Sen. Ron Wyden Urges Federal Agencies to Replace Legacy VPNs Within Two Years Through Zero-Trust Policy Push

Published
Written by:
Rachita Jain
Rachita Jain
VPN Staff Editor
Key Takeaways
  • Federal VPN Proposal: Sen. Wyden urged agencies to replace legacy VPNs with zero-trust systems within two years.
  • Procurement Changes: Proposal would require vendors to certify zero-trust compliance for future federal technology contracts.
  • Current Status: Recommendations remain unapproved; federal agencies have not announced action or implementation plans.

U.S. Senator Ron Wyden has called on three federal cybersecurity agencies to begin phasing out legacy virtual private network (VPN) systems used across civilian government networks within the next two years. The proposal was outlined in a letter sent on Monday to the Cybersecurity and Infrastructure Security Agency (CISA), the Office of Management and Budget (OMB), and the National Institute of Standards and Technology (NIST).

Rather than requesting a study, the letter asks the agencies to take specific actions that could reshape how federal agencies purchase and deploy remote access technology. The recommendations include mandatory migration away from internet-facing VPN appliances and new procurement rules requiring vendors to meet zero-trust security standards before selling remote access products to the U.S. government.

At the time of publication, none of the three agencies had publicly responded to the letter.

Wyden Proposes New Zero-Trust Requirements for Federal Networks

The proposal asks CISA to issue a Binding Operational Directive requiring all federal civilian agencies to remove legacy VPN appliances that are directly accessible from the public internet within two years.

Wyden also recommends that NIST publish technical standards defining what qualifies as a compliant zero-trust remote access solution. According to the letter, those standards should require three core protections:

In addition, the senator is asking OMB to update federal procurement rules so agencies and defense contractors can purchase remote access products only from vendors that formally certify compliance with the new NIST standards.

If adopted, these procurement requirements could affect companies that supply VPN appliances, firewalls, and other remote access products to the federal government.

Recent Cyberattacks Drive the Proposal

Wyden argues that repeated emergency patching has failed to solve what he describes as a broader architectural problem with legacy VPN technology.

Unlike zero-trust network access (ZTNA) systems, traditional VPN appliances are designed to remain visible on the public internet so remote users can connect. That public exposure allows attackers to discover and target the devices.

The letter points to several cyber campaigns involving internet-facing VPN and network edge products, including attacks affecting products from Ivanti, Cisco, and Fortinet. Among the incidents cited are:

According to the letter, these incidents demonstrate that applying security patches alone may not eliminate risks when the underlying architecture continues exposing devices directly to the internet.

What This Means for VPN Users

The proposal is currently a policy recommendation rather than a binding government requirement. Senator Wyden does not have the authority to require CISA, OMB, or NIST to implement the requested measures, and the agencies have not announced whether they plan to act on the recommendations.

For federal agencies, no immediate operational changes have been announced. Likewise, VPN users outside the federal government are not required to take any action based on the letter.

However, the proposal highlights the continued shift toward zero-trust security models, which authenticate users and devices before granting access instead of relying on traditional internet-facing VPN gateways. If federal agencies adopt the recommended standards and procurement rules, vendors serving the U.S. government may need to redesign products to meet the new requirements.

For privacy-conscious users, the development underscores an ongoing industry trend toward reducing publicly exposed remote access infrastructure in favor of architectures intended to limit potential attack surfaces. Since the proposal has not been adopted, no action is currently required by consumers or enterprise VPN users.


For a better user experience we recommend using a more modern browser. We support the latest version of the following browsers: For a better user experience we recommend using the latest version of the following browsers: