iso27001partnersUK certification, costed Get a cost estimate

DfE cyber security standards for schools and colleges: what suppliers are asked

Written from the standards themselves · Editor-reviewed · Checked against the current editions on 1 October 2026
By the iso27001partners.co.uk editorial team · Published 1 October 2026 · Last reviewed 1 October 2026 · 8 min read
4 primary sources cited on this page. How we check what is on this site
When procuring new contracts Supplier assessments

DfE tells schools to work with “third-party cloud suppliers to check that they are also meeting these standards by performing supplier assessments – this needs to be carried out when procuring new contracts”.

The Department for Education publishes seven cyber security standards for schools and colleges. They are written for the school, but several of them point outwards: at outsourced IT support, cloud services and software suppliers. If you sell technology to schools, this is where the questions in your next tender or renewal come from. This page sets out the standards from the DfE's own text and what each one asks of suppliers.

The seven standards

“Schools and colleges have a statutory responsibility to keep children and young people safe online as well as offline, as detailed in the statutory guidance Keeping children safe in education (KCSIE).” “The cyber security standards set out DfE’s recommended approach to meeting those expectations.”

DfE cyber security standards (titles verbatim) and what each can mean for a supplier (our reading)
StandardFor a supplier
1Conduct a cyber risk assessment annually and review every termYour service's risks may appear in the school's assessment; expect questions
2Create and implement a cyber awareness plan for students and staffIf your product holds logins, expect to explain what users must do
3Secure digital technology and data with anti-malware and a firewallHosted services: how malware and network threats are handled on your side
4Control and secure user accounts and access privilegesAccounts, privileged access, authentication on your service
5License digital technology and keep it up to dateYour patching and end-of-support dates; this standard names cloud suppliers
6Develop and implement a plan to back up your data and review this every yearWhere the school's data is backed up and how it is restored
7Report cyber attacksHow you will tell the school about an incident affecting its data

What the standards tell schools to ask suppliers

Supplier-facing lines in the DfE cyber security standards (verbatim)
WhoDfE saysStandard
Outsourced IT support“If your IT support is outsourced, then you will need to discuss with them how they are meeting the requirements of this standard.”Risk assessment
Outsourced IT support“you may wish to consider asking them whether they are certified with Cyber Essentials or Cyber Essentials Plus”Risk assessment
Digital technology suppliers“any digital technology suppliers to make sure they are also compliant with this standard”User accounts
Third-party cloud suppliers“third-party cloud suppliers to check that they are also meeting these standards by performing supplier assessments – this needs to be carried out when procuring new contracts”Licensing and updates
External IT support“If you have external IT support that will carry out the activities within this standard, make sure that your contract with them is compliant with General Data Protection Regulation (GDPR).”User accounts
Developers of commissioned software“make sure custom-built or commissioned applications are developed securely and align with the UK software security code of practice”Anti-malware and firewall

Supplier assessments at procurement

The cloud-supplier line is the one with a trigger: the check happens when a new contract is procured. A supplier with evidence ready — what controls apply to the service, who verified them and when — answers it once instead of per school.

The contract itself

For external IT support DfE adds that the contract must comply with data protection law. For what that contract has to contain when you process personal data for the school, see UK GDPR Article 28.

Cyber Essentials: colleges and schools differ

“Cyber Essentials is a government-backed certification that happens on an annual basis.”

Colleges

“Cyber Essentials is a requirement for colleges under their funding agreement.”

Schools

“Some schools may wish to complete it as part of their cyber security activities.” The standards are described as a way to work towards it. For suppliers, the Cyber Essentials question reaches you through the outsourced-IT line above.

Risk protection arrangement

One line in the standards is a firm obligation for some schools: “If you have risk protection arrangement, you must evidence that the relevant users have undertaken the free National Cyber Security Centre (NCSC) training.”

Where ISO 27001 fits (our reading)

The DfE standards do not mention ISO 27001. They are a short set of controls for a school; ISO 27001 is a management system for running controls like them. The overlap, by control title:

DfE standards and related ISO/IEC 27002:2022 control titles (our reading; titles from the standard's contents)
DfE standardRelated ISO/IEC 27002 control or ISO/IEC 27001 clause
Cyber risk assessmentISO/IEC 27001 clause 6.1.2 (information security risk assessment)
Cyber awareness plan6.3 Information security awareness, education and training
Anti-malware and a firewall8.7 Protection against malware; 8.20 Networks security
User accounts and access privileges5.15 Access control; 5.18 Access rights; 8.2 Privileged access rights; 8.5 Secure authentication
Licensing and updates8.8 Management of technical vulnerabilities; 8.19 Installation of software on operational systems
Back-up plan8.13 Information backup
Report cyber attacks5.24 Information security incident management planning and preparation; 5.26 Response to information security incidents
Supplier assessments5.19 Information security in supplier relationships; 5.23 Information security for use of cloud services

What a certificate gives a school

An ISO 27001 certificate whose scope covers the service a school buys shows that an accredited body has audited how you manage those controls. It does not answer the Cyber Essentials question, which asks about a different, technical scheme. See ISO 27001 vs Cyber Essentials.

