// Charities & Non-Profits

CYBER ESSENTIALS FOR
CHARITIES & NON-PROFITS

Charities and non-profit organisations hold sensitive donor, volunteer, and beneficiary data - and are increasingly targeted by cyber criminals who view them as under-resourced and under-protected. Grant funders are tightening eligibility requirements, the Charity Commission expects trustees to protect digital assets, and the NCSC actively recommends Cyber Essentials for all charitable organisations. Certification protects your mission, your people, and your funding.

// Why It Matters

WHY CYBER ESSENTIALS IS CRITICAL FOR UK CHARITIES

From grant funding eligibility to trustee obligations and donor data protection, Cyber Essentials addresses the core cyber risks facing charitable organisations.

GRANT FUNDING ELIGIBILITY

The National Lottery Community Fund, UKRI, and a growing number of government grant programmes require or strongly recommend Cyber Essentials as part of their application criteria. Without it, your organisation may fail eligibility checks before reviewers even read your proposal.

TRUSTEE DUTY OF CARE

The Charity Commission makes clear that trustees have a legal responsibility to protect charity assets - including digital ones. A cyber attack resulting in financial loss or data breach can constitute a reportable serious incident. Cyber Essentials provides auditable evidence that trustees have taken reasonable steps to meet that obligation.

PROTECT DONOR & BENEFICIARY DATA

Charities hold personal data on donors, volunteers, service users, and beneficiaries - all subject to UK GDPR. A data breach can trigger an ICO investigation and cause lasting reputational damage. Cyber Essentials provides the technical controls that protect this data from the most common attack methods.

FREE CYBER INSURANCE INCLUDED

UK-registered charities with annual income under £20m that achieve Cyber Essentials are eligible for free cyber liability insurance up to £25,000 through IASME - at no extra cost. For organisations with limited reserves, this is a significant benefit that would otherwise be a meaningful budget line.

NCSC RECOMMENDED

The National Cyber Security Centre specifically recommends Cyber Essentials for all charitable organisations, recognising that charities face the same threats as commercial businesses but often with fewer dedicated IT resources. The NCSC's own guidance references Cyber Essentials as the practical first step.

PROTECT YOUR FINANCIAL RESERVES

Ransomware and business email compromise attacks on charities often target the finance function - intercepting BACS transfers or encrypting systems during fundraising campaigns. The five Cyber Essentials controls block the vast majority of these attack vectors and protect your organisation's ability to continue its work.

// The Five Controls

WHAT CYBER ESSENTIALS COVERS FOR CHARITIES

Certification verifies that five essential technical safeguards are in place - the controls the NCSC identifies as blocking the majority of opportunistic attacks on charitable organisations.

Control 1

FIREWALLS

Establish a secure network perimeter to block unauthorised external access to your charity's systems, donor databases, and financial accounts.

Control 2

SECURE CONFIGURATION

Remove default passwords, disable unnecessary software, and harden every device - including those used by remote volunteers and home workers.

Control 3

USER ACCESS CONTROL

Ensure staff and volunteers only access the systems and data they need - limiting the damage any single compromised account can cause.

Control 4

MALWARE PROTECTION

Deploy anti-malware protection to stop ransomware and spyware executing via phishing emails, malicious attachments, or compromised links.

Control 5

PATCH MANAGEMENT

Keep all operating systems and software patched within 14 days of a security release - closing known vulnerabilities before attackers can exploit them.

// Two Tiers

CYBER ESSENTIALS VS CE PLUS FOR CHARITIES

The right certification level depends on your organisation's size, grant requirements, and data sensitivity.

CertificationVerificationBest Suited For
Cyber EssentialsVerified self-assessment questionnaire covering your IT infrastructure, reviewed by an approved assessor.Most charities and non-profits - meets grant eligibility requirements, trustee duty of care, and unlocks free cyber insurance.
Cyber Essentials PlusSelf-assessment plus an independent hands-on technical audit and vulnerability scan by a qualified assessor.Larger charities handling highly sensitive beneficiary data, those working in government supply chains, or organisations requiring maximum assurance for institutional funders.

Not sure which tier your organisation needs? Contact us and we will advise →

Tier 1

CYBER ESSENTIALS

A verified self-assessment questionnaire reviewed by an approved assessor. Meets NLCF, UKRI, and most government grant eligibility requirements. Sufficient for the vast majority of charities and non-profits.

