How to choose a system your team will actually use—and raise more because of it
2026 Edition
Bloomerang
You know what your donors need from you. The harder question is what you need from a system.
Shopping for a new nonprofit CRM, often referred to as a donor database, can be challenging. With so many vendors to choose from, it's difficult to know which option is truly best for your organization.
Most vendor websites say close to the same thing. And feature lists look identical. The stakes feel high, because they are: this is a system your team will rely on as a source of truth. It will also house information your donors expect you to keep secure: giving histories, conversation notes, and more.
This guide won't tell you which platform to buy. It will give you the questions to ask, a way to weigh the answers, and worksheets your team can use to make the call—and explain it to your board.
Part 01
Why this year
is different
If you haven't evaluated donor management software in a while, three things have changed enough to reset your requirements.
The 2026 Giving Signals Report, conducted with The Harris Poll, surveyed more than 1,000 active U.S. donors and 400 nonprofit fundraising leaders.1 Three findings change what you should require from a system:
Three questions to carry into every demo:
AI is everywhere, but few are using it to improve fundraising outcomes. Among 826 nonprofit professionals surveyed, 4.5% use smart donation forms, 2.3% use predictive AI to identify likely mid-level or major donors, and 1.2% use AI agents for fundraising.2 Every vendor you talk to this year will show you AI. Part 5 gives you a way to tell the difference between a feature that changes what your team can do and one that writes a slightly faster thank-you note.
Through the first quarter of 2026, total dollars raised grew an estimated 4.3% year over year while donor counts fell 0.8%—and retention declined across the small, midsize, major, and supersize donor segments.3 Growth is coming from fewer, deeper relationships rather than more of them.
That puts retention and recurring giving near the center of any software decision. Across the sector, 71% of monthly donors were still giving after 12 months, compared with 24% of new one-time online donors. Monthly giving made up 27% of online revenue overall, and 22% at organizations under $1M.4 Acquisition matters too, and the Giving Signals data says the opening is real: eight in 10 Millennials plan to give to a new nonprofit this year. But new donors are the hardest to keep. The system you want helps you welcome new donors, deepen relationships, and give supporters meaningful reasons to remain involved.
Of monthly donors were still giving after 12 months
Of new one-time online donors were still giving after 12 months
Part 02
Should you
switch at all?
Switching costs real time and real money. Sometimes that's the right trade. Sometimes the honest answer is "not right now," and discovering that now beats finding it out mid-migration.
Here's how to tell the difference.
| Switch now if… | Wait if… |
|---|---|
| You can't answer "who gave last year but not this year?" | You're inside 90 days of your year-end or a major campaign. |
| Failed recurring payments go unnoticed until a donor tells you. | The complaint is one feature, not the system—ask your current vendor first. |
| Gift acknowledgments regularly take more than 48 hours. | You're only using a small percentage of the available features—but the ones you use, you use well. |
| It's challenging to segment supporters, such as donors at risk of lapsing, potential new donors, or major gift donors. | The real problem is integrations nobody has taken advantage of. |
| You can't easily create accurate data reports. | There's no one on staff to own the transition—a system without an owner fails no matter how good it is. |
| Your staff doesn't find your current software to be user-friendly, and it's difficult to train new staff members to use it. | You can't name what success would look like six months after go-live. |
| The one person who understands the database is leaving. | You don't have alignment on requirements across your team. |
“Perform an internal audit of ‘what works’ versus ‘what doesn't’ and an itemization prioritization of what software features are needed, along with the overall goals and expectations of a software package. Also, have a full understanding of what metrics your organization wants to measure in its fundraising program so that the proper benchmarks are created when looking at potential software providers.”
Part 03
What to define
before you shop
Understanding how you use your current system is critical to choosing a new system. Work through these questions with your team before you attend a single demo. The answers become your requirements—and the gaps in your answers are usually the most revealing part of the exercise.
