Cyber security for UK charities 2026: what the regulator actually expects

The Charity Commission's annual return does not ask about cyber security — no version of it ever has. What UK charity regulators actually expect is real, just different: risk management under CC26, UK GDPR's Article 32 security duty if you hold personal data, the ordinary serious incident reporting duty if a cyber incident is serious enough to count, and NCSC guidance plus Cyber Essentials as good practice, not a mandate. No UK charity regulator requires a cyber security policy.

Corrected 5 September 2026. An earlier version of this article said the 2026 Charity Commission annual return added explicit cyber security questions, and explained “why the Commission added” them. It did not add any — the annual return’s question guide contains no cyber security question, in any section. We read it end to end and got this wrong, the same mistake as an earlier version of our annual return walkthrough. This article now covers what UK charity regulators actually expect on cyber security, which is real, just not on the return.

The Charity Commission’s annual return does not ask about cyber security. It never has. The question guide that governs both the 2025 and 2026 returns — read in full — has eight sections, and none of them asks whether your charity has had a cyber incident, whether you have a cyber security policy, or whether you have considered cyber risk in a risk register. That claim has now been independently checked and disproved three separate times across our research. If your charity is preparing its annual return, cyber security is not one of the boxes you need to find.

That doesn’t mean regulators have nothing to say about it. They do — it just isn’t in the return.


What UK charity regulators actually expect

Risk management. The Charity Commission’s guidance on charity risk (CC26) sets an expectation that trustees identify and manage the risks their charity faces, cyber included, as part of routine financial and operational oversight. For most charities this is a matter of good governance, not a standalone legal filing: a written risk statement in the trustees’ annual report is a legal requirement only for charities that must have their accounts audited (Charities (Accounts and Reports) Regulations 2008, reg 40(2)(b)(ii)(ee)) — everyone else is “encouraged”, not required, to publish one.

UK GDPR’s security duty. If your charity holds personal data — donor records, beneficiary details, staff files — UK GDPR Article 32(1) requires you to “implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk”. This is a real, general legal duty. It is outcome-based: Article 32 does not mandate Cyber Essentials, a named password policy, or any specific control. Cyber Essentials and NCSC guidance are evidence you could point to in showing you have met the duty — they are not themselves the requirement. The Charity Commission’s own cyber guidance (November 2024) grounds this in the ordinary trustee duty to manage resources responsibly: being aware of the risk, taking reasonable steps, and responding properly if something happens.

Serious incident reporting — if something happens. There is no standing cyber-specific report to file. But if your charity experiences a cyber incident serious enough to count as a serious incident — a significant data breach, a loss of funds, an incident that damages your ability to deliver your charity’s purposes — the ordinary serious incident reporting duty applies, the same as for any other serious incident. The Commission’s own words: repeated low-value fraud, theft or cyber-crime is something “the Commission would expect you to report”, even in aggregate, and a decision not to report a borderline case should still be minuted.

NCSC guidance and Cyber Essentials — good practice, not a mandate. The National Cyber Security Centre publishes free guidance for small organisations, and Cyber Essentials, the government-backed self-assessment certification, costs £320 for the smallest organisations. Both are useful evidence that you have taken reasonable steps under UK GDPR Article 32 — neither is legally required for a charity in general. (Cyber Essentials or an equivalent can become a contractual requirement if you deliver a government or NHS contract that handles personal data or sits on official-classification IT systems — that obligation comes from procurement rules, not charity regulation.)

Say it plainly: no UK charity regulator requires a cyber security policy. Not the Charity Commission, not as a condition of registration, not as an annual return question. The Commission’s own cyber guidance frames a written policy as something you can do, not something you must: “You can set this out in a policy or cyber attack action plan.” If a funder or a government contract requires Cyber Essentials or a written policy, that is a condition of the funding or the contract — not a regulatory requirement that applies to every charity.


What “cyber” means for a small charity

Five things matter most:

  1. Email security — most cyber incidents start with phishing.
  2. Account access — strong passwords, MFA, no shared accounts.
  3. Data backup — regular, tested.
  4. Software patching.
  5. Beneficiary and donor data protection — UK GDPR overlaps (see our GDPR checklist).

