E-Rate & CIPA Compliance

CIPA-Compliant Web Filter

The Children's Internet Protection Act asks one concrete thing of your network: a technology protection measure that actually blocks obscene material, child sexual abuse material, and content harmful to minors. This page explains exactly how our filter meets that requirement — and how it proves it when an E-Rate audit arrives.

3Required content classes blocked
120M+Domains classified
57+Content categories
On/OffCampus enforcement

CIPA Technology Protection MeasureAll three required content classes blocked from deployment
E-Rate Audit-Ready ReportingCategory-level block logs exportable by school and date range
120M+ Domain DatabaseRefreshed daily with multi-category classification
On & Off Campus EnforcementPolicy follows managed devices to any network
What the law actually requires

What "CIPA-compliant" actually means for a filter

CIPA is short, but it is specific. Schools and libraries that receive E-Rate discounts must certify that they enforce a technology protection measure on computers with internet access. That filter must block or restrict access to three specific classes of visual depictions.

The Certification Standard

CIPA does not name an approved vendor list, a required technology, or a specific product feature set. "CIPA-compliant filter" is therefore shorthand for a filter that can be honestly certified: it blocks the three required classes of content, it is actually enforced on the machines the certification covers, and the institution can show evidence of both. That evidence part matters more than most product pages admit — a filter you cannot report on is a filter you cannot defend in an audit.

Obscene Material

Content that meets the legal definition of obscenity must be blocked for all users, adults included. Our adult and pornography categories cover the domains where this content lives, refreshed daily so new sites are caught as they appear rather than after a complaint.

Child Sexual Abuse Material

CSAM is illegal everywhere and must be blocked without exception. Domains associated with this material are classified into blocking categories that no school policy can accidentally open — there is no configuration in which they pass.

Material Harmful to Minors

A broader class covering sexual content that is inappropriate for minors even where legal for adults. Because our database labels a domain with multiple categories, a mixed site can be restricted for students while its legitimate uses stay reachable for staff.

Worth repeating: CIPA does not require blocking social media, games, or any category beyond these three classes. Everything else you block is a local policy choice — a sensible one, often, but a choice. A good CIPA compliance web filter makes both layers explicit: the mandatory floor and the district policy built on top of it.

Enforcement & evidence

How the filter enforces — and proves — compliance

The technology protection measure requirement is satisfied by enforcement, not intent. A filter that works but cannot prove it worked is a liability when the audit arrives.

Technology Protection Measure

Our filter enforces it through category-based blocking: more than 120 million domains are classified into 57+ content categories, and the categories that map to CIPA's required content classes are blocked in every student-facing policy from the moment you deploy.

Because classification is multi-category — a single domain can be labeled both "Video" and "Adult" — the filter makes accurate calls on the mixed sites that trip up simple blocklists. And because new domains are classified as they appear, the certification you sign stays true tomorrow, not just on the day you configured the filter.

  • CIPA-mandated categories locked on for minors in every policy template
  • SafeSearch enforced on major search engines so image results are filtered too
  • HTTPS and encrypted traffic categorized, not waved through
  • Cloud or on-premise deployment — the same classification data drives both
Layer 1 — CIPA floor (always on): obscene material, CSAM, harmful-to-minors categories. Blocked for minors in every configuration.
Layer 2 — District policy (your call): gambling, weapons, self-harm, proxies, AI essay writers, streaming during testing windows — tuned by grade band, building or user group.

Separating the layers means an exception request from a teacher can never quietly punch a hole in the compliance floor.

E-Rate Audit Reporting

E-Rate certifications can be reviewed years after the funding year closes, and the question an auditor asks is disarmingly simple: show me. Districts that filter through opaque appliances often struggle here — the filter worked, but nobody can produce a record proving what it blocked, for whom, during the period in question.

Category-level reporting closes that gap. Instead of a haystack of URLs, your records say: adult content, obscenity and harmful-to-minors categories were blocked district-wide for all student groups, continuously, with logs to match. That is the shape of evidence audits are looking for, and it takes minutes to produce rather than weeks to reconstruct.

If E-Rate is new territory, our guide to E-Rate funding and CIPA obligations explains how the certification cycle works and where filtering evidence fits into it.

What an auditor can be shown, on demand

  • Policy export showing the CIPA-mandated categories blocked for minors
  • Category-level block logs by school, grade band and date range
  • Change history: who altered which policy, and when
  • Evidence that take-home devices carry the same enforcement
  • Exception records with the reason each was granted
Why data depth matters

A certification is only as strong as the data behind it

When you certify that your filter blocks the required content, you are really certifying the quality of its classification database.