Before anything else, settle one question: are you buying a donor database, or a complete giving platform? Both are legitimate answers, and the tradeoff is real. Separate best-in-class tools give you more integrations to maintain. One system gives you fewer logins and one version of the truth, and you live with whatever its weakest module is. Answer this before you shop, because it decides which vendors belong on your list—and because changing your answer halfway through an evaluation is how organizations end up with four systems and no plan.
Even a small team has several different jobs inside the database. Make sure you've heard from whoever enters gifts, writes to donors, reports to the board, and reconciles with finance—even if that's three people wearing six hats. Add anyone who will have to approve the purchase.
Ask each of these people the same opening question: what are your top three frustrations with how we do this today? Then have the group vote on which ones a new system actually needs to solve. The ones nobody votes for are process problems. Software won't fix them.
Using the answers to these questions, create lists of "must-have" and "nice-to-have" features. Once complete, look for a system that includes all of your "must-have" and many of your "nice-to-have" features. Keep the must-have list short. If everything is a must-have, the list can't help you choose—and you'll end up buying on price or on whichever demo you saw last.
The companion workbook includes a requirements sheet with these questions laid out for your team to fill in, plus space to rank must-haves.
Part 04
What actually
matters today
Feature lists are easy to compare and nearly useless for deciding. Organize what you're looking for around the three outcomes you actually need instead. Under each outcome, you'll find what to look for and what to ask during a demo.
Outcome 1
Show me how I'd find every donor who gave last year but not this year, and how I'd know that before the year was over.
Outcome 2
Walk me through what happens, start to finish, when a monthly donor's card expires.
Outcome 3
Have someone on my team, who has never seen this software, build the report I need for my next board meeting.
A long list of available connections is not the same as a working one. For every connection you actually depend on, ask what syncs, in which direction, how often, and what happens when it fails. Some CRMs will include the different tools listed above, or the CRM itself may be part of a larger system of all-in-one tools, like a giving platform.
Your nonprofit likely manages a variety of donor engagement and fundraising activities on a daily basis. You send emails, review donor data, plan events, launch social media campaigns, call donors, and more. You probably don't manage all of it in one place, which is why it matters how well a new system connects to the tools you keep.
Connections between systems can:
Look for a system that connects to the tools your organization already uses. These might include:
Part 05
AI, honestly
AI is everywhere. The insight that changes your fundraising isn't—not yet.
Among 826 nonprofit professionals surveyed, 4.5% use smart donation forms, 4.1% use predictive send-time optimization for email, 2.3% use predictive AI to spot likely mid-level or major donors, and 1.2% use AI agents.6 Most AI use happens in a browser tab, disconnected from the database. A general-purpose chatbot can write you a thank-you letter. It can't tell you which donor is about to lapse.
Useful AI within a CRM works with the donor data you already have, and it does three things with it: surfaces opportunities you would have missed, tells you where to focus first, and turns that into a next step someone on your team can actually take.
| Level | What it does | How to judge it |
|---|---|---|
| Assistive | Drafts, summarizes, rewrites. Thank-you letters, appeal copy, meeting notes. | This can save time, but offers limited differentiation because many general-purpose AI tools provide similar capabilities. |
| Analytical | Finds patterns in your own donor data. Who is likely to lapse, who is ready for a larger ask, which recurring gifts are at risk. | This is the level worth paying for. Press hardest here. Ask to see it run on data that resembles yours, and ask what it does when your data is thin. |
| Agentic | Takes action on your behalf. Builds the segment, drafts and queues the appeal, updates the record. | Newest and least settled. Ask to see it working live, not on a roadmap slide—and ask what it will and won't do without a person approving it first. |
And it should leave those decisions to you. AI can prepare, prioritize, and draft. Whether to make the ask—and how to say it to someone you know—stays with your team.
So the question isn't "do you have AI?" It's "what does your AI know about my donors that I don't?"
