In short: The Department for Education publishes twelve digital and technology standards for schools and colleges in England. Six are core: broadband internet, wireless network, network switching, digital leadership and governance, filtering and monitoring, and cyber security. The DfE says all schools and colleges should be working towards meeting those six by 2030, and that filtering and monitoring should be met now. The other six, covering cloud, accessibility, IT support, devices, cabling and servers, carry no date. The useful posture is a documented baseline against all twelve, including the ones you fail, and a dated plan for each gap.

Who this is for
  • A governor, trustee, inspector or insurer has asked where you stand against the standards and you do not have a defensible answer
  • A contract, funding condition or insurer has raised Cyber Essentials and you need to know which level, and what would fail
  • You are a trust inheriting schools with different networks, suppliers and contract end dates
  • Filtering is in place and you are less confident about who reviews the monitoring reports
What it costs to leave it

The standards are rarely failed on the technology. They are failed on evidence: a control you own but never switched on, a backup nobody has restored, a monitoring report nobody read, an accountable leader who turns out not to exist. All of them are cheap to fix in advance and expensive to meet during an inspection, a bid or an incident.

Where your school, trust or college stands, the core six in order, and a plan for governors. Plays from YouTube. Nothing is requested from YouTube, and no cookie is set, until you press play. Read the transcript

The six core standards

The DfE's reason for singling these out is that meeting them gives you “the essential infrastructure and governance” to have a strong digital strategy, make informed decisions, use technology safely, and meet the other six. In the DfE's order:

  • Broadband internet. A full fibre connection, at least 100Mbps down and 30Mbps up for a primary school and capacity for 1Gbps in a secondary or college, a backup connection that fails over automatically, and filtering plus a firewall on the line.
  • Wireless network. Wi-Fi 7 as the minimum when you next upgrade, coverage planned from a heat map rather than an access-point count, central management with automatic security updates, and WPA3 with MFA for whoever administers it.
  • Network switching. 1Gbps to every desk, multi-gigabit ports for access points and servers, five years of manufacturer support as a minimum, security features such as network access control, and core switches on a UPS.
  • Digital leadership and governance. A named SLT digital lead, up-to-date contracts, asset and information asset registers, digital technology in your disaster recovery and continuity plans, and a two-year strategy reviewed every year. The DfE makes these four sequential.
  • Filtering and monitoring. The one core standard the DfE says you should be meeting now. Named roles including a responsible governor, an annual review, filtering that blocks harmful content without obstructing teaching, and monitoring that produces weekly reports somebody acts on.
  • Cyber security. Seven standards: an annual risk assessment reviewed each term, a cyber awareness plan, anti-malware and a firewall, controlled accounts with MFA, licensed and patched software with critical fixes inside 14 days, immutable backups tested termly, and incident reporting.

The six other standards

These carry no 2030 date, but several use the phrase “you should already be meeting this standard” for at least one requirement, so they are not optional in any practical sense.

  • Cloud solutions. Cloud services instead of local servers where you can, data protection compliance including UK or EU residency, one identity and access system, published availability targets you have checked, and 3-2-1 backups for critical data.
  • Digital accessibility. Accessibility in your strategy and policies, hardware and software with the features enabled and not blocked by security policy, and communications everyone can read.
  • IT support. Whether internal, external or hybrid: support that keeps you on the standards, maintains the registers, meets agreed response expectations, is reviewed in writing every year and trains staff.
  • Laptops, desktops and tablets. Devices that follow the strategy, are centrally managed and secure now, meet a short minimum specification including five years of support for laptops and three for tablets, and are disposed of under the WEEE regulations.
  • Network cabling. Cat 6A copper, 16-core OM4 fibre between buildings, installation and testing to British Standards by manufacturer-approved installers, and a 20-year performance warranty.
  • Servers and storage. For whatever stays on site: no single point of failure, a UPS with 30 minutes of run-time, termly security reviews, energy efficiency and a dedicated, locked, windowless room.

The DfE publishes all of this in full at Meeting digital and technology standards in schools and colleges, and that page is the authority rather than this one. What follows is what the standards mean in practice for a school or trust working out where to start.

What “by 2030” actually means

Three sentences from GOV.UK do most of the work, and they are worth quoting exactly.

  • “All schools and colleges should be working towards meeting 6 core standards by 2030.” An expectation, not a statutory duty. Say so in front of governors, then explain why it still matters.
  • “You should be meeting this standard now.” That is the filtering and monitoring page, and it is the only core standard worded that way, because it sits under Keeping children safe in education, which is statutory.
  • “Cyber Essentials is a requirement for colleges under their funding agreement.” For schools, the DfE says they may wish to complete it and that the standards help you work towards it.

