PRACTICAL GUIDE FOR SCHOOLS AND MATS

DfE Digital and Technology Standards for Schools

Understand the six core standards, review the wider technology standards and identify the evidence your school needs to demonstrate its current position.

Use this practical guide to turn standards gaps into clear priorities, responsible ownership and a costed technology roadmap.

Independent practical guidance from asitplan.
Not affiliated with or endorsed by the Department for Education.
OFFICIAL SOURCE
Department for Education
Meeting digital and technology standards in schools and colleges
LAST UPDATED
Official guidance: 24 June 2026
INDEPENDENT RESOURCE
This page last reviewed: August 2026
Technical reviewer: Rob Lloyd
SCOPE
This resource provides a practical interpretation. It does not replace the official guidance and should not be treated as legal, regulatory or certification advice.

What are the DfE Digital and Technology Standards?

The DfE Digital and Technology Standards describe how schools and colleges can use appropriate digital infrastructure, technology and governance.

The guidance covers twelve areas, including connectivity, networks, cyber security, filtering and monitoring, devices, accessibility, cloud services, IT support and digital leadership.

Six of these areas are identified as core standards that schools and colleges should work towards meeting by 2030:

  • broadband internet
  • wireless networking
  • network switching
  • digital leadership and governance
  • filtering and monitoring
  • cyber security

The remaining standards continue to support effective, safe and sustainable use of technology. A school should therefore avoid treating the six core standards as the only areas requiring review.

At a glance

  • Six standards are identified as core standards for 2030.
  • The published guidance covers twelve technology areas in total.
  • Meeting a standard requires more than having a written policy.
  • In practice, asitplan suggests: Schools need technical evidence, accountable ownership and a plan for unresolved gaps.
  • In practice, asitplan suggests: Priorities should reflect risk, service dependency, affordability and safeguarding impact.

The six core standards for 2030

The DfE currently identifies six areas as core standards. These standards address essential connectivity, network infrastructure, governance, online safety and cyber resilience.

The summaries below are plain-English interpretations. Each card links to the corresponding official DfE section for the full published guidance.

Broadband internet

Provide connectivity with suitable capacity, resilience and support for the school’s operational, safeguarding and educational needs.

A useful leadership question is...

  • • Does the connection continue to meet current demand?
  • • Which essential services are affected if the primary connection fails?
  • • Is continuity provision documented and tested?
  • • Are contract, capacity and resilience decisions reviewed before renewal?

Example evidence may include...

  • • current service contract
  • • network and connectivity diagram
  • • capacity or utilisation report
  • • continuity or failover test record
  • • documented ownership and escalation arrangements
View the official broadband standard

Wireless network

Provide secure and reliable wireless service that supports users, devices and teaching throughout the areas where connectivity is needed.

A useful leadership question is...

  • • Does the current wireless network meet actual user and device demand?
  • • Are coverage, capacity and performance reviewed using evidence?
  • • Is wireless access centrally managed and appropriately secured?
  • • Are upgrade decisions based on need rather than technology age alone?

Example evidence may include...

  • • wireless design or coverage information
  • • access-point inventory
  • • central-management evidence
  • • performance or incident records
  • • security configuration review
  • • documented improvement actions
View the official wireless network standard

Network switching

Maintain secure, manageable and reliable switching infrastructure that supports wired services, wireless connectivity and critical school systems.

A useful leadership question is...

  • • Is every managed switch known and recorded?
  • • Is the switching estate supported and centrally manageable?
  • • Are security configuration and administrative access reviewed?
  • • Are resilience and power dependencies understood?

Example evidence may include...

  • • switch asset register
  • • topology diagram
  • • support and warranty information
  • • configuration backup evidence
  • • access review
  • • resilience and power arrangements
View the official network switching standard

Digital leadership and governance

Establish clear leadership, responsibility and decision-making for the safe, effective and sustainable use of technology.

A useful leadership question is...

  • • Who is accountable for digital strategy?
  • • How are technology risks escalated?
  • • How are IT priorities connected to school improvement and finance?
  • • How is progress reported to governors or trustees?
  • • Which decisions belong to leadership and which belong to IT support?

Example evidence may include...

  • • named leadership ownership
  • • current digital or technology strategy
  • • steering-group records
  • • risk register
  • • costed improvement roadmap
  • • governor or trustee reporting
  • • annual review schedule
View the official digital leadership standard

Filtering and monitoring

Support a safe online environment through appropriate technology, clear ownership, effective review and safeguarding-led decision-making.

