DfE Digital and Technology Standards for Schools
Understand the six core standards, review the wider technology standards and identify the evidence your school needs to demonstrate its current position.
Use this practical guide to turn standards gaps into clear priorities, responsible ownership and a costed technology roadmap.
Not affiliated with or endorsed by the Department for Education.
What are the DfE Digital and Technology Standards?
The DfE Digital and Technology Standards describe how schools and colleges can use appropriate digital infrastructure, technology and governance.
The guidance covers twelve areas, including connectivity, networks, cyber security, filtering and monitoring, devices, accessibility, cloud services, IT support and digital leadership.
Six of these areas are identified as core standards that schools and colleges should work towards meeting by 2030:
- broadband internet
- wireless networking
- network switching
- digital leadership and governance
- filtering and monitoring
- cyber security
The remaining standards continue to support effective, safe and sustainable use of technology. A school should therefore avoid treating the six core standards as the only areas requiring review.
At a glance
- Six standards are identified as core standards for 2030.
- The published guidance covers twelve technology areas in total.
- Meeting a standard requires more than having a written policy.
- In practice, asitplan suggests: Schools need technical evidence, accountable ownership and a plan for unresolved gaps.
- In practice, asitplan suggests: Priorities should reflect risk, service dependency, affordability and safeguarding impact.
The six core standards for 2030
The DfE currently identifies six areas as core standards. These standards address essential connectivity, network infrastructure, governance, online safety and cyber resilience.
The summaries below are plain-English interpretations. Each card links to the corresponding official DfE section for the full published guidance.
Broadband internet
Provide connectivity with suitable capacity, resilience and support for the school’s operational, safeguarding and educational needs.
A useful leadership question is...
- • Does the connection continue to meet current demand?
- • Which essential services are affected if the primary connection fails?
- • Is continuity provision documented and tested?
- • Are contract, capacity and resilience decisions reviewed before renewal?
Example evidence may include...
- • current service contract
- • network and connectivity diagram
- • capacity or utilisation report
- • continuity or failover test record
- • documented ownership and escalation arrangements
Wireless network
Provide secure and reliable wireless service that supports users, devices and teaching throughout the areas where connectivity is needed.
A useful leadership question is...
- • Does the current wireless network meet actual user and device demand?
- • Are coverage, capacity and performance reviewed using evidence?
- • Is wireless access centrally managed and appropriately secured?
- • Are upgrade decisions based on need rather than technology age alone?
Example evidence may include...
- • wireless design or coverage information
- • access-point inventory
- • central-management evidence
- • performance or incident records
- • security configuration review
- • documented improvement actions
Network switching
Maintain secure, manageable and reliable switching infrastructure that supports wired services, wireless connectivity and critical school systems.
A useful leadership question is...
- • Is every managed switch known and recorded?
- • Is the switching estate supported and centrally manageable?
- • Are security configuration and administrative access reviewed?
- • Are resilience and power dependencies understood?
Example evidence may include...
- • switch asset register
- • topology diagram
- • support and warranty information
- • configuration backup evidence
- • access review
- • resilience and power arrangements
Digital leadership and governance
Establish clear leadership, responsibility and decision-making for the safe, effective and sustainable use of technology.
A useful leadership question is...
- • Who is accountable for digital strategy?
- • How are technology risks escalated?
- • How are IT priorities connected to school improvement and finance?
- • How is progress reported to governors or trustees?
- • Which decisions belong to leadership and which belong to IT support?
Example evidence may include...
- • named leadership ownership
- • current digital or technology strategy
- • steering-group records
- • risk register
- • costed improvement roadmap
- • governor or trustee reporting
- • annual review schedule
Filtering and monitoring
Support a safe online environment through appropriate technology, clear ownership, effective review and safeguarding-led decision-making.
A useful leadership question is...
- • When was filtering and monitoring last reviewed?
- • Were safeguarding, leadership, IT and user needs represented?
- • Has the organisation tested whether expected categories are handled appropriately?
- • How are concerns, false positives and possible failures escalated?
- • Is review evidence retained with agreed actions and ownership?
Example evidence may include...
- • annual review record
- • filtering and monitoring policy
- • roles and responsibilities
- • supervised test results
- • provider configuration or assurance information
- • recorded findings and actions
- • leadership approval
Cyber security
Protect accounts, devices, systems and data using proportionate security controls, clear ownership and evidence that those controls operate in practice.
A useful leadership question is...
- • Are technology assets and systems accurately recorded?
- • Are accounts, privileges and administrative roles reviewed?
- • Are vulnerabilities and security updates managed?
- • Can important systems and data be recovered?
- • Is there a tested incident-response process?
- • Can leadership see unresolved cyber risks?
Example evidence may include...
- • asset and system registers
- • privileged-access review
- • security-update reporting
- • backup and recovery test
- • incident-response plan
- • staff training records
- • current risk assessment
The wider standards supporting effective school technology
The six core standards should not be assessed in isolation. The wider standards cover important dependencies such as cabling, devices, servers, cloud services, accessibility and the quality of IT support.
Cloud solutions
Review how cloud services are selected, secured, accessed, backed up and managed throughout their lifecycle.
Example evidence: service register, owner, contract, access model, data assessment, backup arrangements, continuity plan and exit requirements
Digital accessibility
Ensure digital technology, content and services can be used by people with different needs and that accessibility is considered during procurement, design and review.
Example evidence: accessibility statements, procurement criteria, user consultation, staff guidance, testing records and improvement actions
IT support
Plan, commission and review IT support so that service delivery, responsibility, strategic advice and improvement activity remain clear.
Example evidence: service specification, SLA, ticket reporting, escalation model, service-review records, asset responsibilities and improvement plan
Laptops, desktops and tablets
Select and manage devices that remain secure, supportable, suitable for their users and sustainable within the school’s replacement plan.
