Working Checklist

CIPA Compliance Checklist

Everything a school, district or library needs to do — and be able to prove — before signing the annual E-Rate certification. Work through the eight steps below in order, gather the evidence noted at each one, and your next audit request becomes a folder you already have rather than a scramble you dread.

8Steps to full compliance
1x / yearCertification to renew
4Evidence folders to keep
0Steps you can safely skip
CIPA-compliant filtering
120M+ domains classified
Daily category updates
On- & off-campus coverage
E-Rate ready
Before you start

How to use this checklist

CIPA compliance fails in predictable ways. It is almost never the filter that is missing — it is the public-hearing minutes nobody kept, the policy that was drafted but never formally adopted, or the take-home Chromebooks that quietly browse unfiltered every evening.

Ordered for dependencies

This CIPA compliance checklist is ordered so that each step produces the paperwork the next one depends on. Follow the sequence the first year; in later years steps 1-3 become a review and steps 4-8 are ongoing operations.

Assign an owner to each step

In most districts the technology director owns the filter and reporting steps, the superintendent's office owns policy adoption and the hearing, and curriculum staff own student education. Where a step says "evidence," put that document into a single shared compliance folder the day it is created — that folder is what an E-Rate reviewer will ask for, sometimes years later.

Do not over-comply

Blocking far beyond the required categories, or monitoring more intrusively than your written procedure describes, does not add compliance credit — it adds teacher friction, parent complaints, and a wider gap between what your documents say and what your network does. The goal of this checklist is a program that is complete, provable, and no heavier than the law demands.

The checklist

Eight steps from zero to certifiable

Follow them in sequence the first year. In later years, steps 1-3 become a review and steps 4-8 are ongoing operations. Click a box to mark a step complete and watch the progress bar move — click a row to expand its detail.

Compliance progress 0 of 8 steps marked
1
2
3
4
5
6
7
8
1

Draft your internet safety policy

Write a policy that addresses minors' access to inappropriate material online; their safety and security when using email, chat and other direct communications; unauthorized access and other unlawful activity; unauthorized disclosure of minors' personal information; and the measures you use to restrict access to harmful material. Use our internet safety policy guide for a section-by-section structure.

Evidence: the dated policy document
2

Give public notice and hold a hearing

Before adoption, provide reasonable public notice and hold at least one public hearing or meeting where the community can comment on the proposed policy. A regular board meeting works if the policy appears on the published agenda.

Evidence: the published notice, the agenda, and minutes recording that the policy was discussed
3

Formally adopt and enforce the policy

Have the board vote to adopt the policy, then actually operationalize it: publish it to staff and families, reference it in student handbooks, and align your acceptable use agreements with it. A policy nobody enforces is a liability at audit time, not an asset.

Evidence: adoption minutes and the distribution record
4

Deploy a filter covering the required categories

Turn on a technology protection measure that blocks obscene content, child sexual abuse material, and material harmful to minors for every computer minors use — and the first two categories for adults as well. Category-based filtering makes this demonstrable: block the adult, explicit and exploitation categories across the network and the mandate is covered, including sites registered yesterday. See our CIPA-compliant web filter for how this works.

Evidence: a screenshot or export of the blocked-category configuration
5

Extend coverage to every device, including take-home

Inventory every path a student takes to the internet under your responsibility: labs, classroom devices, BYOD Wi-Fi, and above all 1:1 devices that go home. Filtering must be consistent across them, which means policy that travels with managed devices off-campus and handles HTTPS traffic.

Evidence: your device management configuration showing the filter enforced off-network
6

Monitor minors' online activity

Establish reasonable monitoring: category-level reports reviewed on a schedule, alerts on high-risk categories, and adult supervision expectations in classrooms and labs. CIPA asks for oversight, not surveillance — define in writing what "monitoring" means in your district so staff apply it consistently.

Evidence: sample reports and the written monitoring procedure
7

Educate students on online safety and cyberbullying

Schedule and deliver instruction on appropriate online behavior, including safe interaction on social networking sites and in chat environments, and recognizing and responding to cyberbullying. Most districts fold this into a digital citizenship curriculum by grade band.

Evidence: the curriculum outline and delivery dates per school
8

Certify for E-Rate and keep everything on file

With steps 1-7 done and documented, complete the CIPA certification in your E-Rate paperwork for the funding year. Then diarize an annual review: confirm the policy still matches practice, re-verify filter categories, and refresh the evidence folder. Our E-Rate and CIPA funding guide explains what happens after you certify.

Evidence: the certification record and your review calendar
Audit readiness

The four evidence folders auditors ask for

When compliance is questioned, nobody asks whether your filter has a nice dashboard. They ask for documents. Keep these four folders current and reviews become short.

Policy folder

The adopted internet safety policy, every revision with dates, and the acceptable use agreements that implement it.

Adoption folder

Public notice, meeting agenda, hearing minutes, and the board vote adopting the policy.

Filter folder

Blocked-category configuration, change log for exceptions and unblocks, and periodic category-level reports.