A useful leadership question is...

  • • When was filtering and monitoring last reviewed?
  • • Were safeguarding, leadership, IT and user needs represented?
  • • Has the organisation tested whether expected categories are handled appropriately?
  • • How are concerns, false positives and possible failures escalated?
  • • Is review evidence retained with agreed actions and ownership?

Example evidence may include...

  • • annual review record
  • • filtering and monitoring policy
  • • roles and responsibilities
  • • supervised test results
  • • provider configuration or assurance information
  • • recorded findings and actions
  • • leadership approval

Cyber security

Protect accounts, devices, systems and data using proportionate security controls, clear ownership and evidence that those controls operate in practice.

A useful leadership question is...

  • • Are technology assets and systems accurately recorded?
  • • Are accounts, privileges and administrative roles reviewed?
  • • Are vulnerabilities and security updates managed?
  • • Can important systems and data be recovered?
  • • Is there a tested incident-response process?
  • • Can leadership see unresolved cyber risks?

Example evidence may include...

  • • asset and system registers
  • • privileged-access review
  • • security-update reporting
  • • backup and recovery test
  • • incident-response plan
  • • staff training records
  • • current risk assessment
View the official cyber security standard

The wider standards supporting effective school technology

The six core standards should not be assessed in isolation. The wider standards cover important dependencies such as cabling, devices, servers, cloud services, accessibility and the quality of IT support.

Cloud solutions

Review how cloud services are selected, secured, accessed, backed up and managed throughout their lifecycle.

Leadership question: Who owns each important cloud service, its data and its exit plan?

Example evidence: service register, owner, contract, access model, data assessment, backup arrangements, continuity plan and exit requirements

Digital accessibility

Ensure digital technology, content and services can be used by people with different needs and that accessibility is considered during procurement, design and review.

Leadership question: How is accessibility considered before technology is purchased or introduced?

Example evidence: accessibility statements, procurement criteria, user consultation, staff guidance, testing records and improvement actions

IT support

Plan, commission and review IT support so that service delivery, responsibility, strategic advice and improvement activity remain clear.

Leadership question: Does the support arrangement maintain technology, manage risk and provide reliable evidence for strategic decisions?

Example evidence: service specification, SLA, ticket reporting, escalation model, service-review records, asset responsibilities and improvement plan

Laptops, desktops and tablets

Select and manage devices that remain secure, supportable, suitable for their users and sustainable within the school’s replacement plan.

Leadership question: Are device decisions based on user need, supportability, condition and total lifecycle cost?

Example evidence: asset register, device standards, support status, warranty data, condition information, assigned use and replacement roadmap

Network cabling

Maintain cabling that supports current network performance, resilience and future infrastructure needs.

Leadership question: Can the school explain what cabling exists, how it was tested and whether it supports current requirements?

Example evidence: cabling diagrams, installation records, test certificates, cabinet records, labelling and identified remediation

Servers and storage

Manage servers and storage according to service need, supportability, security, resilience, recoverability and environmental requirements.

Leadership question: Which school services rely on each server, and what happens if it becomes unavailable?

Example evidence: server inventory, operating-system support status, warranty data, dependency map, backup evidence, recovery test and replacement plan

The standards are connected

Technology standards rarely fail in isolation.

A wireless problem may be caused by switching, cabling, broadband capacity or poor device design. A cyber-security concern may depend on asset accuracy, IT support, identity management, backup or leadership ownership.

A useful assessment should therefore identify dependencies rather than treating each standard as a separate checklist.

asitplan implementation model
Leadership and governance
Cyber security and filtering
Broadband, switching, wireless and cabling
Cloud, servers, storage and devices
Accessible and effective technology use

From standards assessment to measurable improvement

Audit capabilities

audit

Understand the current position

Assess each standard, collect current evidence and record where confidence is limited. A useful audit should distinguish confirmed compliance, partial implementation, unresolved gaps and areas where further evidence is required.

  • record current evidence
  • identify standards gaps
  • document dependencies
  • assign an evidence owner
  • record confidence and review dates

strategise

Decide what should happen next

Translate findings into practical treatment options. Consider risk, safeguarding impact, service dependency, affordability, asset lifecycle and the order in which improvements must be delivered.

