Cyber Essentials for Charities: A Practical Guide for UK Nonprofit Organisations
Some grant funders and institutional donors require Cyber Essentials; the Charity Commission does not impose a universal certificate requirement. This guide covers what the certification means for a UK charity, how the controls map to typical nonprofit infrastructure, and how to certify on a limited budget.

Section 01
Cyber Essentials for Charities: A Practical Guide for UK Nonprofit Organisations
Charities are increasingly being asked for Cyber Essentials by grant funders, local authority commissioners, and institutional donors. The trigger is usually a grant application that lists CE as a prerequisite or a commissioner's due diligence pack that asks whether the organisation holds current certification. What used to be a nice-to-have is becoming a funding gate.
This guide covers what certification actually entails for a UK charity, how the technical controls map to the kind of IT most nonprofits run, and the practical routes through certification for organisations on a tight budget.
Section 02
Why charities are being asked for Cyber Essentials
Three overlapping pressures have pushed Cyber Essentials into charity due diligence:
The Charity Commission’s cybercrime guidance identifies Cyber Essentials as an option for charities. It does not establish a universal certification mandate; check the actual grant, commission and insurance conditions.
Grant funders increasingly require it. The National Lottery Community Fund, Comic Relief, and several local authority commissioning frameworks now list Cyber Essentials as a requirement for grants above certain thresholds. Others request evidence of "cybersecurity assurance" and accept CE as meeting that bar.
Institutional donors and corporate partners. Larger donors conducting due diligence on their grantees routinely ask for CE as part of supplier assurance. It is not universal but it is common enough that most charities applying for five- or six-figure grants should expect the question.
Insurance. Cyber insurance premiums for charities handling beneficiary data are increasingly conditional on CE. Some insurers will not quote without it.
Section 03
What Cyber Essentials actually asks of a charity
The five control areas apply to charities the same way they apply to any other organisation. What differs is the typical infrastructure. Most UK charities run a setup that looks like:
- Microsoft 365 or Google Workspace for email and documents
- A small office (or no office) with laptops provided to paid staff
- Volunteers using their own devices
- A CRM or database (Salesforce, CiviCRM, Beacon, Donorfy, Raiser's Edge)
- Fundraising platforms (JustGiving, Enthuse, Donorbox)
- A website, usually WordPress or a hosted platform
- Finance systems (Xero, QuickBooks, Sage)
That setup maps cleanly onto the five CE control areas, but with some charity-specific wrinkles.
Section 04
The five controls, charity-specific
The NCSC v3.3 requirements define the scheme controls. MDM can help demonstrate consistent controls, but Cyber Essentials does not mandate a particular product or an MDM subscription. Verify the required configuration, firewall, updates, access and malware controls on every in-scope device; documented manual management can also meet the requirements. Encryption, backup, logging and sector-specific information handling may be valuable or separately required; distinguish those from the five scheme controls.
Firewalls and internet gateways. For a small charity with no office, the firewall requirement is met by the software firewall on each laptop. You do not need to buy hardware firewalls. For a charity with a small office, the office router or firewall needs to meet the usual boundary requirements (admin access not exposed, default passwords changed, firmware current). Most charities use whatever router the ISP provided; check it is not running firmware from three years ago.
Secure configuration. This is where charities most often have quiet gaps. Volunteers have been given email accounts but those accounts still exist two years after the volunteer stopped helping. Former trustees still have access to the CRM. A donor database has shared login credentials because "everyone needs access". The baseline ask is that accounts are provisioned and deprovisioned properly, default credentials are changed, and users operate without local admin rights on their devices.
Apply vendor-approved vulnerability fixes within 14 days of release when the vendor rates the vulnerability critical or high, its CVSS v3 score is 7 or higher, or the vendor provides no severity details. This includes supported in-scope operating systems, applications, extensions and firmware; it is not a deadline for every routine update.
User access control. Under v3.3, every user account on every cloud service needs multi-factor authentication. For charities this often means the CRM, the fundraising platform, the finance system, and the email platform. This is the single biggest area charities need to tighten - MFA on the main email platform is usually done but MFA on the sector-specific tools is often not.
Malware protection. Use a supported scheme-permitted approach on relevant in-scope devices. For Windows and macOS, verify the required anti-malware configuration or application allow-listing; do not assume default Mac protections alone prove compliance. Mobile platforms have their applicable approved-app-store and application-signing route.