Education folder

The online-safety curriculum, grade-band schedule, and completion records per building.

A reporting habit that fills the folders for you: Category-level reporting does double duty: it is your monitoring mechanism during the year and your audit evidence afterward. A monthly export showing that the adult, explicit and exploitation categories were blocked district-wide — plus the exception log — is precisely the artifact a reviewer wants to see.

Monthly category report Exception change log Unblock approvals Annual review notes
Ownership map

Who owns each part of the checklist

Give every step a named owner and a named verifier. A common split across districts looks like this.

School board

Adopts the internet safety policy and holds the public hearing required before adoption

Step 2 Step 3

Superintendent

Signs the annual E-Rate CIPA certification and oversees the compliance program

Step 8

Technology director

Deploys and configures the filter, ensures off-campus coverage, runs monitoring reports

Step 4 Step 5 Step 6

Principals & curriculum

Deliver online-safety instruction by grade band and keep completion records per building

Step 1 Step 7
Where districts slip

Six gaps that undo otherwise-compliant schools

Each of these has tripped real districts. All are cheap to fix before certification and expensive to explain after it.

No hearing record

The policy exists and the hearing probably happened — but nobody can produce the notice or minutes. Reconstruct what you can now, and put the hearing on the board agenda again at the next policy revision so the record is airtight going forward.

Unfiltered take-home devices

The campus network is filtered; the Chromebook on a kitchen table is not. Since students spend more unsupervised hours at home than at school, this is the largest real-world exposure — and the easiest for a reviewer to spot.

Forgotten unblock rules

A filter exception created for one teacher's project in 2023 is still open district-wide. Without an exception log and expiry dates, temporary holes become permanent — and contradict the configuration you certified.

Education that is not documented

Teachers do cover online safety and cyberbullying — informally, unevenly, and with nothing written down. Adopt a named curriculum, put delivery dates on a calendar, and record completion, or the requirement is unprovable.

Policy and practice have drifted

The adopted policy describes a filter, categories or procedures you replaced two upgrades ago. Reviewers compare documents to reality; an annual reconciliation of policy text against actual configuration closes the gap.

New content types nobody assessed

Generative AI sites — image generators, deepfake and face-swap tools, AI companion chat — appeared after your policy was written and sit in no category your old filter knows. An AI-tools blocklist covering 16,000+ domains, updated daily, brings them under governance without a policy rewrite.

Why the filter step is the easy one

Let the data do the heavy lifting

Steps 4-6 of the checklist — filtering, coverage and monitoring — are only hard if your filter's knowledge of the web is thin. Ours is not.

120M+Domains already classified
57+Content categories to build policy from
DailyUpdates as new sites appear
16,328+AI-tool domains under control

The ten-minute self-audit

  • Can you open the adopted policy and point to its adoption date?
  • Can you produce the public notice and hearing minutes?
  • Does the filter block the required categories for every student device — at home too?
  • Is there a current exception log with owners and expiry dates?
  • Did every grade band receive documented online-safety instruction this year?
  • Could you hand a reviewer last month's category report today?
Annual check

Run this before every certification

Six questions, ten minutes, once a year — ideally a month before you certify, so there is time to close whatever is open. If every answer is yes, sign with confidence. If any answer is no, the eight steps above tell you exactly which artifact to create.

Districts that institutionalize this self-audit stop thinking of school internet compliance as a project and start treating it as a small recurring habit. That shift matters: staff turn over, policies age, and devices multiply, but a written checklist with named owners survives all three.

If the self-audit surfaces gaps you'd rather not close alone — off-campus enforcement, category coverage, audit reporting — that is exactly what we help schools set up. Pricing is public, and a pilot can run alongside your current setup.

After year one

Keeping compliance alive

The first pass through this checklist is a project; every year after, it is maintenance. Build these rhythms into your calendar.

Each term

Skim the category reports and prune expired exceptions. A workable annual rhythm keeps compliance lightweight: each term, verify the filter configuration still matches policy and remove any temporary unblocks that have outlived their purpose.

Each spring — before E-Rate paperwork

Run the ten-minute self-audit and refresh the four evidence folders. Confirm the policy still matches practice, re-verify filter categories, and ensure the education delivery records are current for every building.

Every two to three years

Bring the internet safety policy back to the board, with notice and a hearing, so the adopted text keeps matching reality. Do this sooner whenever your filtering technology, device program or the online landscape changes materially.

Off-cycle triggers

Two events should always trigger an off-cycle review. The first is a technology change: a new filter, a new device management platform, or a move between cloud and on-premise deployment. The second is a new category of online risk that parents and boards start asking about — generative AI being the current example. Handling these proactively, with a short memo added to the policy folder, is far better than discovering at certification time that your documentation describes a district that no longer exists.

Make the checklist visible

Make the checklist visible beyond the technology office. When principals know the education requirement is theirs, and the board clerk knows hearing minutes are compliance artifacts, the burden spreads thin enough that no single person carries it — and no single resignation breaks it. For background on the legal duties behind these steps, see What Is CIPA?

