Securitylab•October 9, 2026•🇷🇺Translated from Russian

VPN Rules in Russia 2026: No Fine for Ordinary Users but Strict Penalties for Advertising and Extremist Content Access

VPN technology remains legal in Russia, yet a growing set of targeted regulations has created widespread confusion about what users and companies may or may not do. As of 24 September 2026, no separate fine exists for an ordinary citizen merely installing or activating a VPN client. Liability appears only when specific prohibited actions are committed.

The law distinguishes three categories of actors: ordinary users, service operators and advertisers. Each group faces different obligations and sanctions.

What ordinary users may and may not do

  • Connecting to a VPN – no separate penalty.
  • Using a corporate VPN for remote work – permitted under the exception in Article 15.8 of Law No. 149-FZ.
  • Protecting traffic on public Wi-Fi – allowed and does not constitute an offence by itself.
  • Intentionally searching for known extremist materials – fine of 3,000–5,000 rubles under Article 13.53 KoAP.
  • Advertising tools that provide access to blocked resources – fine up to 80,000 rubles for individuals and 500,000 rubles for organisations under Article 14.3 KoAP.

Since 1 September 2025, Article 13.53 KoAP penalises the deliberate search for and access to extremist content. The provision mentions VPN only as one possible technical means. The key requirements remain “intentional” and “knowingly”. Accidental visits or general use of blocked sites do not trigger the fine.

Article 13.52 KoAP targets service operators. Failure to comply with Roskomnadzor demands to integrate with state filtering systems or to block prohibited resources can result in fines of up to 500,000 rubles for the first offence and up to 1 million rubles for repeat violations by legal entities.

Corporate VPN deployments continue to operate normally because the law contains explicit exceptions for closed, pre-defined user groups used for technological purposes. Companies are advised to combine encrypted tunnels with multi-factor authentication, device certificates, least-privilege access and timely revocation of credentials after employee departure.

Advertising and detailed bypass instructions carry significantly higher risk. Roskomnadzor Order No. 196, valid until 1 September 2029, sets stricter criteria for publications that may be viewed as promoting circumvention. Neutral technical explanations of encryption or remote access remain permissible, while promotional links, promo codes and step-by-step guides aimed at accessing restricted resources are not.

VPN creates an encrypted tunnel but does not grant anonymity. The service provider still sees connection metadata, and any account login on a website reveals the user’s identity. The technology also offers no protection against phishing, malware downloads or social-engineering attacks.

By the end of February 2026, Roskomnadzor had restricted access to 469 public VPN services. Corporate users experiencing sudden connection failures are advised to contact their administrators rather than download unknown configuration files or applications from unverified sources.

Under the amendment to Article 63 of the Criminal Code introduced by Law No. 282-FZ, the use of access tools during the commission of a crime may be treated as an aggravating circumstance. Ordinary lawful use of VPN does not constitute a criminal offence.

Related articles

Habr•Policy & Regulation

Troubleshooting Erroneous TSPU Blocks: How Admins Can Collaborate with Russian Regulators

A Moneta client outage traced back to erroneous filtering on Russia's TSPU system rather than internal infrastructure or DDoS protection. Engineers used curl, traceroute, nping, and custom Python scripts to confirm TCP payload-based blocking after the handshake. The team submitted a request via the VTS personal account, received partial acceptance status, then escalated to DCOA and SSOP to obtain the specific TSPU site number. Detailed network traces and active traffic were required for diagnostics. The case highlights coordination challenges between operators, DCOA, and SSOP when erroneous blocks occur on information resources.

AntiMalware•Policy & Regulation

Security Vision Unveils Self-Assessment Portal for Unified Information Security Evaluation Across Corporate Holdings

Security Vision has launched a new Self-Assessment portal designed to consolidate information security self-evaluations for entire corporate groups and holdings. The platform addresses common challenges where subsidiaries maintain inconsistent compliance records, with some requirements fulfilled while others remain unresolved for years in scattered emails and spreadsheets. Security Vision SA covers the complete workflow from defining requirements and distributing questionnaires to calculating results and tracking remediation actions. Parent organizations gain a consolidated view of subsidiary compliance status along with detailed breakdowns by individual systems. The system supports requirement templates, version control, scheduled assessments, automated metric-based answers, and conversion of gaps into actionable plans with assigned owners and deadlines. Additional features include internal policy document management and interactive dashboards for analysis. The first public demonstration is scheduled for the SOC Forum on October 27-28.

Habr•Policy & Regulation

Russian Websites Remain Dependent on Foreign SSL Certificates and Analytics Despite Sanctions

A Russian security researcher developed an open-source tool to scan websites for dependencies on foreign services that could be cut off abruptly. The scan of 50 major Russian sites including banks, retailers, telecoms, airlines, delivery services, online schools and government portals revealed that servers have largely been migrated domestically. However, critical components such as SSL certificates, analytics platforms and fonts remain tied to overseas providers. 43 out of 50 sites still use foreign SSL certificates, primarily from Belgian GlobalSign and American Let's Encrypt, while only four rely on the Russian NUC certificate from the Ministry of Digital Development. The study also highlights legal obligations under Roskomnadzor rules effective since March 2023 requiring prior notification for cross-border personal data transfers. Many sites continue using Google Analytics, Google Fonts and reCAPTCHA without realizing the compliance and resilience risks. The tool assigns letter grades from A to F based on the number of foreign dependencies detected.

Habr•Policy & Regulation

Digitizing Cyber Risks: How to Communicate Cyber Threats to Boards in the Language of Money

The article from Solar details a hybrid methodology for quantifying cyber risks by converting technical threats into financial metrics such as probability and expected losses. It explains that cyber risks represent a specialized form of operational risk characterized by rapid propagation, scalability across IT infrastructure, and heavy dependence on third-party vendors and cloud providers. The process involves four stages: asset and threat identification, incident and vulnerability analysis, translation into monetary values using formulas like ALE, and ongoing monitoring with updates. Qualitative expert assessments are combined with quantitative techniques including Monte Carlo simulations and statistical modeling when data is available. The resulting metrics support investment prioritization through ROSI calculations, integration of cyber risks into enterprise risk management frameworks, and clear communication with directors and investors using business language. Regulatory pressure and the direct impact of incidents on revenue, costs, and business continuity make this approach increasingly essential.