MIS and Safeguarding Vendors: DfE Toolkit Questions Schools Will Ask

MIS and Safeguarding Vendors: DfE Toolkit Questions Schools Will Ask

By EJN Labs · 12 Aug 2026 · 8 min read

The DfE Data Protection Toolkit does not directly order suppliers to run penetration tests, but schools using it will ask MIS and safeguarding vendors for DfE DPT security assurance: evidence of risk-based testing under UK GDPR Article 32. In practice that means an independent penetration test of your platform, typically 4 to 6 days (£4,400 to £8,400) for a web application and API, from a CREST-accredited firm.

What is DfE DPT security assurance and why are schools asking you for it?

DfE DPT security assurance is the evidence schools request under the Data Protection Toolkit, guidance published by the Department for Education to help schools, trusts and colleges meet their data protection duties. Schools ask for it because they must check a supplier can protect pupil data before handing it over.

Those duties are mandatory obligations under UK GDPR and the Data Protection Act 2018, so although the toolkit itself is guidance rather than legislation, the checking is not optional. Supplier due diligence is one of the areas it pushes hardest, covering any MIS, safeguarding platform or other EdTech processor that receives pupil data.

If you sell a management information system, a safeguarding platform, a parental engagement app or a research SaaS product into UK education, the buyer’s data protection officer or trust IT lead is working through a due diligence checklist shaped by the toolkit. Increasingly they want independent evidence rather than self-assessment, and a recent penetration test report from a UK firm is the most persuasive answer you can give.

What does the toolkit actually require from suppliers?

Nothing directly: the DfE Data Protection Toolkit contains no clause saying suppliers must commission an annual penetration test. Instead it restates the school’s obligations as a data controller under UK GDPR, which is how testing expectations reach vendors in practice.

Honesty matters here, because vendors are routinely oversold on this point. The restated obligations include the UK GDPR Article 28 requirement to use only processors that provide sufficient guarantees of appropriate technical and organisational measures, and the Article 32 requirement for security appropriate to the risk, including regular testing and evaluation of those measures.

The practical effect is a strong technical-testing trigger passed down the supply chain: a school cannot sign a processor that offers no evidence of testing without weakening its own compliance position. Safeguarding platforms sit at the sharpest end of this, holding allegations, referrals and case notes about children, so the risk-based bar for “appropriate” security is high. A vendor that arrives with an independent test report and a retest confirmation removes the school’s hardest question before it is asked.

The questions schools and trusts will ask you

Due diligence questionnaires vary between trusts, but the security section is consistent. These are the questions we see education suppliers asked, and what a strong answer looks like.

Question you will be askedWhat a strong answer looks like
When was your platform last independently security tested?Within the last 12 months, by a named CREST-accredited firm, with a report available under NDA
What was in scope?The web application, its APIs, the cloud environment hosting pupil data, and any mobile apps
How do you separate one school’s data from another’s?Described tenant isolation controls, verified by testing rather than asserted
How were the findings handled?A remediation timeline and a retest confirming high and critical issues are closed
What certifications do you hold?Cyber Essentials Plus as a baseline; ISO 27001 for larger contracts

Vendors who can answer all five in a single attachment shorten procurement by weeks.

What to test across an MIS or safeguarding platform

Scope should follow where pupil data lives and who can reach it. For a typical education platform that means four layers.

  • The web application itself, with particular attention to role separation. School platforms carry unusually complex permission models: staff, safeguarding leads, parents, pupils and trust-level administrators all see different slices of the same records, and broken access control between those roles is the finding we encounter most often.
  • The APIs behind it. MIS platforms expose integration APIs to dozens of third party tools, and these endpoints often enforce weaker authorisation than the user interface. Dedicated API penetration testing exercises every endpoint against every role.
  • The cloud environment. Misconfigured storage, over-permissive service roles and exposed admin interfaces are assessed through cloud penetration testing of your AWS, Azure or GCP estate.
  • Mobile apps, where parents or staff use one, including local data storage and the app’s own API traffic.

For multi-tenant platforms we treat tenant isolation as a first-class objective, not an afterthought. When EJN Labs scopes a multi-school platform, we ask for test accounts in at least two separate tenants and at every privilege level, then spend dedicated time attempting to read or modify one school’s records from another school’s session, because that is the specific failure a trust IT lead fears most.

