Part 1 of 13 in Meeting the DfE digital and technology standards.

Somebody is going to ask where your school stands against the DfE digital and technology standards. A governor, a trustee, an insurer, an inspector, a funding body. The uncomfortable part is not the answer. It is not having one.

In short: The Department for Education publishes twelve digital and technology standards for schools and colleges. Six are core: broadband internet, wireless network, network switching, digital leadership and governance, filtering and monitoring, and cyber security. The DfE says all schools and colleges should be working towards meeting those six by 2030, and that filtering and monitoring should be met now. The other six, covering cloud, accessibility, IT support, devices, cabling and servers, carry no date. Start with governance, because the DfE makes it the foundation the rest depend on. Then baseline honestly against all twelve, including the ones you fail, and put a dated plan against each gap.

What the standards are, and what they are not

The standards live on GOV.UK under Meeting digital and technology standards in schools and colleges. They were first published in March 2022 and have been revised since; the current version is dated 8 September 2026.

The strapline is modest: "How schools and colleges can use the right digital infrastructure and technology." Each of the twelve topic areas is broken into individual standards, and each of those follows the same pattern. Why it matters, who needs to be involved, how to meet it, the technical requirements where there are any, and when.

Three things are worth being clear about before you take any of this to a board.

  • They are expectations, not statute. The DfE's wording on the six core standards is that schools "should be working towards meeting" them by 2030.
  • One of them is expected now. The filtering and monitoring page says "You should be meeting this standard now", because it sits underneath Keeping children safe in education, which is statutory guidance.
  • Cyber Essentials is a funding condition for colleges. The cyber security page states that Cyber Essentials "is a requirement for colleges under their funding agreement". For schools it is described as something they may wish to complete.

Everything else about the standards' force comes from outside the DfE: insurers asking for continuity plans, the risk protection arrangement requiring a cyber response plan and evidence of NCSC training, and the plain fact that anyone can now compare your estate to a published benchmark.

The six core standards, and what "by 2030" means

The parent page and each core standard page carry the same sentence: "All schools and colleges should be working towards meeting 6 core standards by 2030." The DfE's stated reason is that meeting the six gives you "the essential infrastructure and governance" to have a strong digital strategy, make informed decisions, use technology safely, and meet the other standards.

Six numbered tiles in a row: broadband internet, wireless network, network switching, digital leadership, filtering and monitoring, and cyber security
The six core standards the DfE says every school and college should be working towards by 2030.

In the DfE's order, they are:

  • Broadband internet. Full fibre, a minimum of 100Mbps down and 30Mbps up for a primary school, capacity for 1Gbps in a secondary or a college, a backup connection, and filtering plus a firewall on the connection.
  • Wireless network. Wi-Fi 7 as the minimum when you next upgrade, coverage planned from a heat map, central management, and WPA3 with MFA for the people who administer it.
  • Network switching. 1Gbps to every desk, multi-gigabit ports for access points, five years of support as a minimum, and a UPS on the core switches.
  • Digital leadership and governance. A named SLT digital lead, three registers, digital technology in your continuity plans, and a two-year strategy reviewed every year.
  • Filtering and monitoring. Named roles, an annual review, filtering that blocks harmful content without obstructing teaching, and monitoring that produces weekly reports somebody acts on.
  • Cyber security. Seven standards, including an annual risk assessment, MFA for staff cloud accounts, critical patches within 14 days and immutable backups tested every term.

Each gets its own post in this series, in that order, with the numbers and the DfE's exact wording.

The other six standards

The remaining six are not core and carry no 2030 date, but four of them use the phrase "you should already be meeting this standard" for at least one of their requirements, so they are not optional in any practical sense either.

  • Cloud solutions. Cloud services as an alternative to local servers, data protection compliance including UK or EU data residency, one identity and access system, published availability targets, and 3-2-1 backups for critical data.
  • Servers and storage. For whatever you keep on site: no single point of failure, a UPS with 30 minutes of run-time, termly security reviews, energy efficiency and a proper physical environment.
  • Laptops, desktops and tablets. Devices that follow the strategy, are centrally managed and secure now, meet a short minimum specification, and are bought and disposed of sustainably.
  • IT support. Whether internal, external or hybrid, support that keeps you on the standards, maintains the registers, meets agreed response expectations, is reviewed every year and trains staff.
  • Network cabling. Cat 6A copper, 16-core OM4 fibre between buildings, British Standards installation and testing, and a 20-year warranty.
  • Digital accessibility. Accessibility in your strategy and policies, hardware and software with the features enabled and not blocked by security policy, and communications everyone can read.

"The standards are rarely failed on technology. They are failed on evidence: a control you own but never switched on, a backup nobody has restored, a monitoring report nobody read."

Why the DfE puts governance first

This is the most useful thing in the whole guidance, and it is easy to miss. The four digital leadership and governance standards are explicitly sequential. Appoint the SLT digital lead first, because you cannot write the strategy without one. Bring the contracts, asset and information asset registers up to date, and get digital technology into your disaster recovery and business continuity plans. Only then write the two-year strategy.

Other standards then hang off that strategy. The devices standard tells you to create the strategy before deciding what to buy. The IT support standard expects support to be planned against it. The cyber security standard says the risk assessment should sit within it.

The practical consequence for a business manager is reassuring. The first standard to close costs nothing but time, and closing it makes every other conversation, including every conversation with a supplier, shorter.

Where schools usually stand

We are not going to quote you a statistic we cannot stand behind. What we can describe is the pattern in most organisations' estates, schools included, and it maps onto the standards uncomfortably well.

