Cyber Essentials for charities & non-profits
Charities handle donor payment details and often vulnerable beneficiaries' data, usually on tight budgets and with volunteer-run IT — a combination attackers actively exploit.
Why charities are being asked for Cyber Essentials
Grant funders, the National Lottery and many corporate partners increasingly ask for Cyber Essentials as a condition of funding or partnership.
What Cyber Essentials covers — the five controls
The same five controls apply to every organisation. Here's what each one means; tap through for the detail.
- Firewalls & internet gateways →A boundary between your devices and the internet, so only the services you actually need are reachable from outside.
- Secure configuration →Devices and software set up to reduce the ways in — default passwords changed, unused features and accounts removed.
- Security update management →Keeping software supported and patched, so known vulnerabilities are closed before attackers use them.
- User access control →Making sure accounts are only used by the right people, with MFA, unique logins and separate admin accounts.
- Malware protection →Protecting devices from malicious software, via anti-malware and/or only allowing approved applications to run.
See if your charitie business is ready
Answer the Cyber Essentials questions in plain English and get a per-control readiness verdict — free, no login needed, and we don't store your answers.
Start the free readiness check →More: Cyber Essentials explained · free readiness check
This is a free readiness / gap report to help you prepare — it is not a certification, and we are not an IASME Certification Body. To certify, you apply through an accredited Certification Body.