Selling Software to Charities? The Charity Cyber Guidance Questions to Expect

Selling Software to Charities? The Charity Cyber Guidance Questions to Expect

By EJN Labs · 25 Aug 2026 · 8 min read

Charity cyber guidance security assurance questions reach you because the Charity Commission expects trustees to manage cyber risk, including supplier software. The guidance does not mandate penetration testing, so charities ask suppliers for evidence instead: independent test reports, remediation records and certifications. A CREST-accredited test at £1,100 to £1,400 per day, typically £4,400 to £8,400 for a web application and API, answers most of those questions.

Why the Charity Commission cyber guidance reaches software suppliers

The guidance reaches suppliers because trustees discharge their duty through you. The Charity Commission frames cyber risk as part of trustees’ duty to protect their charity’s assets, data and reputation, and since trustees cannot inspect your codebase, they ask for evidence during procurement instead.

If you sell case management, fundraising, accountancy or housing software into the UK charity sector, you will increasingly meet these security assurance questions during procurement. The driver is not a law aimed at you.

Charities hold data that attackers value: donor payment details, Gift Aid records, and often sensitive beneficiary information covering health, immigration status or safeguarding history. Most of that data lives inside supplier platforms rather than on charity-owned infrastructure. When a trustee board reviews cyber risk, your product is usually the largest single item on the register, so the due diligence lands on your desk.

What the guidance actually says, and what it does not

The Charity Commission’s cyber security guidance is regulatory guidance that supports trustee duties. It is not legislation, and it does not name penetration testing as a mandatory control for charities, let alone for their suppliers. What it says is about trustee responsibility, not about imposing controls on vendors.

Honesty matters here, because vendors are routinely told the guidance requires things it does not.

What the guidance does expect is a risk-based approach: trustees should understand where their charity’s data sits, secure the systems that process it, and take reasonable steps to assure themselves about third parties. Supplier assurance is the practical consequence. A charity cannot test your platform itself, so it asks you to demonstrate that someone independent has, and that you fixed what they found.

That makes this a customer-ask framework rather than a compliance mandate. The evidence bar is set by the most demanding charity in your pipeline, not by the regulator. Larger charities, housing providers and federated bodies with professional IT functions tend to set that bar at an annual independent penetration test from a CREST-accredited firm, plus Cyber Essentials or ISO 27001 on your own organisation.

The security assurance questions charity buyers will ask

Across charity-sector procurement exercises, the same questions recur. If you can answer these eight before the questionnaire arrives, you are ahead of most of the market.

  1. When was your platform last penetration tested by an independent firm, and can we see the report or a summary letter?
  2. Was the testing firm CREST accredited, and were the testers UK based?
  3. What was in scope: the web application, APIs, mobile apps, and the cloud environment that hosts our data?
  4. Were any high or critical findings identified, and what is your evidence of remediation and retest?
  5. How do you segregate one charity’s data from another’s, and has that segregation been tested?
  6. Do you hold Cyber Essentials, Cyber Essentials Plus or ISO 27001?
  7. How do you test changes: is security testing annual only, or tied to major releases?
  8. Who do you notify, and how quickly, if a test or an incident reveals a risk to our data?

Question five is the one that catches vendors out. Multi-tenant platforms serving many charities need testing that specifically attempts cross-tenant access, because a single broken object reference can expose every client’s beneficiary records at once. Our penetration testing checklist covers how to prepare so the engagement answers these questions first time.

What to test across a typical charity software estate

Web application and APIs

The core platform is where donor and beneficiary data lives, so it anchors the scope. Testing covers authentication, session handling, access control between user roles (a volunteer should never see safeguarding notes), and the APIs behind the interface. API penetration testing matters even for vendors without a public API, because the front end almost always talks to one.

Cloud environment

Most charity software is SaaS on AWS or Azure. A cloud penetration test reviews identity and access configuration, storage permissions, network segmentation and backup exposure, the areas where misconfiguration rather than code flaws causes most real-world charity data breaches.

Mobile applications

Fundraising and volunteer apps carry payment journeys and personal data onto unmanaged devices. Mobile application testing examines local data storage, certificate validation and the mobile API surface.

External infrastructure

Anything you expose to the internet beyond the product itself, such as admin panels, VPN endpoints and mail infrastructure, belongs in an external infrastructure test, because charity buyers increasingly ask about it.

