How does the "register of socially significant services" work in Russia? It's a list of resources that continue to operate when mobile internet is shut down.
The term “whitelist” has caught on in the media and among users, by analogy with website blacklists. The logic is inverted: a blacklist bans the items listed, while a whitelist allows only the items listed and bans everything else. The name is convenient, but unofficial and not entirely accurate. We prefer the term “allowlist”.
The full register has not been officially published. We know about its content from statements by the Ministry of Digital Development, carrier data, and media reports. The ministry compiles and approves the list, while each telecom operator configures access on its own side. As a result, the register is implemented differently by different carriers and not necessarily at the same time. Judging upon our observations, the allowlist includes the services of all major Russian IT companies, including VK and Yandex, major banks such as Sber and Alfa Bank, and the Gosuslugi state digital ID and services portal.
What’s happening
Mass mobile internet shutdowns began in Russia in May 2025. The turning point was Ukraine’s Operation Spiderweb (“Pautina”) on June 1, 2025: after the drone strikes on Russia’s strategic aviation, shutdowns stopped being tied to holidays and became a routine response to any perceived threat. According to the “Na Svyazi” (“On the Line”) monitoring project, cited by OZI, the number of shutdowns kept climbing all summer: 68 cases in May 2025, 652 in June, 1,967 in July, 2,099 in August. That’s more than the entire world saw in all of 2024. This is a monitoring project’s estimate, not official statistics, but international observers confirm the same order of magnitude: Top10VPN named Russia the world leader in shutdown count for 2025.
The situation in the capital in spring 2026 became the culmination. Starting March 6, mobile internet in central Moscow didn’t work for more than a week straight. This was likely the authorities running a final test of allowlists in the capital. According to The Bell, the Moscow shutdowns were ordered not by the Ministry of Digital Development but by the FSB’s (Russia’s Federal Security Service) scientific-technical directorate, which sent carriers lists of specific cell towers. And in a city the authorities had long presented as a symbol of digitalization, demand grew for two-way radios, pagers, and paper maps as people looked for ways to function without a network.
This is exactly the environment where the allowlist shows what it really is. When internet gets cut off, all that remains is whatever someone decided in advance to leave switched on.
Historically, tracking the number of full shutdowns was the only metric available to gauge the scale of network disruptions. In August 2026, data emerged on how often the internet actually runs in allow-list mode. Kommersant reported on a study by Vigo, a company that builds network monitoring tools. Vigo’s specialists analyzed about a billion user sessions. It turned out that in July 2026, in the Central Federal District, only 30.5% of mobile internet sessions ran without restrictions. In every other case, users could only reach whatever was on the allowlist. Compared with January, the number of connections running this way in Central Russia grew by an average of 31%.
Border regions face the tightest restrictions: in the Bryansk, Kursk, and Belgorod regions, as of late July, only 12% of sessions got through unrestricted, on average. Nearly nine out of ten connections reached only sites on the allowlist. These restrictions could formally be explained by drone attacks. But even in Moscow and the surrounding region, supposedly far from the front line, only about 49% of sessions ran outside the allowlist; in St. Petersburg it was 43.9%, and in Leningrad Region 58.9%. As of June, the freest regions were remote ones: the Jewish Autonomous Region (75.7% of sessions unrestricted), Tuva (72.3%), and Magadan Region (69%).
Anton Prokopenko, Vigo’s director of product, suggests that services on the allowlist should run without interruptions, and that the process for getting added to it should be “simple, transparent, and based on clear criteria.” That’s an indirect admission that right now, it’s none of those things. The “big four” (Vimpelcom, MegaFon, MTS, and T2 Mobile) declined to comment on the data.
By August 2026, the allowlist had stopped being an “emergency mode” switched on only under exceptional circumstances. In a number of Central Federal District regions, the allowlist is, in effect, simply how mobile internet normally works now. A caveat: this is a commercial company’s measurement, not official statistics, and it covers mobile networks only, not wired access. There are no other data on how often this mode gets activated.
Who decides what you get to keep
The allowlist is administered by the Ministry of Digital Development (Russia’s ministry overseeing telecom and digital policy). Yet publicly, it was the carriers themselves who proposed the idea. In fall 2025, Vimpelcom CEO Sergey Anokhin put forward the initiative, the ministry quickly approved it, and carriers rolled it out.
