The DfE doesn't tell you which standard to start with. Here's the reasoning we would use in your position.
Twelve standards, no prescribed sequence, and a 2030 deadline that still feels comfortably far away until it isn't. That's the position most schools and trusts are in with the DfE Digital and Technology Standards.
Six are designated ‘core’ standards, which all schools and colleges must be working towards by 2030: broadband internet, wireless network, network switching, digital leadership and governance, filtering and monitoring, and cyber security. The other six: IT support (added November 2025), cloud solutions, digital accessibility, laptops/desktops/tablets, network cabling, and servers and storage, sit alongside them, without the same statutory deadline, but still feed into whether a school can evidence the core six properly.
Left unguided, most schools default to the easiest starting point: whichever standard has the tidiest paperwork already, or whichever their IT provider raises first. That's an understandable instinct, but it isn't a risk-based one. It tends to leave the standard with the highest potential for harm sitting untouched until much later in the cycle, simply because it's the hardest to evidence quickly.
Ease of documentation and risk of harm are two different things, and only one of them should decide where you start.
We put it to a vote
We recently asked our LinkedIn network the same question we're asking you: if you were advising a Headteacher, CFO, or Trust Board on sequencing their digital strategy, which core standard needs to be the non-negotiable starting point? Here's how the vote landed:
- Leadership & Governance – 40%
- Filtering & Monitoring – 30%
- Cyber Security – 30%
- Broadband – 0%
The plurality view matches our own, and the reasoning below sets out why.
Start with who's accountable, not what's easiest
Digital Leadership & Governance goes first for a structural reason, not a sequencing convenience. It's the standard that names your SLT Digital Lead, sets your digital strategy, and establishes a review rhythm every other standard reports into. Start anywhere else, and you're producing evidence for standards with no confirmed owner and no agreed cadence for revisiting it. The evidence tends to go stale.
Then go to the standard that can do the most damage
Cyber security should be reviewed second, ahead of the three network infrastructure standards and deliberately so. Of the twelve, it's the one with by far the highest risk exposure given the sector's current attack rate, and the one governors should reasonably expect the most detailed reporting on. Working through infrastructure first, simply because network diagrams and contracts are easier to pull together than MFA coverage and backup strategy, means the highest-harm standard waits longer for attention. That's the wrong way round.
It also means gaps that surface later, such as end-of-life hardware, unsupported firmware, weak segmentation, get discovered before they've have longer to sit unaddressed, and can be worked back into the cyber security evidence rather than re-opening it as an afterthought.
Let each standard build on the one before it
The remaining core standards follow a similar logic: broadband, wireless network and network switching, all supply the technical detail that cyber security's answers were built on; filtering and monitoring sits on top of that combined network and security picture, but is treated as a safeguarding standard first and a technical one second because it needs DSL input as well as IT.
The other standards that sit outside of the core group: IT support, cloud solutions, servers and storage, network cabling, devices and digital accessibility, follow the same principles rather than a separate one. The ones with the clearest bearing on safeguarding and continuity of learning get evidenced early, and IT support is reviewed annually, because it's the arrangement that keeps everything else working.
A final gap-check across all twelve then feeds any open items back into the next governance review, so nothing is dropped each year.
The question isn't ‘which standard is easiest to close off this term’ — it's ‘which standard, left open, could hurt us most’.
Twelve standards, one hierarchy of risk
It's worth being precise about the scale here, because 'six standards' undersells the task. There are 12 DfE Digital and Technology Standards in total. Six are core, with the 2030 deadline attached; the other six do not carry the same statutory date but still shape whether the core six can be evidenced well. A device estate that is unmanaged, or storage that isn't properly secured, will eventually show up as a gap in your cyber security answers regardless of which column the DfE has filed it under.
Where to go from here
This is the reasoning behind the order. The practical side: the specific actions, evidence to request and the questions to put to your IT provider for each standard, is set in our DfE DS step by step (A4 (Landscape))
This isn't a hand-it-to-IT exercise
It's tempting to pass the whole framework to your IT support provider and wait for a completed tracker back. That's why we don't allow access to our trackers outside of your organisation. The accountability for these standards sits with the school or trust, not the third party IT provider (there's a standard about them so why would it?). This means that someone in your organisation needs to understand each answer well enough to defend it to a governor, auditor or the DfE.
That doesn't mean doing the technical work yourself. It means working through it alongside your provider rather than handing it over to them: asking them to walk you through what each answer means in practice, not just confirm it's been done. A good IT provider will be able to explain a patching cadence or a backup strategy in plain language without the jargon doing the work of hiding a gap If they can't or won't then look to your DfE IT Support standards as that in itself is a risk!