The rest of the standards' force comes from outside the DfE. Insurers may ask for your continuity plans. The risk protection arrangement requires a cyber response plan and evidence of annual NCSC training. And anyone can now compare your estate to a published benchmark, which is the quiet reason a documented baseline is worth more than an undocumented claim.

Why the DfE puts governance first

The four digital leadership and governance standards are explicitly sequential. Appoint the SLT digital lead first, because the DfE says you cannot create the strategy without one. Bring the three registers up to date and get digital technology into your continuity plans. Only then write the two-year strategy, before the next budget cycle.

Other standards hang off that strategy: the devices standard tells you to create it before deciding what to buy, the IT support standard expects support to be planned against it, and the cyber security standard says the risk assessment should sit within it. The first standard to close costs nothing but time, and it makes every other conversation, including every supplier conversation, shorter.

Cyber security: which Cyber Essentials do you actually need?

The DfE cyber security standard is the largest of the six in practice, and much of it is configuration rather than purchase for a school on Microsoft 365 Education. MFA must be enabled for all staff accounts with cloud access and for every administrative account. Critical vulnerability fixes must be applied within 14 days. Backups need at least three copies on two devices with one off-site, immutable, and restore-tested each term.

Cyber Essentials sits alongside rather than inside the standard. Where a contract, insurer or funding condition of your own names it, establish which level before you start. Cyber Essentials is a verified self-assessment; Plus adds independent technical testing against a sample of your devices, and the work and lead time differ substantially. We have written up the difference in Cyber Essentials vs Cyber Essentials Plus, and there is a readiness checklist if you would rather assess yourself first.

Filtering and monitoring, and the half that gets missed

Filtering is the easy half. It is straightforward to buy and to demonstrate: a product is in place, the IWF and CTIRU blocklists are enabled and no administrator can override them, staff and student profiles differ. Monitoring is where inspections find gaps, because the DfE asks for weekly monitoring reports, immediate reports for high-risk incidents, and a named person who reviews them, acts, and records acting.

The practical test is not whether you have a product. It is whether you can say who reviewed last week's report, what they did about it, and where that is written down. IT provides the capability and the evidence; the designated safeguarding lead owns the response.

If you are a multi-academy trust

The standards are identical; the delivery problem is not. A trust typically inherits schools with different networks, suppliers, contract end dates and starting positions, so a single trust-wide compliance statement is rarely true on day one.

What works is a per-school baseline against the twelve areas, then a trust-level roadmap sequenced by risk and by when each contract can actually be changed. Attempts to standardise everything at once stall on the school with the longest remaining contract, and the delay is then read as a trust-wide failure rather than a single procurement date.

The series: one post per standard

We are publishing a plain-English guide to each standard, two a week through September and October 2026, with the DfE's exact wording, the numbers, where schools usually fall short, and what good evidence looks like. 5 of 13 are live so far.

  1. The DfE digital and technology standards: what schools need to do by 2030, and where to start
  2. Digital leadership and governance: the DfE standard most schools skip, and why it comes first
  3. The DfE cyber security standard for schools and colleges: the seven requirements, explained
  4. Filtering and monitoring: the DfE standard you should already be meeting, and the half that gets missed
  5. The DfE broadband standard: full fibre, the right speed for your phase, and a backup line
  6. The DfE wireless network standard: Wi-Fi 7, coverage by survey, and security that keeps guests where they belong (coming 6 October)
  7. The DfE network switching standard: what your switches need to do, and when to replace them (coming 8 October)
  8. The DfE network cabling standard: Cat 6A, OM4 fibre and a 20-year warranty (coming 13 October)
  9. The DfE cloud solutions standard: moving off local servers without losing control of your data (coming 15 October)
  10. The DfE servers and storage standard: resilience, a 30-minute UPS and a room that is not a cupboard (coming 20 October)
  11. The DfE devices standard: what laptops, desktops and tablets have to meet, and what to do with the ones that do not (coming 22 October)
  12. The DfE IT support standard: what good support looks like, and how to review yours (coming 27 October)
  13. The DfE digital accessibility standard: features you already own, and the security policies blocking them (coming 29 October)

Where to start

  • Name the SLT digital lead, and consider the governor digital link role the DfE suggests.
  • Check filtering and monitoring now: the responsible SLT member, the responsible governor, the last annual review, and who read last week's report.
  • Bring the contracts, asset and information asset registers up to date using the DfE templates, with end-of-support and contract end dates in them.
  • Get digital technology into the continuity plans and put a date in the diary to test the disaster recovery plan.
  • Baseline honestly against all twelve areas, including the ones you fail, then write the two-year strategy with a dated plan for each gap.