Ask these in writing, before the contract. Judge the clarity of the answer, not the perfection of the product: a vendor who tells you plainly what their AI can't do yet is more trustworthy than one who implies it does everything. A vendor who can answer these clearly is telling you something. So is one who can't.
| Ask | What a good answer sounds like | Concerning |
|---|---|---|
| Is our donor data used to train your models, or anyone else's? | A direct yes or no, in writing, in the contract. If aggregated or anonymized data is used, they say so plainly, explain what it means, and tell you whether you can opt out. | Reassurance without specifics. "We take privacy seriously." An answer that only appears in a sales call. |
| Which AI providers do you use, and where is our data processed and stored? | Named providers, named regions, and the security standards those providers are held to. | They can't or won't say. You are entitled to know whose systems your donor records pass through. |
| Does the AI respect our existing user permissions? | Yes, and they can demonstrate it. If someone can't see major gift notes today, the AI doesn't surface them tomorrow. | Permissions and AI are described as separate systems, or the answer is "we're working on that." |
| Will AI ever change or overwrite a record without a person confirming? | No—and they show you the confirmation step in the product. | Automatic updates presented as a convenience feature. Anything that writes to donor records unattended. |
| What signals feed this score, and can I see which ones moved it for a specific donor? | They name the inputs, show the top contributing factors on an individual record, and tell you plainly what the model can't explain. They tell you what happens when a record is thin. | "The model determines that." A number with no inputs disclosed. Explanation available only to support staff. |
| Can we turn AI features off, by feature, at the admin level? | Yes, and they show you the controls in the product. | All or nothing. Or a toggle that support has to flip for you. |
| If we leave, does AI-generated content come with us—notes, summaries, scores—and in what format? | A clear yes, with the export format named, in the contract. | AI-generated notes and scores that stay behind when you go. |
In a survey of over 1,000 nonprofit professionals, 76% had no AI strategy and 80% had no acceptable-use policy for AI. The same survey found organizations over $1M adopting generative AI at close to twice the rate of those under $1M—a resource gap, not a reflection of your team's ability. Boards and funders are starting to ask about this.7
You don't need a 15-page policy. You need five lines your team can follow: what data may go into which tools, who approves a new tool, what always gets human review before it reaches a donor, what never leaves your system, and who to ask when it's unclear. A starter template is in Appendix 04.
Part 06
Security, data,
and ownership
Your new system will handle a large volume of donor data. Keeping this data secure is essential for ensuring donors' trust in your organization. Assess the level of data security offered by each of your top options.
Tokenization is the process of exchanging sensitive data for non-sensitive information. The tokens have no inherent meaning or value, meaning that there is no way to return to the original value by just viewing the tokenized data. This helps keep donors' sensitive personal information secure.
A changelog is a record of all of the updates and security patches made to a software system over time. This log helps you understand how the product has evolved and the steps the vendor has taken to make the software more secure and useful.
When you use fundraising software to collect and process donors' payment information, you need a way to ensure that information will stay safe. PCI compliance is a set of security measures intended to prevent data theft. Ask which version of the standard they meet and when they were last assessed, not just whether they're compliant.8
SOC 2 compliance is a voluntary security compliance standard for vendors that handle customer data. A software provider that is SOC 2 compliant has been vetted by outside auditors and has been confirmed to comply with five trust principles: security, availability, processing integrity, confidentiality, and privacy. Ask for the report, and ask whether it's Type I or Type II.
Your donation form is a target—not for your money, but for card validation. Attackers push hundreds of small gifts through public donation pages to find out which stolen cards still work, because a donation form asks for less than a checkout page does and usually skips the shipping address.
One nonprofit saw 1,727 attempted $1 transactions before its processor stepped in. Roughly 200 went through, and every one had to be refunded before the account could be reactivated.9 The cost lands on you: chargeback fees, refund work, a polluted database, or a processor that shuts you off mid-campaign. Ask which fraud controls are on by default rather than sold as an add-on, what the system does automatically when a burst of small gifts arrives, whether you can identify and reverse them in bulk, and who pays the chargeback fees.
