Policy Guide

CIPA Internet Safety Policy

The internet safety policy is the written backbone of CIPA compliance — the document that turns your school internet safety rules from custom into commitment. This guide covers what the policy legally must contain, gives you a section-by-section structure a district can adapt, walks through the public-hearing requirement, and shows how to wire the policy to the filter and acceptable use agreement that make it real.

5Elements the law names
9Sections in our template structure
1Public hearing before adoption
3Documents that must agree
Required Elements

The elements your policy must address

The law names the topics an internet safety policy has to cover. Your document can say much more, but it cannot say less than this.

2.1

Access by minors to inappropriate matter

How the institution restricts minors' access to material that is obscene, child sexual abuse material, or harmful to minors — in practice, a statement that a technology protection measure blocks these categories on all computers minors use, on campus and on managed devices off campus.

2.2

Safety in direct communications

The safety and security of minors when using email, chat rooms and other direct electronic communications — today that includes messaging inside learning platforms, collaborative documents, and chat features embedded in games and AI tools.

2.3

Unauthorized access and unlawful activity

Measures against hacking and other unlawful online activities by minors — account security expectations, prohibitions on circumventing the filter, and consequences aligned with the student code of conduct.

2.4

Protection of minors' personal information

Safeguards against unauthorized disclosure, use and dissemination of personal information regarding minors — increasingly important as students encounter ungoverned AI tools that invite them to paste in exactly that information.

Reference: 47 U.S.C. § 254(h)(5) / (l)
Policy Fundamentals

What an internet safety policy is — and what it is for

The governing document

Under the Children's Internet Protection Act, a school or library taking E-Rate discounts on internet access must adopt and enforce a written internet safety policy. It states what the institution protects students from, how, and who is responsible.

Not the filter, not the AUP

It is not the same thing as your filter settings, and it is not the same thing as the acceptable use agreement students sign. The policy is the governing document; the filter and the AUP are two of the instruments that carry it out.

The artifact that proves intent

A filter shows what your network does today; the adopted policy shows what your governing body committed to, on what date, after hearing from the public. When the two match, compliance is easy to see. When they diverge, every other question gets harder.

If CIPA itself is new to you, read What Is CIPA? first; this guide assumes the basics.

Model Structure

A nine-section internet safety policy your district can adapt

There is no mandated format, which is both freedom and trap. This structure keeps the required elements visible, separates federal minimums from local choices, and gives an auditor a document they can navigate in minutes.

1

Purpose and scope

Why the policy exists, the legal context in one paragraph, and exactly who and what it covers: students, staff, guests; school networks, school accounts, and school-managed devices wherever they connect — including at home.

2

Definitions

Short, plain definitions of the terms the policy relies on: minor, technology protection measure, obscene material, harmful to minors, direct electronic communications, managed device. Borrow the law's language for legal terms rather than paraphrasing it.

3

Filtering and blocked content

State that a technology protection measure blocks obscene material, child sexual abuse material and material harmful to minors for all users, with the harmful-to-minors standard applied to minors. Name the blocked content categories at the level of policy, not vendor screen names, so the document survives product changes.

4

Differentiated access and unblocking

Describe access tiers — by grade band and for staff — and the procedure for adult unblocking for bona fide research or other lawful purposes: who may authorize it, how it is logged, and how long it lasts. Include the process for teachers to request site exceptions.

5

Safety in communications and online behavior

The institution's school internet safety rules for email, chat, messaging and collaborative platforms; expectations for respectful conduct; and the prohibition on sharing personal information about oneself or others without authorization.

6

Monitoring

Define what monitoring means in your institution: supervision norms in classrooms and labs, scheduled review of category-level filtering reports, alerting on high-risk categories, and the boundaries — what the district deliberately does not collect. Written boundaries build trust and prevent scope creep.

7

Education program

Commit to instruction on appropriate online behavior for each grade band, explicitly covering social networking safety and cyberbullying awareness and response, and name who is responsible for delivering and documenting it each year.

8

Emerging technologies, including AI

A short section reserving the district's authority to categorize and restrict new classes of online services — generative AI tools being the current case — under the same principles, so each new technology wave does not require reopening the whole policy.

9

Adoption, review and enforcement

Record the public notice and hearing, the adoption date and adopting body, the review cycle, and how violations are handled through existing conduct codes. This section is where an auditor looks first — make the dates impossible to miss.

