England — DfE digital and technology standards for schools and colleges
The DfE's standards that KCSIE directs governing bodies to. Curated here in full: the filtering and monitoring core standard and the cyber security core standard — the two sets that generate vendor requirements. (The wider suite — broadband, wireless, cloud, devices, accessibility — is linked from the same guidance collection.)
Applicability to EdTech
- Filtering and monitoring (FILTERING-AND-MONITORING.md): roles assigned, provision reviewed at least annually, harmful content blocked without unreasonably impacting teaching, and effective monitoring strategies. Vendor consequences: headsets and the platform must work under school filtering; expect "does your service support our monitoring strategy?" questions.
- Cyber security (CYBER-SECURITY.md): annual risk assessment reviewed termly, cyber awareness plans, anti-malware/firewall, account and access-privilege controls (MFA for cloud services), licensing/patching, backup plans, and attack reporting. These flow into due-diligence questionnaires for cloud vendors serving English schools — our SOC 2 mapping should reference them.
Contents
| Document | Covers |
|---|---|
| FILTERING-AND-MONITORING.md | The filtering and monitoring core standard, in full |
| CYBER-SECURITY.md | The cyber security core standard, in full |
Enforcement
Non-statutory in themselves but enforced through KCSIE ("must have regard") and Ofsted inspection of safeguarding effectiveness.
Related
- KCSIE — points schools at these standards
- SOC 2 — our evidence artefact for the cyber standard
- US CISA CPG — the US voluntary sibling
Sources
Meta
Standard text is reproduced verbatim from the gov.uk guidance pages by tools/gov-uk/build_dfe_standards.py; each page's "Updated" date is pinned (currently 25 August 2026), so verify fails as soon as the DfE revises a standard.