If you find yourself writing a technical requirement that does not seem to be specific to VPNs in any way, then please stop!
The generic cross-vertical versions of the following requirements are a work in progress by other vertical rapporteurs. If a generic requirement isn't on this list, it should be.
* General cryptography requirements
* SBOM
* RDPS Remote Data Processing Service
* Vulnerability handling
* Authentication
* Logging
* Secure Updates
* Distribution of security functions
### Areas of technical requirements still to be written
### Logging
Threat: someone (maybe VPN provider) gets access to remote logs