Adoption Procedure

The public-hearing requirement, demystified

CIPA requires that the internet safety policy be adopted after reasonable public notice and at least one public hearing or meeting where the proposal can be addressed.

Publish notice

Publish notice through your normal public channels, far enough ahead to be "reasonable." Name the policy explicitly on the agenda — not buried in "consent items."

Hold the hearing

A regularly scheduled board meeting satisfies the requirement when the policy appears as an identifiable item on the published agenda and the minutes reflect that it was presented and discussed.

File the evidence

Record discussion and the adoption vote in the minutes. File notice, agenda and minutes together with the adopted text. The most common failure is holding a hearing and keeping no evidence.

Hearing-day running order

Before: publish notice; post the draft policy where the public can read it.
During: present the draft, take comments, note them in minutes; amend if warranted.
After: adopt by vote, date the final text, and file the paper trail in your compliance folder the same week.

The bar is procedural fairness, not a town-hall spectacle: the community must have a genuine chance to know about the policy and speak to it before it takes effect. A regularly scheduled board meeting satisfies the requirement when the policy appears as an identifiable item on the published agenda and the minutes reflect that it was presented and discussed.

Instruments of Enforcement

Tying the policy to the filter and the AUP

A policy that lives in a binder while the filter lives in a console will drift apart within a year. The fix is traceability.

Internet safety policy

The commitment Board-adopted governing document States what is blocked and for whom

Filter configuration

The enforcement Blocks categories for student groups SafeSearch enforced across 120M+ domains

Acceptable use policy

The user agreement Tells users what they may not do Defines consequences for violations

Every enforcement claim in the policy should map to a named, checkable thing in the filter — a blocked category set, a grade-band policy, an off-campus enforcement setting — and every behavioral rule should appear in the acceptable use policy students and staff actually sign. Category-based filtering makes the mapping natural, because policy language and filter language finally share a vocabulary. See our CIPA-compliant web filter for how districts implement that mapping.

Policy-to-Filter Mapping

How policy language maps to filter configuration

Category-based filtering makes the mapping natural, because policy language and filter language finally share a vocabulary. Category-level reporting then closes the loop.

Policy says

"Block content harmful to minors for all students"
"Restrict ungoverned AI tools"
"Enforce SafeSearch on all search engines"
"Safeguards travel with managed devices off campus"
"Differentiated access by grade band"

Filter enforces

Defined set of categories applied to student groups
AI-tools blocklist — 16,000+ domains across essay writers, image generators, deepfake tools and companion chat, updated daily
SafeSearch enforced across 120M+ classified domains
Off-campus enforcement setting enabled for student groups
User groups mapped to grade-band tiers the policy names
Change any one of the three documents, check the other two the same week
Definitions & Distinctions

Internet safety policy vs. acceptable use policy

Districts often maintain one document and assume it covers both jobs. The two overlap, but they answer to different audiences and different requirements.

Internet safety policyAcceptable use policy (AUP)
Primary audienceThe institution, its board, and reviewersIndividual students, staff and families
Legal roleRequired by CIPA for E-Rate participantsNot itself a CIPA requirement — but the natural enforcement vehicle
Adoption processPublic notice and hearing, board adoptionAdministrative issue-and-sign, typically annual
Content focusWhat the institution blocks, monitors and teachesWhat the individual user may and may not do
Change frequencyStable; revised every few years with a hearingRefreshed routinely as tools and expectations shift

Keep them as two documents with one owner. The internet safety policy states commitments at the level of principle and category; the AUP translates them into first-person rules a fourteen-year-old can understand. When the policy changes, the AUP inherits the change at its next annual refresh — and because only the policy carries the hearing requirement, routine AUP updates stay administrative instead of triggering a public process every autumn.

Drafting Standard

Four qualities of a policy that survives contact with reality

The best internet safety policies we see share the same traits — and none of them is length.

SpecificNames categories and procedures, not vibes
NeutralWritten to outlive any single vendor or product
HonestDescribes only what the district actually does
DatedAdoption, review and revision dates on the face of it

The "honest" trait deserves emphasis. Boards sometimes adopt aspirational language — monitoring practices grander than anyone performs, education programs no one scheduled — on the theory that ambition looks good. In a compliance document the opposite is true: every sentence is a promise a reviewer can test. Write down the program you run, run the program you wrote down, and revise the words when the practice legitimately improves.

