DfE cyber security standards for schools and colleges: what suppliers are asked
DfE tells schools to work with “third-party cloud suppliers to check that they are also meeting these standards by performing supplier assessments – this needs to be carried out when procuring new contracts”.
The Department for Education publishes seven cyber security standards for schools and colleges. They are written for the school, but several of them point outwards: at outsourced IT support, cloud services and software suppliers. If you sell technology to schools, this is where the questions in your next tender or renewal come from. This page sets out the standards from the DfE's own text and what each one asks of suppliers.
The seven standards
“Schools and colleges have a statutory responsibility to keep children and young people safe online as well as offline, as detailed in the statutory guidance Keeping children safe in education (KCSIE).” “The cyber security standards set out DfE’s recommended approach to meeting those expectations.”
| Standard | For a supplier | |
|---|---|---|
| 1 | Conduct a cyber risk assessment annually and review every term | Your service's risks may appear in the school's assessment; expect questions |
| 2 | Create and implement a cyber awareness plan for students and staff | If your product holds logins, expect to explain what users must do |
| 3 | Secure digital technology and data with anti-malware and a firewall | Hosted services: how malware and network threats are handled on your side |
| 4 | Control and secure user accounts and access privileges | Accounts, privileged access, authentication on your service |
| 5 | License digital technology and keep it up to date | Your patching and end-of-support dates; this standard names cloud suppliers |
| 6 | Develop and implement a plan to back up your data and review this every year | Where the school's data is backed up and how it is restored |
| 7 | Report cyber attacks | How you will tell the school about an incident affecting its data |
What the standards tell schools to ask suppliers
| Who | DfE says | Standard |
|---|---|---|
| Outsourced IT support | “If your IT support is outsourced, then you will need to discuss with them how they are meeting the requirements of this standard.” | Risk assessment |
| Outsourced IT support | “you may wish to consider asking them whether they are certified with Cyber Essentials or Cyber Essentials Plus” | Risk assessment |
| Digital technology suppliers | “any digital technology suppliers to make sure they are also compliant with this standard” | User accounts |
| Third-party cloud suppliers | “third-party cloud suppliers to check that they are also meeting these standards by performing supplier assessments – this needs to be carried out when procuring new contracts” | Licensing and updates |
| External IT support | “If you have external IT support that will carry out the activities within this standard, make sure that your contract with them is compliant with General Data Protection Regulation (GDPR).” | User accounts |
| Developers of commissioned software | “make sure custom-built or commissioned applications are developed securely and align with the UK software security code of practice” | Anti-malware and firewall |
Supplier assessments at procurement
The cloud-supplier line is the one with a trigger: the check happens when a new contract is procured. A supplier with evidence ready — what controls apply to the service, who verified them and when — answers it once instead of per school.
The contract itself
For external IT support DfE adds that the contract must comply with data protection law. For what that contract has to contain when you process personal data for the school, see UK GDPR Article 28.
Cyber Essentials: colleges and schools differ
“Cyber Essentials is a government-backed certification that happens on an annual basis.”
Colleges
“Cyber Essentials is a requirement for colleges under their funding agreement.”
Schools
“Some schools may wish to complete it as part of their cyber security activities.” The standards are described as a way to work towards it. For suppliers, the Cyber Essentials question reaches you through the outsourced-IT line above.
Risk protection arrangement
One line in the standards is a firm obligation for some schools: “If you have risk protection arrangement, you must evidence that the relevant users have undertaken the free National Cyber Security Centre (NCSC) training.”
