Skip to content
Industry

Cyber Essentials for Schools, Colleges, and Universities

Cyber Essentials is increasingly expected across UK education. DfE guidance, Jisc recommendations, and funder due diligence are pushing schools and further / higher education institutions toward certification. This guide covers how the controls apply to education-specific infrastructure.

woman standing in front of children

Author

Jay Hopkins

Editor

Edited by Jack Wickham

Published

Last reviewed

Read time

11 min read

Share

Section 01

Cyber Essentials for Schools, Colleges, and Universities

Education is under more cybersecurity pressure than most sectors. Schools have been a repeated ransomware target through 2024 and 2025. The Department for Education now publishes explicit cybersecurity standards for schools and colleges. Jisc recommends Cyber Essentials for universities as part of the broader higher education cybersecurity posture. And research funders, corporate partners, and international collaborators are increasingly asking about CE during institutional due diligence.

This guide covers what Cyber Essentials means in a UK educational context, how the controls map to the infrastructure schools and universities typically run, and the specific issues that catch education applicants during assessment.

Section 02

Why education needs Cyber Essentials

DfE Digital Standards for Schools. The DfE core cyber security standard recommends controls and discusses certification as an assurance option; it does not impose a universal Cyber Essentials certificate requirement. Check separate funding and contractual conditions.

Jisc and higher education expectations. Certification can support evidence of baseline technical controls. Check the actual funding and assurance conditions; Cyber Essentials does not automatically satisfy broader institutional obligations.

Research funder due diligence. UKRI, Horizon Europe participants, and individual research funders routinely ask about the cybersecurity posture of institutions bidding for grants, particularly for projects involving personal data (medical research, social sciences, clinical trials).

Ransomware risk. Education was the second-most-targeted UK sector for ransomware in 2024 and 2025. Insurers and internal audit functions are increasingly treating CE as a de-facto minimum for cyber insurance renewal and risk committee sign-off.

Section 03

What school and university infrastructure looks like

The NCSC v3.3 requirements define the scheme controls. MDM can help demonstrate consistent controls, but Cyber Essentials does not mandate a particular product or an MDM subscription. Verify the required configuration, firewall, updates, access and malware controls on every in-scope device; documented manual management can also meet the requirements. Encryption, backup, logging and sector-specific information handling may be valuable or separately required; distinguish those from the five scheme controls.

A typical UK school runs:

  • Microsoft 365 Education or Google Workspace for Education
  • A Management Information System (SIMS, Arbor, Bromcom, ScholarPack)
  • A Learning Platform (Google Classroom, Microsoft Teams for Education, Canvas, Blackboard, Moodle)
  • Admin laptops for teaching and non-teaching staff
  • Classroom computers / iPads / Chromebooks for pupils
  • A safeguarding and monitoring platform (Senso, Smoothwall, Impero)
  • Finance system (PS Financials, IRIS, Access Education)
  • HR / payroll (HR systems shared with the MAT or hosted)

Universities add research computing clusters, library e-resource platforms (EBSCO, JSTOR, ProQuest), student systems (SITS, Banner, Tribal), research data repositories, and significantly more complex identity infrastructures.

Section 04

What is in scope, what is not

Agree the assessment boundary with the Certification Body. Include organisational end-user devices, employee BYOD used for work, and cloud services hosting organisational data or services, including production hosting. Under v3.3, third-party-owned end-user devices are excluded, but their organisational accounts remain in scope; organisation-owned devices loaned to third parties are included. A virtual desktop, browser-only access or Conditional Access does not itself exempt employee BYOD. Any separately managed subset needs a justified technical boundary accepted by the assessor. The v3.3 ownership table specifically includes volunteers’, trustees’ and university research assistants’ BYOD used for organisational work; do not classify these roles as excluded third-party contractors. Students’ own devices are excluded, while organisation-owned student devices are included. Organisational accounts remain in scope.

Assess organisation-owned classroom devices, staff devices, learning platforms, MIS, finance and cloud accounts against the actual boundary. A pupil label is not an automatic exemption.

Section 05

The MIS and the sensitive data question

Management Information Systems hold data that is both high-sensitivity and high-volume: pupil SEN records, safeguarding notes, free school meals eligibility, parental contact details, attendance records, behaviour logs. Losing or leaking this data has serious regulatory and safeguarding consequences.

