Senator Ron Wyden sent a letter on July 27, 2026 to the Office of Management and Budget, the Cybersecurity and Infrastructure Security Agency, and the National Institute of Standards and Technology, calling for a mandatory two-year deadline to eliminate legacy, internet-facing VPN appliances across the federal government. It’s a proposal about enterprise remote-access infrastructure, not the consumer VPN app on your phone, but the reasoning behind it says something worth understanding either way.
What the letter actually asks for
Wyden’s letter asks CISA to issue a Binding Operational Directive requiring civilian federal agencies to eliminate legacy, public-facing VPN appliances within two years, replacing them with modern zero-trust remote access architecture instead. He’s also asking the National Security Agency to impose the same two-year deadline across military, intelligence, and other national security networks using its existing authority.
Nothing here is approved policy yet. It’s a formal recommendation, not a directive already in force, and federal agencies haven’t announced an implementation plan in response as of this writing (The Record, CyberScoop).
Want to compare all VPNs side by side? Check our full VPN comparison table with scores across 18 criteria.
Why Wyden is targeting VPN appliances specifically
The core argument is straightforward: traditional VPN appliances sit on the public internet by design, so anyone can find, scan, and probe them. That exposed “front door” has repeatedly turned out to be exactly how Chinese and Russian state-sponsored hackers have breached government and contractor networks. Wyden’s letter frames continued reliance on legacy VPN appliances as a recurring, predictable failure mode rather than a one-off risk.
That framing lines up with a pattern we’ve covered repeatedly this year on enterprise VPN infrastructure specifically. Palo Alto’s GlobalProtect had a flaw actively exploited by Qilin ransomware just last week (see Qilin Ransomware Is Exploiting a Palo Alto VPN Flaw), SonicWall’s SMA appliances were hit with zero-days for weeks before detection, and Fortinet credentials tied to FortiBleed ended up linked to Lynx ransomware. None of those are isolated incidents. They’re the same category of exposed, internet-facing VPN hardware Wyden’s letter is asking agencies to stop relying on.
Zero trust, not “no VPN”
The proposal isn’t “stop using encrypted remote access.” It’s a push toward zero-trust architecture, where access is verified continuously and granularly per request, rather than a VPN’s traditional model of granting broad network access once a connection authenticates. Wyden’s letter argues that model is outdated for how attackers actually operate today, and that agencies should stop patching an inherently exposed appliance and instead remove the exposed front door entirely.
For more on how that architecture actually differs from a traditional VPN, see VPN vs Zero Trust (ZTNA) in 2026: Which Does Your Business Actually Need?.
This is not about your personal VPN app
It’s worth being explicit about scope, because “government wants to purge VPNs” headlines invite confusion. Wyden’s letter targets legacy, internet-facing VPN appliances, enterprise hardware from vendors like the ones behind the breaches above, used by federal agencies and their contractors for remote network access. It has nothing to do with consumer VPN services like the ones covered on this site, which encrypt an individual’s personal internet traffic and don’t expose a corporate network behind them the way an enterprise VPN gateway does. Nothing in this proposal restricts, bans, or otherwise touches personal VPN use.
This builds on years of federal zero-trust policy
This isn’t the government’s first move toward zero trust. Executive Order 14028, signed in May 2021, directed federal agencies to begin adopting zero-trust principles after a string of major breaches. OMB followed up in January 2022 with memo M-22-09, setting government-wide zero-trust architecture goals agencies were supposed to hit by the end of fiscal year 2024. Most agencies missed that deadline in practice, which is part of why Wyden’s letter pushes for a binding directive with real enforcement teeth rather than another voluntary goal-setting memo.
CISA has also already shown it’s willing to force action on VPN appliances specifically when the threat is severe enough. In January 2024, it issued Emergency Directive 24-01, ordering civilian agencies to immediately disconnect Ivanti Connect Secure and Policy Secure VPN appliances after active, widespread exploitation by state-linked hackers. That directive covered a single vendor’s products under emergency conditions. What Wyden is now asking for is broader and permanent: not an emergency response to one flawed product, but a standing policy that legacy internet-facing VPN appliances, as a category, get replaced on a fixed two-year clock, regardless of vendor.
Which agencies would be affected
The letter’s request splits into two tracks. Civilian federal agencies (the bulk of the federal government outside defense and intelligence) would fall under CISA’s proposed Binding Operational Directive, the same mechanism CISA already uses to mandate patching timelines and configuration baselines across agencies. Military, intelligence, and other national security systems would fall under a parallel deadline enforced by the NSA using its existing authority over those networks, since CISA’s directive authority doesn’t extend to that side of government. Contractors who connect to federal networks through the same legacy VPN infrastructure would likely be swept in indirectly, since agencies typically pass compliance requirements through to their vendors’ remote access setups.
What happens next
Wyden’s recommendations aren’t binding on their own. CISA would need to actually issue the Binding Operational Directive he’s requesting, and the NSA would need to separately act on the military and intelligence side. Neither has happened yet, and agencies haven’t publicly committed to a timeline. Given the current pace of federal cybersecurity policy, a full transition, if it happens at all, would likely play out over years rather than the two-year window Wyden is proposing, especially across the sprawling footprint of vendor contracts and legacy systems involved.
What’s more immediately relevant is the signal it sends: continued high-profile exploitation of enterprise VPN appliances (Palo Alto, SonicWall, Fortinet, and others in just the past few months) has moved from a security-industry talking point to a Senate-level demand for architectural change. That pressure alone tends to accelerate vendor security investment even before any directive is formally issued.
This is a real, notable escalation in how seriously Washington is treating the enterprise VPN appliance problem, but it's a proposal, not enacted policy, and it applies to federal government infrastructure, not the VPN app on your phone. The underlying argument, that internet-facing VPN hardware is a recurring, predictable attack surface, is well supported by this year's run of Palo Alto, SonicWall, and Fortinet incidents. If you're a consumer VPN user, there's nothing to act on here. If you work in federal IT or with a contractor touching these systems, this is the clearest signal yet that legacy VPN appliances are on borrowed time.
Related reading
For the architectural distinction driving this proposal, see VPN vs Zero Trust (ZTNA) in 2026. For the most recent enterprise VPN breach behind this pressure, read Qilin Ransomware Is Exploiting a Palo Alto VPN Flaw.