CIPA, the Children's Internet Protection Act, is the federal law that conditions E-Rate discounts on internet safety. Schools and libraries that receive E-Rate support for internet access or internal connections must adopt an internet safety policy, run a technology protection measure (a content filter), and, for schools, monitor minors' online activity. Compliance is certified to USAC every funding year, today on the FCC Form 486. Our complete CIPA overview covers the requirements, the certification workflow, and the records to keep.
How It Works
CIPA compliance has four working parts for a school, and three for a library:
- An internet safety policy that addresses the specific topics the statute lists, including access by minors to inappropriate content, safety in direct electronic communications, unauthorized access and hacking, unauthorized disclosure of minors' personal information, and measures restricting minors' access to harmful materials.
- A technology protection measure, in practice a content filter, that blocks visual depictions that are obscene, child pornography, or harmful to minors on computers minors use.
- Monitoring of minors' online activities, a requirement that applies to schools.
- Public notice and at least one public hearing or meeting before the internet safety policy is adopted.
The condition attaches to what E-Rate is paying for. CIPA applies when an applicant receives discounts on internet access or on internal connections (Category 2); an applicant receiving discounts only on telecommunications services is not subject to the CIPA conditions. The FCC's consumer guide summarizes the statutory requirements (FCC: Children's Internet Protection Act).
Certification happens through forms, not through an inspection. Today, applicants certify CIPA status on the FCC Form 486 when services start, and consortium members certify their status to the consortium lead on the FCC Form 479. Under the FCC's adopted FY2028 changes (FCC Order 26-30), the Form 486 is eliminated and the CIPA certification moves onto the Form 471 itself. CIPA is also the centerpiece of the FCC's 2026 proposals for schools and libraries; those items are proposed, not final rules, and we walk through them in our breakdown of the proposed E-Rate changes.
What This Means for You
Applicants
Treat the CIPA record set, the adopted policy, the board minutes or hearing notice showing public input, and the filter configuration, as documents you can produce on request, not as a one-time checkbox. Your funding on internet access and Category 2 depends on the certification being accurate every funding year, and discounts don't flow until the certification is filed.
Service Providers
You cannot invoice USAC for a funding request until the applicant's Form 486, which carries the CIPA certification, has been filed and processed. A customer that is late or disorganized on CIPA paperwork delays your payment on an otherwise committed FRN, so it's worth knowing where your customers stand.
Most districts we work with are substantively CIPA compliant, they run filters and have policies, but the paperwork trail is another story. The most common gap isn't a missing filter; it's a policy adopted years ago with no record of the public notice and hearing, which is exactly the document a reviewer or auditor asks for. Substantive compliance without the records to prove it is where CIPA problems actually start.
Common Questions About CIPA
Does CIPA apply to every E-Rate service?
No. CIPA conditions apply to discounts on internet access and internal connections (Category 2). An applicant receiving E-Rate support only for telecommunications services is not subject to CIPA's requirements.
What does the filter actually have to block?
The technology protection measure must block visual depictions that are obscene, child pornography, or, for computers used by minors, harmful to minors. CIPA does not prescribe a specific product or filtering vendor.
Do libraries have to monitor users like schools do?
No. The monitoring requirement for minors' online activities applies to schools. Libraries must have the internet safety policy and the filter, and an administrator may disable the filter for an adult engaged in bona fide research or other lawful purposes.
How do I certify CIPA compliance?
Today, on the FCC Form 486 after services start. Members of a consortium certify their CIPA status to the consortium lead on the FCC Form 479, and the lead certifies on behalf of the group.
What changes for CIPA certification in FY2028?
Under the FCC's adopted order (FCC 26-30), the Form 486 is eliminated starting in FY2028 and the CIPA certification moves onto the Form 471. The underlying CIPA requirements themselves are not changed by that order.
Is CIPA itself changing in 2026?
The FCC has proposed changes that put CIPA at the center of its 2026 program review for schools and libraries, but proposals are not rules. Until the FCC adopts an order, the existing requirements stand. See our analysis of the proposed changes for what's on the table.
What happens if we aren't CIPA compliant?
An applicant that cannot truthfully certify compliance (or undertaking to comply, in its first year) cannot receive E-Rate discounts on internet access or Category 2 services for that funding year. Certifying inaccurately is a far more serious problem than certifying late.
Informational only, not legal advice. E-Rate procedures and forms can change by funding year. Confirm current requirements in the applicable USAC and FCC guidance.