Skip to main content
LiMP VPN
All posts

What Are VPN White Lists in Russia and How Do They Work

What Are VPN White Lists in Russia and How Do They Work

In short: In Russia, "VPN white lists" refers to two distinct regulatory mechanisms: the ЦМУ ССОП corporate registry — roughly 75,000 IP addresses of company and government VPN servers exempted from TSPU filtering — and the Ministry of Digital Development's internet services white list, covering 500+ Russian resources that remain accessible during mobile internet restrictions. For a full explanation of how TSPU filtering works, see our article on how Russia blocks VPN.

Two Meanings of "VPN White Lists"

"VPN white list" in Russia is not one concept but two entirely different regulatory tools that are frequently confused due to their similar names.

The first is the ЦМУ ССОП corporate registry: a list of VPN server IP addresses belonging to legal entities that are excluded from automatic TSPU deep-packet filtering. This gives businesses a lawful mechanism for using corporate VPNs to work with foreign partners and services.

The second is the Ministry of Digital Development's internet services white list: a catalog of Russian websites and apps that remain accessible when mobile internet restrictions are imposed — for example, during mass events or emergencies.

Parameter ЦМУ ССОП VPN Registry Mintsifry Services List
What is listed VPN server IP addresses Russian websites and apps
For whom Legal entities (businesses, gov. agencies) All mobile internet users
Administrator ЦМУ ССОП / Roskomnadzor Ministry of Digital Development
Size (2026) ~75,000 IP addresses 500+ services, ~63,000 IPs
When active Continuously (where TSPU is deployed) During mobile internet restrictions
Application Legal entity applies via RKN portal Government-curated, no application

Both registries operate in parallel, are managed by different agencies, and serve different purposes. Conflating them leads to false expectations — for instance, the mistaken belief that a VPN is "already on the white list" simply because its provider is Russian.

The ЦМУ ССОП Corporate Registry: How the VPN Server White List Works

The ЦМУ ССОП corporate VPN registry lets businesses legally use VPN for work with foreign services by exempting specific IP addresses from automatic TSPU analysis.

ЦМУ ССОП (the Center for Monitoring and Management of the Public Communications Network) is a Roskomnadzor-affiliated body that administers the registry. As of April 2026, it contained approximately 75,000 IP addresses — more than six times its size at the end of 2023. The legal basis is Federal Law 149-FZ "On Information, Information Technologies and Information Protection," Article 15.8.

Who Gets Into the Corporate VPN Registry and Why

The registry is designed for organizations with an objective operational need to connect to foreign IP addresses — not for individual users.

Typical registry participants:

  • Banks and financial organizations — working with international payment systems, correspondent accounts, and foreign regulators.
  • Government agencies — interaction with international organizations and diplomatic communications.
  • Large industrial companies — managing equipment with foreign software and accessing vendor servers.
  • IT companies and developers — working with foreign cloud services, repositories, and CDN networks.
  • Media and telecoms — content exchange with international partners and CDN synchronization.

Requirements for VPN Services to Enter the Registry

Registry inclusion is not an unconditional permit. A company or VPN provider that enters the registry takes on concrete obligations toward the regulator.

Core requirements (per Roskomnadzor and E1.ru, April 2026):

  1. Block access to banned resources. The VPN service must block websites from the RKN registry for its users. This is a non-negotiable baseline with no exceptions.
  2. Readiness to cooperate with the regulator. The organization agrees to provide data upon request from Roskomnadzor and ЦМУ ССОП through established procedures.
  3. Russian cryptographic standards. GOST encryption is recommended (mandatory for government entities in certain cases); where infeasible, a written justification is required.
  4. Notification of infrastructure changes. Changes to IP addresses, servers, or protocols require updating the registry record.

Registry inclusion does not mean the service is "permitted" in the sense of lifting all restrictions — it simply exempts the listed IPs from automatic TSPU filtering. For more on the legal status of VPN use, see our article on VPN legality in Russia.

