Cyber Essentials for schools and academy trusts
Schools have more devices, more users and more turnover than almost any organisation of comparable size — and a scoping question nobody else has to answer.
Cyber Essentials reaches schools from several directions at once. Insurers ask. The Department for Education's digital and technology standards point at the same technical controls the scheme assesses. Trusts set expectations across their schools. And somewhere behind all of it sits the uncomfortable fact that schools hold a great deal of data about children.
The five controls are the same as for any organisation. What differs is the shape of a school's estate, and three questions that only schools have to answer.
The pupil device question
This is the one that stops school certifications before they start, and the answer is more workable than it first appears.
Scope follows access to organisational data and services. A set of classroom tablets used only for teaching and learning, with no route into the management information system, staff email or administrative data, sits in a different position from the business manager's laptop. Devices that do reach administrative systems are in scope, whoever is holding them.
What matters is that the boundary is real and can be described. A school that can say clearly which systems pupil devices reach, and demonstrate that they cannot reach the rest, has a defensible scope. A school that assumes pupil devices are out of scope because they belong to pupils does not — and under the current requirements, any exclusion has to be justified to the assessor rather than simply left off the form.
The pupil device decision determines the size of everything that follows. Make it deliberately, write down the reasoning, and check it against how the network is actually configured rather than how it was designed three years ago.
Shared logins
Schools run on shared credentials more than any other sector. A generic login on the classroom machine. A shared account for supply staff. An office login two people use. A library computer everybody signs into with the same password.
Every one of those fails the access control requirement. Individual accounts for individual people is not a preference in the scheme, it is the requirement — and it is the change schools find most disruptive, because it touches daily habits rather than a configuration setting.
It is also the control that matters most in a safeguarding context, since shared credentials make it impossible to establish who did what.
MFA on the MIS and everything else
Multi-factor authentication is mandatory on every cloud service that offers it, for all users, and missing it fails an assessment outright.
For a school the in-scope list is long: the management information system, staff email, the finance system, the parent communications platform, the learning platform, cashless catering, the website content management system, HR and payroll, and the safeguarding recording system. Schools reliably enable MFA on email and miss two or three of the others.
The safeguarding system deserves specific attention. It holds the most sensitive data in the building, and it is exactly the kind of specialist application where MFA gets overlooked because it was set up years ago by a supplier.
Devices past vendor support
Schools keep equipment a long time, often for good financial reasons. The problem is that unsupported operating systems cannot meet a fourteen-day patching requirement, because no patches are being issued — so they fail.
The recurring culprits are older machines in specialist rooms, equipment attached to a particular piece of hardware or software that will not run on anything newer, interactive whiteboards and their controllers, and network equipment nobody has looked at since installation.
Where replacement is not affordable this year, genuine network segregation is the alternative — but it has to be real separation, not a note in a policy.
People move constantly
Staff, supply teachers, governors, trainees, volunteers, contractors. Schools have more account churn than almost any comparable organisation, and account removal is rarely anyone's named job.
An assessment asks how you know the account list is current. The answer needs to be a process — leavers removed as part of an offboarding routine, access reviewed periodically — rather than a belief that it is probably fine.
Multi-academy trusts
A certificate covers named legal entities, and for a trust the trust is normally the legal entity — so certification can cover the trust and its schools, provided the scope is described accurately and the controls genuinely hold across all of it.
That last clause is the difficulty. Trusts formed by bringing schools together often inherit materially different systems, different suppliers and different local practice. Certifying the trust means every school in scope meets the standard, and the weakest one sets the pace. Establishing where that variation sits, before submitting, is the single most useful thing a trust can do.
Note too that certificates now list every legal entity covered, so what the certificate actually says will be visible to anyone who reads it.
A sensible sequence for a school
- Inventory first — every device by type and operating system version, every cloud service, every category of user. In a school this is the bulk of the work.
- Make the pupil device decision and write down the reasoning.
- Check MFA across every system on the list, not just the obvious ones.
- Find the unsupported devices and decide: replace, or genuinely segregate.
- Deal with shared logins — the longest lead time, because it changes what people do daily.
- Establish the leaver process and be able to describe it.
Schools that start this in the summer term for an autumn assessment find it manageable. Schools that start three weeks before an insurance renewal do not.
Scoping a school properly takes a conversation
Pupil devices, a trust's mixed estate, and specialist systems that predate everyone currently working there — none of that fits a standard questionnaire. Tell us how the school actually runs and we will tell you what your scope should be and what it would take.
Take the free readiness check · hello@passcyber.co.uk
PassCyber is a trading name of Edwards Bros (Spaldwick) Ltd
Scheme requirements are set by the NCSC and IASME and are reviewed periodically. Department for Education standards for schools and colleges are published separately and updated from time to time — check the current version alongside the current Cyber Essentials requirements.