Section 05
How volunteers fit into the scope
Volunteer access needs explicit treatment. Under v3.3, volunteers’ personal devices used for organisational work are included as BYOD, alongside organisation-issued devices. Do not apply the excluded third-party-contractor endpoint rule to volunteers.
Volunteers using organisation-issued devices. Treat them as any other user. Managed laptop, MFA on their cloud accounts, standard user permissions, software firewall active.
Volunteers using personal devices for work email. Include their work-use BYOD under the v3.3 volunteer rule and verify applicable controls. Agree the assessment boundary with the Certification Body. Include organisational end-user devices, employee BYOD used for work, and cloud services hosting organisational data or services, including production hosting. Under v3.3, third-party-owned end-user devices are excluded, but their organisational accounts remain in scope; organisation-owned devices loaned to third parties are included. A virtual desktop, browser-only access or Conditional Access does not itself exempt employee BYOD. Any separately managed subset needs a justified technical boundary accepted by the assessor. The v3.3 ownership table specifically includes volunteers’, trustees’ and university research assistants’ BYOD used for organisational work; do not classify these roles as excluded third-party contractors. Students’ own devices are excluded, while organisation-owned student devices are included. Organisational accounts remain in scope.
Volunteers with occasional access to the CRM or donor database. MFA enforced on their accounts. Time-limited access where possible. Prompt account disablement when the volunteer period ends.
Restricting volunteer access can reduce exposure, but a restricted view or portal does not automatically remove a device or cloud service from scope. Record the actual ownership, account and control arrangements.
Section 06
What about trustees?
Trustees reviewing board papers access organisational data. Under v3.3, trustees’ work-use BYOD is included, as are organisation-issued devices. Keep organisational accounts and cloud services in scope; a trustee is not treated as an excluded third-party contractor.
The realistic positions:
Option 1: Provide trustees with organisation-issued devices. Budget for the actual device and management costs before choosing this route.
Option 2: Control trustee access. A managed portal with MFA can improve sharing and account control, but does not itself exempt an endpoint. Apply the ownership and relationship rules to each device.
Option 3: An agreed subset. Any subset must have a justified separately managed technical boundary accepted by the assessor. A trustee portal, MFA or preventing downloads does not itself exclude employee devices or organisational cloud services.
A board portal can help control access and sharing. It does not replace the scope assessment or establish that endpoint controls are unnecessary.
Section 07
Cost considerations for charities
Cyber Essentials costs the same for a charity as it does for any other organisation - from £299.99 + VAT for the micro tier (1-9 employees, which most small charities fall into). Some certification bodies offer discounted rates for registered charities; it is worth asking.
The more important cost question is what changes you need to make to pass. The typical remediation work for a small charity before their first CE submission includes:
- Licensing MFA on the main cloud services (usually covered by Microsoft 365 Business Basic or Google Workspace Business Starter)
- A password manager for staff (Bitwarden, 1Password, NordPass - several have charity discounts)
- Optional MDM where it helps manage the device estate; check the actual Intune entitlement because not every Microsoft 365 Business licence includes it
- Any changes needed to meet the supported malware-protection requirements; a Windows Home edition alone does not require an additional paid antivirus product
Build the remediation budget from the actual gaps: unsupported devices, missing controls, implementation time and any ongoing licences. Staff count alone does not establish a reliable cost range; obtain quotes before committing the budget.
Section 08
Tools with charity discounts worth knowing about
Several vendors offer meaningful charity discounts through Charity Digital Exchange, TechSoup, or direct programmes:
- Microsoft nonprofit grants or discounts, subject to current eligibility and licence terms; Business Premium includes Intune and Defender but should not be budgeted as an evergreen free grant
- Google Workspace for Nonprofits (free tier available, upgrades discounted)
- Bitwarden nonprofit pricing, subject to current eligibility and published offer terms
- 1Password (discounted for nonprofits via their Community programme)
- Bitdefender GravityZone (reduced-price charity licensing)
Check the current nonprofit offer and actual licence features before budgeting. MFA, device management and malware tooling may already be available, but no particular licence guarantees compliance.
