Posted in Blog

We are Now ISO/IEC 27001:2022 Certified: What It Means for FileZilla Pro Customers

Posted in Blog


We’re Now ISO/IEC 27001:2022 Certified

We are glad to share some news: Business Follows srl, the company behind FileZilla Pro, has achieved ISO/IEC 27001:2022 certification for our Information Security Management System (ISMS). The certification was issued by Scandinavian Certification AS, an accredited certification body and member of the IAF Multilateral Recognition Arrangement, following an independent audit of how we manage information security across our organization.


What ISO 27001 certification means

ISO/IEC 27001 is the leading international standard for information security management. Certification isn’t a one-time checkbox — it means an independent, accredited auditor has verified that we have documented, working processes for identifying security risks, protecting data, responding to incidents, and continuously improving how we do all of that. It has to be earned initially and then maintained through ongoing surveillance audits, which in our case run annually through the certificate’s validity period (August 2026 – August 2029).

What is in scope

Our certification covers the design, development, support, and sale of our client and server file transfer solutions — in other words, the full lifecycle of the products you rely on: FileZilla Pro Client, FileZilla Server, and FileZilla Pro Enterprise Server.

What this means for you

If you’re evaluating FileZilla Pro for your organization — especially for regulated environments or as part of a vendor security review, this certification gives you independently audited assurance around things like:

  • Formal risk assessment and treatment processes
  • Access control and secure credential management
  • Secure software development practices
  • Incident response and business continuity planning
  • Ongoing employee security awareness training
  • Ongoing monitoring, internal audits, and management review

Certificate details

  • Certificate number: ITA-10370-ISMS
  • Standard: ISO/IEC 27001:2022
  • Certification body: Scandinavian Certification AS
  • Valid through: August 28, 2029 (subject to annual surveillance audits)

If your procurement or security team needs a copy of the certificate or our Statement of Applicability for a vendor review, get in touch with us and we’ll be happy to share it.

Thank you to everyone on our team who put in the work to get us here and thank you to all of you for trusting us with your file transfer infrastructure. We’ll keep raising the bar.

Just starting?


Need More?
Buy Now!