Revenue and market access
If departments and schools check ST4S status before buying, a missing or poor result can close the door on whole states or on New Zealand.
Education departments across Australia and New Zealand use ST4S to judge whether school technology is safe enough to adopt. Summit helps edtech vendors prepare with gap analysis, penetration testing evidence and a clear plan to close findings.
Human-led VAPT · NDA first · report in 48h
The work is technical. The consequences of getting ST4S wrong show up in revenue, liability and reputation, which is why we report on it in the language of the boardroom first.
If departments and schools check ST4S status before buying, a missing or poor result can close the door on whole states or on New Zealand.
Student data carries high expectations. A breach involving children is a serious legal and reputational event.
Schools talk to each other. A clear rating and a badge build trust faster than any sales deck.
Assessment queues and school buying cycles are fixed. Someone senior should own the timeline and the evidence.
Schools and departments check ST4S status before approving a platform for classroom use.
Products holding student records or messaging children face the closest scrutiny on privacy and safety.
If you sell into Australian or New Zealand schools from elsewhere, expect to be asked for ST4S status.
Anything that handles student data or accounts, even indirectly, may be asked for the same evidence.
One accountable team takes you from scoping to retest. The people who test your systems are the people who explain the findings to your leadership.
Your product measured against the current Vendor Guide, with a prioritised fix list.
Manual testing of web, mobile and API layers, including tenancy and student-data exposure.
We check that the controls you describe actually work as written.
Policies, test reports and diagrams organised for the questionnaires.
Support while your team fixes findings, then a retest to confirm closure.
An executive summary of risk, readiness and decisions, with technical detail behind it.
Timelines are typical ranges, not promises. Yours depends on scope, team size and how much is already in place.
Decide which product, environments and data flows will be assessed, and download the current Vendor Guide.
Compare your product with the minimum requirements, close gaps in security, privacy and safety, and write the evidence assessors will ask for.
Commission manual penetration testing and fix the findings, so you can show vulnerabilities found and closed.
Submit questionnaires and evidence if selected, then review draft findings with the ST4S team.
If rated low or medium risk, apply for the badge and plan annual reviews.
Every engagement ends with material written for two audiences: a plain-language view for executives and the board, and full technical detail for the engineers who fix things.
Be precise about modules, integrations and where student data lives.
One accountable owner keeps questionnaires, evidence and follow-up moving.
Assessors compare it with how the product behaves.
Have a clear, honest position ready before you are asked.
Work back from the school term or tender date you are targeting.
Safer Technologies 4 Schools (ST4S) is a national initiative that assesses the security, privacy and safety of digital products used in schools. It is run by Education Services Australia (ESA), a ministerial not-for-profit company, with the support of Australian state and territory education departments, the Catholic and independent sectors and the New Zealand Ministry of Education.
Schools and departments use ST4S results to decide which products are safe to adopt. Vendors typically begin with the ST4S Readiness Check, an optional online survey based on the Vendor Guide, then ask to be prioritised for a full assessment. If selected, you submit detailed questionnaires with supporting documents, review draft findings and receive a final report. Products rated low or medium risk can apply for an ST4S badge.
The assessment looks at security, privacy, interoperability, safety and artificial intelligence. Exact requirements, evidence expectations and timings change, so always work from the current Vendor Guide on the ST4S website.
ST4S works from a nationally consistent control framework. These are the areas vendors most often need to prepare for. Check the current Vendor Guide for the exact questions.
Assessors look at how you protect accounts, data and infrastructure. Expect questions on encryption, access control, secure development, vulnerability management and incident response.
Products that handle student and staff personal information must show clear, lawful data practices that align with the relevant Australian or New Zealand privacy requirements.
Schools expect products to exchange data cleanly with other school systems. Assessors look at data formats, APIs and integration approaches.
For products that reach students directly, safety covers content moderation, age-appropriate design and how users can report problems.
Where a product uses AI, assessors ask about governance, safeguards and how student data is used.
ST4S security assessment expects you to show how you find and fix vulnerabilities. Check the current Vendor Guide for exact penetration testing requirements. A manual test with a retest gives assessors a clear record.
Testing of web, mobile and API layers where students and staff log in and handle data.
Checks that one school or user cannot see another's records.
Verification that student data is not leaked through APIs, logs or storage.
A dated report, remediation log and retest confirmation to attach to your submission.
Use the Readiness Check first. Fixing gaps before submission shortens the process.
Privacy, safety and interoperability carry equal weight. A strong security answer does not offset weak privacy practices.
Assessors and schools prefer to see a human tester explore the product, with fixes confirmed by retest.
Policies, test reports and architecture diagrams should reflect the product as it is today.
ST4S, Safer Technologies 4 Schools, is a national initiative that assesses the security, privacy and safety of digital products used in schools in Australia and New Zealand.
Education Services Australia (ESA), a ministerial not-for-profit company, runs it with support from Australian state and territory education departments, the Catholic and independent sectors and the New Zealand Ministry of Education.
Most vendors start with the optional Readiness Check, then ask to be prioritised for a full assessment. If selected, you submit questionnaires and evidence, review draft findings and receive a final report.
Security, privacy, interoperability, safety and artificial intelligence. Read the current Vendor Guide on the ST4S website for the detailed requirements.
It is not a law. In practice many schools and education departments check ST4S status before adopting a product, so it often decides whether a sale goes ahead.
The New Zealand Ministry of Education states participation is free. Confirm current terms on the ST4S website, and budget for your own preparation and testing.
Check the current Vendor Guide for the exact requirement. Independent penetration test results are widely used as evidence of security practice and are worth having ready.
Browse all 23 security and compliance frameworks or see our penetration testing services.
Last reviewed October 2026. Requirements change; confirm current texts and dates before you commit to a plan.
Tell us your scope, your deadline and who is asking. You get a fixed-scope quote in 15 minutes and a named lead from day one.
Get a Quote in 15 mins →Disclaimer. Summit provides independent technical and risk assessments. This is not legal advice or a regulatory certification. Acceptance of any report is decided by the requesting auditor, customer or regulator.