The Children's Internet Protection Act asks one concrete thing of your network: a technology protection measure that actually blocks obscene material, child sexual abuse material, and content harmful to minors. This page explains exactly how our filter meets that requirement — and how it proves it when an E-Rate audit arrives.
CIPA is short, but it is specific. Schools and libraries that receive E-Rate discounts must certify that they enforce a technology protection measure on computers with internet access. That filter must block or restrict access to three specific classes of visual depictions.
CIPA does not name an approved vendor list, a required technology, or a specific product feature set. "CIPA-compliant filter" is therefore shorthand for a filter that can be honestly certified: it blocks the three required classes of content, it is actually enforced on the machines the certification covers, and the institution can show evidence of both. That evidence part matters more than most product pages admit — a filter you cannot report on is a filter you cannot defend in an audit.
Content that meets the legal definition of obscenity must be blocked for all users, adults included. Our adult and pornography categories cover the domains where this content lives, refreshed daily so new sites are caught as they appear rather than after a complaint.
CSAM is illegal everywhere and must be blocked without exception. Domains associated with this material are classified into blocking categories that no school policy can accidentally open — there is no configuration in which they pass.
A broader class covering sexual content that is inappropriate for minors even where legal for adults. Because our database labels a domain with multiple categories, a mixed site can be restricted for students while its legitimate uses stay reachable for staff.
Worth repeating: CIPA does not require blocking social media, games, or any category beyond these three classes. Everything else you block is a local policy choice — a sensible one, often, but a choice. A good CIPA compliance web filter makes both layers explicit: the mandatory floor and the district policy built on top of it.
The technology protection measure requirement is satisfied by enforcement, not intent. A filter that works but cannot prove it worked is a liability when the audit arrives.
Our filter enforces it through category-based blocking: more than 120 million domains are classified into 57+ content categories, and the categories that map to CIPA's required content classes are blocked in every student-facing policy from the moment you deploy.
Because classification is multi-category — a single domain can be labeled both "Video" and "Adult" — the filter makes accurate calls on the mixed sites that trip up simple blocklists. And because new domains are classified as they appear, the certification you sign stays true tomorrow, not just on the day you configured the filter.
Separating the layers means an exception request from a teacher can never quietly punch a hole in the compliance floor.
E-Rate certifications can be reviewed years after the funding year closes, and the question an auditor asks is disarmingly simple: show me. Districts that filter through opaque appliances often struggle here — the filter worked, but nobody can produce a record proving what it blocked, for whom, during the period in question.
Category-level reporting closes that gap. Instead of a haystack of URLs, your records say: adult content, obscenity and harmful-to-minors categories were blocked district-wide for all student groups, continuously, with logs to match. That is the shape of evidence audits are looking for, and it takes minutes to produce rather than weeks to reconstruct.
If E-Rate is new territory, our guide to E-Rate funding and CIPA obligations explains how the certification cycle works and where filtering evidence fits into it.
The moment a district sends devices home, the filtering question follows them. A filter that stops at the firewall leaves your 1:1 program — and arguably your certification — exposed during the hours students use those devices most.
Every device that touches school internet access — managed laptops, lab desktops, staff machines, guest devices — is filtered against the policy for its user group. Coverage is network-wide, so an unmanaged phone on school Wi-Fi is still inside the compliance perimeter.
Policy follows managed take-home devices wherever they connect. The Chromebook that is filtered in third period is filtered the same way on home Wi-Fi at 9 p.m., without a VPN for parents to configure or a setting for students to toggle off.
This consistency does more than tighten compliance. It removes the awkward gap where a district teaches digital citizenship at school and then hands students an unfiltered window to the internet at home on district-owned hardware. One policy, everywhere the device goes, is simpler to run and far easier to explain to a school board.
Generative AI created an entire class of sites that legacy CIPA compliant content filters never anticipated. Our filter ships with a dedicated AI Tools Blocklist to keep pace.
16,328+ AI-tool domains organized into 18 categories and 165+ subcategories, updated daily by screening roughly 300,000 newly registered domains per day. You choose which AI categories to permit for instruction and which to block, per grade band, without hand-curating anything.
Some AI tools — deepfake generators, AI "companion" chatbots, voice-cloning services — raise student-safety and privacy problems that overlap directly with the concerns CIPA exists to address, and they multiply weekly. Protects student data students might otherwise paste into ungoverned tools.
Unmanaged AI use is also audit exposure: a district that cannot say what AI tools students can reach will find that question harder each year.
Blocking is necessary but not sufficient. CIPA also expects monitoring, an adopted safety policy, and student education. A well-instrumented filter makes each of those lighter work.