If your organization receives federal funding from the Department of Health and Human Services, this is no longer optional. The Section 504 rule that took effect in July 2024 requires web content and mobile apps to conform to WCAG 2.1 Level AA, and it reaches human services programs and community health centers, not just hospitals. In May 2026, HHS extended the compliance dates by a year: recipients with 15 or more employees now have until May 11, 2027, and those with fewer until May 10, 2028.10 Even if no rule reaches you, the buyer's logic holds. Ask whether donation and registration forms meet WCAG 2.1 AA, ask to see the vendor's accessibility statement, and ask whether it came from an audit or from an overlay widget. A donor who can't complete your form is a donor you lost without ever knowing.
Covered in Part 5. Treat it as a security question, not a feature question. And if you don't yet have rules about what donor data can go where, you are in the majority of organizations—80% of nonprofits have no acceptable-use policy for AI. This is the moment to write one.
The question almost nobody asks until it's too late: if we leave, what exactly do we get back, in what format, how quickly, and at what cost? Ask whether that includes notes, attachments, custom fields, and AI-generated content—not just names and gifts. Get the answer in the contract.
Major data breaches damage supporters' trust in nonprofit organizations and lead to uncertainty about providing sensitive personal and payment information in the future. With these measures in place, you can be confident your vendor takes donor data protection as seriously as you do.
Part 07
What it
really costs
The subscription is rarely the whole number. Build the full picture before you take anything to your board.
| Category | What to ask |
|---|---|
| Data conversion | What does it cost to move our data across, and what affects that price? The source, format, age, and condition of your current data all matter. |
| Implementation | What's included in the setup, and what costs extra? Does implementation include data conversion, or is that separate? |
| Software licensing | Is this billed monthly or annually? What causes the price to change—records, users, features, gift volume? |
| Training | What's included, in what format, and what does additional training cost when we hire someone in year two? |
| Support | What channels, what hours, and what is the committed response time? Is there a service level agreement in writing? |
| Payment processing | What are the transaction fees, and how do they compare to what we pay today? Are there fee-offset options for donors who want to cover them? |
| Integrations | Which connections are included, which are paid add-ons, and which require a third party? |
| Ongoing consulting | Will we need outside help to keep this running well? How much do comparable organizations spend? |
The real comparison isn't free versus paid. It's the full cost of every option—including the one where you change nothing.
Start with what "free" actually means for the platform you're evaluating. Many no-fee, no-subscription tools recover their cost by prompting the donor to add a "tip" at checkout, often pre-selected by default and set well above what a card processing fee would run. The nonprofit doesn't pay less. The donor might, usually without realizing it, and often without a clear sense of where that money goes. That's not free. It's a cost shifted onto the person the nonprofit is accountable to. This payment model has resulted in lawsuits and calls for more transparent and ethical platform costs.
Add up what you spend today: subscription, transaction fees, the add-on tools you bought to fill gaps, and the hours your team spends moving data between systems that don't talk to each other. That last number is usually the largest, and the one nobody counts. Run the same math on every option in front of you, free ones included. Then decide.
Return on investment and total cost of ownership answer different questions, and they belong in different conversations.
If one vendor's offer is missing something you need, price the way you'd fill that gap—usually another tool—and add it to their column. Otherwise you're not comparing the same thing.
The companion workbook includes a three-year total cost worksheet with these categories built in and a side-by-side comparison for up to three vendors. The math is done for you—fill in the numbers each vendor gives you.
Part 08
Running the
evaluation
Once you have narrowed the field to a handful of systems that fit your needs, it's time to schedule demos. Live demos are a great way to see each product in action and get some of your questions answered directly. To make the most of them, follow these steps before, during, and after.
Involve all of the members of your team who will be using the system.
Give every vendor the same list. Appendix 02 has the full script.
