ST4S Compliance for EdTech Vendors: 2026 Guide

AI Summary

Safer Technologies 4 Schools (ST4S) is the national security, privacy and child safety assessment that Australian and New Zealand schools use to decide whether an EdTech product is safe to buy. There is no application fee and a full assessment generally takes three months, but Victorian government schools are prohibited from purchasing any product rated high, non-compliant or non-participating. The framework moved to v2026.1 on 21 July 2026, updating 41 questions across the full assessment and the AI module.

Most EdTech teams meet ST4S compliance the same way. A school asks for the report partway through procurement, and nobody on the product team knows what the report is.

By then you are roughly three months behind, because that is how long a full assessment generally takes. School buying cycles do not pause while you catch up.

This guide covers what ST4S compliance actually assesses, what each rating does to your pipeline, what changed in the July 2026 release, and the evidence your engineering team needs on file before you start.

National Standard

What is Safer Technologies 4 Schools (ST4S)?

Safer Technologies 4 Schools (ST4S) is a national security, privacy and child safety assessment for digital products used in schools. Education Services Australia administers it on behalf of Australian state and territory governments, the Catholic and independent school sectors, and the New Zealand Ministry of Education. Assessments are coordinated by ESA's National Schools Interoperability Program team.

Suppliers enter one of two ways: self-nomination, or invitation from a school or education authority. Both paths start with the ST4S Readiness Check, a self-assessment you iterate on until you qualify to submit for full assessment.

Clearing the Readiness Check does not put you in a queue automatically. The ST4S Working Group decides which services proceed, weighing usage by local schools, procurement activity, and any recent reported incidents involving your product or products of a similar type.

The full assessment is an online questionnaire spanning data protection, organisational security, software development practices, privacy controls and data breach incidents. You must attest that your answers are true, correct, accurate, up to date and not misleading, and some answers trigger requests for supporting documentation.

ST4S launched in 2019, and releases are planned twice a year. Treat it as a moving standard rather than a certificate you earn once.

Procurement Impact

What your ST4S rating does to your pipeline

Your ST4S rating is not advisory. In Victoria it is written into department policy as a purchasing rule schools are required to follow.

Victorian Government School Purchasing Rules by ST4S Rating

Overall rating Can Victorian government schools buy it?
Non-compliant No. Must not be purchased
Non-participating No. Must not be purchased
High No. Must not be purchased
Medium Yes, for purchase or renewal, once report actions are complete
Low Yes, once report and PIA actions are complete
Use with caution / Use responsibly Yes (applies to products with no PII handling)

Victorian Department of Education guidance states that non-compliant, high and non-participating products must not be purchased, and that schools are encouraged to search for lower risk alternatives where they exist.

Read the non-participating row again. It sits in the same prohibited bucket as high risk and non-compliant, and whatever the reason a product lands there, the outcome for the school is identical.

Medium is workable but not comfortable. It moves remediation work onto the school before they can sign, and a competitor sitting at low risk offers that buyer a shorter path.

Note also that the overall rating on the summary report is what determines product suitability. Full ST4S reports exist for many products but not all, so the summary rating carries most procurement conversations.

Weighing an Australian or New Zealand market entry?

Hireplicity's US-led engineering pods build compliance evidence into the delivery process rather than reconstructing it under procurement pressure.

Book a 30-Minute Call
Framework Evolution

What changed in ST4S v2026.1

ST4S published v2026.1 on 21 July 2026, updating 41 questions across the full assessment and the AI module. Four of the changes create the most work for product and engineering teams.

Key Engineering Updates in ST4S v2026.1

Change What it means for your team
Child safety screening (HR category) Greater emphasis on vendor personnel child safety screening where applicable, with clearer guidance for suppliers operating in education environments
Mandatory AI safety alerts Interactive AI sessions must meet minimum safety alert message requirements
School control over AI features Products must show that schools can manage and control which AI-enabled features students can reach
Authentication risk ratings Access control and authentication answers rescored against the Australian and New Zealand Information Security Manual (ISM)

The HR change deserves attention from anyone using contracted or offshore engineering capacity. Personnel screening is now assessed more directly, so if engineers outside your own payroll can reach student data, screening documentation becomes part of what you have to evidence.