CIPA requires monitoring, not surveillance of every keystroke. Category-level activity reports by school and group give administrators a defensible, privacy-conscious way to show that monitoring happens — and to spot patterns like spikes in proxy-site attempts.
The written policy must be adopted with public notice and describe what the district does about access, safety and disclosure of personal information. Filter policy exports slot directly into it, so the document describes what is actually enforced instead of aspirations.
The Protecting Children in the 21st Century Act added a duty to educate minors about appropriate online behavior, social networking and cyberbullying. Block pages that explain the category and reason turn everyday blocks into small teaching moments rather than mysteries.
Libraries carry a wrinkle schools do not: adult patrons. CIPA permits an authorized person to disable the filter for an adult engaged in lawful use, so a library filter needs clean role separation — strict enforcement on minors' access, a documented unblock path for adults, and logs of both. Our policy model treats that as a first-class configuration rather than a workaround, which keeps the library's certification just as defensible as a district's.
For districts evaluating cipa compliant filtering software side by side, the honest comparison points are data depth, evidence quality, and enforcement reach. Ask every vendor the same three questions. How many domains does the classification database actually cover, and how often is it refreshed? What exact records could you hand an auditor tomorrow for a funding year three years back? And does policy genuinely follow a take-home device, or only when the device behaves? The demos that go quiet on those questions are telling you something.
CIPA also reaches beyond the filter itself. Districts must adopt an internet safety policy, monitor minors' online activity, and educate students about appropriate online behavior, including interacting on social networks and responding to cyberbullying. A web filter is the technical backbone of compliance, but it sits inside that wider policy. If you are earlier in the process, start with our plain-English guide to what CIPA is and who it applies to, then come back to how the technology half gets satisfied.
It is also worth separating the compliance decision from the day-to-day filtering decision, because they are evaluated differently. This page covers the first. For the second — classroom experience, over-blocking, category tuning, the mechanics of how content is classified — see our companion pages on CIPA content filtering and web filtering software for schools. Districts leaning toward a lighter-weight deployment should also look at the DNS-layer filtering option for education, which reaches compliance with less infrastructure.
Most districts complete this inside a few weeks. The filter deploys in a day; the rest is policy work our templates shorten considerably.
CIPA compliance starts on paper: a policy addressing access by minors, safety, unauthorized disclosure of personal information, and education on appropriate online behavior. Our CIPA compliance checklist walks through every element.
Choose cloud or on-premise, point your network at it, and apply the starter policy. The CIPA-mandated categories are blocked for student groups from the first minute.
Layer your local choices — social media, games, AI-tool categories — on top of the compliance floor, with different settings for elementary, middle and high school where it makes sense.
Push the same policy to managed 1:1 devices so the filtering your certification describes is true at home as well as at school.
Make your E-Rate certification with records behind it: policy exports, category block logs, and change history that accumulate automatically for as long as you run the filter.
No. No federal body certifies or approves filtering products, so "CIPA compliant filter" describes capability, not a stamp. Compliance belongs to the school or library: you certify that you enforce a technology protection measure blocking the required content classes. Our job is to make that certification true and provable — the blocking enforced, the evidence exportable.
No. CIPA requires blocking obscene material, CSAM, and material harmful to minors — nothing in the law mandates blocking social platforms or video sites as such. Many districts restrict them anyway for instructional reasons, and the filter makes that easy per grade band, but it is a local decision. Conflating the two is the most common CIPA myth we encounter.
The certification you file is a condition of funding. If a review finds it was not accurate — no filter, or a filter that did not block the required content — the program can deny or claw back discounts, which for a mid-sized district can mean six or seven figures. The practical defense is unglamorous: enforce a real filter and keep records that show it was running.
Yes, within the right boundaries. CIPA allows authorized staff to disable the filter for adults engaged in lawful use, and day-to-day a teacher can request a site exception that applies to a specific group without touching the compliance floor. Every override is logged with who, what and why, so flexibility never becomes an audit problem.
Yes. Nearly all web traffic is encrypted now, so a filter that cannot handle HTTPS is decorative. Our enforcement classifies and blocks encrypted sites by domain category without needing to break open page content, which keeps both compliance and student privacy intact.
Your certification covers the institution's computers with internet access, and a district-owned Chromebook does not stop being a district computer at the school door. Beyond the legal reading, the risk is practical: unfiltered evening hours on district hardware is where incidents actually happen. Extending policy off campus closes both exposures at once.
That page covers filtering as an everyday operational tool — categories, classroom experience, deployment. This one covers the narrower legal question: what CIPA obliges you to block, how our filter enforces it, and what evidence supports the E-Rate certification. Same product underneath; two different questions a district has to answer.
See the compliance floor, the reporting an auditor would ask for, and off-campus enforcement running live — mapped to your district's buildings and grade bands.