Ask each vendor for three references at your size and in your subsector. Then find one or two more on your own, through a peer network or a professional association. The reference a vendor didn't hand-select will tell you the most.
Four questions worth asking every reference:
A call script is in Appendix 03.
Part 09
Switching without
breaking anything
People don't usually worry about the purchase. They worry about the six months after it. Here's the good news: almost everything that goes wrong in a migration is predictable, which means almost all of it is preventable.
This is the step most likely to cost you real money if it's rushed. Ask your new vendor exactly how existing monthly gifts transfer, whether donors will need to re-enter payment details, and whether an overlap period between systems is possible. With 71% of monthly donors still giving after a year and 54% still giving after two,11 a handful of sustainers lost in a rushed migration is a multi-year revenue loss, not a one-time inconvenience.
If donors do need to act, tell them early, tell them plainly, and thank them for it. Then watch the failure rate closely for 60 days.
Migrating messy data means paying to move a mess. Before conversion begins, agree on dates and owners for standardizing formats, merging duplicates, and clearing out what's outdated. Decide what you're deliberately leaving behind, and write it down so nobody goes looking for it after the migration concludes.
One person needs clear responsibility for the transition and enough authority to make decisions. Establish who configures permissions, who sets up workflows, who connects the other systems, and by when. Unclear ownership is a common cause of delayed launches.
“The #1 mistake I see nonprofits make in shopping for donor database software is thinking that the process ends when a choice is made. Choosing a product is just the start. Be sure to budget time and money to have your staff take the time required to transfer your existing data into the new software. And budget the time and money to train your staff on how to use it effectively. Initial training is great but make sure to have check-ins each quarter too.”
Part 10
Your 30-day
decision plan
An open-ended search expands to fill whatever time you give it. Give it four weeks.
| Week | What you do | What you have at the end |
|---|---|---|
| Week 1—Define | Work through Part 2 with your team and decide whether you're switching at all. If yes, work through Part 3. Rank your must-haves. Brief your board. | A written requirements list and a short must-have list everyone agrees on. |
| Week 2—Shortlist | Research candidates. Send your written questions to three or four vendors. Book demos with the same scenarios for each. | Written answers from every vendor, and demos on the calendar. |
| Week 3—See it work | Run the demos with your team. Take the keyboard. Score each vendor the same day. Start the total cost worksheet. | A completed scorecard and cost comparison for each finalist. |
| Week 4—Verify and decide | Call references, including at least one you found yourself. Confirm exit terms and AI answers in writing. Compare three-year costs. Make the decision. | A decision you can explain in one page to your board. |
Making
your choice
There's no perfect system. There's a right-sized one—the one that fits how your team actually works, and helps you do more with everything you already have.
Share this with your team as you search and vet. Work the questions, score the vendors, check the references, and run the numbers. Then trust the work.
You've done the diligence. Whatever you choose next, you'll be choosing it with eyes open—and a team that trusts its system is a team that can aim higher.
Download the free companion workbook and define your requirements, compare vendors, and calculate the cost of each option.
Download the companion workbook
Three worksheets with the math already built in:
Editable, ready to fill in with your team. The scripts and templates in the appendix are yours to copy straight out.
Sources for every figure cited in this guide appear in the sources section below. All figures verified September 2026. Sector benchmarks in this category are updated quarterly—check the linked sources for the most current data.
Appendices
Ready to use
Appendix 01
Send the same list to every vendor before the demo. Ask for written answers.
Sending questions in advance does three things: it shifts the conversation from the vendor's script to your requirements, it gives you comparable answers instead of comparable impressions, and it produces a document you can put in a board packet.
Copy this list, add anything specific to your organization, and send it with your demo invitation.
Appendix 02
Give every vendor the same scenarios, so you are comparing like with like.
