability . 67
5.10.6 Mapping of requirements to use cases. 67
5.11 Non-interference .
...