  • NLCF, UKRI & government grant eligibility
  • Trustee duty of care - auditable evidence
  • Free £25k cyber insurance (eligible organisations)
  • IASME fee included, IASME public register listing

Tier 2

CYBER ESSENTIALS PLUS

Adds an independent technical audit and vulnerability scan. An approved assessor actively tests your systems to verify controls work in practice. Best for larger charities or those handling sensitive beneficiary data at scale.

  • Everything in Cyber Essentials
  • Independent technical audit & vulnerability scan
  • Strongest evidence for institutional funders
  • Government supply chain eligibility
// The Process

HOW WE WORK WITH YOUR ORGANISATION

We understand that charities often operate with limited IT resource and volunteer-led structures. We work flexibly around your team - guiding your organisation through Cyber Essentials from initial scoping to your issued certificate without disrupting your day-to-day charitable work.

What Is Included

  • Initial scoping call to assess your organisation's IT environment and grant requirements
  • Guided submission support against the Cyber Essentials question set
  • Gap identification and plain-English guidance on remediation
  • Support through the self-assessment questionnaire
  • IASME assessor review and formal certification
  • Certificate, digital badge, and IASME public register listing

// Key Regulatory References

NCSC - Cyber Essentials for Charities

The National Cyber Security Centre specifically recommends Cyber Essentials for charities of all sizes, recognising the sector's particular vulnerability and the disproportionate impact a cyber incident can have on a charity's operations and beneficiaries.

National Lottery Community Fund (NLCF)

NLCF requires or strongly recommends Cyber Essentials for organisations receiving grants above certain thresholds. Eligibility checks are applied during the application process - certification needs to be in place before funding is confirmed.

Charity Commission - Trustee Responsibilities

The Charity Commission's guidance requires trustees to protect charity assets and report serious incidents including data breaches and financial losses caused by cyber attacks. Cyber Essentials provides the auditable evidence that due diligence was exercised.

UK GDPR - Article 32

Requires appropriate technical security measures for personal data. The five CE controls directly satisfy this obligation, reducing your ICO regulatory exposure for donor, volunteer, and beneficiary data.

Free Cyber Insurance via IASME

UK-registered charities with annual income under £20m are eligible for free cyber liability insurance up to £25,000 through IASME upon achieving Cyber Essentials - at no additional cost to the certification fee.

IASME Approved Body
NCSC
Recommended
100%
Remote Assessment
£25k
Free Cyber Insurance*
// FAQ

COMMON QUESTIONS FROM CHARITIES

Cyber Essentials is required or strongly recommended by a growing number of UK grant funders, including the National Lottery Community Fund, UKRI, and many local authority and government grant programmes. Funders increasingly treat it as a baseline trustworthiness and safeguarding requirement - charities without it risk failing eligibility checks.
The Charity Commission does not currently mandate Cyber Essentials, but its guidance makes clear that trustees have a legal responsibility to protect charity assets including data. A successful cyber attack resulting in loss of funds or a data breach can constitute a reportable serious incident. Cyber Essentials provides auditable evidence that trustees have taken reasonable steps to meet that obligation.
Yes - small charities are frequently targeted precisely because they are perceived as having weaker defences. The NCSC specifically recommends Cyber Essentials for charities of all sizes. For organisations with under £20m turnover, certification also unlocks free cyber liability insurance up to £25,000 through IASME - a significant benefit for charities with limited reserves.
Yes. Charities hold personal data on donors, volunteers, beneficiaries, and staff - all subject to UK GDPR. A data breach involving donor information can be both a regulatory matter and a reputational crisis. Cyber Essentials provides the five core technical controls that protect against the majority of attacks used to access and exfiltrate personal data.
For most charities with a small IT environment, the guided self-assessment can be completed within a few days once the five controls are in place. Our initial controls review identifies any gaps before formal submission, so your team knows exactly what needs addressing before committing to the assessment. We work flexibly around volunteer-run structures and limited IT resource.

PROTECT YOUR MISSION. SECURE YOUR FUNDING.

Talk to our UK-based team. We guide charities and non-profits through Cyber Essentials efficiently - plain English, fixed price, no unnecessary complexity.

Get Certified Today →See Pricing →
// Blog & Guides

LATEST INSIGHTS

View All Articles →
// Get Certified

CHARITIES CERTIFIED - FAST AND FIXED PRICE

Cyber Essentials for charities and non-profits from £320 + VAT. Fixed price, no hidden fees, guided by an IASME Approved Certification Body. Free cyber insurance included for eligible organisations.