Cyber Essentials for Charities: Cost, Discounts, Steps

Cyber Essentials is a UK government-backed certification confirming an organisation has five basic technical controls against common cyber attacks; Cyber Essentials Plus adds independent technical verification and costs more. Charity pricing is generally lower than commercial rates, and funded or discounted places periodically appear via NCSC-recognised partners. Most small charities with basic IT hygiene already in place can reach certification within about 30 days, and more funders now ask for it as a funding condition.

What Cyber Essentials is (and CE vs CE Plus)

Researching CharityIQ’s compliance module meant working through the NCSC’s charity guidance end to end, and Cyber Essentials for charities kept surfacing in sector advice and funder due-diligence questionnaires alike. Here’s the plain-English version. Cyber Essentials is a UK government-backed certification scheme, run through the National Cyber Security Centre (NCSC), that verifies an organisation has five basic technical controls in place to defend against the most common internet-based attacks. It is a self-assessment questionnaire, checked and certified by an accredited assessor, rather than a full security audit.

Cyber Essentials Plus covers the same five controls but adds independent technical verification, including vulnerability scanning and, in some cases, on-site or remote testing of your actual systems, rather than relying solely on your own answers. It costs more and takes longer than standard Cyber Essentials because of this extra verification step, and most charities are better served starting with standard Cyber Essentials before considering Plus, unless a specific funder or contract explicitly requires the higher tier. Our charity compliance handbook maps where certification sits in the wider picture.

Why funders and commissioners now ask for it

Funders, local authorities and commissioning bodies increasingly ask for Cyber Essentials certification, or evidence of equivalent controls, before awarding grants or contracts that involve handling personal data or public money. This reflects a wider push across the UK public and voluntary sector to reduce cyber risk in supply chains, not just within large organisations themselves. If such grants are on your radar, our grant readiness checker shows whether you’d clear the basics.

The NCSC’s guidance for the charity sector highlights that charities are a genuine target for cyber criminals, holding valuable personal data on donors and beneficiaries while often running with limited IT resource compared to their commercial counterparts. (If an incident lands, our data breach playbook sets out the first steps.) For charities applying to public sector contracts specifically, Cyber Essentials has been a baseline requirement on certain government contracts for some years, and that expectation is increasingly filtering down into grant conditions and due diligence questionnaires from major funders too.

What it costs (and charity discounts/funded places)

Cyber Essentials costs less for small organisations than many charities assume, with pricing generally banded by organisation size, and it typically costs considerably less than Cyber Essentials Plus given the added verification involved in the higher tier. I’m deliberately not printing a price table here: the bands are set and periodically revised by the NCSC’s certification bodies and IASME, the scheme’s delivery partner, so check the current figures on the day you budget.

Charity-specific discounts and fully funded places do appear periodically, often via regional or national infrastructure bodies, local authority digital inclusion programmes, or specific funder-backed schemes aimed at improving sector-wide cyber resilience. These offers change frequently and are usually time-limited or capped in number, so check what’s live before assuming full price. Checking directly with an NCSC-recognised certification body, and searching for any live charity technology or digital resilience grants through Grant Finder, is the fastest way to find out what is currently available to your charity.

The 5 controls, translated for small charities

The five Cyber Essentials controls are firewalls, secure configuration, user access control, malware protection and security update management — the baseline the NCSC scheme checks against common internet attacks. Every one of them is achievable for a small charity without specialist IT staff. Translated out of jargon, here is what each actually means day to day.

Control What it means in practice
Firewalls Your internet router and devices are configured to block unwanted incoming traffic, not left on factory default settings
Secure configuration Devices and software are set up to remove unnecessary accounts and features, and default passwords are changed
User access control Staff and volunteers only have access to the data and systems their role actually needs, with strong, unique passwords
Malware protection Anti-malware software is installed and kept active on all devices that access charity data
Security update management Software and operating systems are kept updated, with critical security patches applied promptly, generally within 14 days

Most of these are settings and habits rather than purchases: reviewing who has admin rights on your systems, turning on automatic updates, and using a password manager cost little or nothing beyond staff time. They’re habits I lean on at my own charity too — our data protection self-check checklist covers the same ground from the ICO’s angle.