The AI updates point in a consistent direction. ST4S is moving past asking whether you use AI toward asking whether schools can govern it, which is much harder to retrofit than to design in.

A fifth update, in the Privacy and Functionality category, improves visibility of built-in reporting tools for wellbeing services so schools can see what support features a product offers.

Audit Readiness

The ST4S Evidence Chain

The assessment reviews your documentation, inspects your service and checks your privacy policy. The half that stalls teams is documentation, because you must attest your answers are accurate and produce supporting evidence when asked.

We call the pattern the ST4S Evidence Chain. Four links, each dependent on the one before it:

Link 1

Policy

A written, dated, owned document stating what your organisation does. Information security, data retention and deletion, privacy, and incident response are the minimum set.

Link 2

Control

The technical or process implementation of that policy, running in production. Encryption at rest, role-based access, screening procedures, patch cadence.

Link 3

Artifact

Proof the control operated. Access logs, screening records, deployment history, test coverage reports, incident response records.

Link 4

Attestation

Your signed statement that the answers are true, correct, accurate and current, backed by documentation on request.

Break any link and the chain fails. A policy without a control is a claim, and a control without an artifact cannot be verified.

The artifact link is worth stress-testing first. Controls tend to get built for security and logging tends to get built for debugging, and neither is designed to produce the dated record a reviewer asks for.

A quick self-test: pick one control and ask how long it would take to produce evidence it operated last quarter. If the answer runs past a day, that is your gap.

Marketing Rules

The ST4S Product Badge and the rule that disqualifies products

The ST4S Product Badge is a separate opt-in program for suppliers already assessed. Eligibility requires a successful assessment on a 2020 or later framework version and an outcome of low risk, medium risk or use responsibly.

One eligibility rule catches vendors out. The product must not contain advertising, or use or share information for advertising, marketing, promotional or similar purposes, and that restriction extends to de-identified data.

An exemption exists but is narrow. Users under 18 must not be able to view advertising, schools must be able to opt out or choose a plan without ads, schools must agree before advertising displays, and schools must be able to approve which advertisers appear.

If your monetisation model leans on ad-supported free tiers, that is a product decision with procurement consequences, not just a marketing one. Even where an exemption is granted, ST4S notes some schools will still choose ad-free alternatives.

The badge is invitation-based, requires a licence agreement, and is a registered trademark in Australia. Holding it means committing to a Readiness Check or full assessment at least annually.

Policy Timeline

The 2028 deadline vendors misread

A common reading of Victoria's 2028 deadline is that vendors must be ST4S ready by then. That is not what the policy says, and the real requirement is sharper.

Victorian Department of Education policy requires schools to migrate school-managed technologies to department-provided technologies by the end of 2028 wherever the department offers an equivalent. Schools must not adopt a different technology where a department technology delivers the same service.

That splits your risk across two clocks.

Category displacement runs to 2028. If the department provides something equivalent to your product, schools are directed away from you regardless of how you rate.

The ST4S gate is running right now. For categories the department does not provide, schools may still adopt your software, but only under ST4S report review, privacy impact assessment, and the department's child safety, records management and information security requirements.

Vendors watching 2028 while ignoring ST4S compliance have the timing backwards.

Frequently Asked Questions

Frequently asked questions

There is currently no application fee for the ST4S assessment process. Suppliers carry their own costs for compliance work, including remediation, documentation and any engineering changes needed to meet the criteria. The assessment itself is free; closing the gaps it exposes is where budget goes (ST4S Assessment Costs & Pricing).