How a supplier-side engagement runs

A supplier-side engagement starts from the questions your charity buyers will ask, not from a generic methodology. A scoping call maps your architecture, covering tenants, user roles, APIs, hosting and integrations with payment and Gift Aid services, and scope is agreed in days so you know the cost up front.

That is the approach we take at EJN Labs when scoping charity-sector platforms.

Testing runs against a staging environment or, with agreed safeguards, production. For multi-tenant platforms we set up two test tenants and spend deliberate effort attempting to cross between them. All testing is performed by UK-based testers working to CREST methodology.

You receive a full technical report for your engineers and a summary letter written for sharing: it states scope, methodology, accreditation and outcome without exposing exploit detail. That letter is the artefact procurement teams actually want. After remediation, a retest confirms fixes and updates the letter, giving you a clean document for the next twelve months of bids.

What it costs and how scope drives the price

Penetration testing is priced in tester days at a typical UK day rate of £1,100 to £1,400. Scope drives days: the number of applications, API endpoints, user roles and cloud accounts. Typical ranges for charity software vendors:

ScopeTypical effortTypical cost
External infrastructure2 to 3 days£2,200 to £4,200
Web application and API4 to 6 days£4,400 to £8,400
Mobile app plus supporting API5 to 7 days£5,500 to £9,800
Full SaaS estate (app, API, cloud, external)8 to 12 days£8,800 to £16,800

These are typical UK ranges rather than a quote; an exact price follows a short scoping call. For a fuller breakdown of what moves the number, see our guide to penetration testing costs in the UK.

How EJN Labs approaches assurance for charity software vendors

EJN Labs is a CREST-accredited UK penetration testing firm, and we hold Cyber Essentials Plus and ISO 27001 ourselves, so we sit on the same side of supplier questionnaires that you do. Our CREST penetration testing engagements for software vendors are scoped around buyer evidence: tenant segregation, role-based access to sensitive records, payment journeys and cloud configuration.

We write findings in terms a trustee board can act on, not just CVSS scores, and the shareable summary letter is included as standard. If you are comparing firms, our guide to choosing the best UK penetration testing provider sets out the questions worth asking.

Frequently Asked Questions

Does the Charity Commission cyber guidance require suppliers to have a penetration test?

No. The guidance is regulatory guidance supporting trustee duties, not legislation, and it does not mandate penetration testing for charities or their suppliers. It expects trustees to take a risk-based approach and assure themselves about third parties, which is where supplier testing evidence enters the picture.

In practice charities meet that assurance expectation by asking suppliers for independent testing evidence. That is why the question appears in procurement even though no rule requires it.

What evidence do charity buyers actually accept?

A summary letter from a CREST-accredited firm is what most charity buyers accept, stating scope, methodology, date and outcome, plus confirmation that high and critical findings were remediated and retested. Some larger charities and housing bodies ask instead for the full report under NDA.

Cyber Essentials Plus or ISO 27001 held by your own organisation strengthens the answer, but it rarely replaces the request for application-level testing evidence.

What does a penetration test cost for a charity software vendor?

UK day rates typically run £1,100 to £1,400. A web application and API test is usually 4 to 6 days, so £4,400 to £8,400. External infrastructure is 2 to 3 days at £2,200 to £4,200, and a full SaaS estate covering app, API, cloud and external surface is 8 to 12 days at £8,800 to £16,800. Exact pricing follows scoping.

How often should we test our platform?

Test annually as a baseline, then after major releases, significant architecture changes or new integrations with payment or Gift Aid services. Most charity questionnaires ask for a test within the last twelve months, so an annual cycle keeps the evidence they expect on hand at every review.

Vendors on frequent release cycles often pair an annual full test with smaller targeted tests on changed components, which keeps evidence current without retesting everything.

Is multi-tenant segregation testing really necessary?

Yes, whenever more than one charity shares your platform. Cross-tenant access flaws are among the most damaging findings in SaaS testing, because a single defect exposes every client’s data, including safeguarding and beneficiary records. Informed charity buyers now ask for segregation testing explicitly.

Testing segregation properly requires two tenants and deliberate manual effort, so confirm it is written into the scope rather than assumed.

Get assurance evidence your charity clients will accept

If charity cyber guidance questions are slowing your sales cycle, a scoped CREST-accredited test with a shareable summary letter resolves them for the next twelve months. Tell us about your platform and we will return a fixed scope and price: get a CREST pentesting quote.

Leave a Reply

Your email address will not be published. Required fields are marked *