Where ISO 27001 fits (our reading)
The DfE standards do not mention ISO 27001. They are a short set of controls for a school; ISO 27001 is a management system for running controls like them. The overlap, by control title:
| DfE standard | Related ISO/IEC 27002 control or ISO/IEC 27001 clause |
|---|---|
| Cyber risk assessment | ISO/IEC 27001 clause 6.1.2 (information security risk assessment) |
| Cyber awareness plan | 6.3 Information security awareness, education and training |
| Anti-malware and a firewall | 8.7 Protection against malware; 8.20 Networks security |
| User accounts and access privileges | 5.15 Access control; 5.18 Access rights; 8.2 Privileged access rights; 8.5 Secure authentication |
| Licensing and updates | 8.8 Management of technical vulnerabilities; 8.19 Installation of software on operational systems |
| Back-up plan | 8.13 Information backup |
| Report cyber attacks | 5.24 Information security incident management planning and preparation; 5.26 Response to information security incidents |
| Supplier assessments | 5.19 Information security in supplier relationships; 5.23 Information security for use of cloud services |
What a certificate gives a school
An ISO 27001 certificate whose scope covers the service a school buys shows that an accredited body has audited how you manage those controls. It does not answer the Cyber Essentials question, which asks about a different, technical scheme. See ISO 27001 vs Cyber Essentials.
Checking scope
A school should check that the scope on the certificate covers the service it is buying. How, on certificate verification.
One pack, every school
A one-page answer per standard, your Cyber Essentials status, your Article 28 terms and, if you hold it, your ISO 27001 certificate and scope. That is what the supplier lines in the standards are asking for.
We do not audit, certify or consult, and are paid the same fixed fee per enquiry whichever firm you use. The standards are quoted from GOV.UK; the supplier column and the ISO mapping are our reading.
Where this fits
Common questions
What are the DfE cyber security standards for schools?
Seven standards the Department for Education publishes for schools and colleges: an annual cyber risk assessment, a cyber awareness plan, anti-malware and a firewall, control of user accounts, licensing and updates, a back-up plan, and reporting attacks. DfE: “The cyber security standards set out DfE’s recommended approach to meeting those expectations.”
Are the DfE cyber security standards mandatory?
DfE describes them as its recommended approach. The duty behind them is statutory: “Schools and colleges have a statutory responsibility to keep children and young people safe online as well as offline, as detailed in the statutory guidance Keeping children safe in education (KCSIE).” Some specific obligations are firmer: for example, schools with the risk protection arrangement must evidence NCSC training.
Do schools need Cyber Essentials?
Not as a rule for schools: “Some schools may wish to complete it as part of their cyber security activities.” For colleges it is different: “Cyber Essentials is a requirement for colleges under their funding agreement.”
What will a school ask its IT or cloud supplier?
The standards tell schools to discuss with outsourced IT support how it meets them, to consider asking whether it holds Cyber Essentials or Cyber Essentials Plus, and to check that third-party cloud suppliers meet the standards by performing supplier assessments when procuring new contracts.
Does the DfE require ISO 27001 from suppliers?
No. The standards do not mention ISO 27001. The certification they name is Cyber Essentials. An ISO 27001 certificate whose scope covers the service is evidence you can offer in a supplier assessment — our reading, not a DfE statement.
Do the standards apply to multi-academy trusts?
They are written for schools and colleges, and the standards refer to IT leads in a multi-academy trust or local authority where something needs their action or approval.
Sources cited on this page
- Department for Education, Cyber security standards for schools and colleges (updated 16 September 2026)
- ISO/IEC 27002:2022, official preview (contents, foreword, introduction, clauses 1–3), read first-hand
- ISO/IEC 27001:2022, official preview (clauses 1 to 6.3 and contents), read first-hand
- NCSC, Cyber Essentials overview
Every figure above was read from the source it is attributed to on 20 September 2026. Figures that are our own arithmetic rather than a published rule are labelled as estimates wherever they appear. How we check this.
Selling to schools or colleges?
Say what you supply, what a school has asked for, and your deadline.
Your enquiry is ready to send
Here is what happens after you submit:
- Your answers go to ISO 27001 consultancies that advertise for your sector.
- No more than three of them may contact you, using the details you gave.
- You decide who, if anyone, you speak to. You are committed to nothing.
We are not a certification body and cannot issue, arrange or influence a certificate. Only a UKAS-accredited certification body can do that, and you appoint it yourself.