Acronis Cyber Files Cloud is a file sync and share service delivered through the Acronis Cyber Protect Cloud platform that allows employees to synchronise and share files under corporate control. The most important piece of information on this page is not the product's features but its lifecycle: Acronis has placed the "Files Sync and Share" and "Advanced Files Sync and Share: Notarization and eSignature" functionality into End of Life as of December 31, 2025 (Acronis Support KB, 2026). For that reason we do not recommend this service for new deployments.
The official timeline is as follows: mainstream support ended on December 31, 2025; sales of Advanced Files Sync and Share stopped on June 1, 2026; sales of Files Sync and Share end in September 2026; and extended support for Files Sync and Share ends on December 31, 2026 (Acronis Support KB 000029635, last updated May 5, 2026). In other words, the planning window available to an organisation using the service today runs until the end of the year in which extended support expires.
| Stage | Date | What it means in practice |
|---|
| End of mainstream support (Files Sync and Share and Advanced FSS) | December 31, 2025 | Any expectation of new features and standard support has ended |
| End of sale for Advanced Files Sync and Share (Notarization and eSignature) | June 1, 2026 | The notarization and eSigning add-on can no longer be purchased |
| End of sale for Files Sync and Share | September 2026 | The service closes to new purchases |
| End of extended support for Files Sync and Share | December 31, 2026 | The final date by which data migration and export work must be complete |
The reason we put this information at the top of the page is simple: marketing a service that is being retired means the organisation will have to migrate a second time two years later. At Sora Yazılım we are an authorised channel partner for the Acronis solution family and we provide licensing, deployment, migration and managed services to organisations invested in Acronis; part of that role is stating plainly where each product sits in its lifecycle. For organisations using Acronis Cyber Files Cloud, the work we do is no longer deployment but moving the data to a new platform without loss and without breaking KVKK (Turkey's data protection law) obligations.
What exactly did Acronis Cyber Files Cloud do?
Short answer: it was a service that synchronised files between an employee's device and a corporate storage area and kept sharing outside the organisation under policy control and an audit trail. The capabilities listed in Acronis's official Advanced File Sync and Share data sheet from 2021 included synchronisation and sharing from iOS, Android, Windows, Mac and browser clients, folder sharing, PDF editing, unlimited versioning, an audit trail, encryption at rest and in transit, two-factor authentication and policy controls.
The Advanced File Sync and Share add-on layered remote notarization of files on the Ethereum blockchain, embedded eSigning, notarization and signature certificates, and independent verification on top of that. It was designed for scenarios in which the claim "this document existed on this date with this content" has to be proven — contracts, tender files or laboratory reports, for example. Because sales of this add-on ended on June 1, 2026, organisations that need a provable document workflow now have to look elsewhere for a solution.
| Capability | Files Sync and Share | Advanced File Sync and Share |
|---|
| Synchronisation and sharing from iOS, Android, Windows, Mac and the browser | Included | Included |
| Folder sharing | Included | Included |
| PDF editing | Included | Included |
| Unlimited versioning | Included | Included |
| Audit trail | Included | Included |
| Encryption at rest and in transit | Included | Included |
| Two-factor authentication and policy controls | Included | Included |
| Remote file notarization on the Ethereum blockchain | Not included | With the add-on |
| Embedded eSigning and signature certificates | Not included | With the add-on |
| Independent verification | Not included | With the add-on |
| Lifecycle status | EOL December 31, 2025; sales end September 2026, extended support ends December 31, 2026 | EOL December 31, 2025; sales ended June 1, 2026 |
One correction: the phrase "AES-256 encryption" appears frequently on the internet and in older content about this service. Acronis's official File Sync and Share data sheet says only "encryption at rest and in transit"; the information that AES-256 runs in Galois/Counter (GCM) mode with a randomly generated 256-bit key protected by the SHA-2 (256-bit) hash of the password has been verified for Acronis's backup encryption, not for the file sharing service (Acronis Cyber Protect 16 Web Help — Encryption, 2026). We recommend wording the technical measure you record in your compliance file around this distinction.
What happens to our data as the service closes, and by when do we have to move?
Short answer: the final date by which you must move is December 31, 2026, but in practice the project needs to be finished well before that. The extended support period is not a phase in which the service continues to be developed; it is a window granted so that existing deployments can be shut down in an orderly way. The sales side is already closing: sales of Advanced FSS ended on June 1, 2026, and sales of Files Sync and Share end in September 2026 (Acronis Support KB, 2026).
In a migration project, the item that actually consumes time is not copying the data but the context that has to travel with it: sharing links, access granted to external stakeholders, folder-level permission schemes, version history and audit records. In a given organisation, copying hundreds of thousands of files takes days, while redesigning who can access what takes weeks. That is why we plan the migration not as a "file move" project but as an "access model renewal" project.