Documentation that does double duty

Reports that serve as audit evidence

Category-level reporting fills your compliance folders while you use it for day-to-day oversight. Generate these on a schedule and the evidence accumulates without extra effort.

Monthly category report

Shows which categories were blocked district-wide, confirming the required categories stayed enforced all month.

Exception change log

Records every unblock request with the requester, reason, scope, approval, and expiry date to prevent permanent gaps.

Unblock approval records

Names the person who approved each exception and the criteria used, linking filter decisions to your written policy.

Quarterly configuration export

A snapshot of your filter settings proving the blocked-category list matched your policy on a specific date.

High-risk category alerts

Flagged attempts at self-harm, explicit, or exploitation content reviewed and acknowledged by a named staff member.

Annual review notes

A one-page memo confirming policy-to-practice alignment, signed by the technology director and filed in the policy folder.

Two kinds of districts

Audit-ready vs. at-risk: how the same rules play out

Both districts below have a filter and both signed the certification. Only one of them can prove what they signed.

Checklist areaAudit-ready districtAt-risk district
Internet safety policy Board-adopted, dated, matches current practice A draft on a shared drive that never reached the board
Public notice & hearing Notice, agenda and minutes filed in the adoption folder "We probably discussed it at some meeting"
Filter configuration Required categories blocked, exports kept quarterly Settings changed by many hands, no snapshots kept
Take-home devices Same policy enforced off-campus on managed devices Filtering ends at the school firewall
Monitoring Written procedure plus scheduled report reviews Logs exist somewhere; nobody reads them
Student education Named curriculum with completion records per building Left to individual teachers, undocumented

The uncomfortable truth in that table is that the at-risk district may be filtering perfectly well. Its exposure is documentary, not technical — and documentary exposure is entirely self-inflicted. Every artifact in the left-hand column takes minutes to produce at the moment the work happens, and can be nearly impossible to reconstruct years later when a reviewer asks. The checklist exists to make sure those minutes get spent.

Questions

Checklist questions we hear from districts

The pacing item is the public process: notice, a hearing, and a board vote typically span one to two board cycles. The technical side is faster — a cloud filter with the required categories blocked can be live in days, and monitoring reports begin accumulating immediately. Most districts starting cold can complete all eight steps within a term.

No. The notice-and-hearing requirement attaches to adopting the internet safety policy, not to each funding year. You do need to re-certify annually, and it is good practice to re-run the public process when the policy changes substantively, keeping the minutes each time.

The spine is the same — policy, public process, filter, certification — but libraries emphasize the adult-access provisions: a documented procedure for an adult patron to have the filter disabled for lawful use, and filtering on any terminal a minor can reach. The student-education step is a school-specific obligation.

Reasonable oversight, defined by you and applied consistently. In practice: classroom and lab supervision norms, scheduled review of category-level reports, and alerts on high-risk categories such as self-harm or explicit content. It does not require reading students' communications or logging every page each child visits.

It can satisfy the letter of the law, but it leaves you proving a negative — that a hand-maintained list catches obscene and harmful sites among hundreds of thousands of new domains daily. Category-based filtering across 120M+ classified domains is easier to defend: you show the blocked categories and the daily update process, and coverage of brand-new sites follows automatically.

Give every step a named owner and a named verifier. A common split: the board owns adoption and hearings; the superintendent owns certification; the technology director owns filtering, coverage and reporting; principals own delivery of online-safety instruction. The verifier's only job is confirming the evidence landed in the compliance folder.

Treat them as a governed category rather than a series of one-off blocks. Decide which AI uses your district permits for instruction, block the categories you don't — essay writers, deepfake tools, AI companion chat — and note the decision in your policy folder. A dedicated AI-tools blocklist updated daily keeps the decision enforced as new tools launch.

You can outsource the technical steps — deployment, category configuration, off-campus enforcement and reporting — but the checklist as a whole stays with the institution. The public hearing, the board adoption, the student instruction and the annual certification are governance acts only the district can perform. A good vendor makes steps four through six almost effortless; it cannot vote on your policy or teach your students.

Traffic that rides your network should pass through the same technology protection measure, which is why guest and BYOD Wi-Fi belong on the coverage inventory in step five. You are not expected to reach into a student's personal device settings, but any internet access you provide to minors should be filtered to the required categories. The clean approach is a single policy applied at the network layer so personal and school-owned devices are treated alike on your Wi-Fi.

Adults are not exempt from the two core categories: obscene material and child sexual abuse material must be blocked for everyone. The material-harmful-to-minors layer is what you scope to student devices and grade bands. Handle this with user-group policy rather than separate systems — staff accounts see a lighter profile, student accounts a stricter one, and both are documented in the same filter configuration you keep as evidence.

Close every box on the checklist

We'll walk your team through category coverage, off-campus enforcement and the reports that fill your audit folders automatically — so certification day is just a signature.

Book a Walkthrough See Pricing