Do Schools and Colleges Need Penetration Testing Under the DfE Standard?

Do Schools and Colleges Need Penetration Testing Under the DfE Standard?

By EJN Labs · 27 Jul 2026 · 8 min read

The DfE cyber standard does not impose a universal penetration testing mandate on schools and colleges. It sets risk-based expectations: secure devices and accounts, tested backups, incident planning, and Cyber Essentials where required by contracts or funding. Penetration testing is how many trusts evidence those controls actually work. Typical UK costs run from £2,400 to £12,600 depending on scope.

DfE cyber standard penetration testing is one of the most common questions we hear from trust IT leads and college finance directors, usually right after an audit or a condition-of-funding letter lands. The Department for Education expects schools and colleges to meet its cyber security standards, but the standards describe outcomes rather than naming a single mandatory test. This post explains where testing fits, what to scope, and what it costs.

Why the DfE cyber standard matters for schools and colleges

The DfE cyber standard matters because education is one of the most attacked sectors in the UK. Schools hold sensitive safeguarding records, pupil and parent data and staff payroll, increasingly run through cloud MIS platforms and Microsoft 365 or Google Workspace tenancies with thin IT resource behind them.

The Department for Education publishes its cyber security standards as part of the digital and technology standards for schools and colleges in England, and that threat picture is why they exist.

The standards are expected practice for schools and colleges rather than a statute. That distinction matters less than it sounds. Multi-academy trusts answer to the ESFA on financial and governance assurance, insurers ask for evidence of the standards at renewal, and some DfE-linked contracts and funding arrangements attach specific conditions, including Cyber Essentials certification. In practice, a trust that cannot evidence the standards is exposed on funding, insurance and reputation all at once, before any attacker gets involved.

What the standard actually asks for, and where testing fits

Honesty first: the DfE cyber security standards do not say every school must commission an annual penetration test. Anyone telling you otherwise is selling, not advising. What the standards do expect includes:

  • Protecting all devices on the network with properly configured firewalls and up-to-date software
  • Securing accounts with multi-factor authentication and least-privilege access, especially for staff and administrative accounts
  • Regular, tested backups that would survive a ransomware event
  • An incident response and business continuity plan the school has actually rehearsed
  • At least annual cyber security training for staff
  • Cyber Essentials or Cyber Essentials Plus where a contract, funding condition or the trust’s own risk assessment calls for it

Penetration testing enters through two doors. First, Cyber Essentials Plus involves independent technical verification of your controls, and boards frequently commission a fuller test alongside it. Second, the standards are outcome-based: “devices are protected” and “accounts are secured” are claims, and a penetration test is the recognised way to turn claims into evidence. The DfE position is risk-based, so governors and audit committees decide the depth of assurance, and independent testing is the strongest form available. Our penetration testing checklist walks through how to prepare before you commission anything.

What schools, colleges and trusts should test

External infrastructure and remote access

Everything reachable from the internet: firewalls, VPN endpoints, remote desktop gateways, the school website and any self-hosted portals. This is where ransomware groups start, and it is the highest-value first test for most schools. See our external infrastructure penetration testing service for what this covers.

Microsoft 365 or Google Workspace tenancy

Most school data now lives in the cloud tenancy, not on a server in a cupboard. A cloud penetration test reviews conditional access, MFA coverage, legacy authentication, sharing settings and admin role sprawl, which map directly onto the account-security expectations in the standard.

MIS, safeguarding and parent-facing applications

Management information systems, safeguarding platforms and payment portals hold the most sensitive data a school processes. Where these are supplier-hosted, your job is to ask the supplier for their test evidence; where the school or trust hosts or heavily configures them, they belong in your own scope.

Internal network and segregation

For larger colleges and multi-academy trusts, an internal test answers the question that matters after phishing: if one staff laptop is compromised, can an attacker reach finance, the MIS database or every school in the trust? Flat networks across academy sites are the most common structural finding we see in education estates.

How an engagement runs for a school or trust

An engagement starts with a short scoping call with your IT lead or managed service provider. We count external IP addresses, cloud tenancies, key applications and sites, then agree a testing window scheduled around term dates, exam periods and coursework deadlines so testing never disrupts teaching.