How an engagement runs

An engagement runs from scoping to testing in a predictable path: a short call plus a questionnaire covering user roles, tenant structure, API surface and hosting, then agreed rules of engagement, then a testing window of a few days to two weeks depending on scope.

Testing ideally runs against a staging environment seeded with realistic but synthetic data, so live pupil records are never touched, and any critical finding is flagged the day it is found rather than held back for the report.

You receive a report with an executive summary for procurement audiences and technical detail for your engineers, followed by a free retest window. Our penetration testing checklist shows how to prepare so no testing days are lost to access problems.

What it costs and how scope drives the price

UK penetration testing is priced on tester days, and reputable firms charge a day rate in the £1,100 to £1,400 range. Scope drives days: the number of user roles, tenants, API endpoints and applications matters far more than your company size.

Typical supplier scopeDaysTypical UK cost
Web application and API of a single platform4 to 6£4,400 to £8,400
Platform plus cloud configuration review6 to 9£6,600 to £12,600
Multi-product estate including a mobile app9 to 12£9,900 to £16,800

These are typical UK ranges rather than quotes; an exact price needs a short scoping conversation, and our guide to penetration testing costs in the UK breaks down what moves the number. One commercial note: a single well-scoped test is reusable evidence across every school you sell to for the following year.

How EJN Labs approaches testing for education suppliers

EJN Labs is a UK firm delivering CREST-accredited penetration testing with UK-based testers, and we hold Cyber Essentials Plus, ISO 27001 and ISO 9001 ourselves, so we sit on the same side of supplier due diligence questionnaires that you do. For MIS and safeguarding vendors we scope around the questions schools will actually ask: tenant isolation, role separation, API authorisation and cloud configuration. Reports are written to be shared, critical findings are raised immediately, and retesting is included so your procurement pack shows issues closed, not just found. If you are comparing firms, our guide to choosing the best UK penetration testing provider sets out the questions worth asking any of us.

Frequently Asked Questions

Does the DfE Data Protection Toolkit require vendors to have a penetration test?

Not directly. The toolkit is Department for Education guidance and contains no penetration testing mandate for vendors. It supports schools’ duties under UK GDPR, though, and schools discharge those duties by asking vendors for security evidence, with an independent penetration test being what most questionnaires expect.

The duties behind it require schools to use processors offering sufficient guarantees and to ensure regular testing of security measures, and the expectation is strongest for platforms holding safeguarding records.

What does a penetration test cost for an MIS or safeguarding vendor?

Expect £4,400 to £8,400 to test the web application and API of a single platform, which typically takes 4 to 6 days at UK day rates of £1,100 to £1,400. Larger scopes cost more, and exact pricing comes from scoping.

Adding a cloud configuration review takes the engagement to 6 to 9 days, £6,600 to £12,600, while a multi-product estate including a mobile app runs 9 to 12 days, £9,900 to £16,800.

Will testing put live pupil data at risk?

It should not, and scoping is designed to prevent it. We test against a staging environment seeded with synthetic data wherever one exists, agree written rules of engagement before any testing starts, and handle all engagement material under our own ISO 27001 controls. Where production testing is unavoidable, destructive techniques are excluded and activity windows are agreed in advance with your team.

How often should an EdTech supplier retest?

Retest annually as a baseline, because most school and trust questionnaires ask for a test within the last 12 months. Retest sooner after significant change: a new module, a rebuilt API, a cloud migration or a new mobile app all alter your attack surface.

A dated report loses persuasive power quickly in procurement, which is why many vendors align testing with their sales cycle ahead of the autumn buying season.

What should we share with schools from the report?

Share the executive summary, the scope statement and the retest confirmation under NDA, rather than the full technical detail. That combination answers the school’s real questions: what was tested, by whom, what severity of issues emerged and whether they are now fixed.

This is what vendors commonly do already, and we write our executive summaries specifically so they can be handed to a data protection officer without redaction.

Turn security assurance into a sales advantage

If schools are asking you the toolkit questions, arrive with the answers already written. EJN Labs scopes MIS, safeguarding and EdTech platforms in a single short call and delivers a report your next procurement round can rely on. Get a CREST penetration testing quote and we will come back with a fixed scope and price.

Leave a Reply

Your email address will not be published. Required fields are marked *