The first version included 57 resources: the state news agency RIA Novosti, major banks and carriers, Gosuslugi (Russia’s state digital ID and services portal), VKontakte, Odnoklassniki, Mail.ru, the national messenger Max, Yandex’s services, and the marketplaces Ozon, Wildberries, and Avito. By spring 2026, the list had grown past a hundred services. It’s estimated the allowlist now includes around 500 resources (this is an estimate; there’s no official figure).
What the list’s composition itself reveals:
Max has been on the allowlist since September 2025. Telegram is not, and it stops working during shutdowns.
Technical requirements for candidates exist and are broadly known. According to Kommersant’s account, a service must meet requirements around server location, must use static Russian IP addresses, unproxied connections, and transparent TLS/SNI routing. In other words, a resource has to be fully visible to the carrier and the regulator, which by definition excludes any anonymizing infrastructure from the allowlist.
The admission procedure for the list is opaque. Formally, a resource has to be “socially significant,” but no public criteria for that significance exist. A company can file an application, but the Ministry of Digital Development will consider it only if a relevant federal agency has petitioned on its behalf. In other words, technical compliance is a necessary condition but not a sufficient one: whether you actually end up on the “accessible” list remains an administrative decision made case by case.
Getting on the list means trading it for the state’s access to your data. In February 2026, the FSB banned adding banking apps to the allowlist unless they had SORM installed (Russia’s lawful-intercept system, which gives security services access to data). The logic is straightforward: if you want to keep working during a shutdown, you have to let yourself be watched, read, and listened to.
Mechanics
A caveat: we’re describing this mechanism based on data from independent researchers, relevant communities, and academic publications, not on carriers’ internal documentation, which remains unavailable.
The technical foundation is TSPU (technical means for combating threats), deep packet inspection (DPI) hardware that every provider has been required to install since 2019 under the “sovereign Runet” law. Roskomnadzor (Russia’s federal internet censorship and telecom regulatory agency) is the sole party that controls it; carriers themselves have no access to its settings. A peer-reviewed Censored Planet study (Xue et al., presented at the ACM IMC 2022 conference) identified more than a million hosts across 650 autonomous systems sitting behind TSPU devices, and showed that blocking triggers on domain name (SNI), on IP address, and on the QUIC protocol.
The allowlist operates on two levels. The first is by domain name: the equipment looks at which site a request is heading to and lets through only approved ones. The second, harsher level works by IP address and entire autonomous systems: it only lets through traffic to approved address blocks.
This filtering has a distinctive signature. According to researchers in the field, a restricted connection doesn’t drop instantly. The connection “hangs” after transferring roughly 16 kilobytes of data (a hallmark of DPI payload inspection limits). Sometimes that’s just enough for part of a page to load before the connection cuts off.
But the most telling part is the collateral damage. In February 2026, a researcher known as 0ka scanned a Russian provider’s network and found that restrictions targeted 72 “necessary” ASNs (Autonomous System Numbers), but 391 ended up affected (over 225 million IP addresses). The blocking caught some of the world’s largest clouds and content delivery networks (Amazon, Hetzner, OVH, DigitalOcean, Cloudflare, Akamai), which host an enormous share of the “unapproved” internet. The method is blunt: filtering happens wholesale, by autonomous system.
One example shows just how blunt. When the Cogent autonomous system got blocked (its address space is also used by third-party networks), the filters collateralized endpoints with no connection to Russia at all: a home router in the US and a router in Libya. Russian filtering hit someone else’s infrastructure on other continents, simply because it happened to sit in the “wrong” address block.
What breaks along the way
The allowlist has a technical size limit. The Ministry of Digital Development itself acknowledges that “adding a large number of services isn’t possible.” Whatever didn’t make it in on time, or wasn’t deemed necessary, gets left out.
The starkest example is medicine. For about eight months, restrictions meant that during internet shutdowns, continuous glucose monitoring systems for diabetics stopped working (apps that transmit sensor readings to a phone in real time). They only got added to the allowlist after the issue became public. While approvals dragged on, people with a chronic condition were left without data on their own health status every time the internet went down.
Any service that doesn’t make the allowlist simply disappears during a shutdown, and the list’s administrator makes that call, not the patient and not the doctor.
