Jump to content

DfE refreshes the digital and technology standards manual


The Department for Education has made another round of amendments to its Meeting digital and technology standards in schools and colleges manual, with the latest changes published on 25 August. Taken together, this year's updates focus on three areas: generative AI in filtering and monitoring, the new Cyber Essentials 2026 requirements, and Wi-Fi 7. They are worth working through before the first safeguarding and IT review of term.

 

What has changed in 2026

  • Generative AI and filtering (25 August and 10 June). The filtering and monitoring core standard now directs schools to the DfE's Generative AI: product safety standards whenever they introduce a specific AI product. Your annual review should now cover where AI tools are used across web and in-app products, and whether your filtering and monitoring solution can actually handle real-time, dynamic, personalised and AI-generated content. Rolling out a new generative AI tool is also listed as a trigger for reviewing provision outside the annual cycle.
  • Cyber Essentials 2026 (24 June). The cyber security core standard has been revised to reflect the new technical requirements the NCSC introduced in Cyber Essentials 2026. If you hold or are working towards certification, compare your current controls against the updated requirements.
  • Wi-Fi 7 (17 April). The wireless network standard now includes Wi-Fi 7 requirements. Importantly, the DfE clarifies that schools only need to upgrade when their existing wireless network no longer meets their needs, so this is not a mandated refresh.
  • Security updates (7 April). The cyber security standard now makes clear that fixing a vulnerability can involve changes beyond applying a software patch, which is relevant to how you evidence remediation.
  • Report Fraud (12 February). References to Action Fraud have been updated to its new name, Report Fraud. Check your incident response plans and staff guidance still point to the right place.
  • Filtering clarifications (January and February). The DfE added further detail on filtering solutions to the technical requirements and clarified timing: schools and colleges should already be meeting the filtering and monitoring standard now.

 

Worth rechecking this term

The filtering and monitoring standard is one of six core standards, and the DfE expects all six to be met by 2030. The current text is explicit on several points IT teams should verify: IWF and CTIRU blocklists must be in place and must not be possible to disable or override by anyone, including system administrators at school, trust or local authority level; any temporary filtering exceptions must be approved and documented by the responsible SLT member; and monitoring plans should include weekly incident reports, immediate alerts for high-risk incidents, and a documented process for recording what action was taken.

 

Source: Department for Education · Read the update

 

(NOTE: This has been abbreviated by AI so double check things)


User Feedback

Recommended Comments

itskdog

Posted

Strongly doubt there will be too much buy-in from many SLTs without any enforcement.

 

As long as it's just a stick with no carrot, the expense and inconvenience will put people off.

  • Like 3
synaesthesia

Posted

1 hour ago, itskdog said:

Strongly doubt there will be too much buy-in from many SLTs without any enforcement.

 

As long as it's just a stick with no carrot, the expense and inconvenience will put people off.

Not all that much has changed which is likely to cost anything, there does appear to be clarification on cyberessentials as the DfE is very specifically not saying anything about MFA for pupils so CE is absolutely entirely a choice for anyone other than FE. That at least has removed one of the bigger concerns.

  • Like 1
itskdog

Posted

3 hours ago, synaesthesia said:

Not all that much has changed which is likely to cost anything, there does appear to be clarification on cyberessentials as the DfE is very specifically not saying anything about MFA for pupils so CE is absolutely entirely a choice for anyone other than FE. That at least has removed one of the bigger concerns.

 

By cost I was more talking about things like SSO services, patching solutions for everything other than the OS (to meet the 14-day deadline), replacing servers to have a supported OS, etc. that were already in there before, it was more that there's still no enforcement even in the updated version, which will affect the number of schools who will be ready by 2030.

 

And of course even MFA for staff will get pushback from technophobic SLT members, and you can't really have an exception for them as otherwise everyone else will complain and you can't say "Even XYZ has to do it, we're not even making an exception for them".

synaesthesia

Posted

2 minutes ago, itskdog said:

 

By cost I was more talking about things like SSO services, patching solutions for everything other than the OS (to meet the 14-day deadline), replacing servers to have a supported OS, etc. that were already in there before, it was more that there's still no enforcement even in the updated version, which will affect the number of schools who will be ready by 2030.

 

And of course even MFA for staff will get pushback from technophobic SLT members, and you can't really have an exception for them as otherwise everyone else will complain and you can't say "Even XYZ has to do it, we're not even making an exception for them".

Yeah but if anyone doesn't have MFA in for all staff already, regardless of SLT opinion, they are failing the school and the school are failing themselves. I'd have my "gun and badge" on the table before they brushed that off.

 

loxford01

Posted

And now they've published more amendments on 8th and 16th September. How do we stay compliant with changes every few months?



Guest
Add a comment...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.




×
×
  • Create New...