Step-by-step to certification in 30 days

Most small charities with reasonably up-to-date IT can reach Cyber Essentials certification within about 30 days of starting, working through preparation, self-assessment and submission in that order. The timeline stretches mainly when device inventories are incomplete or when the charity relies heavily on personal devices that need bringing into scope. I’d budget the full 30 days and let the inventory eat week one.

  1. Week 1: scope and inventory. List every device and cloud service that touches charity data, including staff and volunteer personal devices used for charity work.
  2. Week 1-2: close the obvious gaps. Turn on automatic updates, review and remove unnecessary user accounts, ensure malware protection is active everywhere in scope.
  3. Week 2-3: complete the self-assessment questionnaire via an NCSC-recognised certification body, answering honestly rather than aspirationally; assessors follow up on inconsistencies.
  4. Week 3-4: submit and respond to any queries from your chosen certification body, who will clarify or request evidence for specific answers before issuing certification.

From experience: Cyber Essentials preparation at a small charity is mostly admin, not IT. The five controls are largely settings you change once; the genuinely hard part is the honest inventory of every device and cloud account that touches charity data, personal devices included. That inventory is the piece I actively maintain at my own charity, and an incomplete scope is precisely what trips charities up at assessment — give the first week to the list alone.

Charities running mostly cloud-based systems (Microsoft 365, Google Workspace) with managed updates typically move faster through this process than those with a mix of ageing on-premise equipment, since much of the “secure configuration” and “update management” work is already handled by the cloud provider.

If you fail first time

Failing a Cyber Essentials assessment on the first attempt is common and not a lasting mark against your organisation; certification bodies typically allow you to address specific gaps identified and resubmit within a defined window rather than starting the whole process again from scratch. Treat a first-attempt failure as a targeted gap list, not a full restart.

The most common reasons for failure are incomplete device inventories (personal devices or old equipment left out of scope), unpatched software beyond the update window, and unclear or missing password and access control policies. Once you have addressed the specific points the assessor flags, most charities pass on resubmission within a few weeks. Building ongoing cyber resilience beyond the certification itself, including staff awareness of phishing, is covered in our cyber security pillar and our dedicated post on phishing attacks targeting charities; for how cyber incidents intersect with your annual filing obligations, see our cyber security and the annual return post. CharityIQ’s own approach to helping charities stay secure is outlined at /security/.

What to do next

Start with a full device and cloud service inventory this week, then work through the five controls table above to identify your gaps before you pay for an assessment. Check for current charity discounts or funded places before budgeting at full commercial price.

Want compliance and certification tracking handled alongside the rest of your governance record? Join the compliance module waitlist →

Frequently asked questions

Pricing is banded by organisation size and is generally lower than typical commercial rates, with Cyber Essentials Plus costing more than standard Cyber Essentials due to the added independent verification. Check the current pricing and any live charity discounts or funded places before budgeting.

It is not a general legal requirement for all charities, but it is increasingly a condition attached to specific public sector contracts, and some grant funders now ask for it, or evidence of equivalent controls, as part of due diligence.

Most small charities with reasonably current IT systems can complete the process, from initial scoping through to certification, within around 30 days. Timelines extend where device inventories are incomplete or significant gaps need closing before submission.

Standard Cyber Essentials is a self-assessment questionnaire checked by an accredited assessor; Cyber Essentials Plus adds independent technical verification, including vulnerability scanning of your actual systems. Plus costs more and takes longer, and is generally only necessary where a specific funder or contract requires it.

No, Cyber Essentials verifies specific technical security controls; it does not replace your obligations under UK data protection law, which are covered separately by the Information Commissioner's Office guidance for charities.