IT providers for schools, colleges and trusts

There are 433 IT providers serving Education clients listed in the Assurix directory, including 3 with verified Assurix trustmarks.

Last updated: 13 August 2026

Schools run on tight budgets and term-time rhythms, and both shape the kind of IT support that works. A provider who fits education understands that the summer holiday is when big changes happen, that a September start can't slip, and that safeguarding duties sit right alongside security.

There are IT providers on this page who work with schools, colleges, and multi-academy trusts. Providers that have earned the Assurix Trusted MSP badge are shown first, and any working toward it appear as On the Journey.

Whether you're a business manager at a single primary or an IT lead across a trust of twenty schools, the sections below cover what a good provider should be able to show, the questions worth asking, and how the standards for the sector fit together. Pupil data deserves care, and the right provider treats it that way.

What to look for in an education IT provider

Education has its own pressures. These are the areas where the right provider makes a real difference.

Understanding of safeguarding duties
Keeping Children Safe in Education sets expectations that include filtering and monitoring of online content. A provider who works with schools should understand how the technical side of safeguarding fits together with your policies and your designated safeguarding lead.
Care with pupil data
Schools and trusts hold data about children, which calls for careful handling under UK GDPR. Ask a provider how they control access to that data and how they'd help you respond if something went wrong.
Awareness of DfE standards
The Department for Education publishes cyber security standards for schools and colleges. A provider used to the sector will know these and be able to map your current setup against them, so you can see where you stand.
Fit with insurance conditions
Schools in the Risk Protection Arrangement have to meet certain conditions to hold its cyber cover. A provider who has seen this before can help you keep the technical requirements in place, rather than discovering a gap at renewal.
Working around term time
Big changes in a school can't land in the middle of exams or a September intake. Look for a provider who plans upgrades around the school calendar and can keep things steady during the busiest weeks.

Questions worth asking a school IT provider

Ask these early. They surface how well a provider really knows education.

  1. How do you support the filtering and monitoring side of our safeguarding duties? Safeguarding is a core responsibility for schools, so the technical support behind it needs to be solid.
  2. How do you protect and control access to pupil data? You're holding information about children, which deserves careful, well-managed handling.
  3. Are you familiar with the Department for Education's cyber security standards for schools? Familiarity means a provider can help you work toward them instead of learning as they go.
  4. Can you help us meet the conditions attached to our cyber cover under the RPA? Missing a condition could affect a claim, so it's better checked up front.
  5. How do you schedule upgrades and maintenance around term time? A provider who respects the school calendar causes far less disruption.
  6. Can you show independent evidence of your own security, not just describe it? A school handling children's data has good reason to want proof rather than assurances.

IT providers serving Education

How the standards fit together in education

Education carries duties that reach well beyond the IT cupboard. Keeping Children Safe in Education sets safeguarding expectations, and part of that is the filtering and monitoring of online content, which is as much a technical job as a pastoral one.

On the security side, the Department for Education publishes cyber security standards for schools and colleges. They give a school or trust a clear picture of what good looks like, and a provider who knows them can help you see where your current setup lines up and where it doesn't.

Insurance adds another layer. Schools in the Risk Protection Arrangement have to meet certain conditions to hold its cyber cover, so the technical steps behind those conditions need to stay in place. Underneath all of it, schools and trusts hold pupil data, which includes information about children and deserves careful handling under UK GDPR. For further and higher education, Jisc supports the sector and is a useful reference point.

What the Trustmark offers a school

Assurix is an independent trustmark for UK IT providers, and its whole idea is proof rather than promises. A provider carrying the Trusted MSP badge has passed all 64 controls, with continuous monitoring behind the badge and an annual reassessment on top. For a school or trust weighing up a provider, that ongoing evidence sits well next to your safeguarding and data duties, because it's checked over time and not just once.

Frequently asked questions

Does an education IT provider handle our safeguarding duties?

A provider supports it, but the duty stays with the school. Safeguarding is led by the school and its designated safeguarding lead, and a good provider handles the technical side, especially the filtering and monitoring of online content that Keeping Children Safe in Education expects. That means the systems that block harmful material and flag concerns need to work reliably and be set up correctly. When you talk to a provider, ask how they support that technical layer and how they'd help if a filtering system stopped working during the school day.

What are the DfE cyber security standards?

The Department for Education publishes a set of cyber security standards for schools and colleges. They describe what a sensible security setup looks like, covering areas like accounts, backups, and keeping software up to date. They give a school or trust a shared reference to work from, rather than everyone guessing. A provider who knows the standards can walk through your current setup with you and show where you already meet them and where there's work to do. That saves time and makes budgeting easier.

How does the Risk Protection Arrangement affect our IT?

Schools in the Risk Protection Arrangement have to meet certain conditions to hold its cyber cover. Those conditions often touch technical areas your IT provider manages, so the two are connected. If a required control slips out of place, it could affect your cover when you need it most. It's worth asking a provider whether they know the current conditions and can help you keep the technical side in line with them, and to flag it well before your renewal rather than after.

We're a multi-academy trust. Does that change what we need?

It can. A trust juggles several schools, each with its own history, kit, and habits, so a provider needs to bring some consistency across them without ignoring local differences. Shared standards, clear access controls, and a plan that respects each school's term dates all help. Ask a provider how they'd handle onboarding a new school into the trust, how they keep security consistent across sites, and how they report back to you centrally so you can see the whole picture in one place.

What does an Assurix Trusted MSP badge mean here?

It means the provider has passed all 64 Assurix controls, with no partial passes, and is checked continuously rather than once a year. The controls align to the NCSC Cyber Assessment Framework v4. Providers working toward the badge are listed as On the Journey within a six-month window, though that status isn't a pass in itself. The rest are listed as not yet Assurix-verified, which is neutral. Plenty of strong providers simply haven't been through the process.

Related pages