The Department for Education has made another round of amendments to its Meeting digital and technology standards in schools and colleges manual, with the latest changes published on 25 August. Taken together, this year's updates focus on three areas: generative AI in filtering and monitoring, the new Cyber Essentials 2026 requirements, and Wi-Fi 7. They are worth working through before the first safeguarding and IT review of term.
What has changed in 2026
- Generative AI and filtering (25 August and 10 June). The filtering and monitoring core standard now directs schools to the DfE's Generative AI: product safety standards whenever they introduce a specific AI product. Your annual review should now cover where AI tools are used across web and in-app products, and whether your filtering and monitoring solution can actually handle real-time, dynamic, personalised and AI-generated content. Rolling out a new generative AI tool is also listed as a trigger for reviewing provision outside the annual cycle.
- Cyber Essentials 2026 (24 June). The cyber security core standard has been revised to reflect the new technical requirements the NCSC introduced in Cyber Essentials 2026. If you hold or are working towards certification, compare your current controls against the updated requirements.
- Wi-Fi 7 (17 April). The wireless network standard now includes Wi-Fi 7 requirements. Importantly, the DfE clarifies that schools only need to upgrade when their existing wireless network no longer meets their needs, so this is not a mandated refresh.
- Security updates (7 April). The cyber security standard now makes clear that fixing a vulnerability can involve changes beyond applying a software patch, which is relevant to how you evidence remediation.
- Report Fraud (12 February). References to Action Fraud have been updated to its new name, Report Fraud. Check your incident response plans and staff guidance still point to the right place.
- Filtering clarifications (January and February). The DfE added further detail on filtering solutions to the technical requirements and clarified timing: schools and colleges should already be meeting the filtering and monitoring standard now.
Worth rechecking this term
The filtering and monitoring standard is one of six core standards, and the DfE expects all six to be met by 2030. The current text is explicit on several points IT teams should verify: IWF and CTIRU blocklists must be in place and must not be possible to disable or override by anyone, including system administrators at school, trust or local authority level; any temporary filtering exceptions must be approved and documented by the responsible SLT member; and monitoring plans should include weekly incident reports, immediate alerts for high-risk incidents, and a documented process for recording what action was taken.
Source: Department for Education · Read the update
(NOTE: This has been abbreviated by AI so double check things)

Recommended Comments