K-12 education & libraries

E-Rate eligible security for school districts and public libraries

CIPA-compliant filtering, FERPA and COPPA-aligned student data protection, and E-Rate eligible network and cybersecurity services — operated across Verity, Core, Sentry, and Citadel. Armorstack is a SPIN-registered E-Rate vendor.

K-12 school districts
Public libraries
Charter & independent schools
Regional education agencies
1:1 device programs
Why K-12 Is Different

Thin IT staff, a federal funding program, and a building full of minors’ data

Districts and libraries run 1:1 device programs, cloud learning platforms, and student information systems on staffing that rarely matches the network they’re defending — while ransomware groups specifically target K-12. E-Rate adds its own machinery: CIPA filtering, competitive bidding, and Form deadlines that determine whether services get paid for. Ed-tech AI tools add FERPA/COPPA and shadow-AI questions on top. Armorstack builds the security program and the E-Rate paperwork as one coordinated process.

The Regulatory Landscape

Five frameworks every district and library should know

These are the real, named programs and laws that govern student data, content filtering, and federal funding eligibility.

E-Rate (Schools & Libraries Program)

Authorized by the Telecommunications Act of 1996 and administered by USAC under FCC oversight, E-Rate provides 20-90% discounts on eligible broadband, networking, and cybersecurity services. Category 1 covers wide-area connectivity; Category 2 covers internal connections like switches, wireless access points, and firewalls. The application cycle runs through Forms 470 (competitive bidding), 471 (funding request), and 486 (service confirmation and CIPA certification) — missing a 486 deadline forfeits committed funds.

Source: Universal Service Administrative Company / FCC (usac.org/e-rate)

CIPA

The Children’s Internet Protection Act requires schools and libraries receiving E-Rate discounts to adopt an internet safety policy and deploy technology that blocks or filters obscene content, child pornography, and material harmful to minors. CIPA compliance is certified on E-Rate Form 486 and is a precondition for continued Category 1 and 2 funding.

Source: Federal Communications Commission (fcc.gov/consumers/guides/childrens-internet-protection-act)

FERPA

The Family Educational Rights and Privacy Act gives parents (and eligible students at 18 or in postsecondary education) rights over education records held by federally funded educational institutions, including the right to inspect records within 45 days of a request and restrictions on disclosing personally identifiable information without consent. Enforced by the Department of Education’s Student Privacy Policy Office.

Source: U.S. Department of Education, Student Privacy Policy Office (studentprivacy.ed.gov)

COPPA

The Children’s Online Privacy Protection Act governs online collection of personal information from children under 13, requiring verifiable parental consent before most data collection by online services. For districts deploying ed-tech and learning platforms to elementary students, COPPA obligations sit alongside — and interact with — FERPA’s education-record protections.

Source: Federal Trade Commission (ftc.gov/coppa)

FCC Schools & Libraries Cybersecurity Pilot Program

A separate $200 million, three-year FCC pilot launched in 2024 to test whether universal service funds should cover cybersecurity services and equipment for schools and libraries — not yet a permanent part of E-Rate. As of the funding wave released January 28, 2026, USAC had committed $28.1 million (about 14% of the budget) across two waves and 325 funding requests. Eligibility and future permanence are still being determined; this is separate from standard E-Rate Category 1/2 funding.

Source: FCC / USAC Cybersecurity Pilot Program (fcc.gov/cybersecurity-pilot-program; usac.org)
Our Approach

How Armorstack Secures Districts & Libraries

One converged model, four coordinated portfolios — each mapped directly to the standards above.

Sentry

Shadow AI and cyber operations, with a 24/7 SOC.

Detection for SIS and 1:1 fleets; CIPA-aligned filtering/monitoring as part of broader security — not a checkbox.

Citadel

Physical security on the same record as cyber and identity.

Campus access control and surveillance; Cat 2 can help offset when properly scoped and documented.

Verity

Governance that survives the board and the auditor.

Internet safety policy, CIPA documentation, FERPA/COPPA vendor governance, Form 486-ready evidence.

Core

Infrastructure that stays observable as AI workloads scale.

As SPIN-registered vendor and FCC-licensed carrier: Cat 1 broadband and Cat 2 network/security infrastructure built for classrooms.

FAQ

K-12 & Library Security & Compliance Questions

What is the difference between Category 1 and Category 2 E-Rate funding?

Category 1 covers wide-area connectivity — broadband internet access, fiber, and WAN services connecting a building to the internet. Category 2 covers internal connections: switches, wireless access points, cabling, and firewalls inside eligible buildings. Category 1 is funded at Priority 1, meaning it’s fully funded before Category 2 in years when demand exceeds available funds.

Is the FCC Cybersecurity Pilot Program the same as regular E-Rate funding?

No. It’s a separate $200 million, three-year pilot launched in 2024 specifically to test whether universal service funds should cover cybersecurity services and equipment. As of the January 2026 funding wave, about 14% of the total budget had been committed across two waves. It has not yet been made a permanent part of standard E-Rate Category 1/2 funding.

Does CIPA require blocking all social media and messaging apps?

No. CIPA specifically requires filtering for obscene content, child pornography, and material harmful to minors, plus monitoring of minors’ online activity. It does not mandate blanket blocking of every social platform — districts have discretion in policy design as long as the statutory categories are addressed and the policy is adopted after public notice and a hearing.

How do FERPA and COPPA interact for a K-12 ed-tech platform?

FERPA governs education records held by the school; COPPA governs online collection of personal information from children under 13 by the ed-tech vendor. A school can often consent on a parent’s behalf for legitimate educational purposes under FERPA, but the vendor still has independent COPPA obligations around data collection, use, and retention — both need to be addressed in a vendor contract.

What’s in the first engagement?

A structured review of your CIPA filtering policy and technology, FERPA/COPPA data-handling practices across student information systems and ed-tech vendors, network security posture, and E-Rate Category 1/2 eligibility for any recommended remediation — so security fixes and funding applications move together.

Security operations and E-Rate funding, run as one process