In short: The Department for Education expects schools, colleges and trusts in England to meet six core digital and technology standards by 2030: broadband internet, cyber security, digital leadership and governance, filtering and monitoring, network switching, and wireless network. They are expectations rather than statute, but they now appear in grant conditions and procurement rules, which gives them practical force. A November 2025 update added clearer benchmarks per standard and progress reporting expectations from 2026, so the useful posture is a documented baseline and a dated roadmap rather than a claim of compliance.

Who this is for
  • You have been asked to evidence progress against the standards and are not sure where you stand
  • A grant condition or framework bid has raised Cyber Essentials and you need to know which level
  • You are a trust inheriting schools with different networks, suppliers and contract dates
  • You have filtering in place and are less confident about the monitoring half
What it costs to leave it

The standards are rarely failed on the technology. They are failed on evidence: filtering is bought and monitoring alerts go unreviewed, a policy asserts patching that nobody can produce a report for, and the named accountable leader turns out not to exist. All three are cheap to fix in advance and expensive to meet during an inspection or a funding round.

The six standards

  • Broadband internet. A connection sized for the way the school actually uses it, with resilience appropriate to how much teaching depends on it.
  • Cyber security. The largest of the six in practice. Cyber Essentials is now the expected minimum, with Cyber Essentials Plus required for some grant conditions and framework procurement.
  • Digital leadership and governance. A named senior leader accountable for digital, with governors informed well enough to challenge. This is the one most often missing entirely.
  • Filtering and monitoring. The standard that overlaps directly with safeguarding duties under Keeping Children Safe in Education, which is why it usually gets attention first.
  • Network switching. Switching capable of carrying what the school now runs, rather than what it ran when the cabinet was last touched.
  • Wireless network. Coverage and capacity across teaching spaces, which is a survey question rather than an access-point-count question.

The DfE publishes these in full, and they are the authority rather than this page. What follows is what they mean in practice for a school or trust trying to work out where to start.

What the November 2025 update changed

Three things, and the third is the one that changes behaviour.

  • Clearer benchmarks for each standard, so it is more obvious what meeting one looks like.
  • Guidance on funding available to support compliance.
  • Progress reporting expectations beginning in 2026. The expectation is now that you assess your current capability, build a roadmap and evidence improvement over time.

That last point is worth reading carefully, because it changes what a good answer looks like. Declaring compliance in one go was never realistic for most schools. Showing a documented baseline, including the standards you currently fail, with a dated plan against each, is both achievable and a stronger position under scrutiny than an unevidenced claim.

Cyber security: which Cyber Essentials do you actually need?

Cyber Essentials is now the expected minimum under the cyber security standard. Cyber Essentials Plus is required for some ESFA and DfE grant conditions and for procurement through certain CCS frameworks.

The distinction is not cosmetic. Cyber Essentials is a verified self-assessment; Plus adds independent technical testing against a sample of your devices. The work and the lead time differ substantially, so if a funding deadline is driving this, establish which one is actually required before you start. Assuming the wrong one costs weeks you may not have. We have written up the difference in full in Cyber Essentials vs Cyber Essentials Plus, and there is a readiness checklist if you would rather assess yourself first.

Filtering and monitoring, and the half that gets missed

This standard overlaps directly with safeguarding duties under Keeping Children Safe in Education, which is why it usually receives attention before the others.

Filtering is the easy half. It is straightforward to buy, and straightforward to demonstrate: a product is in place and categories are blocked. Monitoring is where inspections find gaps, because it produces alerts that a named person has to review, act on and record acting on. A monitoring system whose alerts nobody reads satisfies the purchase order and not the duty.

The practical test is not whether you have a product. It is whether you can say who reviewed last week's alerts, what they did about them, and where that is written down.

Digital leadership and governance

The standard most often missing entirely, and the cheapest to fix. It asks for a named senior leader accountable for digital, and governors informed well enough to ask useful questions.

In practice, the failure mode is that digital sits with whoever happens to be interested, reporting to nobody in particular, with governors seeing an IT item only when something has gone wrong. Naming an accountable leader and putting a short standing item on the governance calendar costs nothing and closes the standard.