Retaining audit records is a separate topic. For shares containing personal data, the record of who accessed which file and when cannot be pulled from the source once the service closes. For that reason, in the project plan we define exporting the audit trails and storing them in the organisation's own archive as a distinct milestone that comes before data migration.
Which platform should we move to instead of Acronis Cyber Files Cloud?
Short answer: there are three reasonable routes — Microsoft 365 (SharePoint, OneDrive and Teams), Google Workspace (Drive and Shared drive), or a file server kept in-house. The right choice depends on where you want the data to sit, your existing identity infrastructure and how much you share with external stakeholders. What the three options have in common is this: none of them takes the backup responsibility off your hands.
| Criterion | Microsoft 365 (SharePoint / OneDrive / Teams) | Google Workspace (Drive / Shared drive) | In-house file server |
|---|
| Where the data sits | Microsoft cloud regions | Google cloud regions | The organisation's own data centre or server room |
| Identity and access management | Integrated with Entra ID | Integrated with Google identity management | Through Active Directory |
| Sharing with external stakeholders | Built-in guest sharing and link policies | Built-in sharing and domain-based restrictions | Requires an additional portal or a VPN/ZTNA layer |
| Backup responsibility | With the customer; cloud-to-cloud backup is designed separately | With the customer; cloud-to-cloud backup is designed separately | With the customer; agent-based backup is designed |
| Acronis's role in this scenario | Microsoft 365 cloud-to-cloud backup (cloud deployment only) | Backup of Gmail, Calendar, Contacts, Drive and Shared drive | Disk/file-level backup and recovery |
| Typical reason for choosing it | The shortest route if the organisation already uses Microsoft 365 | Organisations already working on Google tools | A requirement that data stay in the country and under the organisation's own control |
The route we see most often in practice is Microsoft 365, because in most organisations email and identity already live there and the licence and management cost of a separate file sharing product disappears. As part of our Microsoft 365 solutions we design the SharePoint site architecture, OneDrive policies and external sharing rules, and map the folder structure from Cyber Files Cloud onto that model. In organisations with a requirement that data stay in the country, an in-house file server is preferred; in that case we design the backup side through an on-premises management server with Acronis Cyber Protect 16 or with Acronis backup solutions.
Once we move to SaaS, who owns the backup responsibility?
Short answer: it stays with you. Microsoft and Google are responsible for the continuity of the infrastructure; restoring content deleted by user error, encrypted by ransomware or exfiltrated from a stolen account is the customer's responsibility. That is why, in every organisation that moves file sharing to SaaS, we plan cloud-to-cloud backup as a second step.
Acronis meets this need through Acronis Cyber Protect Cloud. According to the official documentation, Microsoft 365 and Google Workspace cloud-to-cloud backup is among the capabilities available in the cloud deployment model only; the same list also includes direct backup to public cloud, EDR, disaster recovery as a service and remote desktop (Acronis Cyber Protect 16 Web Help, 2026). Google Workspace protection covers Gmail mailboxes, Calendars, Contacts, Google Drive and Shared drive data, and up to 5,000 items per company can be protected without loss of performance (Acronis Cyber Protect Cloud user guide, 2026).
The backup itself also needs protecting. Since September 2024, immutable storage in Governance mode with a 14-day retention period has been enabled by default across all Acronis-hosted storages and all Partner and Customer tenants; if Compliance mode is selected, that setting cannot be undone, the retention period cannot be changed and there is no way back to Governance mode (Acronis Cyber Protect 16 Web Help, 2026). This is a structural measure that ensures backups cannot be deleted even if an administrator account is compromised.
The cost of skipping this step is measurable. The Verizon 2025 Data Breach Investigations Report analysed 22,052 security incidents and 12,195 confirmed data breaches between November 1, 2023 and October 31, 2024; it reported that ransomware was present in 44% of the breaches analysed, rising from 39% in large organisations to 88% in SMB breaches, and cited the low likelihood of SMBs having current and readily accessible backups as an advantage for attackers (Verizon DBIR 2025). Leaving a backup gap while changing file sharing platforms is an open invitation to exactly this picture.
Which security risks does file sharing amplify, and how are they closed?
Short answer: a sharing link is a legitimate channel that opens the organisation's security perimeter outwards, and attackers exploit that legitimacy. A fake "a file has been shared with you" notification is one of the most effective ways of leading a user to a page where they enter their credentials. The numbers show the weight of this channel: ENISA Threat Landscape 2025 analysed 4,875 incidents between July 1, 2024 and June 30, 2025 and identified the leading initial access vectors as phishing (approximately 60%) and exploitation of vulnerabilities (21.3%) (ENISA, 2025).
