Digital oversight and Ofsted’s September 2026 inspection toolkit

Ofsted inspection toolkit

With the new academic year close, this is one of the last useful windows for schools to bring their digital evidence together before September pressure returns.

Ofsted’s updated school inspection toolkit comes into force for inspections from 7 September 2026. For schools due or eligible for inspection, an inspection could arrive at any point in the new academic year. While much of the attention has focused on curriculum, SEND, attendance and inclusion, the framework also has clear digital and technology dimensions.

For school leaders, the important link is with the Department for Education’s six core digital and technology standards: broadband internet, wireless network, network switching, digital leadership and governance, filtering and monitoring, and cyber security.

Schools with current records and a clear understanding of their digital risks will be better able to demonstrate effective oversight than those relying solely on historic decisions or untested supplier assurances.

What has changed in the inspection toolkit?

Ofsted’s updated inspection materials take effect from 7 September 2026, including the school inspection toolkit, operating guide and supporting information for schools.

One of the headline changes is the move to a five-point report-card scale: exceptional, strong standard, expected standard, needs attention and urgent improvement. Safeguarding is assessed separately as met or not met.

Expected standard is not simply the old “good” grade under a new name. The new model creates more room for inspectors to recognise stronger practice, while also identifying where a school is below the expected level before issues become urgent.

Digital evidence sits mainly in leadership and governance, because it shows how the school manages resources, risk, safeguarding, compliance and improvement. It may also be relevant to curriculum and teaching, where technology supports pupils’ education, and to safeguarding,through online safety, filtering, monitoring and cyber resilience.

The digital estate is not just an operational issue for IT. It is part of the evidence base for how well the school is led, how safely it operates and how prepared it is for modern teaching and learning.

Digital evidence that may support inspection discussions

The six DfE digital and technology standards give school leaders a useful structure for thinking about inspection evidence. Inspectors are unlikely to ask for technical detail in isolation. Where digital matters are relevant, inspectors may look at whether leaders understand the current position, whether risks are being reviewed, and whether there is dated evidence of action.

Ofsted does not prescribe a separate digital evidence pack or expect schools to create documents solely for inspection. The examples below are records that schools may already hold through normal management and governance.

Broadband internet
Schools should be able to show that their broadband capacity has kept pace with current demand. A recent connectivity review, bandwidth report or contract review can all help demonstrate that capacity has been considered against current device numbers, cloud use, online assessment and future demand. The risk is relying on an installation decision made several years ago, before the school’s digital use changed.

Cyber security
Cyber evidence needs to show active practice. That means more than a cyber policy on file. Leaders should be able to show the basics are in place: multi-factor authentication, patch management and tested backups. They should also be able to evidence how incidents are monitored, escalated and responded to, including supplier contact routes. Governor minutes or risk register entries referencing cyber risk are also useful because they show oversight, not just technical activity.

Digital leadership and governance
Digital evidence should show clear responsibility and regular review. Leaders should be able to explain who owns digital strategy, how data protection is overseen, and how governors are kept informed. Evidence may include a current digital strategy, named digital and DPO responsibilities, committee minutes and risk register entries. A strategy written once and left untouched may no longer reflect the school’s current systems, risks or procurement priorities, making it harder to show that digital decisions are being actively governed.

Filtering and monitoring
Filtering and monitoring is closely linked to safeguarding, so evidence needs to be current. Schools should be able to show that systems have been reviewed, alerts reach the right people, and settings reflect current users, devices and risks. This should include newer risks such as dynamic and AI-generated content, not just traditional blocked categories. A supplier name in a policy carries more weight when it is supported by review logs, alert routes and recent test records.

Network switching
Switching can become difficult to evidence when the network has grown in pieces over several years. Extra switches may have been added to solve short-term capacity problems, sometimes without a clear record of age, management capability or resilience. That makes it harder for leaders to understand where risks sit. A current network diagram, switch inventory and notes on VLAN capability, management capability and PoE capacity can help show that the school has a reliable view of its infrastructure.

Wireless network
Wireless evidence should show that coverage and capacity match how teaching and learning now operate. It is not enough to know that Wi-Fi reaches a room. Leaders need confidence that it can support the number of devices being used in that space. A wireless survey, heatmap, access-point map, supplier review or record of known weak spots can help. The common issue is access points placed for basic coverage, rather than the density needed for shared devices, online assessment or one-to-one use. That can leave the school with Wi-Fi that appears adequate on paper, but struggles under real classroom demand.

What “evidence” means in practice

Having a policy is only part of the evidence picture. The most useful evidence connects what the school says it does with what happens in practice and how leaders know it is being reviewed.

That usually means three types of evidence:

Stated policy: acceptable use, online safety, cyber, digital strategy and procurement documents.

Active practice: logs, test records, review dates, asset registers and supplier reports.

Governed practice: SLT reports, governor minutes, risk register entries and school improvement planning.

Before inspection, schools should collate, date and check the evidence they already hold, then identify any obvious gaps while there is still time to address them.

A practical evidence set might include:

Strategy and governance: a current digital strategy or ICT entry in the school development plan, plus governor minutes referencing progress against the DfE digital standards.

Ownership: named responsibility for digital leadership and data protection.

Cyber and safeguarding: patch records, backup test evidence, a dated incident response plan, and filtering and monitoring review logs.

Infrastructure: a switch and access-point inventory showing age, management capability and known risks.

How Everything ICT can help

Everything ICT helps schools and trusts review their digital estate against the DfE’s core standards and turn that review into clear, practical next steps.

Where support is needed, we can help source appropriate suppliers for areas such as connectivity, infrastructure, cyber security, filtering and monitoring, device management or managed services. As a compliant procurement service, we help schools access trusted suppliers through appropriate routes, while keeping value, safeguarding, resilience and whole-life cost in view.

That gives leaders a clearer picture of where the digital estate is strong, where evidence is missing, and what may need attention before an inspection, renewal or wider ICT decision.