If you are a multi-academy trust

The standards are identical; the delivery problem is not. A trust typically inherits schools with different networks, different suppliers, different contract end dates and genuinely different starting positions, so a single trust-wide compliance statement is rarely true on day one.

What works is a per-school baseline against the six standards, then a trust-level roadmap sequenced by risk and by when each contract can actually be changed. Attempts to standardise everything at once tend to stall on the school with the longest remaining contract, and the delay is then read as a trust-wide failure rather than a single procurement date.

Where to start

Baseline honestly, including the standards you fail. A documented gap with a dated plan against it is a stronger position under scrutiny than an undocumented claim of compliance, and it is also what the progress reporting expectation is actually asking for.

We work with schools, colleges and trusts on exactly this, and the sector context sits on our education page. If a funding deadline or a bid is driving the timing, say so at the start: it changes the order the work should be done in.

Frequently asked

What are the DfE digital and technology standards?

Six core standards the Department for Education expects schools, colleges and trusts in England to meet by 2030: broadband internet, cyber security, digital leadership and governance, filtering and monitoring, network switching, and wireless network. They are standards rather than law, but they are increasingly referenced in funding conditions and procurement, which gives them practical force. A November 2025 update added clearer benchmarks for each standard, guidance on funding, and progress reporting expectations that begin in 2026.

Are the DfE digital standards mandatory?

Not in the sense that a statutory duty is mandatory, and treating that as the end of the answer is a mistake. They are expectations, but they now appear in grant conditions and framework procurement rules, so the practical consequence of not meeting them is losing access to funding or being unable to bid. The safeguarding-adjacent standards carry more weight again, because filtering and monitoring overlaps directly with duties under Keeping Children Safe in Education, which is statutory.

Do schools need Cyber Essentials?

It is now the expected minimum under the cyber security standard, and Cyber Essentials Plus is required for some ESFA and DfE grant conditions and for procurement through certain CCS frameworks. The distinction matters more than it looks: Cyber Essentials is a verified self-assessment while Plus adds independent technical testing, so the work involved and the lead time are meaningfully different. If a funding deadline is driving it, establish which one is actually required before starting, because assuming the wrong one costs weeks.

What does a school cyber security policy need to cover?

At minimum: who is accountable, what is being protected, the controls in place across access, devices, patching, backup and email, how incidents are reported and handled, and when the policy is next reviewed. What separates a policy that survives scrutiny from one that does not is evidence rather than wording. A policy asserting that patching happens is worth very little without a report showing patch compliance, and an inspector or an insurer will ask for the second. Write the policy around what you can actually evidence, then close the gaps that exposes.

How does filtering and monitoring relate to KCSIE?

They are the same requirement approached from two directions. Keeping Children Safe in Education places a safeguarding duty on schools to ensure children are safe online, and the DfE's filtering and monitoring standards set out what the technology side of that duty looks like in practice. The part most often underdone is monitoring rather than filtering: blocking is straightforward to buy and easy to demonstrate, whereas monitoring produces alerts that a named person has to review and act on, and that process is where inspections find gaps.

What does progress reporting from 2026 mean for us?

The November 2025 update introduced clearer benchmarks per standard and an expectation that schools assess their current position, build a roadmap and evidence improvement over time rather than declaring compliance in one go. Practically, that means the useful first step is an honest baseline against each of the six standards, including the ones you fail, because a documented gap with a dated plan against it reads far better than an undocumented claim of compliance that does not survive a question.

We are a multi-academy trust. Does this work differently?

The standards are the same but the delivery problem is not. A trust typically inherits schools with different networks, different suppliers, different contract end dates and very different starting positions, so a single trust-wide compliance statement is rarely true on day one. What works is a per-school baseline against the six standards, then a trust-level roadmap that sequences the work by risk and by when each contract can actually be changed. Trying to standardise everything simultaneously usually stalls on the school with the longest remaining contract.

Know where you stand before someone asks

An honest baseline against all six standards, including the ones you fail, with a dated plan against each. The findings are yours either way.