Acronis's own telemetry points the same way: according to the H2 2025 Cyberthreats Report, more than 7,600 ransomware victims were publicly disclosed worldwide in the second half of 2025, and phishing accounted for 83% of email threats (Acronis Cyberthreats Report H2 2025). When you change the file sharing layer, therefore, three adjacent layers have to be planned alongside it:
- Email layer: Acronis Advanced Email Security or an equivalent solution to stop fake sharing notifications and phishing links before they reach the inbox; when an architecture outside Microsoft 365 is chosen, Trend Micro Email Security is a comparable alternative.
- Endpoint layer: synchronised folders are the fastest route for encryption that begins on one endpoint to spread across the whole organisation; Acronis Advanced Security + EDR cuts that chain at the endpoint and provides the return from a clean restore point in the same console.
- Access layer: zero trust based access is needed to control where and with which device files are accessed from; in organisations with a Fortinet investment on the network side, FortiSASE can bring SaaS access and remote worker traffic under a single policy.
What are the file sharing and backup obligations under KVKK?
Short answer: KVKK does not mandate a particular product name; it expects the data controller to take appropriate technical and administrative measures. The "Backing Up Personal Data" section of the Personal Data Security Guide published by the Turkish Personal Data Protection Authority states that, if data is damaged, destroyed or stolen, the data controller must use the backed-up data to resume operations as quickly as possible; that data backup strategies must be developed against ransomware; that only the system administrator should be able to access backed-up personal data; and that data set backups must always be kept off the network (KVKK Personal Data Security Guide).
When moving from one file sharing platform to another, these provisions translate into concrete controls: sharing links that expire and are password protected, an inventory of shares open outside the organisation, folder-level permissions rebuilt according to the principle of least privilege, retention of audit trails, and backups kept in an undeletable area separate from the production environment. Immutable storage is precisely the technical equivalent of that last item.
The data residency question comes up frequently in Turkey. Istanbul (Turkey) appears under the "Acronis Cloud DC" heading on Acronis's official data centre list (Acronis Cyber Cloud Data Centers). This creates an option worth evaluating for organisations that want backups kept in the country while moving file sharing to SaaS: with production data sitting in Microsoft or Google regions, placing the backup copy in the Acronis region in Turkey may come onto the agenda. Because which storage region can be selected for which service depends on the tenant and partner configuration, we confirm this with Acronis at the start of the project. Where production data and the backup copy sit must be addressed separately in the data processing inventory and in privacy notices.
The cost side is part of this decision too. According to the IBM Cost of a Data Breach Report 2025, the global average cost of a data breach fell from USD 4.88 million to USD 4.44 million; against that, 65% of organisations have still not fully recovered from a breach, and among those saying they have fully recovered, 76% took more than 100 days (IBM & Ponemon, 2025). Because the file sharing layer is one of the areas holding the most personal data in an organisation, any gap opened during migration is written directly into that cost line.
How does Sora Yazılım run the migration project?
Short answer: in an order that starts with the inventory, continues with the access model and leaves data copying until last. This is the flow we apply in organisations using Cyber Files Cloud:
- Inventory: which folders are shared with whom, links open outside the organisation, unused areas and directories containing personal data are all mapped.
- Target architecture: a choice is made between Microsoft 365, Google Workspace or an in-house file server; the site/library structure and permission scheme are designed.
- Audit trail archiving: access and sharing records are exported before the service closes and taken into the organisation's own archive.
- Pilot migration: one department's data is moved, permissions and version history are verified, and user training is delivered.
- Backup design: cloud-to-cloud or agent-based backup is brought into service for the target platform, and retention periods and immutable storage are configured.
- Recovery drill: restore scenarios are tested at the level of a deleted file, an entire library and an account.
- Shutdown: once all data has been verified, the Cyber Files Cloud tenant is closed down in a controlled way.
We carry out the infrastructure-side steps of this flow — identity integration, network and storage preparation, automation and monitoring — as part of our DevOps and infrastructure services. If you have developed a portal, form or workflow that connects to Cyber Files Cloud, our custom web and backend development service comes into play to move those integrations to the new platform. The goal is that no business process is left hanging when the service closes.
If you use Acronis Cyber Files Cloud, we recommend starting to plan now so that the migration is complete by December 31, 2026, when extended support ends. Share your current folder and sharing inventory, your user count and your data residency preference, and we will prepare a roadmap and proposal covering the recommended target platform, the data migration method, the backup design and the delivery schedule. Get in touch via our contact page — Turkish-language technical support and post-migration operational support are included in the way we work.