Russian Cryptographic Regulation
Federal Law on Electronic Signatures
The Federal Law on Electronic Signatures (Federalny Zakon ob Elektronnoy Podpisi, No. 63-FZ of 6 April 2011) establishes the legal framework for cryptographic signatures in the Russian Federation. The Law replaced the earlier Federal Law No. 1-FZ of 2002 and introduced a three-tier classification of electronic signatures: (1) the simple electronic signature (prostaya elektronnaya podpis), which uses codes or passwords to confirm signature formation by a specific person; (2) the enhanced unqualified electronic signature (usilennaya nekvalifitsirovannaya elektronnaya podpis, NEKP), obtained through cryptographic transformation of information using a signature key; and (3) the enhanced qualified electronic signature (usilennaya kvalifitsirovannaya elektronnaya podpis, UKEP), which must be created and verified using cryptographic tools certified by the Federal Security Service (FSB).
Only the UKEP is recognised as the legal equivalent of a handwritten signature for all purposes under Article 6 of 63-FZ. The NEKP is equivalent to a handwritten signature only where specifically agreed by the parties or provided by law. The simple electronic signature is recognised only in limited cases, primarily for state and municipal services. The Ministry of Digital Development (Mintsifry) maintains the Register of Certification Authorities (akreditovannye udostoverayushchie tsentry), which are authorised to issue UKEP certificates. These certification authorities must be accredited by Mintsifry and use FSB-certified cryptographic equipment.
GOST Cryptographic Standards
Russian cryptographic regulation is built on a suite of national standards (GOST — Gosudarstvenny Standart) developed by the Federal Agency for Technical Regulation and Metrology (Rosstandart) in coordination with the FSB. The principal cryptographic standards include: GOST R 34.10-2012 (since superseded by GOST R 34.10-2021), which specifies the Russian national elliptic curve digital signature algorithm; GOST R 34.11-2012 (Streebog hash function), the national hash function standard producing 256-bit or 512-bit digests; and GOST R 34.12-2015 (Kuznyechik and Magma block ciphers), which defines symmetric encryption algorithms. The FSB has issued guidance requiring that all cryptographic means used in government information systems, state secrets protection, and critical information infrastructure comply with these GOST standards.
The Kuznyechik block cipher (GOST R 34.12-2015, also known as GOST 28147-89 replacement) uses a 128-bit block size and 256-bit key length, with 10 rounds of substitution-permutation network operations. The Magma cipher provides a 64-bit block size and is maintained for legacy compatibility. Streebog is mandatory for state information systems and is increasingly adopted in private sector applications for document signing, secure messaging, and VPN implementations.
FSB Requirements for Cryptographic Products
The FSB exercises regulatory authority over cryptographic products through its Licensing and Certification Directorate. The Federal Law on Licensing of Certain Activities (No. 99-FZ of 2011) requires a licence from the FSB for any activity involving the development, production, distribution, maintenance, or repair of cryptographic means (kriptograficheskie sredstva). The licensing regime covers encryption hardware and software, electronic signature tools, and cryptographic modules embedded in other products. Licensees must comply with FSB regulations on key management, physical security of cryptographic equipment, and access control for cryptographic personnel.
The FSB’s Certification System for Cryptographic Means (SKZI — Sredstva Kriptograficheskoy Zashchity Informatsii) requires that all cryptographic products used in government systems, state secrets, or for the protection of personal data undergo mandatory certification. The certification process involves: (1) technical evaluation of the cryptographic algorithm implementation against GOST standards; (2) vulnerability assessment and penetration testing by FSB-accredited laboratories; (3) production facility inspection to verify secure manufacturing practices; and (4) ongoing compliance monitoring. Certification is valid for five years, with recertification required for new versions or upon discovery of vulnerabilities.
TLS and VPN Regulation
Russian law imposes specific requirements on TLS implementations and VPN services. The Federal Law on Communications (No. 126-FZ of 2003) requires telecommunications operators to use FSB-certified cryptographic means for protecting subscriber communications. The FSB has issued technical regulations requiring TLS 1.2 or higher using GOST R 34.10-2012 for server authentication and GOST R 34.11-2012 for certificate validation. The National Certification Authority (Natsionalny Udostoverayushchy Tsentr) issues TLS certificates for government and regulated commercial websites, while private certification authorities may issue certificates for other purposes provided they use FSB-certified infrastructure.
VPN services operating in Russia are subject to the Sovereign Internet Law (No. 90-FZ of 2019), which requires telecommunications operators to install Technical Means of Counteracting Threats (TSPU) capable of blocking VPN traffic. The Federal Law on Information, Information Technologies and Information Protection (No. 149-FZ) prohibits the use of VPN and anonymisation services to access content blocked in Russia. Roskomnadzor maintains the Unified Register of Prohibited Information and has authority to require VPN providers to block access to restricted content. Enforcement has been active: Roskomnadzor has blocked several major VPN providers, including ExpressVPN, NordVPN, and ProtonVPN, and has issued administrative fines to telecommunications operators that fail to block VPN traffic.
Encryption Bans and Restrictions
Russian law does not impose a general prohibition on encryption but restricts the use of non-certified cryptographic means in specific contexts. The Federal Law on State Secrets (No. 5485-1 of 1993) prohibits the use of non-certified encryption for protecting information classified as a state secret. The FSB Order No. 378 of 2016 establishes that cryptographic means for protecting personal data in state information systems must be certified by the FSB. Use of non-certified encryption in these contexts may constitute an administrative offence under Article 13.12 of the Code of Administrative Offences, with fines of up to 300,000 RUB for legal entities.
The Yarovaya Law (No. 374-FZ of 2016) introduced obligations for organisers of information dissemination — including messaging services, social media platforms, and email providers — to provide the FSB with keys for decrypting user communications. This has been interpreted as requiring encryption backdoors, though the FSB has not formally mandated a specific technical mechanism. Services that refuse to comply, such as Telegram (which was blocked in Russia from 2018 to 2020 before compliance), face blocking and administrative penalties. The requirement has been criticised as effectively criminalising end-to-end encryption.