Close

GESS Assessment Audit

gess_full_large_color

What is GESS?

GESS is not a new security standard; rather, it is a crosswalk of internationally agreed upon set of security controls pulled from major cyber security frameworks that are most applicable to the PK20 education ecosystem. By following and becoming certified in GESS, it will streamline the providers’ ability to implement required security controls while at the same time meeting school expectations across jurisdictions, all with one common set of controls.

You can view the full control set here.

What is GESS?

GESS is not a new security standard; rather, it is a crosswalk of internationally agreed upon set of security controls pulled from major cyber security frameworks that are most applicable to the PK20 education ecosystem. By following and becoming certified in GESS, it will streamline the providers’ ability to implement required security controls while at the same time meeting school expectations across jurisdictions, all with one common set of controls.

You can view the full control set here.

How does the GESS third-party assessment work?

Each GESS assessment will follow these stages.

#

Stage

What happens

Who leads

1

Setup

Agree scope, formalise terms, classify product tier, issue self-assessment workbook and evidence checklist to the vendor.

Assessor

2

Assessment

Vendor completes self-assessment against GESS controls and submits evidence. Assessor verifies each control against submitted evidence and evidence checklist. Live session for controls requiring demonstration.

Joint

3

Report

Assessor produces non-conformity register and assessment report. Vendor has a 5-business-day factual review window. Final report and certification outcome issued to client.

Assessor

4

Remediation & closure

Vendor produces remediation plan for all non-conformities. EDDS Institute reviews and approves. Follow-up verification of Critical and High items. Closure letter issued.

Vendor (Assessor verifies)

What factors are considered in classifying my product’s tier?

Tiers are determined by a number of factors, shown in this table below. The tier level determines the exact controls to be evaluated, with lower levels requiring fewer controls than higher levels. This impacts the final price for an assessment.

Note that the tier classification follows a highest tier rule. After determining each level for each factor, the highest level will be your overall tier (e.g., if you have mostly level 2, but then one that is level 3, you will be assessed by the level 3 control set).

Factor

Level 1 — Foundational

Level 2 — Standard

Level 3 — Enhanced

Level 4 — Critical

Data sensitivity

None / anonymous only

Standard PII (name, school, grade)

Extended PII + behavioural + communications

Special category / sensitive data

Persistent student records

None — session only

Up to 10,000

10,000 – 500,000

> 500,000 or any sensitive data element

Student accounts

None required

Basic identifiers

Full profiles

Rich / sensitive profiles

Student interaction

None / passive view

Supervised, teacher-mediated

Direct — peer interaction possible

Vulnerable groups / clinical context

Third-party sharing and sub-processors

None

Minimal, contractually restricted

Multiple controlled sub-processors; vendor maintains register and agreements

Aggregation or brokering function; or sub-processor independently triggers a higher tier

Data persistence

Session only

Academic year + clear deletion

Multi-year retention

Indefinite / complex deletion

Communications

None

None

Teacher–student or peer messaging

Messaging + sensitive context

AI student profiling

None — no AI, or purely presentational AI with no student data processed

None — embedded AI only (grammar tools, spell-check, content recommendations). No student profile generated or persisted.

Session-based adaptive AI; cohort or class-level learning analytics; AI tutoring without persistent individual student profiles

AI generating persistent individual student profiles; predictive risk or attainment scoring; automated decisions about individual students; behavioural pattern analysis producing individual reports

Biometrics

No

No

No

Yes — facial recognition, fingerprint, voice biometric, iris scan, or equivalent

Under-13 sensitivity

Equivalent — no PII collected

Heightened scrutiny applies

Significant — heightened for all under 18

Maximum — especially for under-13 data

What are the prices per tier?

A4L members receive a discount for receiving a GESS assessment.

 

Level 1 — Foundational

Level 2 — Standard

Level 3 — Enhanced

Level 4 — Critical

Non-member

$2,500

$6,500

$10,000

$12,000

A4L Member

$2,000

$5,200

$8,000

$10,000

The SDPC model Data Privacy Agreements (DPAs) have had a huge impact on the K12 EdTech ecosystem by establishing common expectations and streamlining the DPA execution process for both districts and providers.

Since 2016, over 222,000 standard DPAs have been executed and subscribed to.

By applying an average legal fee of $250 per hour, and minimal negotiation time of 1hr for each district and vendor per DPA, these standard DPAs have saved participating districts and vendors over $111 million.