Winning a grant used to mean the hard part was over. The proposal was strong, the mission was compelling, the numbers checked out and the funder said yes. That was enough.
It isn't always enough anymore.
A growing number of foundations, government agencies, and institutional funders are now requiring grant recipients to meet baseline cybersecurity and data governance standards before funds are released. For many nonprofits, this requirement arrives as a surprise and the gap between what they have and what's required is wider than anyone expected.
When a Security Questionnaire Becomes a Funding Blocker
Here's how it unfolds. A nonprofit serving foster youth in California secures a $200,000 state grant. Three weeks before the first disbursement, the funder sends over a compliance checklist. It asks about multi-factor authentication, data encryption, endpoint protection, access controls, and incident response procedures.
The organization's executive director forwards it to the part-time IT person they use for helpdesk issues. He does his best but the honest answer to most of those questions is either "no" or "I'm not sure." The disbursement gets delayed. Legal gets involved. The program launch that was planned for the following month gets pushed back six weeks.
That's not a fundraising failure. That's IT support for nonprofits failure and it's becoming a pattern across the sector.
What Funders Are Now Requiring
The specific requirements vary by funder, but the categories showing up most consistently in compliance checklists include-
- Multi-factor authentication on all email and cloud platform access.
- Documented data handling and retention policies especially for any donor or client PII.
- Endpoint protection on all devices that access organizational systems.
- A basic incident response plan, even a one-page document counts in most cases.
- Evidence of regular access reviews to ensure former staff and volunteers don't retain system access.
None of these are unreasonable asks. Most of them are things a well-supported nonprofit should have anyway. But the problem is that many organizations in the sector have been operating without dedicated IT guidance and these gaps accumulate quietly until a funder asks the question.
The Volunteer and Turnover Problem Makes It Worse
Nonprofits face a specific IT challenge that most for-profit businesses don't: high turnover and heavy reliance on volunteers. Both create real complexity around access management.
A program coordinator leaves after eight months. Her Google Workspace account is deactivated, but her login to the donor CRM was set up separately and never removed. A volunteer who helped with a fundraising gala six months ago still has edit access to the shared drive where event materials and some donor contact lists are stored.
These aren't dramatic breaches. They're the kind of low-visibility exposure that accumulates over time and shows up clearly when a funder runs a compliance review or when something actually goes wrong.
Getting Ahead of It Before the Next Grant Cycle
The organizations that handle this best treat IT compliance not as a grant requirement but as an operating standard. That shift in mindset changes what gets prioritized and when.
Practically, it means-
- Running an access audit at least twice a year before grant seasons, not after funding is already committed.
- Maintaining a live policy document that covers data handling, device use, and incident response.
- Using a managed IT partner that understands nonprofit compliance requirements, not just general small business IT.
- Building MFA and endpoint protection into the baseline for every staff and volunteer account, not just leadership.
How Verve IT Works With Nonprofits
At Verve IT, we work with nonprofits across California who are navigating exactly these organizations that are doing meaningful work with lean resources and need IT support for nonprofits that understands the constraints.
We help clients build the compliance foundation that funders are looking for: access governance, documented policies, endpoint security, and the kind of audit trail that answers a security questionnaire with confidence rather than a long pause.
If your organization has a grant cycle coming up and you're not sure your IT environment would pass a compliance review, that's a conversation worth having before the questionnaire arrives, not after.