120M+ Domains under classification
Full coverage
Daily Category refresh cycle
Continuous
Multi Categories per domain
Multi-label
16,328+ AI-tool domains tracked
Growing daily
Cutting through the noise

What CIPA requires vs. what vendors imply it requires

Plenty of products are sold on compliance fear. This table is the honest version — and our filter handles both columns, with the second clearly labeled as your policy, not the law's.

CapabilityRequired by CIPADistrict Policy Choice
Block obscene material and CSAM Yes, for all users
Block material harmful to minors Yes, for minors
Internet safety policy + student education Yes, alongside the filter
Monitor minors' online activity Yes
Block social media outright No Optional, per grade band
Block games, streaming, AI tools No Optional, widely done
Track individual keystrokes No Not something we sell
Beyond the building

On campus, off campus, same certification

The moment a district sends devices home, the filtering question follows them. A filter that stops at the firewall leaves your 1:1 program — and arguably your certification — exposed during the hours students use those devices most.

On the District Network

Every device that touches school internet access — managed laptops, lab desktops, staff machines, guest devices — is filtered against the policy for its user group. Coverage is network-wide, so an unmanaged phone on school Wi-Fi is still inside the compliance perimeter.

Network-wide coverage

On the Kitchen Table

Policy follows managed take-home devices wherever they connect. The Chromebook that is filtered in third period is filtered the same way on home Wi-Fi at 9 p.m., without a VPN for parents to configure or a setting for students to toggle off.

Off-campus enforcement

One Policy, Everywhere

This consistency does more than tighten compliance. It removes the awkward gap where a district teaches digital citizenship at school and then hands students an unfiltered window to the internet at home on district-owned hardware. One policy, everywhere the device goes, is simpler to run and far easier to explain to a school board.

Unified enforcement
The newest gap in older filters

AI tools: managed, not ignored

Generative AI created an entire class of sites that legacy CIPA compliant content filters never anticipated. Our filter ships with a dedicated AI Tools Blocklist to keep pace.

AI Tools Blocklist

16,328+ AI-tool domains organized into 18 categories and 165+ subcategories, updated daily by screening roughly 300,000 newly registered domains per day. You choose which AI categories to permit for instruction and which to block, per grade band, without hand-curating anything.

Essay writers & paraphrasers Homework & code solvers Image generators

Student Safety & Privacy

Some AI tools — deepfake generators, AI "companion" chatbots, voice-cloning services — raise student-safety and privacy problems that overlap directly with the concerns CIPA exists to address, and they multiply weekly. Protects student data students might otherwise paste into ungoverned tools.

Deepfake & face-swap Voice cloning AI companion chat

AI Coverage by the Numbers

  • 200+ deepfake and face-swap tools identified and blockable
  • 250+ voice-cloning services, 470+ AI companion/character chat sites
  • Essay writers and homework solvers grouped for academic-integrity policy

Unmanaged AI use is also audit exposure: a district that cannot say what AI tools students can reach will find that question harder each year.

The rest of the certification

The filter is one pillar of CIPA — here is how it supports the others

Blocking is necessary but not sufficient. CIPA also expects monitoring, an adopted safety policy, and student education. A well-instrumented filter makes each of those lighter work.

Monitoring Minors' Activity

CIPA requires monitoring, not surveillance of every keystroke. Category-level activity reports by school and group give administrators a defensible, privacy-conscious way to show that monitoring happens — and to spot patterns like spikes in proxy-site attempts.

CIPA requirement met

The Internet Safety Policy

The written policy must be adopted with public notice and describe what the district does about access, safety and disclosure of personal information. Filter policy exports slot directly into it, so the document describes what is actually enforced instead of aspirations.

CIPA requirement met

Educating Students

The Protecting Children in the 21st Century Act added a duty to educate minors about appropriate online behavior, social networking and cyberbullying. Block pages that explain the category and reason turn everyday blocks into small teaching moments rather than mysteries.

CIPA requirement met

A Note for Libraries

Libraries carry a wrinkle schools do not: adult patrons. CIPA permits an authorized person to disable the filter for an adult engaged in lawful use, so a library filter needs clean role separation — strict enforcement on minors' access, a documented unblock path for adults, and logs of both. Our policy model treats that as a first-class configuration rather than a workaround, which keeps the library's certification just as defensible as a district's.