A demo shows you what the software can do. A scenario shows you what it feels like to use. Send these in advance and ask each vendor to walk through all five.
| Scenario | What to watch for |
|---|---|
| 01 A $5,000 grant arrives from a donor-advised fund sponsor. The check is from the sponsor, the advisor's name is on the paperwork, and the donor is in a memo line. | How does it land, how does it get soft-credited to the right household, and how do we acknowledge an actual human? Ask what a fundraiser has to do by hand. Then ask what happens when that same donor gives again next year. |
| 02 Build a segment of donors who gave $100–$499 last year. Draft an appeal that names what $250 buys. Send it. Then show us the impact report that goes back to the people who gave. | Most systems handle the ask and break at the report-back—which is the half that drives retention. Watch for the moment the vendor leaves the product, and count how many separate tools that sequence touched. |
| 03 Have someone on our team who has never seen this system build the report we take to our board. | Insist on this one. Hand over the keyboard. If it needs the vendor to drive, you have found a single point of failure. |
| 04 Show us one donor the system says is ready for a larger ask. Show the signals behind it, and what it says when the record is thin. Then let us mark it wrong. | Can it name its inputs in plain language, on that donor's record? Could you repeat the reasoning to a board member? And what does the system do with your correction—anything at all? |
| 05 Log in as a part-time gift processor and ask the AI a question that can only be answered from major gift notes. | The answer should be nothing. If the AI can see what the user can't, permissions and AI are two systems rather than one. Most vendors have never been asked to demo this, which is exactly why it is worth a slot. |
| 06 Add your own. | Pick the thing your team complains about most often. That is the scenario that will tell you the most. |
Bring everyone who will use the system. Ask your questions rather than following theirs. Take the keyboard for at least five minutes. Note anything the vendor promises verbally—it needs to appear in the contract later. And score the vendor the same day, while it is still fresh.
Appendix 03
Ask the same five questions of every reference.
Ask each vendor for three references at your size and in your subsector. Then find one or two more yourself, through a peer network or professional association. The reference the vendor didn't hand-select will usually tell you the most.
“Thanks for taking the time. We're evaluating [vendor] and we're trying to understand what it's actually like once you're past the sales process. I have about five questions that should take twenty minutes.”
Appendix 04
Five decisions your team needs written down. One page is enough.
In a survey of 1,321 nonprofit professionals, 76% had no AI strategy and 80% had no acceptable-use policy for AI. You don't need a fifteen-page document. You need five decisions your team can actually follow.
Fill in the brackets, share it with everyone who touches donor data, and revisit it once a year.
Boards are increasingly asking how AI is being used and how donor data is protected. A one-page policy answers that question before it becomes uncomfortable. Share it as an information item, note who owns it, and put the annual review on the calendar.
[Organization name]—AI Use Policy
Adopted [date] · Reviewed annually • Owner: [name, role]
We use AI to [drafting donor communications, summarizing notes, analyzing giving patterns, building reports]. We do not use AI to [make final decisions about individual donors, generate impact claims or program outcomes, or replace human review of anything a supporter will read].
Donor names, contact details, payment information, gift history, personal notes, and anything shared in confidence may only be used in [approved system(s)]. This information must never be entered into a public or consumer AI tool. Anonymized or general questions—writing help, research, brainstorming—may use [approved general tools].
No new AI tool is used with organizational data until [name, role] approves it. Approval requires clear answers to: does this vendor train on our data, where is our data processed, and can we get it back or delete it? Approved tools are listed at [location].
A person reviews and approves anything AI-generated before it reaches a supporter, a funder, or the board. AI does not change donor records without a person confirming. When AI has meaningfully shaped something we publish, we are willing to say so.
When it isn't clear whether something is allowed, ask [name] before doing it. Nobody will be criticized for asking. We would rather answer the question than discover the answer later.
Companion to The Buyer's Guide to Donor Management Software, 2026 Edition. AI policy figures: TechSoup and Tapp Network, The State of AI in Nonprofits: 2025 (survey of 1,321 nonprofit professionals, fielded 2024). All other benchmark figures referenced here are footnoted with source links in the sources section.
