To comply with the Children’s Internet Protection Act, a school or library receiving E-rate discounts or certain federal library funds must adopt a written internet safety policy covering five specific topics, install content filters on every computer with internet access, hold a public hearing before adopting the policy, certify compliance on the correct FCC form, and keep the paperwork for at least ten years. Everything else in CIPA compliance flows from those five steps.
Who Has to Comply
CIPA reaches two groups. The first is any school (public or private) or library that participates in the E-rate program and receives discounts on Category One internet access or any Category Two services such as internal connections and managed broadband.1Universal Service Administrative Company. Children’s Internet Protection Act (CIPA) The second is libraries that receive funds under the Library Services and Technology Act; under 20 U.S.C. § 9134, those libraries cannot use federal grant money to buy internet-access computers or pay for internet service unless they adopt and enforce CIPA-compliant safety policies and filtering.2Office of the Law Revision Counsel. 20 USC 9134 – State Plans
Private schools that take E-rate discounts are covered on the same terms as public schools. The only procedural difference is that the public notice requirement is satisfied by notifying the school’s constituent group rather than the general public.1Universal Service Administrative Company. Children’s Internet Protection Act (CIPA)
If your institution doesn’t take E-rate or LSTA money for internet-related purposes, CIPA doesn’t apply. It’s a funding-conditions statute, not a general regulation of school or library internet use.
The Written Internet Safety Policy
Every covered institution has to adopt a written internet safety policy that addresses five topics listed in 47 U.S.C. § 254(l):3Office of the Law Revision Counsel. 47 USC 254 – Universal Service
- How the institution restricts minors from accessing inappropriate material online.
- Protections for minors using email, chat rooms, and other direct messaging.
- Prohibitions against hacking and other unlawful online activities by minors.
- Safeguards against unauthorized disclosure of minors’ personal information.
- Measures to keep minors from accessing material that is harmful to them.
Schools have one extra element libraries don’t: the policy must address monitoring the online activities of minors. The FCC has been clear that this does not require logging every website an individual visits; it requires the policy to describe how staff will supervise students’ internet use.4Federal Communications Commission. Children’s Internet Protection Act (CIPA)
Student Education for Schools
The Protecting Children in the 21st Century Act, passed in 2008, added a compliance element that gets missed. Schools subject to CIPA must educate minors about appropriate online behavior, including interacting with others on social networking sites and in chat rooms, and recognizing and responding to cyberbullying.4Federal Communications Commission. Children’s Internet Protection Act (CIPA) An auditor can ask for evidence that this instruction is actually happening. Filtering software alone doesn’t cover it.
Filtering on Every Internet Computer
Written policy is only half the job. Filters must be installed and running on every computer with internet access. On all machines, filters must block visual depictions that are obscene or constitute child pornography. On computers used by minors (anyone under 17 under CIPA), the filter must also block material harmful to minors.3Office of the Law Revision Counsel. 47 USC 254 – Universal Service The filter has to be active during all hours the computers are available for use.1Universal Service Administrative Company. Children’s Internet Protection Act (CIPA)
An authorized person, typically an administrator, librarian, or IT supervisor, may disable the filter for an adult user engaged in legitimate research or other lawful purposes.4Federal Communications Commission. Children’s Internet Protection Act (CIPA) The institution needs an internal process for who can authorize an unblock, how quickly it happens, and how it is documented. Handing bypass access to every staff member, or leaving the filter off by default, creates audit exposure.
What the Filter Has to Block Is a Local Decision
Beyond the statutory categories, the federal government does not decide what specific content should be blocked. The statute forbids any federal agency from establishing criteria for what counts as “inappropriate,” reviewing local determinations, or second-guessing the standards a local authority applies.3Office of the Law Revision Counsel. 47 USC 254 – Universal Service The school board, library board, or local educational agency configures the filter. Two neighboring districts can take different approaches and both remain compliant, as long as the statutory categories are covered.
The Public Notice and Hearing
Before adopting or amending the policy, the institution must give reasonable public notice and hold at least one public hearing or meeting on the proposed policy and its filtering technology.3Office of the Law Revision Counsel. 47 USC 254 – Universal Service Federal law does not set a specific number of days for “reasonable” notice. Follow whatever your state or local rules require for public meetings, and give more notice rather than less.
Keep proof: a posted agenda, a newspaper announcement, or signed minutes with a date will all satisfy USAC on audit.1Universal Service Administrative Company. Children’s Internet Protection Act (CIPA) If you later amend the policy, additional hearings are not required by federal law unless your own policy or state or local rules demand them.
Certifying Compliance
Compliance is not self-executing. You have to certify it on the right FCC form.
FCC Form 486 both notifies the Universal Service Administrative Company that services have started for the funding request numbers on file and certifies CIPA compliance. File it no later than 120 days after either the service start date or the date of the Funding Commitment Decision Letter, whichever is later.5Universal Service Administrative Company. FCC Form 486 Filing Missing that deadline can stall funding.
Schools and libraries that participate in a consortium but are not the billed entity file FCC Form 479 with the consortium leader. Form 479 certifies that the individual member is enforcing its own safety policy and filtering. The consortium’s billed entity collects signed Form 479s from each library member before submitting the consortium’s E-rate application.6eCFR. 47 CFR 54.520 – Children’s Internet Protection Act Certifications
If This Is Your First Funding Year
First-time E-rate applicants do not have to be fully compliant on day one. In the first funding year, you can certify that you are “undertaking actions” to comply, meaning you are actively working toward full compliance and expect to meet all requirements by the next funding year.1Universal Service Administrative Company. Children’s Internet Protection Act (CIPA) This grace period can extend into a second year if state or local procurement rules prevented you from buying filtering technology in time, but a waiver is required. Even during this window, document every step: draft policies, vendor quotes, board agendas where CIPA was discussed. Auditors will want to see that “undertaking actions” was real.
Records You Have to Keep for Ten Years
All CIPA records must be retained for at least ten years after the later of the last day of the applicable funding year or the service delivery deadline for that funding request.1Universal Service Administrative Company. Children’s Internet Protection Act (CIPA) That retention period runs longer than most institutional records, and it catches administrators off guard when audits reach back years.
For each funding year, USAC audits typically request:
- The written internet safety policy that was in effect during the funding year.
- Proof that public notice was given and at least one hearing or meeting occurred: a website posting, newspaper ad, or dated meeting minutes.
- Proof the policy was formally adopted, such as board minutes reflecting approval.
- A description of the filtering technology in use.
- Evidence the filter was installed and operating during the funding year: provider reports showing blocked sites, service provider bills confirming the filter was active, or IT logs showing the hours the filter was engaged.
- Copies of FCC Form 486 and, where applicable, FCC Form 479.
USAC does give applicants a chance to correct minor errors before starting fund recovery.1Universal Service Administrative Company. Children’s Internet Protection Act (CIPA) If you cannot produce the core documents, though — the policy, proof of the public hearing, or evidence the filter was active — recovered funds add up quickly across multiple funding years. A single organized CIPA file per funding year, closed out and stored when the year ends, is the cheapest insurance available.