Executive Summary
August marked a significant structural pivot in Iran’s digital architecture as the newly released Cyberspace Regulation Plan consolidated internet governance away from the Ministry of ICT and into hardline, non-elected bodies like the Supreme Council of Cyberspace. Beneath nominal language invoking "net neutrality" and "user rights," the policy codifies a system of total traceability by enforcing a 2019 framework that requires every online interaction, service, and pseudonym to be permanently linked to a verified real-world identity profile.
Simultaneously, the plan formalizes a tiered, "class-based" access model. By explicitly exempting state filtering from neutrality rules, it creates a legal basis to grant privileged, unrestricted access—via whitelists and "white SIM cards"—to specific groups such as researchers and journalists, while leaving the general public under heavy censorship.
These regulatory shifts directly reflected on the physical network throughout August. Technical telemetry from Kentik, Cloudflare, and IODA indicates that the network’s post-January recovery stalled, culminating in multiple BGP routing disruptions and a sharp 50% to 70% drop in international traffic volume during the final week of the month.
Introduction
The release of the second version of the Cyberspace Regulation Plan marks the most significant development in Iranian internet policy this month. While framing itself around user rights and net neutrality, the plan builds a legal framework for heightened control, reduced anonymity, and unequal access.
The plan provides an enforcement mechanism for the 2019 National Cyberspace Identity Validation System, formally legalizes filtering exemptions for select groups, and shifts oversight away from the Ministry of ICT toward the Supreme Council of Cyberspace. Ultimately, it signals a model where the state tightly regulates who is online, what they can access, and which institution holds power over the network.
Part One: Internet Policy
The Cyberspace Regulation Plan: A Piece of the Puzzle for Building a Complete User Profile
To understand the significance of the Cyberspace Regulation Plan, it must be viewed alongside a September 2019 resolution by the Supreme Council of Cyberspace: the National Cyberspace Identity Validation System. The primary goal of the new plan is to establish the legal and enforcement mechanisms required to fully implement this validation framework, effectively eliminating true online anonymity.
The central premise of the 2019 identity system is that every interaction across the country’s cyberspace, direct or indirect, must ultimately lead to a unique physical person. While pseudonyms and temporary identifiers remain permissible at the service level, the underlying infrastructure must link these identifiers back to a real-world entity. This applies not just to individuals, but to devices, organizations, specific content, and physical locations.
The system introduces two key verification layers:
- Identity Providers: Responsible for verifying core identity information, issuing unique identifiers, and conducting fundamental authentication.
- Attribute Providers: Responsible for validating fluid credentials over time, such as professional status, educational degrees, or financial standing.
Article 5 of the new plan penalizes service providers that fail to enforce these identity validation requirements. Additionally, by prohibiting any "concealment or falsification of identity," the document creates a legal basis to criminalize privacy-preserving tools, such as VPNs. Because these multi-layer identities must be mapped together across communication, service, and application levels, implementing authorities gain the technical capability to build comprehensive, integrated activity profiles for every user.
User Rights: Guarantees with Major Exceptions
Article 6 outlines user rights—such as guaranteed internet access—that initially appear designed to protect consumers, but are severely limited by structural exceptions.
While Paragraph (a) prevents ISPs from arbitrarily disconnecting or throttling users, it explicitly carves out exemptions for orders issued by judicial bodies or other authorized state agencies. Consequently, this provision offers no protection against localized or nationwide internet blackouts.
Net Neutrality vs. Iran’s Internet Pricing System
Paragraph (b) introduces net neutrality principles for the first time, prohibiting operators from prioritizing or throttling traffic based on content, source, device, or provider identity. On paper, this prevents anti-competitive bandwidth allocation.
In practice, this conflicts directly with existing pricing regulations. Under Regulation No. 266 of the Communications Regulatory Authority (CRA), internet traffic in Iran has been split into "domestic" and "international" tiers since 2017, offering significantly lower rates for state-approved domestic services. Operators also utilize "fair usage thresholds" to throttle service once international data caps are hit. This price-and-volume manipulation inherently contradicts the core premise of equal traffic treatment.
Exemptions from Internet Filtering: A Legal Basis for Tiered Internet Access
The policy further undermines net neutrality by explicitly excluding state censorship from its rules. Note 1 specifies that filtering ordered by the Committee for Determining Instances of Criminal Content remains completely exempt, meaning "neutrality" only applies to the narrow subset of traffic the state permits.
Furthermore, Note 2 authorizes filtering exemptions for select user groups in educational, technological, research, and media sectors. This establishes the formal legal groundwork for a tiered ("class-based") internet:
- General Public: Remains subject to strict state filtering, throttling, and monitoring.
- Privileged Groups: Granted access to whitelisted, unfiltered connections (commonly referred to as "white SIM cards").
Who Holds the Keys to Iran’s Internet?
Beyond user-facing impacts, the Cyberspace Regulation Plan reshapes the balance of institutional power in Iranian tech governance.
The plan reduces the government and the Ministry of Information and Communications Technology (MICT) to managing basic infrastructure. Policy oversight, enforcement, violation monitoring, and direct command over cybersecurity operations are concentrated within non-elected bodies—primarily the Supreme Council of Cyberspace and the National Cyberspace Center. This institutional shift removes democratic oversight and centralizes network control within security-oriented institutions.
Part Two: Internet Network
August: Recovery Stalls as Instability Returns to Iran’s Internet
The latest data from Kentik shows that Iran’s internet traffic rose steadily between May 26 and August 1. But throughout August, this recovery did not continue at the same stable pace, and traffic levels experienced significant ups and downs. Although traffic began to rise again in the final days of the month, Doug Madory, Director of Internet Analysis at Kentik, noted that Iran’s traffic levels still remained far below those recorded before January 8.

Cloudflare Radar data, alongside Kentik’s figures, further reinforces the picture of network instability in the second half of August.
Cloudflare Radar also shows a clear turning point during the month. Its traffic volume data indicates that until around August 24, Iran’s traffic, despite daily fluctuations, remained broadly close to levels seen during the previous comparison period. From August 25, however, both Total Bytes and HTTP Bytes dropped sharply and remained at significantly lower levels through the end of the month.

Cloudflare’s Traffic Trends chart makes the scale of this decline even clearer. From August 25 onward, Total Bytes and HTTP Bytes were around 50% to 70% lower than during the previous comparison period for much of the day. HTTP Requests also fell by roughly 40% to 55% during most periods.
By the end of the month, there was still no clear sign of a full return to the levels seen before the decline.

IODA data also shows clear signs of instability in Iran’s internet connectivity over the past month. Between August 5 and August 17, IODA recorded four drops in Iran’s BGP signal. This indicator reflects how many of Iran’s network routes remain visible in the global internet routing system.
The longest disruption occurred on August 15 and lasted for around 16 hours, while the sharpest drop was recorded on August 17.

Around August 15 and 16, IODA’s Active Probing signal also declined noticeably, falling to around 86%.
A drop in this indicator suggests that users may experience disruptions such as intermittent connectivity, some websites failing to load, or slower and less stable internet access.
Taken together, these technical indicators show that Iran’s internet has still not returned to the conditions seen before January 8.