Section 09
The common charity scoping mistake
Paid staff, volunteers and trustees each need explicit scope decisions. Agree the assessment boundary with the Certification Body. Include organisational end-user devices, employee BYOD used for work, and cloud services hosting organisational data or services, including production hosting. Under v3.3, third-party-owned end-user devices are excluded, but their organisational accounts remain in scope; organisation-owned devices loaned to third parties are included. A virtual desktop, browser-only access or Conditional Access does not itself exempt employee BYOD. Any separately managed subset needs a justified technical boundary accepted by the assessor. The v3.3 ownership table specifically includes volunteers’, trustees’ and university research assistants’ BYOD used for organisational work; do not classify these roles as excluded third-party contractors. Students’ own devices are excluded, while organisation-owned student devices are included. Organisational accounts remain in scope. Record each group and its actual ownership, access and control arrangements rather than assuming a portal creates an exclusion.
Writing that distinction clearly in the questionnaire makes the submission easier to assess and less likely to trigger follow-up questions.
Section 10
Practical path to certification for a small charity
For a charity in the Micro scheme size band, the fastest prepared route described here is conditional on complete, compliant submission and the assessment terms; it is not a comparison of every provider or a preparation-time guarantee:
1. Inventory the cloud platforms actually used. Verify the applicable controls on each; using more than one provider is not itself a scheme failure.
2. Check available controls and licensing. Buy additional tools only where existing supported controls cannot meet the requirements. MDM can help demonstrate consistent controls, but Cyber Essentials does not mandate a particular product or an MDM subscription. Verify the required configuration, firewall, updates, access and malware controls on every in-scope device; documented manual management can also meet the requirements.
3. Verify device controls. MDM is one practical management option; demonstrate compliance on every in-scope laptop.
4. Enforce MFA for every user accessing in-scope cloud services; implement it where available elsewhere. Not just the main email; also the CRM, finance system, and fundraising platform.
5. Document the scope. Paid staff, volunteers, trustees, with how each is handled.
6. Run Fig Group's free readiness checker. Identify remaining gaps before paying for the assessment.
7. Submit. Basic starts at £299.99 + VAT for 1–9 staff. Fig Group guarantees Basic assessment within six working hours for a complete, compliant submission received before midday on a UK Business Day, subject to the certification terms. Preparation, clarification and remediation are separate; certificate issuance requires a successful assessment.
Section 11
Bottom line
Cyber Essentials is accessible for charities. The controls are reasonable, the costs are manageable (often zero beyond the assessment fee for charities already on a modern cloud platform), and the certification opens access to funding that is increasingly conditional on evidence of basic cybersecurity practice. The charities that struggle are the ones that leave everything until a grant application asks for it. The charities that get it right treat it as a standing operational posture rather than a one-off compliance task.
About the author

Jay Hopkins
Managing Director, Fig Group
Jay Hopkins is the Managing Director of Fig Group and an IASME-licensed Cyber Essentials assessor. He was previously Head of Technology for a global regulated firm. He works with UK organisations across regulated sectors on baseline compliance, supply-chain assurance, and AI-augmented security tooling.
Next step
Ready to get certified?
Get Cyber Essentials Basic certified with Fig Group from £299.99 + VAT. Our guarantee is within six working hours of receiving a complete, compliant submission before midday UK time on a UK Business Day, subject to our certification terms.
Related solutions
Continue exploring Fig Group
Related guides
Continue reading
Industry
Cyber Essentials for Recruitment Agencies: A Practical Guide
Recruitment agencies handle large volumes of personal data - CVs, right-to-work documents, payroll data - and are increasingly required to hold Cyber Essentials by PSLs, MSP agreements, and public-sector frameworks. This guide covers how the controls apply to typical agency infrastructure.
Read articleIndustry
Cyber Essentials for Financial Services and Fintech
FCA expectations, client due diligence, and supply-chain audit requirements can make Cyber Essentials a contractual requirement for particular financial services and fintech firms; it is not a universal FCA certification mandate. This guide covers how CE fits alongside the FCA Handbook, how the controls apply to fintech cloud stacks, and the specific issues that come up during assessment.
Read articleIndustry
Cyber Essentials for London Criminal Barristers’ Chambers: What the BSB Does Not Require, But Everyone Is Asking For
The Bar Standards Board does not formally require Cyber Essentials. Solicitor firms, CPS counterparts, institutional lay clients, and insurers are increasingly asking for it. This guide covers how CE applies to a criminal barristers’ chambers in London and why the certification has become a practical necessity even without a formal mandate.
Read article

