Cyber Essentials for UK Charities and CICs: A Practical Guide
Published 15 July 2026
Why funders are asking for it
- National Lottery Community Fund grants over £100k commonly reference CE
- Local authority grant agreements increasingly mention "basic cyber assurance"
- NHS and ICB partnerships need at minimum a DSPT and often CE alongside
- Corporate donors with their own CE want their funded partners aligned
The honest cost picture
For small charities, CE is typically £320 + VAT (micro band, <10 staff) or £440 + VAT (small, 10–49 staff). Full pricing in our 2026 cost guide. The free £25,000 cyber liability insurance is a meaningful benefit for charities holding donor or beneficiary data.
Volunteer devices: the sector's biggest scope question
If volunteers use their own laptops to access charity email, fundraising platforms or case management systems, those cloud accounts are in scope. The device itself does not need full MDM, but the account must have MFA, password policy and a documented offboarding routine. See our BYOD guide.
Shared inboxes and generic accounts
Shared accounts like info@, donations@ or safeguarding@must use individual sign-in with MFA, not a shared password. In Microsoft 365 use shared mailboxes (no licence required) with delegated access. In Google Workspace use delegation or groups. A shared password on a shared inbox auto-fails.
Trustee sign-off
The CE declaration is signed by a board-level person. For charities that is usually a trustee or the CEO. Build a one-page trustee briefing covering: what CE certifies, what it does not, the renewal date, who maintains the controls, and how the insurance benefit works.
The lowest-friction route for a small charity
- Adopt Microsoft 365 Business Basic or Google Workspace Business Starter
- Enforce Security Defaults / 2-Step Verification on every account
- Block legacy authentication
- Enable BitLocker / FileVault on every charity-owned laptop
- Document the volunteer device policy in one page
- Keep a simple cloud services list (SharePoint, JustGiving, Salesforce NPSP, etc.)
Renewal cadence and funder reporting
CE is annual. Build the renewal date into your funder reporting calendar so you can produce a current certificate on request. A lapsed certificate during a funding decision is a frustrating own goal.
