Serving an audience inside Russia stopped being a latency problem and became a reachability one. Since June 2025 the large Russian ISPs have throttled Cloudflare-fronted sites hard enough that pages do not finish loading. CDN delivery into Russia and the CIS in 2026 is not a coverage decision: it is a decision about whether you run a separate, locally contracted estate, or accept that the audience is unreachable.
A local estate, or none.
No configuration on a Western edge fixes this. If the audience is worth money, you buy from a network with in-country points of presence and a Russian registration, and counsel scopes the engagement first. If it is not, serve from outside and stop paying for the pretence of coverage.
What actually broke
Sites using Cloudflare’s Encrypted ClientHello went dark for Russian users in the autumn of 2024, and Roskomnadzor followed with a statement advising against the service. IP-level problems spread in March 2025. From 9 June 2025, Cloudflare reported that major operators — Rostelecom, MTS, MegaFon, VimpelCom and MGTS among them — were throttling traffic to its network so that only the first 16 KB of a response arrives.
That number is the part worth understanding. Sixteen kilobytes is enough for the handshake to complete and the first packets of an HTML document to land, so the connection looks healthy from outside: synthetic checks return 200 while no stylesheet, script or image ever finishes. Monitoring that probes from beyond the perimeter, or treats a status code as success, reports a working site to the last user standing — the distinction behind synthetic monitoring that does not cry wolf.
Who carries the traffic now
The domestic market is a three-way split. TAdviser’s tracking of 2024 revenue put CDNvideo, counted under Beeline, first on 25.2 per cent, Ngenix on 24.8 and EdgeCenter on 23.5. Ngenix, part of Rostelecom’s data-centre business, publishes more than 50 nodes across 23 Russian cities plus Belarus, Armenia and Kazakhstan; CDNvideo is the video-first Moscow network with the deepest regional footprint we track. VK Cloud and Yandex Cloud sell CDN wired into their own storage and load balancers, which suits estates already inside them.
One detail catches Western architects out: Russian state-facing services are expected to terminate TLS with GOST cipher suites, which no mainstream browser trusts out of the box — Ngenix lists GOST alongside RSA and ECDSA for that reason. Traffic touching a state system needs a second termination stack with its own certificates.
The paperwork is the product
Since 1 February 2024 hosting providers serving Russia must appear in the Roskomnadzor register, and the “landing law” obliges large foreign internet companies to hold a local legal presence and a regulator account. In 2025 the sites of twelve foreign hosting providers — Amazon Web Services, Hetzner, DigitalOcean and GoDaddy among them — were blocked for non-compliance. No foreign CDN serves this market quietly from offshore: the registration is the product, and takedown response times are a contractual commitment.
The CIS is not one market
Uzbekistan’s international connectivity largely transits Kazakhstan and Russia, so a Moscow node can serve Tashkent better than a Frankfurt one — and a routing change inside Russia moves Uzbek latency without anyone touching that path. Measure each country with real user data before buying “CIS coverage”, and keep the region out of your global steering pool: a weighting that assumes interchangeable edges will send traffic where it cannot be delivered.
What legal decides before engineering does
Sanctions move faster than architecture here. The European Union adopted its twentieth Russia package in April 2026, and from 25 May 2026 the supply of managed security services to entities established in Russia is prohibited without a licence, reaching Russian subsidiaries of EU companies. WAF, DDoS mitigation and bot management bought for a Russian entity sit close to that description, and the EU has begun applying anti-circumvention measures to third countries.
If the answer is yes, build a genuinely separate estate: its own contract, certificates, logs, purge path and in-country monitoring, with no shared steering — the discipline that also governs data sovereignty and delivery in 2026. The mistake is the middle ground: a global contract with a box ticked for Russia, monitored from Frankfurt, quietly failing since June 2025.