Comparing CIPA Filtering Options

For districts evaluating cipa compliant filtering software side by side, the honest comparison points are data depth, evidence quality, and enforcement reach. Ask every vendor the same three questions. How many domains does the classification database actually cover, and how often is it refreshed? What exact records could you hand an auditor tomorrow for a funding year three years back? And does policy genuinely follow a take-home device, or only when the device behaves? The demos that go quiet on those questions are telling you something.

CIPA also reaches beyond the filter itself. Districts must adopt an internet safety policy, monitor minors' online activity, and educate students about appropriate online behavior, including interacting on social networks and responding to cyberbullying. A web filter is the technical backbone of compliance, but it sits inside that wider policy. If you are earlier in the process, start with our plain-English guide to what CIPA is and who it applies to, then come back to how the technology half gets satisfied.

It is also worth separating the compliance decision from the day-to-day filtering decision, because they are evaluated differently. This page covers the first. For the second — classroom experience, over-blocking, category tuning, the mechanics of how content is classified — see our companion pages on CIPA content filtering and web filtering software for schools. Districts leaning toward a lighter-weight deployment should also look at the DNS-layer filtering option for education, which reaches compliance with less infrastructure.

Getting there

From unfiltered to certifiable in five steps

Most districts complete this inside a few weeks. The filter deploys in a day; the rest is policy work our templates shorten considerably.

1

Adopt or refresh the internet safety policy

CIPA compliance starts on paper: a policy addressing access by minors, safety, unauthorized disclosure of personal information, and education on appropriate online behavior. Our CIPA compliance checklist walks through every element.

Policy foundation
2

Deploy the filter as your technology protection measure

Choose cloud or on-premise, point your network at it, and apply the starter policy. The CIPA-mandated categories are blocked for student groups from the first minute.

Same-day deployment
3

Tune district policy by grade band

Layer your local choices — social media, games, AI-tool categories — on top of the compliance floor, with different settings for elementary, middle and high school where it makes sense.

Per grade band
4

Extend enforcement to take-home devices

Push the same policy to managed 1:1 devices so the filtering your certification describes is true at home as well as at school.

1:1 ready
5

Certify, and keep the evidence flowing

Make your E-Rate certification with records behind it: policy exports, category block logs, and change history that accumulate automatically for as long as you run the filter.

Audit-ready records
Questions

CIPA compliance questions, answered plainly

No. No federal body certifies or approves filtering products, so "CIPA compliant filter" describes capability, not a stamp. Compliance belongs to the school or library: you certify that you enforce a technology protection measure blocking the required content classes. Our job is to make that certification true and provable — the blocking enforced, the evidence exportable.

No. CIPA requires blocking obscene material, CSAM, and material harmful to minors — nothing in the law mandates blocking social platforms or video sites as such. Many districts restrict them anyway for instructional reasons, and the filter makes that easy per grade band, but it is a local decision. Conflating the two is the most common CIPA myth we encounter.

The certification you file is a condition of funding. If a review finds it was not accurate — no filter, or a filter that did not block the required content — the program can deny or claw back discounts, which for a mid-sized district can mean six or seven figures. The practical defense is unglamorous: enforce a real filter and keep records that show it was running.

Yes, within the right boundaries. CIPA allows authorized staff to disable the filter for adults engaged in lawful use, and day-to-day a teacher can request a site exception that applies to a specific group without touching the compliance floor. Every override is logged with who, what and why, so flexibility never becomes an audit problem.

Yes. Nearly all web traffic is encrypted now, so a filter that cannot handle HTTPS is decorative. Our enforcement classifies and blocks encrypted sites by domain category without needing to break open page content, which keeps both compliance and student privacy intact.

Your certification covers the institution's computers with internet access, and a district-owned Chromebook does not stop being a district computer at the school door. Beyond the legal reading, the risk is practical: unfiltered evening hours on district hardware is where incidents actually happen. Extending policy off campus closes both exposures at once.

That page covers filtering as an everyday operational tool — categories, classroom experience, deployment. This one covers the narrower legal question: what CIPA obliges you to block, how our filter enforces it, and what evidence supports the E-Rate certification. Same product underneath; two different questions a district has to answer.

Certify with confidence this funding year

See the compliance floor, the reporting an auditor would ask for, and off-campus enforcement running live — mapped to your district's buildings and grade bands.

Request a Compliance Demo See Pricing