By EJN Labs · 22 Sep 2026 · 7 min read
Trustees are personally accountable for how their charity protects supporters’ and beneficiaries’ data, which is why DPA 2018 pen test questions have become a standard part of onboarding a tech supplier. UK GDPR Article 32(1)(d) requires a process for regularly testing the effectiveness of security measures, though it does not name penetration testing as the method. In our experience, a CREST-accredited test report typically satisfies that question.
Why do charity trustees ask suppliers about penetration testing?
Trustees ask because they are personally responsible for their charity’s donor and beneficiary data, and a supplier’s software sits inside that duty. In our experience, an independent test report is the fastest way to close the question, since it shows external verification, not a self-declared checklist.
Charities handle sensitive categories of data: safeguarding records, financial supporter details, and sometimes health or vulnerability information tied to service delivery. A breach at a software supplier rarely stays contained to that supplier’s reputation, because the charity itself carries the data protection risk and the reputational fallout with its own donors and beneficiaries. Charity Commission guidance reminds trustees that managing that risk responsibly remains their duty even when day-to-day security work is delegated to an IT team or a supplier. Trustees who sit on audit or risk committees increasingly write penetration testing questions into new supplier contracts and renewal reviews.
What does the Data Protection Act 2018 actually require of your charity contract?
The Data Protection Act 2018 brings UK GDPR Article 32(1)(d) into UK law, and that clause requires a process for regularly testing, assessing and evaluating the effectiveness of technical and organisational security measures. It does not name penetration testing, an accreditation, or a testing frequency as the method.
In supplier questionnaires, “DPA 2018 compliance” is often shorthand for this exact clause, even though the specific duty sits in UK GDPR rather than the Act’s own text. Because the method is left open, trustees cannot simply tick a box against it; they ask suppliers directly what testing has actually been done, by whom, and how recently. That is why the question tends to arrive as a specific, evidenced request rather than a general compliance statement on a form.
What third-party assurance requirements will a charity’s procurement team list?
In our experience, charity questionnaires typically group the ask into four areas: proof of independent testing rather than self-assessment, confirmation the test covered systems touching their data, evidence of your incident response process, and a way to review your latest report or a redacted summary.
Framing these as third-party assurance requirements, rather than a generic security questionnaire, is what changes how you should respond. A vague statement that you “take security seriously” rarely survives a trustee-level review; what does is a report naming the methodology used, the systems in scope, and dated findings with a remediation status. The table below maps the questions we see most often to the evidence that tends to satisfy them.
| What the questionnaire asks | What it is really checking | Evidence that satisfies it |
|---|---|---|
| Has the platform been independently penetration tested? | Manual testing, not just automated scanning | CREST-accredited report naming methodology and scope |
| When was the last test carried out? | Currency of the evidence | Report dated within the last 12 months, or a retest schedule |
| Were the findings fixed? | Whether vulnerabilities were left open | Remediation evidence and retest confirmation |
| Can we see a summary? | Suitability for a non-technical trustee board | Executive summary written for a non-technical reader |
How does a penetration test for a charity’s tech supplier get scoped?
Scoping starts with what the software touches: which application, which APIs, and whether donor payment data or beneficiary case records pass through it. EJN Labs agrees the systems in scope, the test window and reporting format first, then runs manual testing against those systems rather than an automated scan.
In our experience, charity-facing platforms usually fall into a similar shape: a web application handling donor or case management, sitting in front of one or more APIs, sometimes with a payment provider integration that stays out of scope because someone else already tests it separately. A typical engagement runs in four stages:
- Scoping call. We confirm which application, API endpoints and environments are in scope, and what the buyer’s questionnaire is actually asking for.
- Testing. UK-based testers manually assess authentication, access control and data handling in the web application itself, supplementing but never replacing that work with automated scanning.
- Reporting. Findings are graded by severity, with enough technical detail for your developers and a plain-English summary for your buyer’s trustees.
