Posted in Blog

The EU Cyber Resilience Act Is Here: Here’s How FileZilla Pro Is Getting Ready

Posted in Blog


If you follow EU tech policy, you’ve probably heard of the Cyber Resilience Act (CRA) — new European legislation that sets baseline security requirements for any product with digital elements sold in the EU. It’s a big deal, and it applies to FileZilla Pro.

We wanted to give you a quick, plain-language update on what it means for you, and what we’re doing about it.

What the CRA changes

The CRA introduces obligations for companies like ours — “Manufacturers,” in the law’s terms — to build and maintain software more securely: things like software bills of materials (SBOMs), structured vulnerability handling, and secure-by-design documentation. Most of these requirements phase in gradually, with the bulk taking effect in December 2027.

One obligation, though, arrives much sooner.

The first milestone: 11 September 2026

Starting 11 September 2026, manufacturers must report actively exploited vulnerabilities and security incidents to EU authorities — within 24 hours of becoming aware, a fuller notification within 72 hours, and a final report once a fix ships. Reports go through ENISA’s new Single Reporting Platform.

In practice, this covers a narrow, serious scenario: a vulnerability in FileZilla Pro that’s actively being exploited before a fix is available. We expect this to be rare. But rare doesn’t mean we can be unprepared.

What we’ve done:

  • Designated Assigned Representatives authorized to file reports to the EU platform, with backup coverage so this never depends on one person’s availability.
  • Updated our internal security triage process so that any sign of active exploitation is routed to our security team immediately, so we can move fast against the 24-hour deadline.
  • Committed to publishing a customer-facing advisory at the same time we report to regulators, so you hear from us directly rather than finding out secondhand.
  • Put the same process in place, in parallel, for the open-source FileZilla project. That’s not a formality, the FileZilla project team is largely the same group of people who develop, maintain, and secure FileZilla Pro day to day, so this is one team applying one standard of readiness across both product lines, with the two sides committed to notifying each other the moment either spots active exploitation.

This means that if this scenario ever arises, you can expect fast, transparent communication from us — not silence while we sort out a regulatory process on the fly.

More milestones ahead

11 September is the first CRA deadline, not the last. Further obligations — SBOMs, formal vulnerability handling, secure-by-design documentation — phase in through 2027, and we’re tracking each one the same way: understand it early, build the process before the deadline, not after.

Why we’re confident we’ll get this right

Security compliance is not new territory for us. Business Follows recently achieved ISO/IEC 27001 certification, the international standard for information security management. That certification reflects independently audited practices for exactly this kind of work — structured risk management, incident response, and continuous improvement.

The CRA asks us to formalize how we handle security incidents and disclose them responsibly. That’s already how we operate. We’re glad the rest of the industry is catching up.

Questions about our CRA readiness or how it affects your use of FileZilla Pro? Reach out to us at info@filezillapro.com.

Just starting?


Need More?
Buy Now!