Donor management software, often called a nonprofit CRM or a donor database, is the system a nonprofit relies on as its source of truth for supporter records. It houses giving histories, conversation notes, communication preferences, and more. Before you shop, settle whether you are buying a donor database or a complete giving platform: separate best-in-class tools give you more integrations to maintain, while one system gives you fewer logins and one version of the truth, and you live with whatever its weakest module is. See Part 3.
Switch now if you can't answer "who gave last year but not this year?"; failed recurring payments go unnoticed until a donor tells you; gift acknowledgments regularly take more than 48 hours; it's challenging to segment supporters; you can't easily create accurate data reports; your staff doesn't find the software user-friendly; or the one person who understands the database is leaving. Wait if you're inside 90 days of year-end or a major campaign, the complaint is one feature rather than the system, there's no one on staff to own the transition, you can't name what success would look like six months after go-live, or you don't have alignment on requirements across your team. See Part 2.
The subscription is rarely the whole number. Build the full picture across eight categories before you take anything to your board: data conversion, implementation, software licensing, training, support, payment processing, integrations, and ongoing consulting. Add up what you spend today too—subscription, transaction fees, the add-on tools you bought to fill gaps, and the hours your team spends moving data between systems that don't talk to each other. That last number is usually the largest, and the one nobody counts. See Part 7.
Ask seven questions in writing, before the contract: Is our donor data used to train your models, or anyone else's? Which AI providers do you use, and where is our data processed and stored? Does the AI respect our existing user permissions? Will AI ever change or overwrite a record without a person confirming? What signals feed this score, and can I see which ones moved it for a specific donor? Can we turn AI features off, by feature, at the admin level? If we leave, does AI-generated content come with us—notes, summaries, scores—and in what format? Judge the clarity of the answer, not the perfection of the product. See Part 5.
Assistive AI drafts, summarizes, and rewrites—thank-you letters, appeal copy, meeting notes. It saves time but offers limited differentiation because many general-purpose AI tools provide similar capabilities. Analytical AI finds patterns in your own donor data: who is likely to lapse, who is ready for a larger ask, which recurring gifts are at risk. This is the level worth paying for. Agentic AI takes action on your behalf—builds the segment, drafts and queues the appeal, updates the record. It's the newest and least settled, so ask to see it working live rather than on a roadmap slide. See Part 5.
Four fundamentals: tokenization, an updated changelog, PCI compliance, and SOC 2 compliance. Ask which version of the PCI standard they meet and when they were last assessed, not just whether they're compliant, and for SOC 2 ask for the report and whether it's Type I or Type II. Add four more this year: payments fraud protection against card-testing attacks, accessibility conformance to WCAG 2.1 Level AA, where your data goes when AI touches it, and exit terms—what exactly you get back, in what format, how quickly, and at what cost. See Part 6.
An open-ended search expands to fill whatever time you give it. Give it four weeks. Week 1, define requirements and decide whether you're switching at all. Week 2, shortlist and send written questions to three or four vendors, booking demos with the same scenarios for each. Week 3, run the demos with your team, take the keyboard, score each vendor the same day, and start the total cost worksheet. Week 4, call references including at least one you found yourself, confirm exit terms and AI answers in writing, compare three-year costs, and make the decision. See Part 10.
This is the step most likely to cost you real money if it's rushed. Ask your new vendor exactly how existing monthly gifts transfer, whether donors will need to re-enter payment details, and whether an overlap period between systems is possible. With 71% of monthly donors still giving after a year and 54% still giving after two, a handful of sustainers lost in a rushed migration is a multi-year revenue loss, not a one-time inconvenience. If donors do need to act, tell them early, tell them plainly, and thank them for it. Then watch the failure rate closely for 60 days. See Part 9.
All figures verified September 2026. Sector benchmarks in this category are updated quarterly—check the linked sources for the most current data.
Fundraising and donor management software built for purpose.