Glossary

CIPA

CIPA — the Children's Internet Protection Act — is a condition attached to certain federal discounts and grants. A school receiving E-rate support for internet access must certify that it enforces a technology protection measure and an internet safety policy, or forgo those discounts.

Last reviewed 2026-08-04 ยท Kastr is pre-launch; we publish dated status rather than logos.

What CIPA requires, and who inside a district owns it
RequirementWhat it means in practiceUsual owner
Technology protection measureFiltering that blocks obscenity, child pornography and, for minors, material harmful to minorsNetwork or systems team
Internet safety policyA board-adopted policy covering access to inappropriate material, minors' safety in electronic communications, unauthorised disclosure of personal information, hacking, and unlawful activityBoard and cabinet
Public notice and hearingA public meeting with reasonable notice before the policy is adopted, documented in board minutesBoard secretary
Monitoring of minors' online activitiesA stated practice; CIPA does not prescribe a tool or require tracking of individualsTechnology department
Education of minors about online behaviourInstruction covering interaction on social networking sites and chat rooms, and cyberbullying awareness and responseCurriculum and counselling
Annual certificationCertified to the programme administrator as part of the E-rate filing cycleE-rate coordinator

What triggers it, and what does not

CIPA is not a general obligation on schools. It is a condition on funding, and the condition attaches to specific categories of service. A school seeking E-rate discounts for internet access or for internal connections must certify compliance. Historically, support for telecommunications service alone did not carry the same filtering obligation, which is the origin of most of the confusion in the market.

A district that takes no E-rate support and no covered grant funding is not bound by CIPA at all. Many such districts filter anyway, for reasons that have nothing to do with federal law, and several states impose their own filtering requirements independent of it.

The certification runs on the E-rate calendar, alongside the annual programme filings. Districts in their first year of compliance certify that they are undertaking the steps; thereafter they certify that the policy and the measure are in place.

CIPA permits an administrator to disable the filter for an adult engaged in bona fide research or another lawful purpose. That authority is part of the statute, not a workaround, and districts should have a written procedure for it.

What CIPA has to do with a communications platform: nothing

This entry exists mostly to say that plainly, because "CIPA compliant" appears on ed-tech vendor pages where it has no meaning.

CIPA governs what a district's internet connection does when a minor uses it. A school-home communications platform is not an internet access service, does not sit between a student and the web, and cannot filter anything. There is no CIPA certification for SaaS products, and no certifying body that issues one.

If a security questionnaire asks whether your comms vendor is CIPA compliant, the accurate answer is that CIPA obligations attach to the district's internet access and its board-adopted policy, not to a messaging application. A vendor that answers "yes" to that question without qualification has told you something about its answering process rather than about its product. Kastr's answer is no, and the reason is that the question does not apply to us.

The adjacent question that is worth asking a communications vendor is about the internet safety policy's second element — safety of minors in electronic communications. If a platform offers student-to-student or student-to-adult messaging, that is squarely within the policy the board adopted, and the district's own rules on monitoring and moderation apply to it. Kastr has no student accounts and no student messaging, which removes that surface entirely.

The misconceptions

"CIPA requires us to filter take-home devices." The statute concerns computers with internet access provided through the funded service. Off-campus filtering on district-issued devices is a widespread district policy and a common state requirement, but it is not the plain requirement of CIPA itself. This is precisely the sort of question to put to counsel rather than to a filtering vendor's blog.

"CIPA requires us to log every site every student visits." It requires a stated practice of monitoring minors' online activities. It does not prescribe individual tracking or a retention period, and it explicitly does not require tracking of internet use by any identified individual.

"CIPA is a student privacy law." It is not. It is a content-access law. Districts conflate it with FERPA and state privacy statutes constantly, and the conflation matters because it sends the wrong department to answer the wrong question.

"We certified once, so we are done." Certification recurs with the funding cycle, and the underlying policy needs to still be the one the board adopted. A policy last reviewed when the district issued its first tablets is a finding waiting to be made.

This entry describes what the rule says. Whether and how it applies to your district is a question for your own counsel, not for a vendor.

Questions people actually ask

Is CIPA required if a district does not take E-rate funding?

CIPA is a condition on certain federal discounts and grants. A district receiving none of them is not bound by it federally, though many states impose their own filtering requirements and most districts filter as a matter of policy regardless.

Does CIPA require filtering on take-home devices?

The federal requirement concerns computers with internet access provided through the funded service. Off-campus filtering of district devices is common practice and is required by some states, but treat it as a policy and state-law question rather than a settled CIPA one.

What is an internet safety policy?

A board-adopted policy addressing access to inappropriate material, the safety of minors using electronic communications, unauthorised disclosure of personal information about minors, hacking and other unlawful activity, and measures restricting access to harmful materials. Adoption requires public notice and a hearing.

Does a communications platform fall under CIPA?

No. CIPA governs filtering and internet safety policy for internet access provided to minors. A school-home messaging platform provides no internet access and cannot filter web content. There is no CIPA certification for SaaS applications.

One price. Every feature. Locked for three years.

$3.50 per student per year under 5,000 students. No tiers, no add-on modules, no per-message fees. Published on the site because you should not have to book a call to learn a price.