If your charity has these basics, you’re in the top 30% of small UK charities for cyber posture.

NCSC’s free guidance

The NCSC publishes a Small Charity Guide for charities up to 250 employees. Covers: backups, malware protection, smartphones, passwords, phishing.

Plus the Cyber Action Toolkit — bite-sized actions, ~5 minutes each.

For charities under 250 employees: free 30-minute consultation with a Cyber Advisor. Genuinely free, genuinely useful. Start here, not with paid consultancy.

From CharityIQ. CharityIQ tracks your charity’s cyber posture against NCSC’s small charity standards — incident log, policy version, training records. See compliance →

Cyber Essentials — what it is and whether you need it

Cyber Essentials is UK government-backed certification covering five technical controls: firewalls, secure configuration, access control, malware protection, patch management.

Two levels. Cyber Essentials is a self-assessment; the fee is set by organisation size, from £320 for the smallest organisations to £600 for the largest, plus VAT, per certification. Cyber Essentials Plus adds a hands-on technical audit and is not fixed-price: it is quoted according to the size and complexity of your network, with the self-assessment as a prerequisite.

Get it if: a funder asks (many UK funders now require it), you process sensitive data (safeguarding, mental health, asylum), you apply to public sector contracts.

Otherwise: NCSC Small Charity Guide alone may be enough.

NCSC has run funded Cyber Essentials programmes covering certification cost for specific charity sectors. Check NCSC’s funded programmes.


5-step cyber plan for the next quarter

90 days, under £200 spent (often free).

Week 1-2 — Audit and policy. Inventory your IT (devices, accounts, software, cloud). Adopt or update a cyber policy (1-2 pages) if you decide you want one — see above, it isn’t required, but it’s a reasonable way to show you’ve thought about Article 32. Add cyber to your risk register.

Week 3-4 — Email and accounts. Enable MFA on email, banking, payroll, CRM. Audit dormant accounts. 30-minute staff phishing briefing.

Week 5-6 — Data and backups. Test restore from backup to separate location. Patch operating systems, browsers, plugins. Document data flows (feeds UK GDPR ROPA).

Week 7-10 — Specific actions. Decide on Cyber Essentials. Run phishing simulation (educational, not punitive). Update sub-processor list. Set up incident response procedure.

Week 11-13 — Review. 15-minute trustee briefing. Tabletop exercise: “Suppose someone pays a fake invoice. What happens?” Document everything.


Common mistakes

1. Shared accounts — “easier” but breaks audit trail.

2. No MFA on banking — highest-risk gap; enable today.

3. Ageing software — Windows 7 still in use, plugins out of date.

4. No backup test — backups that haven’t been tested aren’t backups.

5. Phishing not trained — “common sense” isn’t enough.

6. Trustee oversight at zero.


What to do this week

  1. Read the NCSC Small Charity Guide.
  2. Enable MFA on email and banking. Lowest-effort, highest-impact change.
  3. Schedule a 15-minute trustee briefing for the next board meeting.

Cyber + GDPR + governance, in one place.
Start a free 14-day CharityIQ trial.
Start free trial →

Frequently asked questions

No. The question guide covering the 2025 and 2026 returns has no cyber security question anywhere in it — not as a standalone question, not folded into another section. An earlier version of this article said otherwise and was wrong.

Yes — soft targets with valuable data.

£300-£1,500/yr covers most needs for a small UK charity, mainly Cyber Essentials certification if you choose to get it.

Anyone with system access — including trustees and volunteers.

Contain it (disconnect, change passwords), report it (insurance, IT provider), and decide whether it meets the threshold for a Charity Commission serious incident report or an ICO breach notification. Don't hide it.

Cyber security is the technical/procedural protection; UK GDPR is the legal duty covering what you do with personal data, including Article 32's security requirement. They overlap heavily but aren't the same thing.

Yes — NCSC's free guidance and toolkit are aimed specifically at small organisations, charities included.