Example evidence: asset register, device standards, support status, warranty data, condition information, assigned use and replacement roadmap
Network cabling
Maintain cabling that supports current network performance, resilience and future infrastructure needs.
Example evidence: cabling diagrams, installation records, test certificates, cabinet records, labelling and identified remediation
Servers and storage
Manage servers and storage according to service need, supportability, security, resilience, recoverability and environmental requirements.
Example evidence: server inventory, operating-system support status, warranty data, dependency map, backup evidence, recovery test and replacement plan
The standards are connected
Technology standards rarely fail in isolation.
A wireless problem may be caused by switching, cabling, broadband capacity or poor device design. A cyber-security concern may depend on asset accuracy, IT support, identity management, backup or leadership ownership.
A useful assessment should therefore identify dependencies rather than treating each standard as a separate checklist.
From standards assessment to measurable improvement

audit
Understand the current position
Assess each standard, collect current evidence and record where confidence is limited. A useful audit should distinguish confirmed compliance, partial implementation, unresolved gaps and areas where further evidence is required.
- record current evidence
- identify standards gaps
- document dependencies
- assign an evidence owner
- record confidence and review dates
strategise
Decide what should happen next
Translate findings into practical treatment options. Consider risk, safeguarding impact, service dependency, affordability, asset lifecycle and the order in which improvements must be delivered.
- prioritise recommendations
- identify immediate mitigations
- estimate cost ranges
- record dependencies
- build a phased roadmap


achieve
Deliver and evidence progress
Give each approved action an owner, target review point and clear completion evidence. Maintain an up-to-date view of progress so leadership can understand what has improved and which risks have been temporarily accepted.
- record accountable ownership
- monitor roadmap progress
- retain completion evidence
- review residual risk
- report clearly to leadership
Note: asitplan currently supports action tracking and roadmap oversight through its integrated platform features.
What evidence should a school retain?
A policy or verbal assurance does not always demonstrate that a control operates in practice. Evidence should be current, attributable and proportionate to the importance of the service or risk being assessed.
Strong evidence
- • dated system or platform export
- • current configuration report
- • completed recovery or failover test
- • approved review with recorded decisions
- • asset or account register reconciled against source data
- • supplier evidence checked against the service being delivered
Supporting evidence
- • recent screenshot
- • service report
- • completed checklist
- • meeting record with supporting documents
- • sample-based physical verification
Weak evidence
- • verbal assurance
- • undated screenshot
- • inherited policy with no known owner
- • policy without operating evidence
- • assumption based only on equipment age
- • statement that a supplier is “dealing with it”
These are asitplan evidence-quality examples. They are not a DfE-prescribed grading system.
Who should be involved?
| Activity | Leadership | Finance/operations | IT support | DSL/safeguarding | Governors/trustees |
|---|---|---|---|---|---|
| Agree review scope | Accountable | Consulted | Responsible for technical scope | Consulted where relevant | Informed |
| Supply technical evidence | Informed | Informed | Responsible | Consulted where relevant | Informed |
| Review filtering and monitoring | Accountable | Consulted | Technical input | Safeguarding lead | Oversight |
| Prioritise investment | Accountable | Financial input | Technical advice | Consulted where relevant | Oversight |
| Accept material residual risk | Accountable | Consulted | Advises | Consulted where relevant | Oversight |
| Monitor roadmap progress | Accountable | Consulted | Responsible for assigned activity | Consulted where relevant | Receives assurance |
This is a suggested responsibility model. Local governance, employment arrangements and support contracts may allocate responsibilities differently.
Where should a school start?
Confirm ownership
Identify the senior leader accountable for digital strategy and confirm who supplies technical, financial and safeguarding evidence.
Assess the six core standards
For each core standard, record the current position, supporting evidence, known gaps and evidence confidence.
Review wider dependencies
Check whether cloud services, cabling, devices, servers, storage, accessibility or IT support affect the core-standard findings.
Prioritise risk and impact
Separate urgent risk treatment from planned improvement, routine maintenance and temporarily accepted exceptions.
Build a costed roadmap
Give each action an owner, treatment, estimated cost range, dependency, target period and completion evidence.
Report and review
Provide leadership with a concise view of current risks, investment requirements, agreed actions and progress since the previous review.
This six-step method is an asitplan implementation suggestion and is not presented as an official DfE-prescribed process.
Common misunderstandings about the DfE standards
“We have an IT provider, so the standards are the provider’s responsibility.”
An IT provider may supply technical evidence and deliver agreed improvements, but strategic decisions, risk acceptance, safeguarding and financial approval remain organisational governance matters. Exact responsibilities should be documented locally.
“Old equipment automatically fails the standard.”
Age is useful planning information, but decisions should also consider support status, security, condition, performance, service criticality, repairability and future requirements.
“Meeting the six core standards means the other standards can be ignored.”
The official guidance says schools and colleges should continue to refer to all the standards to support effective use of digital technology.
“A green RAG status means the standard requires no further review.”
Technology, guidance, suppliers and organisational requirements change. Evidence should have an owner and a review point.
“A written policy proves that the control is operating.”
Policies establish intention and responsibility. Operational evidence is normally needed to demonstrate that the expected process or control is being followed.
Understand your current standards position
Use the free asitplan health check to establish an initial view of your current technology position. For a complete assessment, combine questionnaire responses with current technical evidence, asset information and leadership review.
The health check provides an initial indication. It is not DfE certification and does not replace a complete, evidence-led review.
Turn standards evidence into an achievable technology plan
Assess your current position, understand the dependencies and build a prioritised, costed roadmap that leadership can review and act upon.
asitplan supports assessment, evidence, planning and reporting.
It does not provide DfE certification or guarantee compliance.