Skip to main content
Products Back
Solutions Back
Resources Back
Success Services Back
For Partners Back

Would Your Data Practices Pass a Funder’s Security Review?

Answer 8 quick questions about how your organization protects payroll, HR, and grant-funded program data — and get a personalized readiness score with specific steps to prepare for funder due diligence and audits.

Start Your Assessment
Takes about 2 minutes

Do you know whether your major funders or grant agreements include specific data security or cybersecurity requirements?

Since October 2024, OMB’s Uniform Guidance (2 CFR 200.303(e)) requires federal grant recipients and subrecipients to take “reasonable cybersecurity measures” — and private foundations are following suit.

Submit press Enter ↵

If a funder asked for evidence of your data security practices during a site visit or audit, what could you produce today?

Funder due-diligence reviews increasingly ask for documented policies, not just verbal assurance.

Submit press Enter ↵

How is personally identifiable information (PII) — employee, donor, and program participant data — segmented across your grant-funded programs?

Multi-program nonprofits often mix restricted-fund data in ways that don’t match what each funder actually authorized.

Submit press Enter ↵

Does your payroll and HR system require multi-factor authentication (MFA) to log in?

MFA is one of the specific safeguards named in OMB’s 2024 cybersecurity guidance for grant recipients.

Submit press Enter ↵

If a subgrantee, fiscal sponsor, or program partner requested access to shared payroll or HR data, how would that access be managed?

Collaboratives, fiscal sponsorships, and pass-through grants are common in the nonprofit sector — and each one is a data-sharing relationship that needs its own controls.

Submit press Enter ↵

Does your organization have a documented incident response plan for a payroll or HR data breach — including funder and donor notification steps?

Many grant agreements now specify a notification window if a breach affects grant-funded data or personnel.

Submit press Enter ↵

Have staff who manage payroll, HR, or grant reporting been trained on funder-facing data security expectations?

This includes knowing what a funder site visit, compliance review, or audit is likely to ask for.

Submit press Enter ↵

When was the last time your organization reviewed who has access to payroll and HR systems across all active grants and programs?

Access permissions tend to drift as grants end, staff roles change, and seasonal or project-based positions turn over.

See My Results press Enter ↵