For schools that window matters more than in most sectors, and we agree in advance how any system holding safeguarding data will be handled.

Testing itself usually takes two to nine days depending on scope. You receive a report with an executive summary written for governors and the audit committee, technical findings with reproduction steps for your IT team or MSP, and a prioritised remediation plan. We include a free retest of critical and high findings so you can evidence closure, which is exactly the paper trail ESFA-style assurance reviews and insurers want to see.

What it costs and how scope drives the price

Penetration testing is priced on effort. UK day rates for CREST-accredited testing typically run £1,200 to £1,400, and the number of days is driven by how much estate you put in scope. Typical ranges for education engagements:

EngagementTypical effortTypical UK cost
External infrastructure test (single school)2 to 3 days£2,400 to £4,200
Cloud tenancy review (M365 or Workspace)2 to 4 days£2,400 to £5,600
Web application or portal test4 to 6 days£4,800 to £8,400
Internal and external test (college or MAT)6 to 9 days£7,200 to £12,600

A small primary school with one internet connection and a cloud tenancy sits at the bottom of that table. A twelve-school trust with shared finance systems sits at the top. Our guide to penetration testing costs in the UK breaks down every factor that moves the number. Exact pricing for your estate comes from a scoping call, and you can start that with our quote form.

How EJN Labs approaches testing for schools and colleges

EJN Labs is a UK firm delivering CREST-accredited penetration testing with UK-based testers, and we hold Cyber Essentials Plus and ISO 27001 ourselves, so we know both sides of the certification process schools are being pushed towards. When we scope an education estate, we start from the data: where safeguarding records, pupil data and payroll actually live, then work outwards to every path that reaches them, rather than testing whatever list of IP addresses happens to exist. We map findings against the DfE standards’ expectations so the report doubles as board evidence, because in a school the person who approves the budget is rarely the person who patches the firewall.

Frequently Asked Questions

Does the DfE cyber standard require penetration testing?

Not universally. The DfE’s cyber security standards set risk-based expectations, including secured devices and accounts, tested backups and incident planning, with Cyber Essentials where contracts or funding require it. Penetration testing is not named as a blanket obligation for schools and colleges.

It remains the strongest independent evidence that the expected controls actually work, and many trusts commission a test for exactly that reason.

What does a penetration test cost for a school or college?

Typical UK costs run from £2,400 to £12,600 at day rates of £1,200 to £1,400. An external infrastructure test for a single school takes 2 to 3 days, £2,400 to £4,200, while a combined internal and external test for a college or multi-academy trust runs 6 to 9 days, £7,200 to £12,600.

Scope drives the price, and a short scoping call fixes the exact figure.

Is Cyber Essentials enough for a school, or do we need a full test?

Cyber Essentials Plus may be enough for a small primary school, where it is proportionate, but a college or trust holding data across multiple sites needs a scoped penetration test, which finds the issues certification never looks at: your MIS, cloud tenancy configuration and internal network segregation.

Cyber Essentials is a baseline self-assessment and Cyber Essentials Plus adds independent verification of five core controls, which is why neither examines those deeper areas in depth.

How often should schools and colleges run penetration tests?

Test annually if you are a trust or college, aligned with the DfE standards’ expectation of ongoing risk management, plus a retest after any major change such as a new MIS, a migration to the cloud or joining schools into a trust.

Smaller single schools with simple estates sometimes test every two years and rely on Cyber Essentials Plus in between, which is a defensible risk-based position.

Will testing disrupt teaching or put safeguarding data at risk?

Not when it is scoped properly. We schedule testing windows around term dates and exam periods, agree rules of engagement for any system holding safeguarding or pupil data, and use UK-based testers operating under strict confidentiality and ISO 27001 controls. Testing reads and probes systems; it does not bulk-extract records, and any sensitive access needed to prove a finding is agreed with you first.

Turn the DfE standards into evidence your board can sign off

If your trust, school or college needs to show governors, insurers or a funding body that its cyber controls stand up, a scoped penetration test is the most direct way to do it. Tell us about your estate through our CREST pentesting quote form and we will come back with a fixed scope and price, planned around your term dates.

Leave a Reply

Your email address will not be published. Required fields are marked *