GESS Assessment Audit
GESS is not a new security standard; rather, it is a crosswalk of internationally agreed upon set of security controls pulled from major cyber security frameworks that are most applicable to the PK20 education ecosystem. By following and becoming certified in GESS, it will streamline the providers’ ability to implement required security controls while at the same time meeting school expectations across jurisdictions, all with one common set of controls.
You can view the full control set here.
GESS is not a new security standard; rather, it is a crosswalk of internationally agreed upon set of security controls pulled from major cyber security frameworks that are most applicable to the PK20 education ecosystem. By following and becoming certified in GESS, it will streamline the providers’ ability to implement required security controls while at the same time meeting school expectations across jurisdictions, all with one common set of controls.
You can view the full control set here.
Each GESS assessment will follow these stages.
|
# |
Stage |
What happens |
Who leads |
|
1 |
Setup |
Agree scope, formalise terms, classify product tier, issue self-assessment workbook and evidence checklist to the vendor. |
Assessor |
|
2 |
Assessment |
Vendor completes self-assessment against GESS controls and submits evidence. Assessor verifies each control against submitted evidence and evidence checklist. Live session for controls requiring demonstration. |
Joint |
|
3 |
Report |
Assessor produces non-conformity register and assessment report. Vendor has a 5-business-day factual review window. Final report and certification outcome issued to client. |
Assessor |
|
4 |
Remediation & closure |
Vendor produces remediation plan for all non-conformities. EDDS Institute reviews and approves. Follow-up verification of Critical and High items. Closure letter issued. |
Vendor (Assessor verifies) |
Tiers are determined by a number of factors, shown in this table below. The tier level determines the exact controls to be evaluated, with lower levels requiring fewer controls than higher levels. This impacts the final price for an assessment.
Note that the tier classification follows a highest tier rule. After determining each level for each factor, the highest level will be your overall tier (e.g., if you have mostly level 2, but then one that is level 3, you will be assessed by the level 3 control set).
|
Factor |
Level 1 — Foundational |
Level 2 — Standard |
Level 3 — Enhanced |
Level 4 — Critical |
|
Data sensitivity |
None / anonymous only |
Standard PII (name, school, grade) |
Extended PII + behavioural + communications |
Special category / sensitive data |
|
Persistent student records |
None — session only |
Up to 10,000 |
10,000 – 500,000 |
> 500,000 or any sensitive data element |
|
Student accounts |
None required |
Basic identifiers |
Full profiles |
Rich / sensitive profiles |
|
Student interaction |
None / passive view |
Supervised, teacher-mediated |
Direct — peer interaction possible |
Vulnerable groups / clinical context |
|
Third-party sharing and sub-processors |
None |
Minimal, contractually restricted |
Multiple controlled sub-processors; vendor maintains register and agreements |
Aggregation or brokering function; or sub-processor independently triggers a higher tier |
|
Data persistence |
Session only |
Academic year + clear deletion |
Multi-year retention |
Indefinite / complex deletion |
|
Communications |
None |
None |
Teacher–student or peer messaging |
Messaging + sensitive context |
|
AI student profiling |
None — no AI, or purely presentational AI with no student data processed |
None — embedded AI only (grammar tools, spell-check, content recommendations). No student profile generated or persisted. |
Session-based adaptive AI; cohort or class-level learning analytics; AI tutoring without persistent individual student profiles |
AI generating persistent individual student profiles; predictive risk or attainment scoring; automated decisions about individual students; behavioural pattern analysis producing individual reports |
|
Biometrics |
No |
No |
No |
Yes — facial recognition, fingerprint, voice biometric, iris scan, or equivalent |
|
Under-13 sensitivity |
Equivalent — no PII collected |
Heightened scrutiny applies |
Significant — heightened for all under 18 |
Maximum — especially for under-13 data |
A4L members receive a discount for receiving a GESS assessment.
|
|
Level 1 — Foundational |
Level 2 — Standard |
Level 3 — Enhanced |
Level 4 — Critical |
|
Non-member |
$2,500 |
$6,500 |
$10,000 |
$12,000 |
|
A4L Member |
$2,000 |
$5,200 |
$8,000 |
$10,000 |
Copyright © Access 4 Learning Community
To help us improve our website, we use cookies and Google Analytics to track basic visitor numbers and see which pages are viewed most and how you found us. Consenting allows us to collect this anonymous browsing data.
The SDPC model Data Privacy Agreements (DPAs) have had a huge impact on the K12 EdTech ecosystem by establishing common expectations and streamlining the DPA execution process for both districts and providers.
Since 2016, over 222,000 standard DPAs have been executed and subscribed to.
By applying an average legal fee of $250 per hour, and minimal negotiation time of 1hr for each district and vendor per DPA, these standard DPAs have saved participating districts and vendors over $111 million.