This page is the explanation of what each standard asks for and why. If what you want instead is the version you can sit down and work through, point by point, that is the DfE digital standards checklist, which covers the same twelve areas as things to check in your own school.

We work with schools, colleges and trusts on exactly this, and the sector context sits on our education page. If a funding deadline, a bid or an inspection window is driving the timing, say so at the start: it changes the order the work should be done in. And if the question is whether you are allowed to buy from us at all without a framework, how schools and trusts buy sets out the value bands and what we provide at each. On-site work is IT support across Yorkshire from our Brough office and engineers based across Yorkshire and the UK, with the rest of the UK covered remotely by the same team.

Frequently asked

What are the DfE digital and technology standards?

They are the Department for Education's published guidance on the digital infrastructure and technology schools and colleges in England should have. There are twelve topic areas. Six are core standards: broadband internet, wireless network, network switching, digital leadership and governance, filtering and monitoring, and cyber security. The other six cover cloud solutions, digital accessibility, IT support, laptops, desktops and tablets, network cabling, and servers and storage. Each area is broken into individual standards with a stated reason, who needs to be involved, how to meet it and when. The guidance was first published in March 2022 and the current version is dated September 2026.

Are the DfE digital standards mandatory?

The DfE's wording is that all schools and colleges should be working towards meeting the six core standards by 2030. That is an expectation rather than a statutory duty, and it is worth being precise about that in front of governors. Two things carry more weight. Filtering and monitoring is described as a standard you should be meeting now, because it sits under Keeping children safe in education, which is statutory guidance. And the cyber security page states that Cyber Essentials is a requirement for colleges under their funding agreement. Beyond those, the practical force comes from insurers, the risk protection arrangement, and anyone who asks you to evidence your position.

Do schools need Cyber Essentials?

The DfE cyber security standard says Cyber Essentials is a requirement for colleges under their funding agreement, and that some schools may wish to complete it as part of their cyber security activities. It also says the standards can help you work towards certification. If a contract, insurer or funding condition of your own names Cyber Essentials, establish which level it requires before you start: Cyber Essentials is a verified self-assessment, Cyber Essentials Plus adds independent technical testing, and the work and lead time differ substantially. Assuming the wrong one costs weeks.

What does a school cyber security risk assessment need to cover?

The DfE standard asks for a cyber risk assessment completed annually, repeated after significant change or an incident, and revisited every term. It should review your assets and the cyber risk attached to each, confirm everything is licensed, supported and updated, cover a record of processing activities with your data protection officer, and review access, permissions, password policy and email security. The output feeds a risk management process and a cyber response plan inside your business continuity planning, with risks flagged to governors or trustees. A cyber response plan is also required for risk protection arrangement cover.

How does filtering and monitoring relate to KCSIE?

They are the same requirement approached from two directions. Keeping children safe in education places a statutory duty on governing bodies and proprietors to make sure appropriate filtering and monitoring is in place, and the DfE standard sets out what that looks like in practice: named roles including a responsible governor, an annual review, filtering with blocklists no administrator can override, and a monitoring plan with weekly reports and immediate reports for high-risk incidents. The half most often underdone is monitoring, because it produces alerts a named person has to review and record acting on.

What is the DfE plan technology for your school service?

It is the free service the DfE names on the parent page and on every core standard page as the way to work towards meeting the standards; the IT support standard describes it as helping schools measure progress. It gives you a self-reported position. A baseline carried out by someone who can see your tenant, your network cabinet and your contracts finds the gaps a questionnaire cannot, in particular the difference between a control you own and a control that is switched on. Use both.

We are a multi-academy trust. Does this work differently?

The standards are the same but the delivery problem is not. A trust typically inherits schools with different networks, different suppliers, different contract end dates and very different starting positions, so a single trust-wide compliance statement is rarely true on day one. What works is a per-school baseline against the twelve areas, then a trust-level roadmap that sequences the work by risk and by when each contract can actually be changed. The governance standard names a trust IT director among the people the SLT digital lead works with, which is the right place to hold the trust-wide view.

Know where you stand before someone asks

An honest baseline against all twelve standards, including the ones you fail, with a dated plan against each. The findings are yours either way.