Census day has been and gone, but the autumn data season has not. The return is due to the DfE by Wednesday 28 October, free school meals checks run to Monday 2 November, and the school workforce census follows on Thursday 5 November. For specialist settings, every one of those dates is harder than it looks.
Free school meals is the change this year. From the start of this term, every pupil in a household receiving Universal Credit is eligible, whatever the household earns. There are now two categories: Targeted FSM, which still attracts pupil premium, and Expanded FSM, which brings meals only. Every live eligibility period needs a verification date, and eligibility must now be rechecked at least once a year. The DfE has given schools until 2 November to complete the checks, as a one-off, and checks recorded by then count towards funding. One warning: an MIS that rolled last year's FSM status forward has not done the check for you.
Attendance is still the pressure point. A hospital school records a pupil who attended for forty minutes between a ward round and a procedure, or who was too unwell on Tuesday and made up the session on Thursday, or who is dual-registered with a home school two hundred miles away. Alternative provision faces a comparable problem for different reasons: short placements, part-time timetables, reintegration weeks, and pupils on roll somewhere else entirely. The codes exist for all of this. Most systems make you fight for them, and the cost lands as a fortnight of reconciliation before every return.
R3flect handles attendance the way these settings actually operate. It was reconfigured to work with the revised attendance codes as they came in, and it accounts for the patterns of pupils receiving treatment rather than treating them as exceptions. The result is a return you can generate rather than assemble.
Workforce is the one that catches people out. The reference date is 5 November and the census covers every full-time and part-time member of staff, including those in pupil referral units. Local authority deadlines for maintained schools and PRUs fall well before the DfE's, some as early as 10 November. Ethnicity and disability are the usual gaps: since last year, the census flags them as "not yet obtained" for anyone in post more than three months. R3flect's staff deployment view shows where people are actually working, which helps with the return and with the eleven months when no return is due.
And underneath both sits the evidence. EHCP reviews, Individual Support Plans, intervention records, SEMH tracking. None of it is collected by the census, and all of it is what somebody asks about afterwards. When that evidence sits in the same record as the attendance data, the answer takes minutes. When it does not, it takes a week and still feels incomplete.
Finish the FSM checks and resubmit. If a completed check changes your autumn data, update the MIS and resubmit to COLLECT promptly.
Clear COLLECT queries as they arrive, and confirm your local authority's own deadline, which may be earlier than 28 October.
Start workforce data now, beginning with ethnicity and disability. The last two weeks before 5 November will be busy for other reasons.
Things Schools Should Consider: our checklist for what to require from a technology provider.
For several years the DfE's digital and technology standards sat in the category of things schools intended to get to. That is no longer a safe assumption.
The direction of travel is clear from KCSIE 2026, in force since 1 September. The effectiveness of filtering and monitoring must now be reviewed at least once every academic year. The review must cover all internet-connected devices, in all relevant locations. A formal record of those checks must be kept. And crucially, the review is led by the senior leader responsible, supported by the designated safeguarding lead and IT support. It cannot be handed wholesale to a technical team or to an external supplier.
That last point is the significant one. Responsibility has been moved explicitly into leadership, and an annual review that cannot be evidenced is, for practical purposes, an annual review that did not happen.
AI runs through the same guidance. KCSIE 2026 places it inside safeguarding, online safety, filtering and monitoring, staff training and governance, and recognises AI-generated imagery, including deepfakes, as a safeguarding matter. The awkward part is that AI does not belong to any single department. It is a teaching question, an IT question, a safeguarding question and a governance question simultaneously, which is precisely why it falls between them.
None of this requires panic. It requires three things: knowing which tools are actually in use across your setting, being able to show that filtering and monitoring work on every device in every location, and having a record with a date on it.
We help schools with all three and, because Bitnet is Cyber Essentials certified and holds the same standards internally that we advise on, we can show you our own evidence before we ask to see yours.
For most organisations, cyber security and AI have sat on separate agendas: one owned by IT, the other by whoever got excited about it first. This year they arrived on the same page.
The threat is not easing. The government's Cyber Security Breaches Survey 2025/26 found that 73% of secondary schools, 88% of further education colleges and 98% of higher education institutions had identified a breach or attack in the previous twelve months. For secondary schools that is a sharp rise, up from 60% a year earlier. Phishing remains the main route in, reported by 90% of primary and 96% of secondary schools that identified an attack.
The weak point is the supply chain. Fewer than half of schools and FE colleges were covering supply chain security, the area of greatest relative weakness in education. That will not last. Organisations that supply into schools, trusts and the public sector should expect to be asked for their own evidence, and soon.
AI now has a standard to meet. In January the DfE published its Generative AI: product safety standards, covering filtering, monitoring and logging, security, privacy and data protection, design and testing, and governance. Products are expected to be secured against malicious use, including jailbreaking, and aligned with the cyber security standards for schools and colleges. The updated filtering and monitoring standards now ask settings to assess the risks of any generative AI tools they introduce and to include them in the annual review. Feature 02 covers what KCSIE 2026 adds.
And AI is already in use, approved or not. Staff are using AI tools through personal accounts, on organisational data, with no record of who is using what. Copilot and AI agents can reach everything a user can reach, which is exactly why permissions, labelling and data loss prevention need to be in place first. The risk is not the technology. It is deploying it on top of data nobody has governed.
Where Bitnet Secure fits. Bitnet Secure brings together managed Microsoft security, managed IT, cloud migration, data governance with Microsoft Purview aligned to UK GDPR, and AI governance. Our AI governance service covers discovery, controls and governance for Copilot and AI agents, so you know what is in use, decide what is allowed, and can show the record when somebody asks. We are Cyber Essentials certified ourselves.
Our free online security assessment asks eighteen plain-English questions across identity, devices, email, data, backup and governance, and gives you an instant score out of 100 with the priority fixes that move it most.
A new home. bitnets.co.uk relaunches this month with two clear routes: Bitnet Educate for schools, trusts and specialist settings, and Bitnet Secure for business technology and security. Case studies, training materials and every article in one resource centre.
EDART Version 4 is in development, bringing a new dashboard interface, attendance functionality and school workforce and staff management. Full detail in next month's issue.
Cyber Essentials. Bitnet is certified. If your procurement process asks for it, and increasingly it will, that box is already ticked.
A plain checklist of what to require from a technology provider, covering certification, DfE standards alignment, AI governance, evidence and audit trails, data portability and exit terms. Written to be taken into a procurement meeting.