Charity Commission Cyber Guidance: Do Trustees Need Penetration Testing?

Charity Commission Cyber Guidance: Do Trustees Need Penetration Testing?

By EJN Labs · 3 Aug 2026 · 8 min read

The Charity Commission’s cyber security guidance does not mandate penetration testing. It expects trustees to manage cyber risk proportionately, and a penetration test is the strongest evidence that technical controls actually work. Most UK charities test the systems holding donor and beneficiary data, at £1,100 to £1,400 per tester per day, with a typical engagement of 4 to 6 days costing £4,400 to £8,400.

What the charity cyber guidance says about penetration testing

The Charity Commission’s cyber security guidance does not require trustees to commission a penetration test. It is regulatory guidance rather than a prescriptive standard, and it contains no clause saying trustees must carry out a penetration test, so any provider telling you otherwise is overselling.

Trustees researching charity cyber guidance penetration testing usually want a straight answer to that single question before anything else.

What the guidance does say matters more. Trustees have a legal duty to protect their charity’s assets, and the Commission is explicit that those assets include data, funds and the systems the charity depends on. Cyber security is framed as a governance responsibility that sits with the board, not something delegated entirely to an IT volunteer or an outsourced provider. Trustees are expected to understand the charity’s cyber risks, put proportionate controls in place, and be able to show they have done so.

That last part is where penetration testing enters the picture. Risk-based technical testing and supplier assurance are how a board demonstrates that its controls are more than a policy document, and a test report is the most direct evidence a trustee can put in front of the Commission, an insurer, a funder or the ICO after an incident.

Why cyber risk is a trustee duty, not an IT problem

Charities are attractive targets: they hold sensitive data about donors, beneficiaries and service users, they move money, and they typically run leaner security operations than commercial firms of similar size. A charity that loses safeguarding or beneficiary records faces harm that goes well beyond a fine.

The Commission’s serious incident reporting regime makes this a board-level matter. A significant cyber attack or personal data breach is the kind of event trustees are expected to report as a serious incident, alongside any ICO notification under UK GDPR. The questions that follow are about governance: what risks had the board identified, what controls were in place, and how had the charity checked those controls worked. A recent penetration test report, with findings remediated and retested, answers the third question well.

There is also a funding dimension. Local authorities, commissioners, grant-makers and cyber insurers increasingly ask charities to evidence security controls, and independent testing answers those questionnaires from a position of strength.

What a charity should actually test

The guidance expects proportionality, so scope should follow risk. For most UK charities the estate breaks down into four areas.

Donation and fundraising platforms

Anything taking payments or storing donor records is the highest-value target. If the platform is third-party SaaS, the priority is supplier assurance: asking the vendor for their test reports and checking your configuration and admin access. If your charity runs its own donation forms, portal or CRM integrations, those need API and web application testing in their own right.

Case management and beneficiary data

Systems holding beneficiary or safeguarding records carry the greatest potential for harm. Testing here focuses on access control: can one caseworker see records they should not, can a compromised account escalate privileges, and are exports properly restricted.

Microsoft 365 and cloud services

Most charities live in Microsoft 365 or Google Workspace, often on donated licences with default settings. A cloud configuration review checks multi-factor authentication coverage, legacy authentication, mailbox rules, sharing settings and admin role sprawl. This is where charity engagements tend to find the most serious issues, because tenants grow organically as volunteers and staff come and go.

External infrastructure and remote access

External infrastructure testing maps what an internet-based attacker can reach: the website, VPN endpoints, remote desktop services, and anything a previous IT provider left exposed. For small charities this is often the sensible first test.

How an engagement runs for a charity

A charity engagement starts with a scoping call, usually with the COO, a trustee with the digital brief, or the outsourced IT provider. We ask what data the charity holds, where it lives and what the board is trying to evidence, then produce a fixed quote from that scoping.

Because charity budgets are constrained, we would rather test the two systems that hold beneficiary data properly than skim ten systems superficially. We also agree testing windows that avoid campaign peaks such as year-end appeals.