The economics of mobile service break down too. Subscribers pay for a data package but can only use it within the allowlist’s bounds. Sergey Kudryashov, a partner at Strategy Partners, describes this as the “unused package effect”: the gap between what people pay for and what they actually get keeps growing, and subscribers are switching carriers more often in search of a better deal. Carriers themselves, he says, are redesigning their plans and pushing wired access harder, since restrictions don’t reach it yet.
There is an interesting detail from Konstantin Ankilov, CEO of TMT Consulting: carriers are getting bailed out by the fact that internet plans bundle in voice service, and voice calling is in demand again. The logic makes sense. When mobile internet only works via the allowlist, people go back to making regular phone calls. Except by this point, the phone call itself has become a regulated channel: since fall 2025, organizations have had to buy call labeling, and carriers cut off unlabeled mass calls (we have a recent piece on exactly this topic). The result is a closed loop: the internet narrows down to the allowlist, people switch to voice, and voice by then is already under its own permission regime.
International context
Analysts describe this as a shift toward a “closed, tightly controlled digital perimeter” modeled on China’s firewall: a move from a globally connected network to a self-contained national one. The Polish OSW center argues that the Russian authorities’ goal is to guarantee access only to approved resources while cutting off sources the state hasn’t sanctioned.
An important caveat about reliability: even the approved services run unreliably. According to OZI’s estimate, by mid-2026 the share of successful connections in allow-list mode didn’t exceed 10%. During the March shutdown in Moscow, even services on the list malfunctioned. The system that was supposed to keep “socially significant” services running can’t reliably manage even that.
It is not a conversation about the future
Mechanisms like this are usually discussed in the subjunctive: the infrastructure is built, the switch is installed, and it’ll get flipped the next time things escalate. With the allowlist, that framing is already outdated. Data from Central Russia shows there’s nothing left to flip: the mode is on and running most of the time, and in some regions, full internet access has become the exception rather than the rule.
The nature of the question itself has changed too. It’s no longer about whether restrictions will get introduced, but about where their boundary sits. Today the allowlist holds just over a hundred services, and getting on it depends on a petition from the relevant agency and a willingness to install surveillance equipment. That means the next time things escalate (an election this fall, a possible new mobilization wave in the fall, a major incident, and those happen regularly), authorities won’t need to expand the infrastructure. They’ll just need to expand the geography and strictness of enforcement.
It’s also worth adding what habituation does on its own. When restricted access becomes background noise, there’s no longer an event worth reporting on. People notice and talk about a week-long shutdown, but a permanent mode where half of all sessions get reduced to the approved list just gets read as ordinary service quality.
This is exactly how a temporary measure turns into the norm: not through a loud decision, but through the absence of any occasion to notice it happening.
Recommendations
There’s no fully reliable way to keep access during allow-list mode, and it’s worth saying that plainly. The circumvention tools we’ve covered in our VPN pieces work unreliably during hard shutdowns. Filtering by IP and autonomous system hits the very infrastructure those tools depend on.
What’s actually within your control is knowing in advance what mode your network is running in, and not depending on a single channel. For the first part, we built a simple tool: a browser-based Web Checker 2.0 that tests resource availability and shows whether your access is restricted. It’s available at this link and runs directly from your device.
Check your blocking mode
This new version of the web checker was built specifically for checking blocking mode. It distinguishes normal access from allow-list mode and, importantly for a disconnected-internet scenario, lets you save the web checker file locally and save the check results to a file, so you can send it to us later once connectivity returns. The web checker needs no installation, runs through the browser, and behaves no differently than an ordinary attempt to open a website.
The general digital-safety principle for situations like this hasn’t changed: don’t rely on a single path to any critical service, plan backup means of communication and data access in advance, and keep in mind that home wired internet and Wi-Fi aren’t affected by these restrictions for now; this is strictly about mobile networks.
Conclusion
Allowlists change the basic principle behind how the network operates: internet access (even with Roskomnadzor’s existing blocks) turns into a privilege, handed out from a list and in exchange for transparency to surveillance. The official framing talks about care and protection from drones. In practice, the country can be left with exactly whatever internet those at the top decide it needs, at any given moment.
The main thing is reliably established: the mechanism is built, running, and in the country’s central regions it no longer operates episodically but affects the majority of connections. Everything else consists of estimates from researchers and monitoring projects, and we’ve tried to keep the two kinds of information clearly separated. It’s worth tracking how this develops through measurement data rather than official statements. That’s exactly what we’re doing.