DfE cyber security core standard for schools and colleges guidance

UK Government · February 12, 2026 · ✓ verified

The Department for Education has published core cyber security standards for schools and colleges, requiring schools and colleges to meet them by 2030.

  • Main announcement and requirements: The DfE requires schools and colleges to adopt the cyber security core standard (one of 6 core standards) and to work towards meeting it by 2030, including annual cyber risk assessments that are reviewed every term, formal incident reporting routes (Report Fraud, NCSC, ICO), and that colleges hold Cyber Essentials certification as part of funding rules.
  • Key technical and implementation details:IT support must patch high-risk vulnerabilities within 14 days, implement multi-factor authentication (MFA) for senior leaders and staff handling sensitive data, maintain at least 3 backup copies (2 separate devices, one off-site) with immutable backups, test backups termly, and follow specified account-management, firewall, anti-malware and licensing controls; the DfE sector incident reporting email is Sector.Incidentreporting@education.gov.uk.
Keep reading
ITIF webinar on public opposition to data centers Information Technology and Innovation Foundation · Aug 26 Moldova and U.S. discuss power line partnership Moldova State News Agency · Jul 31 Data4 says AI is reshaping data center infrastructure DATA4 Group · Jul 31 Guide explains how data center tiers work Digital Edge DC · Jul 31
Telborg · US Data Centers
Track the US data-center buildout — every day.

Real-time verified news and daily AI-written briefings, built from primary sources — power, grid, permits, land, financing. Start free.

Get Telborg Pro · $189/mo Get the daily briefing — free →

Every field traced to a primary source.