  • prioritise recommendations
  • identify immediate mitigations
  • estimate cost ranges
  • record dependencies
  • build a phased roadmap
Strategise and roadmapping
Achieve compliance and progress

achieve

Deliver and evidence progress

Give each approved action an owner, target review point and clear completion evidence. Maintain an up-to-date view of progress so leadership can understand what has improved and which risks have been temporarily accepted.

  • record accountable ownership
  • monitor roadmap progress
  • retain completion evidence
  • review residual risk
  • report clearly to leadership

Note: asitplan currently supports action tracking and roadmap oversight through its integrated platform features.

What evidence should a school retain?

A policy or verbal assurance does not always demonstrate that a control operates in practice. Evidence should be current, attributable and proportionate to the importance of the service or risk being assessed.

Strong evidence

  • • dated system or platform export
  • • current configuration report
  • • completed recovery or failover test
  • • approved review with recorded decisions
  • • asset or account register reconciled against source data
  • • supplier evidence checked against the service being delivered

Supporting evidence

  • • recent screenshot
  • • service report
  • • completed checklist
  • • meeting record with supporting documents
  • • sample-based physical verification

Weak evidence

  • • verbal assurance
  • • undated screenshot
  • • inherited policy with no known owner
  • • policy without operating evidence
  • • assumption based only on equipment age
  • • statement that a supplier is “dealing with it”

These are asitplan evidence-quality examples. They are not a DfE-prescribed grading system.

Who should be involved?

ActivityLeadershipFinance/operationsIT supportDSL/safeguardingGovernors/trustees
Agree review scopeAccountableConsultedResponsible for technical scopeConsulted where relevantInformed
Supply technical evidenceInformedInformedResponsibleConsulted where relevantInformed
Review filtering and monitoringAccountableConsultedTechnical inputSafeguarding leadOversight
Prioritise investmentAccountableFinancial inputTechnical adviceConsulted where relevantOversight
Accept material residual riskAccountableConsultedAdvisesConsulted where relevantOversight
Monitor roadmap progressAccountableConsultedResponsible for assigned activityConsulted where relevantReceives assurance

This is a suggested responsibility model. Local governance, employment arrangements and support contracts may allocate responsibilities differently.

Where should a school start?

1

Confirm ownership

Identify the senior leader accountable for digital strategy and confirm who supplies technical, financial and safeguarding evidence.

2

Assess the six core standards

For each core standard, record the current position, supporting evidence, known gaps and evidence confidence.

3

Review wider dependencies

Check whether cloud services, cabling, devices, servers, storage, accessibility or IT support affect the core-standard findings.

4

Prioritise risk and impact

Separate urgent risk treatment from planned improvement, routine maintenance and temporarily accepted exceptions.

5

Build a costed roadmap

Give each action an owner, treatment, estimated cost range, dependency, target period and completion evidence.

6

Report and review

Provide leadership with a concise view of current risks, investment requirements, agreed actions and progress since the previous review.

This six-step method is an asitplan implementation suggestion and is not presented as an official DfE-prescribed process.

Common misunderstandings about the DfE standards

“We have an IT provider, so the standards are the provider’s responsibility.”

An IT provider may supply technical evidence and deliver agreed improvements, but strategic decisions, risk acceptance, safeguarding and financial approval remain organisational governance matters. Exact responsibilities should be documented locally.

“Old equipment automatically fails the standard.”

Age is useful planning information, but decisions should also consider support status, security, condition, performance, service criticality, repairability and future requirements.

“Meeting the six core standards means the other standards can be ignored.”

The official guidance says schools and colleges should continue to refer to all the standards to support effective use of digital technology.

“A green RAG status means the standard requires no further review.”

Technology, guidance, suppliers and organisational requirements change. Evidence should have an owner and a review point.

“A written policy proves that the control is operating.”

Policies establish intention and responsibility. Operational evidence is normally needed to demonstrate that the expected process or control is being followed.

Understand your current standards position

Use the free asitplan health check to establish an initial view of your current technology position. For a complete assessment, combine questionnaire responses with current technical evidence, asset information and leadership review.

The health check provides an initial indication. It is not DfE certification and does not replace a complete, evidence-led review.

Turn standards evidence into an achievable technology plan

Assess your current position, understand the dependencies and build a prioritised, costed roadmap that leadership can review and act upon.

asitplan supports assessment, evidence, planning and reporting.
It does not provide DfE certification or guarantee compliance.