Charities and non-profit organisations hold sensitive donor, volunteer, and beneficiary data - and are increasingly targeted by cyber criminals who view them as under-resourced and under-protected. Grant funders are tightening eligibility requirements, the Charity Commission expects trustees to protect digital assets, and the NCSC actively recommends Cyber Essentials for all charitable organisations. Certification protects your mission, your people, and your funding.
From grant funding eligibility to trustee obligations and donor data protection, Cyber Essentials addresses the core cyber risks facing charitable organisations.
The National Lottery Community Fund, UKRI, and a growing number of government grant programmes require or strongly recommend Cyber Essentials as part of their application criteria. Without it, your organisation may fail eligibility checks before reviewers even read your proposal.
The Charity Commission makes clear that trustees have a legal responsibility to protect charity assets - including digital ones. A cyber attack resulting in financial loss or data breach can constitute a reportable serious incident. Cyber Essentials provides auditable evidence that trustees have taken reasonable steps to meet that obligation.
Charities hold personal data on donors, volunteers, service users, and beneficiaries - all subject to UK GDPR. A data breach can trigger an ICO investigation and cause lasting reputational damage. Cyber Essentials provides the technical controls that protect this data from the most common attack methods.
UK-registered charities with annual income under £20m that achieve Cyber Essentials are eligible for free cyber liability insurance up to £25,000 through IASME - at no extra cost. For organisations with limited reserves, this is a significant benefit that would otherwise be a meaningful budget line.
The National Cyber Security Centre specifically recommends Cyber Essentials for all charitable organisations, recognising that charities face the same threats as commercial businesses but often with fewer dedicated IT resources. The NCSC's own guidance references Cyber Essentials as the practical first step.
Ransomware and business email compromise attacks on charities often target the finance function - intercepting BACS transfers or encrypting systems during fundraising campaigns. The five Cyber Essentials controls block the vast majority of these attack vectors and protect your organisation's ability to continue its work.
Certification verifies that five essential technical safeguards are in place - the controls the NCSC identifies as blocking the majority of opportunistic attacks on charitable organisations.
Control 1
Establish a secure network perimeter to block unauthorised external access to your charity's systems, donor databases, and financial accounts.
Control 2
Remove default passwords, disable unnecessary software, and harden every device - including those used by remote volunteers and home workers.
Control 3
Ensure staff and volunteers only access the systems and data they need - limiting the damage any single compromised account can cause.
Control 4
Deploy anti-malware protection to stop ransomware and spyware executing via phishing emails, malicious attachments, or compromised links.
Control 5
Keep all operating systems and software patched within 14 days of a security release - closing known vulnerabilities before attackers can exploit them.
The right certification level depends on your organisation's size, grant requirements, and data sensitivity.
Not sure which tier your organisation needs? Contact us and we will advise →
Tier 1
A verified self-assessment questionnaire reviewed by an approved assessor. Meets NLCF, UKRI, and most government grant eligibility requirements. Sufficient for the vast majority of charities and non-profits.
Tier 2
Adds an independent technical audit and vulnerability scan. An approved assessor actively tests your systems to verify controls work in practice. Best for larger charities or those handling sensitive beneficiary data at scale.
We understand that charities often operate with limited IT resource and volunteer-led structures. We work flexibly around your team - guiding your organisation through Cyber Essentials from initial scoping to your issued certificate without disrupting your day-to-day charitable work.
// Key Regulatory References
NCSC - Cyber Essentials for Charities
The National Cyber Security Centre specifically recommends Cyber Essentials for charities of all sizes, recognising the sector's particular vulnerability and the disproportionate impact a cyber incident can have on a charity's operations and beneficiaries.
National Lottery Community Fund (NLCF)
NLCF requires or strongly recommends Cyber Essentials for organisations receiving grants above certain thresholds. Eligibility checks are applied during the application process - certification needs to be in place before funding is confirmed.
Charity Commission - Trustee Responsibilities
The Charity Commission's guidance requires trustees to protect charity assets and report serious incidents including data breaches and financial losses caused by cyber attacks. Cyber Essentials provides the auditable evidence that due diligence was exercised.
UK GDPR - Article 32
Requires appropriate technical security measures for personal data. The five CE controls directly satisfy this obligation, reducing your ICO regulatory exposure for donor, volunteer, and beneficiary data.
Free Cyber Insurance via IASME
UK-registered charities with annual income under £20m are eligible for free cyber liability insurance up to £25,000 through IASME upon achieving Cyber Essentials - at no additional cost to the certification fee.
Talk to our UK-based team. We guide charities and non-profits through Cyber Essentials efficiently - plain English, fixed price, no unnecessary complexity.
Cyber Essentials for charities and non-profits from £320 + VAT. Fixed price, no hidden fees, guided by an IASME Approved Certification Body. Free cyber insurance included for eligible organisations.