  • Controls owned but not enabled. Microsoft 365 Education licensing includes a great deal of what the cyber security standard asks for. MFA is available on every tenant; the standard says it "must be enabled for all staff accounts with access to cloud services", which is a different thing.
  • Accounts that never leave. Supply staff, leavers, shared classroom logins, old student accounts. The standard asks for a termly account review and immediate disabling on leaving.
  • Backups that have never been restored. The standard wants three copies on two devices with one off-site, immutable, and a restore tested each term. Most estates can show the job ran. Few can show a restore.
  • Filtering bought, monitoring unread. Filtering is straightforward to procure and to demonstrate. Monitoring produces weekly reports that a named person has to review and act on, and that is the half that goes missing.
  • A cabinet nobody has opened. Switches past the end of firmware support, which the switching standard says "should be replaced", and cabling that quietly caps what the new Wi-Fi can do.

None of these is expensive to find. All of them are expensive to discover during an inspection, a bid or an incident.

If you are a multi-academy trust

The standards are the same for every school in a trust. The starting positions are not. A trust typically inherits different networks, different suppliers, different contract end dates and different levels of care, so a single trust-wide statement of compliance is rarely true on day one.

What works is a per-school baseline against the twelve areas, then a trust-level roadmap sequenced by risk and by when each contract can actually be changed. Trying to standardise everything simultaneously stalls on the school with the longest remaining contract, and the delay reads as a trust-wide failure rather than a single renewal date. The governance standard helps here too: the DfE names a trust IT director among the people the SLT digital lead works with, which gives you a legitimate place to hold the trust-wide view.

Where to start this term

The order below follows the DfE's own sequencing and costs nothing until step five.

  1. Name the SLT digital lead, and consider the governor digital link role the DfE suggests. The head or principal appoints them; they do not need to be technical.
  2. Check filtering and monitoring now. Who is the responsible SLT member, who is the responsible governor, when was the last annual review, and who read last week's monitoring report.
  3. Bring the three registers up to date using the DfE templates for contracts, assets and information assets. Put end-of-support dates and contract end dates in them.
  4. Get digital into the continuity plans, in hard copy and in the cloud, and put a date in the diary to test the disaster recovery plan.
  5. Baseline against all twelve areas, honestly, including the ones you fail. Use the DfE's free plan technology for your school service, and get someone independent to look at the tenant, the cabinet and the contracts.
  6. Write the two-year strategy before the next budget cycle, with a dated plan against each gap, sequenced so the disruptive work lands in the holidays.

Where Systech fits

We are a Microsoft-first IT provider, and much of what the core standards ask for is Microsoft 365 configuration, identity, device management and network design rather than new purchases. We work with schools, colleges and trusts on exactly this: an honest baseline against the standards, the cyber security and Cyber Essentials work that closes the largest gaps, Intune device management so the devices standard is evidenced rather than asserted, networking design that does not stall on the cabling, and backup that has actually been restored. We do not certify Cyber Essentials ourselves and we do not sell filtering software; we configure, integrate and evidence what you choose. Our standards guide collects the whole series as it publishes.

If you would rather start with a number than a plan, book the free DfE digital standards baseline. Sixty minutes, a governor-ready position against all twelve areas, and a dated plan for each gap. You keep the findings whether or not anything else follows.

Frequently asked

What are the DfE digital and technology standards?

They are the Department for Education's published guidance on the digital infrastructure and technology schools and colleges in England should have. There are twelve topic areas. Six are designated core standards: broadband internet, wireless network, network switching, digital leadership and governance, filtering and monitoring, and cyber security. The other six cover cloud solutions, digital accessibility, IT support, laptops, desktops and tablets, network cabling, and servers and storage. Each area is broken into individual standards with a stated reason, who needs to be involved, how to meet it and when. The guidance was first published in March 2022 and is updated regularly; the current version is dated September 2026.

Are the DfE digital standards mandatory for schools?

The DfE's own wording is that all schools and colleges should be working towards meeting the six core standards by 2030. That is an expectation rather than a statutory duty, and it is worth being precise about it in front of governors. Two things carry more weight. Filtering and monitoring is described as a standard you should be meeting now, because it sits under the statutory safeguarding guidance, Keeping children safe in education. And the cyber security page states that Cyber Essentials is a requirement for colleges under their funding agreement. Beyond those, the practical force comes from insurers, the risk protection arrangement, and anyone who asks you to evidence your position.

Which DfE standard should a school tackle first?

Digital leadership and governance, and the DfE says so itself: the four standards in that area are sequential, and the last of them, a two-year digital technology strategy, is a prerequisite for the devices and IT support standards. Name a senior leader responsible for digital technology, bring the contracts, asset and information asset registers up to date, include digital technology in your disaster recovery and business continuity plans, then write the strategy. None of that needs a purchase. Alongside it, check filtering and monitoring immediately, because it is the one core standard the DfE expects to be met now rather than by 2030.

What is the DfE plan technology for your school service?

It is the free service the DfE names on the parent page and on every core standard page as the way to work towards meeting the standards. The IT support standard describes it as helping schools measure progress towards meeting them. It is worth using, and it is also worth understanding what it is not: it gives you a self-reported position, not an independent one. A baseline carried out by someone who can see your tenant, your network cabinet and your contracts will find the gaps a questionnaire cannot, particularly the difference between a control you own and a control that is switched on.

Ryan Mangan
Ryan Mangan

Founder & CTO of Systech IT Solutions, Microsoft MVP and Chartered Fellow of the BCS, and author of the bestselling Mastering Azure Virtual Desktop. Ryan has spent nearly two decades in end-user computing and cloud delivery, helping organisations adopt Azure, Microsoft 365 and modern workspace technology pragmatically.