Generally around three months, provided documentation is complete and minimum criteria are met (ST4S Assessment Timeline). ST4S describes the process as comparable to SOC or ISO reviews, covering documentation review, service inspection and privacy policy verification. Incomplete submissions extend that timeline, so closing Readiness Check gaps first is worthwhile.

ST4S assessments are valid for two years from completion (ST4S Validity Period). Reassessment is required at that mark, or sooner if significant changes affect your privacy, security or online safety posture, and notifying ST4S of those changes is the supplier's responsibility. Product Badge holders must additionally complete a Readiness Check or full assessment at least annually.

Victorian schools find them on Arc Software, where the department publishes risk assessment reports as they become available. Each entry typically includes a summary report with an overall risk rating, plus a full ST4S report for many products. Schools in other jurisdictions contact their ST4S Working Group member.

Yes. The New Zealand Ministry of Education oversees ST4S alongside its Australian counterparts, with Education Services Australia facilitating the process (NZ Ministry of Education Guidance). The Ministry tells New Zealand suppliers that completing ST4S helps them build trust with customers across both countries and smooths entry into international markets, particularly Australia.

Strategic Summary

Start before the school asks

ST4S compliance is a procurement gate, not a badge you chase afterward. The rating decides whether a school is permitted to buy your product, and a full assessment takes about three months from a standing start.

The teams that clear it quickly are not necessarily the ones with the best security. They are the ones who can produce policy, control, artifact and attestation without a scramble, because those four things were part of how they shipped.

If you are building for Australian or New Zealand schools and your evidence chain has gaps, the cheapest time to close them is before a school asks for the report.

Planning an ANZ school market entry? Hireplicity has shipped 50+ EdTech platforms with compliance built into the SDLC, and our Philippine engineering pods work in AEST-compatible hours. Schedule a scoping call.

TB

Taylor Basilio

Author & CEO, Hireplicity

Taylor Basilio is the CEO of Hireplicity and CTO of Resonant Education. He has 18+ years of experience designing and shipping EdTech platforms — from K–12 LMS systems to Series A SaaS products built to FERPA, COPPA, ST4S, and WCAG standards. Taylor leads architecture calls for every new Hireplicity engagement.

ANZ EDTECH COMPLIANCE

Clear the ST4S Procurement Gate Before Your Competitors Do

Schedule a 30-minute scoping call with Taylor Basilio. We will evaluate your current codebase against ST4S v2026.1, surface your evidence gaps, and deliver a written remediation roadmap in 48 hours.

Sources & References

  1. Safer Technologies 4 Schools — General Informationhttps://st4s.edu.au/general-information/
  2. Safer Technologies 4 Schools — ST4S Framework v2026.1 (July 21, 2026) — https://st4s.edu.au/docs/st4s-framework-v2026-1/
  3. Safer Technologies 4 Schools — ST4S Product Badge Programhttps://st4s.edu.au/badge-program/
  4. Safer Technologies 4 Schools — Assessment costs and pricinghttps://st4s.edu.au/docs/st4s-assessment-costs-and-pricing/
  5. Safer Technologies 4 Schools — How long is an assessment valid for?https://st4s.edu.au/docs/how-long-is-an-assessment-valid-for/
  6. Safer Technologies 4 Schools — How long does an assessment take?https://st4s.edu.au/docs/how-long-does-an-assessment-take/
  7. Victorian Department of Education — Software and Administration Systems: Guidancehttps://www2.education.vic.gov.au/pal/software-administration-systems/guidance
  8. Victorian Department of Education — Technologies and ICT Services: Policyhttps://www2.education.vic.gov.au/pal/technologies-ict-services/policy
  9. New Zealand Ministry of Education — Safer Technologies for Schools information for suppliershttps://www.education.govt.nz/suppliers-and-providers/administration/digital-technology/safer-technologies-schools-information-suppliers
Next
Next

Offshore Development Red Flags: What to Check Before You Sign