- Retest. Once fixes are in, we confirm they hold, so the report you hand over shows closed findings rather than open ones.
How much does the test trustees ask for typically cost?
The typical UK day rate for CREST-accredited testing runs £1,100 to £1,400 per day. A single web application handling donor or case data typically needs 4 to 6 days, so £4,400 to £8,400 in total, with the exact figure set by scoping.
Adding the APIs behind that application usually extends the engagement to 6 to 9 days, at the same £1,100 to £1,400 day rate, so £6,600 to £12,600. A retest once fixes are in typically adds 1 to 2 days, or £1,100 to £2,800. These are typical UK ranges rather than quotes; for a wider view of how testing prices are built up, see our guide to penetration testing costs in the UK, and a scoping call through the quote form will confirm the exact figure for your platform.
| Scope | Typical effort | Typical UK cost |
|---|---|---|
| Web application handling donor or case data | 4 to 6 days | £4,400 to £8,400 |
| Web application plus the APIs it depends on | 6 to 9 days | £6,600 to £12,600 |
| Retest after remediation | 1 to 2 days | £1,100 to £2,800 |
How EJN Labs approaches penetration testing for charity sector suppliers
EJN Labs is a CREST-accredited penetration testing firm, certified to ISO 27001, ISO 9001 and Cyber Essentials Plus. All testing is carried out by UK-based testers, which matters when a charity’s data protection due diligence asks where test data is handled and stored.
For charity-sector suppliers, we start from the questionnaire itself: which questions your buyer is actually asking, and which parts of your platform they touch. A typical engagement covers the web application handling donor or case data from end to end, tests it manually rather than relying on scanner output alone, and finishes with a report structured so a trustee board or IT sub-committee can read the summary without a security background. If you are comparing firms, our penetration testing checklist sets out what a properly scoped engagement should include.
Frequently Asked Questions
Does the Data Protection Act 2018 require penetration testing?
No. The security duty sits in UK GDPR Article 32(1)(d), which the Data Protection Act 2018 brings into UK law, requiring a process for regularly testing your security measures. It does not name penetration testing as the method, though trustees commonly treat an independent test as the clearest evidence of it.
What DPA 2018 pen test questions do charity trustees typically ask?
Charity trustees typically ask whether testing was independent and manual, whether it covered every system touching donor data, how recently it ran, and whether the findings were fixed and retested. A CREST-accredited report answering those points usually closes a charity’s due-diligence review.
What evidence satisfies a charity’s third-party assurance requirements?
A penetration test report from a CREST-accredited firm is the evidence we most often see accepted: it names the systems tested, methodology used, findings by severity, and confirmation issues were fixed and retested. Many procurement teams also ask for a short executive summary for a trustee board pack.
How much does a penetration test cost for a charity’s tech supplier?
The typical UK day rate for CREST-accredited testing runs £1,100 to £1,400 per day. A single web application handling donor or case data typically needs 4 to 6 days, so £4,400 to £8,400 in total; adding its APIs extends that to 6 to 9 days, or £6,600 to £12,600. A scoping call gives you the exact figure.
How often should we retest to keep our evidence current?
Charity buyers commonly treat a penetration test report as current for around 12 months, after which they expect a fresh one rather than an older result. An annual retest also covers any features you have shipped since the last engagement, since a test only ever reflects the system as it stood on the day it ran.
Get pen test evidence ready for your next charity contract
If a security questionnaire is holding up a charity contract, we can scope a CREST-accredited test around exactly what your buyer is asking for. Get a CREST pentesting quote and we will give you a fixed price for the defined scope for your platform.
Related reading for charities and their technology suppliers
If you supply software or IT services into the charity sector, these cover related ground: Charity Commission cyber guidance and where penetration testing fits, the wider set of questions charities expect from software vendors, and our wider look at GDPR and penetration testing obligations.




Leave a Reply