The scheme controls apply to an in-scope MIS. The following mixes relevant access controls with broader safeguarding and recovery recommendations; backups and a fixed one-day offboarding deadline are not universal scheme requirements:

  • MFA on every user account accessing a cloud MIS; implement it where available for other deployments
  • Role-based access - not every teacher needs access to every pupil's safeguarding notes
  • Leaver processes - when a teacher leaves, MIS access is removed within one working day
  • No shared accounts (a classroom computer should not be logged into the MIS as "office1")
  • Backup and recovery for the MIS data in the event of ransomware

Confirm MFA support and enforcement for your actual MIS version and deployment. For an in-scope cloud MIS, every user account needs MFA; do not assume a vendor name proves configuration.

Section 06

Pupil devices and the BYOD question in schools

Assess pupil device ownership, connectivity and use. Organisation-owned devices loaned to pupils are included under the third-party-loan rule. Personally owned pupil devices are excluded under the v3.3 student-device rule, while their organisational accounts remain in scope. Confirm the treatment with the Certification Body.

Network segmentation and separate identities can support a well-defined separately managed subset, but an SSID, OU or pupil-only label alone does not prove an acceptable boundary. Organisational cloud services cannot be excluded merely because they are used by pupils.

Section 07

University research computing

HPC clusters, research servers, experimental kit and repositories need an explicit scope decision based on use and connectivity. A separate research security regime is not an automatic exemption. Agree any justified separately managed subset with the Certification Body before assessment. Basic and Plus apply the same control requirements to the agreed scope; Plus adds technical verification. Do not select Plus as a way around unsupported or unpatched research systems.

Section 08

Five education-specific failure patterns to check

1. Cloud MIS without enforced MFA. Check your actual service configuration and every relevant user account.

2. Shared classroom computer logins with MIS access. The classroom PC is logged in as "classroom1" which has MIS access "for the office to update". Shared accounts fail.

3. Leaver processes lagging the academic cycle. A teacher leaves in July; their accounts are not disabled until September (or later, or never). Remove access when it is no longer required, including across holiday periods; a one-working-day target can be a local policy rather than a universal scheme deadline.

4. Staff devices without current control evidence. An old image or policy is not proof of current configuration, supported software and update compliance. MDM is one possible management tool, not the scheme requirement itself.

5. Employee BYOD without evidenced controls. Personal devices used for work are generally in scope. Meet the applicable controls, through MDM or another evidenced approach, or prevent the work access; simply recording an exception does not establish compliance.

Section 09

Practical path to certification for a school

If you are an academy, MAT, or maintained school with 50-500 staff:

1. Decide the scope boundary. Assess staff, pupils, research systems and cloud services; agree any justified separately managed subset with the assessor.

2. Enforce MFA for every user accessing an in-scope cloud service - include applicable staff, pupil, research and administrator accounts on M365, MIS, finance, HR and safeguarding platforms.

3. Verify device controls. Use MDM or another evidenced management approach to meet the five scheme controls; employee BYOD accessing work data is generally included, while access restrictions must be implemented in practice.

4. Run a leaver reconciliation. Pull the HR list; compare against active accounts in every in-scope system; disable anything that should not be there.

5. Document scope clearly with the agreed boundary, ownership rules, included cloud services and any accepted subset.

6. Submit. CE small (10-49 staff) £399.99 + VAT; medium (50-249) £449.99 + VAT; large (250 - 9,999) £549.99 + VAT.

Select the price band using the actual organisational staff count, including relevant non-teaching staff, rather than teachers or pupil numbers alone.

Section 10

Bottom line

Cyber Essentials can support education assurance and reduce common cyber risks. A defensible assessment includes the actual organisational estate and cloud services, with any subset agreed in advance; preparation should establish controls rather than assume pupil, research or employee BYOD exemptions.

Check your readiness | View pricing | Talk to an assessor

About the author

Jay Hopkins

Jay Hopkins

Managing Director, Fig Group

IASME-licensed Cyber Essentials AssessorIASME Cyber Assurance Assessor

Jay Hopkins is the Managing Director of Fig Group and an IASME-licensed Cyber Essentials assessor. He was previously Head of Technology for a global regulated firm. He works with UK organisations across regulated sectors on baseline compliance, supply-chain assurance, and AI-augmented security tooling.

Next step

Ready to get certified?

Get Cyber Essentials Basic certified with Fig Group from £299.99 + VAT. Our guarantee is within six working hours of receiving a complete, compliant submission before midday UK time on a UK Business Day, subject to our certification terms.