Testing is carried out by UK-based testers over one to two weeks for most charity scopes, with anything critical flagged the day we find it. The report has two layers: a plain-English summary for trustees and funders, and technical findings with remediation steps for whoever manages your IT. A retest of fixed findings closes the identify, control, verify loop the guidance describes. If you are preparing internally first, our penetration testing checklist covers what to have ready before a test starts.

What it costs and how scope drives the price

Penetration testing in the UK is priced by the day, typically £1,100 to £1,400 per tester per day at a CREST-accredited firm. Typical charity scopes look like this:

ScopeTypical effortTypical cost
External infrastructure test2 to 4 days£2,200 to £5,600
Cloud / Microsoft 365 configuration review3 to 5 days£3,300 to £7,000
Donation platform or case management web app4 to 6 days£4,400 to £8,400
Combined estate (external, cloud and one application)6 to 9 days£6,600 to £12,600

These are typical UK ranges rather than fixed prices; the exact figure depends on the size and complexity of what you ask us to test. A small charity with one website and an M365 tenant sits at the bottom of these ranges; a housing or care charity with multiple integrated applications sits higher. For a fuller breakdown of what moves the price, see our guide to penetration testing costs in the UK, or get an exact figure through our quote form.

How EJN Labs approaches testing for charities

EJN Labs is a UK-based, CREST-accredited penetration testing firm, and we hold Cyber Essentials Plus and ISO 27001 ourselves. When we scope a charity estate we start from the data, not the technology: which systems hold donor, beneficiary or safeguarding records, and how a realistic attacker would reach them. That usually means prioritising the M365 tenant and the primary application, because that is where a constrained budget buys the most risk reduction.

We write reports knowing trustees, funders and insurers will read them, and we are careful with data handling during testing: sensitive records are never exfiltrated when a screenshot of access is sufficient. The same discipline applies when we test law firms and other organisations handling special category data.

Frequently Asked Questions

Does the Charity Commission require penetration testing?

No. The Charity Commission’s cyber security guidance does not mandate penetration testing. It expects trustees to manage cyber risk proportionately as part of their duty to protect charity assets, including data and funds, so a test remains a risk-based decision rather than a regulatory requirement.

A penetration test is still the strongest single piece of evidence that your technical controls work, which is why many boards commission one.

What evidence does the guidance expect trustees to hold?

Trustees are expected to show cyber risk sits on the risk register, proportionate controls are in place, staff and volunteers receive awareness training, and suppliers handling charity data have been assessed. The guidance also expects serious cyber incidents to be reported to the Commission.

Independent testing supports several of these expectations at once by verifying controls and providing a board-readable report.

How much does penetration testing cost for a charity?

Expect £2,200 to £5,600 for an external infrastructure test, £4,400 to £8,400 for a donation platform or case management application, and £6,600 to £12,600 for a combined estate. UK penetration testing is priced by the day, typically £1,100 to £1,400 per tester per day.

Those ranges reflect 2 to 4 days for external infrastructure, 4 to 6 days for an application, and 6 to 9 days for a combined estate at a CREST-accredited firm. Exact pricing depends on scope, which is confirmed at a short scoping call.

Our IT is fully outsourced. Do we still need our own test?

Outsourcing IT does not outsource the trustee duty. The Commission’s guidance treats supplier assurance as part of governance, so the board should verify what its providers deliver rather than assume it. An independent test of your externally managed estate frequently finds gaps between what a contract promises and what is actually configured, and it gives trustees evidence that does not depend on the supplier marking its own homework.

Is Cyber Essentials enough for a small charity instead of a penetration test?

For a very small charity, yes, Cyber Essentials is a strong baseline, a sensible first step, and the guidance points charities towards it. It certifies that five core controls are in place, but it does not simulate an attacker against your specific systems.

Charities holding sensitive beneficiary data, taking online payments, or bidding for public contracts generally need both, certification for the baseline and testing for assurance.

Give your board evidence, not assumptions

If your trustees want to know how exposed the charity really is, a scoped penetration test answers with evidence you can put in front of the board, funders and insurers. Tell us what systems and data you hold, and we will return a fixed quote. Get a CREST penetration testing quote.

Leave a Reply

Your email address will not be published. Required fields are marked *