SORM in plain terms: how law enforcement access infrastructure works
SORM (СОРМ) is the System for Operative Investigative Activities. In practice, it is equipment that Russian telecom operators are required to install in their networks at their own expense, and that gives the FSB (ФСБ) remote access to traffic and metadata. It exists in three generations: SORM-1 for telephone connections, SORM-2 for internet traffic, SORM-3 for long-term data storage.
An important caveat up front: SORM is not an “all-seeing eye,” but a set of specific technical channels with specific limitations. Some traffic (for example, messages in messengers with end-to-end encryption) is fundamentally unavailable for decryption even with full interception. Understanding the limits of the system’s capabilities is more useful than operating with generalized fears.
Below is a neutral breakdown of what each SORM generation includes, who gets access and under what conditions, and what technically remains outside this system.
In short
- SORM is mandatory equipment that gives security services remote access to operator traffic.
- SORM-1: phone calls and SMS. SORM-2: internet traffic. SORM-3: storage of metadata and content.
- Access is held by the FSB under a court decision, but the technical connection is permanent.
- Metadata (who communicated with whom, when, and from where) is almost always available; the content of messengers with E2E is not.
- Under the “Yarovaya law,” operators store the content of voice calls and messages for up to 6 months, and metadata for up to 3 years.
What SORM is: three generations
The system was built in stages starting in the 1990s and now operates as three parallel circuits. Each covers its own type of data.
SORM-1: telephone connections
Originally developed for wiretapping telephone conversations and intercepting SMS. It includes equipment on the operator’s side that makes it possible to capture the content of a conversation and its metadata in real time (subscriber numbers, time, duration, base stations). It has operated for all telephone operators since the moment they receive a license.
SORM-2: internet traffic
Introduced in the 2000s as broadband access spread. It connects to the routers of operators and providers. It captures internet traffic in plaintext: HTTP sessions without HTTPS, unencrypted protocols, metadata of TCP/IP connections. Encrypted traffic (HTTPS, TLS) is visible only at the “who communicated with whom” level — server addresses, data volume, time. The content inside a TLS tunnel is unavailable without an attack on the certificate.
SORM-3: long-term storage
The third generation, connected with the “Yarovaya law” (2016, amendments to the Federal Law “On Communications” and the Federal Law “On Countering Terrorism”). It requires operators to store the content of voice calls and messages for up to 6 months, and connection metadata for up to 3 years. At the request of the security services, data for this period can be retrieved “retroactively.”
What an operator is required to install
The equipment is purchased by the operator from certified manufacturers. Operators also pay for the storage infrastructure. Without a SORM connection, an operator will not receive a license from Roskomnadzor (Роскомнадзор), so installation is effectively unavoidable.
What is available by different types of communication
| Data type | Available through SORM | What remains outside it |
|---|---|---|
| Phone calls | Conversation content, numbers, time, base stations | Calls through encrypted messengers (Signal, WhatsApp E2E) |
| SMS | Full text, numbers, time | Messages in messengers with E2E |
| HTTP traffic (without HTTPS) | Page content, forms, passwords in plaintext | Practically nothing — an outdated protocol |
| HTTPS traffic | SNI (site address), data volume, time, IP | Page content, message texts, files |
| Messengers with E2E (Signal, WhatsApp) | Connection fact, traffic volume, TLS metadata | Message texts, voice, files |
| VPN with modern encryption | Fact of VPN use, server IP, volume | Content inside the tunnel |
| Geolocation via cellular network | Base station to which the phone is connected | Exact GPS coordinate without the subscriber’s consent |
How to check right now
It is impossible to check yourself in SORM — the system works on the operator’s side, and the operator does not notify the subscriber about security-service access. But you can assess the context: if you or your close contacts appear in public risk registries (the MVD (МВД) wanted database, the foreign agents registry, the list of terrorists and extremists), the likelihood of targeted interest from the security services is higher.
Registry checks are available on the Wanted Radar homepage (the MVD wanted database) and on official agency portals: minjust.gov.ru, fedsfm.ru. This does not settle the question of “surveillance,” but it gives a starting point for assessing risks.
Warning signs vs false alarm
A warning sign means specific grounds to believe that you are under targeted interest: an opened case, a summons for questioning, close contacts appearing in public cases. In this situation, it makes sense to discuss with a lawyer which communication channels to use.
A false alarm is a general feeling that “they are listening to me.” Mass interception of traffic is technically possible, but routine analysis requires huge resources and does not work by default. Without procedural grounds, targeted collection of data on a specific person is not carried out.
What to do next
- For sensitive correspondence, use messengers with end-to-end encryption — Signal, WhatsApp, Threema.
- Enable a PIN code on the SIM card and a separate password for the messenger account.
- Enable two-factor authentication (TOTP apps, not SMS) on critical services.
- Do not use unprotected HTTP — modern browsers warn about it, but check the lock in the address bar.
- Understand the limits of a VPN: it hides the content from the telecom operator, but not from the VPN service provider.
- Do not transmit sensitive data via SMS — it is a completely open channel.
- At elevated risk, consult a lawyer and do not rely on technical tools as your only protection.
Disclaimer: this material is informational and is not legal advice. For a specific situation, contact a lawyer. The technical capabilities of SORM and the provisions of the “Yarovaya law” changed in 2016–2026; for the current version, check consultant.ru.
Conclusion
SORM is functioning infrastructure with specific technical capabilities and specific limitations. It gives the security services access to telephony, open internet traffic, and connection metadata, but it does not cancel modern cryptography. Understanding exactly what is available and what is not makes it possible to make informed decisions about choosing communication channels and not be guided by extremes — neither “everything is under the hood” nor “a VPN is enough.”