The Department for Education publishes a cyber security standard that schools and colleges are expected to work towards. This page takes each of its seven expectations and adds three things the official wording leaves to you: what it means in plain English, who actually implements it, and what evidence to keep. The official text — always the authority — is linked in the sources at the end.
DfE expectation 1
Conduct a cyber risk assessment annually and review every term
In plain English: Once a year, look properly at what could go wrong and what you'd do about it — then glance back each term to check nothing has changed. Not a hundred-page document: a live list of your biggest risks, owned by someone.
Who implements it: Leadership owns it; IT (in-house or provider) informs it. This one cannot be delegated to a supplier — it is a judgement about the school's risks, not a technical task.
Evidence to keep: The dated assessment, the termly review notes, and cyber risk appearing on the school's risk register.
DfE expectation 2
Create and implement a cyber awareness plan for students and staff
In plain English: A plan for keeping people alert — not one INSET slide a year. The measure of success is how quickly somebody reports something odd, not how few people ever click.
Who implements it: Leadership sets it; everyone receives it. Free materials exist — the NCSC's schools training, and our printable posters.
Evidence to keep: The plan itself, training dates and attendance, and examples of the reporting route being used.
DfE expectation 3
Secure digital technology and data with anti-malware and a firewall
In plain English: Every device that touches school data runs protection, and a firewall — with its default password changed — stands between the school network and the internet.
Who implements it: Almost entirely your IT provider or technician. The school's job is to ask and file the answer.
Evidence to keep: A statement from whoever runs IT of what protection runs where, and confirmation the firewall's default credentials are gone.
DfE expectation 4
Control and secure user accounts and access privileges
In plain English: People can reach what their job needs and nothing more; accounts are protected by more than a password (multi-factor authentication); and the all-powerful admin accounts are few, known, and used only for admin work.
Who implements it: IT implements; leadership insists. The word to use in the asking is enforced — MFA that is merely available protects only volunteers.
Evidence to keep: An MFA enforcement report, a list of admin account holders, and a working leaver process that switches accounts off.
DfE expectation 5
License digital technology and keep it up to date
In plain English: Software is genuine, supported, and actually receiving updates. Anything out of support is either replaced or knowingly accepted as a risk, in writing, with a date.
Who implements it: IT operates the patching; leadership owns the out-of-support decisions, because those are spending decisions.
Evidence to keep: The patching cadence in writing, and the list of out-of-support systems with their plans or dated risk acceptances.
DfE expectation 6
Develop and implement a plan to back up your data and review this every year
In plain English: Copies of what matters exist, at least one copy is beyond the reach of an attacker who controls your network, and someone has proved a restore actually works — recently.
Who implements it: IT builds it; leadership asks the two questions that matter: could ransomware reach every copy, and when did we last restore something?
Evidence to keep: The backup plan, the yearly review date, and a note of the last successful test restore.
DfE expectation 7
Report cyber attacks
In plain English: When an attack happens, the school tells the right people rather than quietly coping: Report Fraud, your insurer or the RPA where conditions apply, the ICO within 72 hours where personal data is involved — and the DfE's own reporting expectations.
Who implements it: Named in the incident plan, in advance. Deciding who reports during the incident is how reporting gets missed.
Evidence to keep: The incident plan naming who reports to whom, reachable when systems are down.
Working towards it, honestly
Very few schools meet all seven from a standing start, and the standard’s own framing — work towards — expects that. What separates a well-governed school is knowing which parts it doesn’t meet yet, with dates and owners. Our checklist maps each item to these expectations so the same work counts twice, and the complete guide explains the why behind them. Schools asked for a certificate — by procurement, insurers or a trust — usually mean Cyber Essentials, a different thing from this standard, and worth understanding separately.
Where Ceidwad fits, stated plainly: Atlas keeps a live, dated record of a school’s position against expectations like these — the assurance and evidence half. It does not implement the controls, and nothing on this page needs it.