Checking scope

A school should check that the scope on the certificate covers the service it is buying. How, on certificate verification.

One pack, every school

A one-page answer per standard, your Cyber Essentials status, your Article 28 terms and, if you hold it, your ISO 27001 certificate and scope. That is what the supplier lines in the standards are asking for.

We do not audit, certify or consult, and are paid the same fixed fee per enquiry whichever firm you use. The standards are quoted from GOV.UK; the supplier column and the ISO mapping are our reading.

Where this fits

Common questions

What are the DfE cyber security standards for schools?

Seven standards the Department for Education publishes for schools and colleges: an annual cyber risk assessment, a cyber awareness plan, anti-malware and a firewall, control of user accounts, licensing and updates, a back-up plan, and reporting attacks. DfE: “The cyber security standards set out DfE’s recommended approach to meeting those expectations.”

Are the DfE cyber security standards mandatory?

DfE describes them as its recommended approach. The duty behind them is statutory: “Schools and colleges have a statutory responsibility to keep children and young people safe online as well as offline, as detailed in the statutory guidance Keeping children safe in education (KCSIE).” Some specific obligations are firmer: for example, schools with the risk protection arrangement must evidence NCSC training.

Do schools need Cyber Essentials?

Not as a rule for schools: “Some schools may wish to complete it as part of their cyber security activities.” For colleges it is different: “Cyber Essentials is a requirement for colleges under their funding agreement.”

What will a school ask its IT or cloud supplier?

The standards tell schools to discuss with outsourced IT support how it meets them, to consider asking whether it holds Cyber Essentials or Cyber Essentials Plus, and to check that third-party cloud suppliers meet the standards by performing supplier assessments when procuring new contracts.

Does the DfE require ISO 27001 from suppliers?

No. The standards do not mention ISO 27001. The certification they name is Cyber Essentials. An ISO 27001 certificate whose scope covers the service is evidence you can offer in a supplier assessment — our reading, not a DfE statement.

Do the standards apply to multi-academy trusts?

They are written for schools and colleges, and the standards refer to IT leads in a multi-academy trust or local authority where something needs their action or approval.

Sources cited on this page

  1. Department for Education, Cyber security standards for schools and colleges (updated 16 September 2026)
  2. ISO/IEC 27002:2022, official preview (contents, foreword, introduction, clauses 1–3), read first-hand
  3. ISO/IEC 27001:2022, official preview (clauses 1 to 6.3 and contents), read first-hand
  4. NCSC, Cyber Essentials overview

Every figure above was read from the source it is attributed to on 20 September 2026. Figures that are our own arithmetic rather than a published rule are labelled as estimates wherever they appear. How we check this.

Selling to schools or colleges?

Say what you supply, what a school has asked for, and your deadline.

Step 1 of 6
What has made this a live question?

Almost nobody certifies for its own sake. Whatever is pushing this usually also sets the deadline, so it is worth saying first.

When do you need the certificate in your hand?

Stage 1 and Stage 2 are separate visits with a gap between them, so the certificate always lands some weeks after the last audit day. A date inside three months is a different piece of work from a date inside a year.

How many people would be inside the scope?

Not your whole payroll — everyone doing work under your control inside the certified scope, contractors included. This is the number the audit-day table in ISO/IEC 27006-1 runs on, so it decides the audit fee before anything else does.

What exists already?

There is no wrong answer here and nothing to be embarrassed about. Most enquiries are at the first option.

How do you want the work done?

The three routes cost very different amounts and suit very different teams. If you have not decided, say so — that is a useful answer too.

Where should the consultancy reach you?

This is the only step that asks you to type anything.

By clicking “Send my enquiry” I agree that iso27001partners.co.uk may pass the details above to up to three ISO 27001 consultancies that advertise for my sector, so that they can contact me at the business details I have given. Consent is not a condition of anything — every page, table and calculator on this site works without it. You can withdraw consent at any time by replying to any message you receive, or by writing to us through the enquiry form on any page. We are not a certification body, not an accreditation body and not a consultancy; the disclaimer linked in the footer sets out the whole arrangement.

  • Your details go to consultancies only, and to no more than three
  • Free to you — consultancies pay us a fixed fee per enquiry, set in advance
  • No obligation, and no certification body is involved at this stage

Your enquiry is ready to send

Here is what happens after you submit:

  1. Your answers go to ISO 27001 consultancies that advertise for your sector.
  2. No more than three of them may contact you, using the details you gave.
  3. You decide who, if anyone, you speak to. You are committed to nothing.

We are not a certification body and cannot issue, arrange or influence a certificate. Only a UKAS-accredited certification body can do that, and you appoint it yourself.

Free enquiryFive clicks · no obligation Start now