Policy Lifecycle

Key milestones after board adoption

2–3 wks
Publish & distribute
30 days
Staff briefing complete
Annual
Reconciliation review
2–3 yrs
Full revision cycle
Implementation

After adoption: making the policy part of school life

Adoption is the legal milestone, but enforcement is what the certification actually attests.

1

Publish and distribute

Within a few weeks of the board vote, publish the policy where families can find it and summarize it in student handbooks in age-appropriate language.

2

Brief staff on roles

Brief staff — especially the difference between the school internet safety rules students must follow and the procedures staff use for exceptions and adult unblocking.

3

Integrate into onboarding cycles

New-hire onboarding and the annual AUP signature cycle are the natural moments to keep awareness current without extra meetings.

4

Annual reconciliation

Once a year, someone reads the policy next to the filter configuration and the AUP and files a short note confirming they still agree — or listing what changed.

5

Verify filter alignment

Walk through each enforcement claim in the policy and verify the filter configuration matches — blocked category sets, grade-band policies, off-campus enforcement settings, and SafeSearch rules should mirror the adopted text exactly.

6

Update the AUP

Ensure the acceptable use policy reflects every behavioral rule in the internet safety policy. Students and staff should sign the updated AUP at the next annual refresh cycle so all three documents stay aligned.

7

Build the compliance index

Pair that reconciliation note with the artifacts from our CIPA compliance checklist and the funding-side records described in E-Rate and CIPA funding, and your policy becomes the index to a compliance program that can be inspected on any given Tuesday.

Interpretive Notes

Internet safety policy questions, answered

No. CIPA specifies the topics an internet safety policy must address, not a format. That is why the nine-section structure above separates required elements from local choices — you can adapt it freely as long as every mandated element remains clearly covered and the adoption process is documented.
The law sets no fixed revision schedule; the duty is to adopt and enforce a policy that reflects your actual safeguards. Practically, review it annually alongside your E-Rate certification and revise it — with notice and a hearing — whenever technology or practice changes enough that the text no longer matches reality. Every two to three years is a common cycle.
Reserve the full notice-and-hearing process for substantive changes: new monitoring practices, materially different blocking commitments, expanded scope. Typo-level corrections and formatting do not change what the community was consulted on. When in doubt, run the public process — it costs one agenda item and removes the question.
Better not to. Commit to a technology protection measure and to blocking defined categories of content; keep vendor names, product screenshots and console terminology in an operational appendix or runbook. Then a product migration changes your appendix, not your board-adopted policy.
CIPA requires neither a social media ban nor an AI section — blocking obligations cover obscene material, child sexual abuse material and content harmful to minors. But a good policy records your local decisions on both, and an "emerging technologies" section lets you govern new tool categories, including AI, without reopening the document each time the landscape shifts.
A pairing works best: the technology director drafts the enforcement and monitoring sections because they know what is actually implemented, while an administrator or board policy committee shapes scope, education and conduct sections. Legal counsel reviews the definitions against the statutory language. One owner then keeps policy, filter and AUP reconciled year over year.
Describing a district that no longer exists — a policy written for computer labs and a campus firewall, silent on the take-home devices where most student browsing now happens. If your students carry managed devices home, the policy must say the safeguards travel with them, and your filter must make that sentence true.
Yes, and a single district-wide policy is usually cleaner than a patchwork of building-level documents. Adopt one internet safety policy through one public process, then express the differences between elementary, middle and high schools as grade-band access tiers within it rather than as separate policies. That keeps your commitments consistent, your hearing record simple, and your filter configuration — user groups mapped to the tiers the policy names — a direct reflection of the adopted text.
The filtering, communications, unauthorized-access and personal-information elements apply to both. The education-and-monitoring commitments added by later law are aimed at schools instructing minors, so a public library's policy leans instead on the adult-access provision: a documented procedure for disabling the filter for an adult's lawful use. Libraries should still adopt the policy through public notice and a hearing, and still keep the filter configuration matched to the words.

Make your policy and your filter tell the same story

We map every commitment in your internet safety policy to enforced categories, off-campus coverage and audit-ready reports — so the words your board adopted describe the network you actually run.