How a Company Adds Its VPN to the Registry

The registration procedure involves the following steps:

  1. Prepare documentation. The organization describes its VPN use case, lists server IP addresses, and specifies the protocols and encryption methods used.
  2. Submit the application. The application is filed through the personal account on the RKN portal or the official ЦМУ ССОП resource. A qualified electronic signature (UKEP) is required.
  3. Regulator review. ЦМУ ССОП checks compliance with the stated requirements and may request additional documents.
  4. Status assignment. Upon approval, the organization's IP addresses are added to the registry — the review period is up to 10 business days.
  5. Ongoing maintenance. The organization must promptly notify the regulator of any VPN infrastructure changes and confirm its registry status annually.

The Internet Services White List: A Separate Concept

The Ministry of Digital Development's internet services white list is a standalone instrument with no connection to the VPN registry, despite the similar name.

The list appeared in September 2025 to ensure the accessibility of critical Russian services during potential mobile internet restrictions. By 2026, it covers more than 500 Russian resources, corresponding to approximately 63,000 IP addresses out of ~46 million total Russian addresses. The list is updated weekly by the Ministry.

The key distinction from the VPN registry:

  • The VPN registry lists corporate VPN servers — so they are not filtered by TSPU.
  • The Mintsifry list covers destination websites and services — so they remain accessible to users.

Categories covered by the Mintsifry list:

  • Government portals (Gosuslugi, FTS, PFR)
  • Russian banks and payment services
  • Marketplaces (Wildberries, Ozon, Yandex Market)
  • Transport services (Russian Railways, airlines)
  • Social networks (VKontakte, Odnoklassniki)
  • Media and news outlets

Notable omission: Telegram and some major banks are not on the list — their accessibility during mobile internet restrictions is not guaranteed. The list applies only to mobile (4G/LTE) internet restrictions; fixed broadband and home Wi-Fi are unaffected.

What Changed with White Lists in 2026?

August–September 2026 brought a large-scale cleanup of the white lists, after Mintsifry identified a systemic vulnerability in how they were administered.

The problem lies in shared IP (CGNAT) architecture. With CGNAT, a single public IP address is simultaneously used by dozens or hundreds of different hosting or CDN clients. When a legitimate company added its IPs to the VPN registry, all neighbors sharing that IP pool were automatically exempted from TSPU filtering too — including services that had no business being there.

According to CNews (August 2026), Mintsifry found VPN services and platforms of prohibited categories that had exploited the CGNAT mechanism to enter the white lists without authorization. The agency demanded that hosting providers and CDN operators:

  • Segregate IP addresses into separate isolated subnets, rather than sharing a CGNAT pool.
  • Provide accurate, verifiable data on which specific client owns each IP address.
  • Enable technically precise per-IP blocking without collateral impact on neighboring clients.

RUVDS CEO Nikita Tsaplin described the goal: "The regulator wants only necessary, approved structures to remain in the white networks." For the market, this means shifting from shared IP to dedicated subnets — raising infrastructure costs for smaller providers.

The cleanup also caused collateral damage: some legitimate companies whose IPs temporarily overlapped with violators were removed from the registry pending investigation. This is a real risk for organizations running corporate VPN on shared hosting. For details on which VPN services have been affected by restrictions, see which VPNs are blocked in Russia.

What VPN White Lists Mean for the Ordinary User

For a private VPN user, the ЦМУ ССОП corporate registry is not directly relevant — it was designed for legal entities and governs corporate infrastructure.

Practical implications that do affect individual users:

  • You cannot enter the VPN registry as an individual. The registry is open only to organizations — ЦМУ ССОП will not accept applications from private persons.
  • Registry status is not a quality signal for consumers. The registry serves regulatory purposes; it does not guarantee speed, privacy, or service reliability.
  • The 2026 cleanup caused collateral impact. Some shared IP addresses used by multiple hosting clients fell under restrictions — this can affect services you rely on if they ran on shared infrastructure.
  • The Mintsifry services list indirectly affects everyone. During mobile internet restrictions, it determines what remains accessible. If a service you need is not on the list, it will not open when restrictions are active.

If you are interested in privacy and security while using VPN, explore LiMP VPN features: the service operates under a strict no-logs policy and uses modern data protection protocols. See also LiMP VPN pricing plans.

What Are VPN White Lists in Russia and How Do They Work