Every good roadmap starts with one important piece of information: You are here.
The same is true for cybersecurity readiness. Before we can determine where we need to go next, we need a clear picture of where we are today, our strengths, our gaps, and our greatest opportunities for improvement.
That is where CoSN’s Cybersecurity Readiness for Education (CCRE) Framework and Rubric comes in.
Since 2023, the Cybersecurity Rubric for Education (CC4E) has provided K–12 school systems with a practical way to assess their cybersecurity maturity, identify strengths and gaps, and prioritize what comes next. Through the CC4E, that work expanded to include practical tools and resources, the CCRE designation, professional learning, and a growing community of practitioners.
In June 2026, the CC4E transitioned to CoSN, becoming part of CoSN’s Cybersecurity Readiness for Education (CCRE) initiative. We are building on the strong foundation established through CC4E while expanding the reach and impact of this work through CoSN’s national community of EdTech leaders, creating even greater opportunities to learn from one another, collaborate, and strengthen cybersecurity readiness across K–12 education.
The CCRE Cybersecurity Rubric gives our members and schools a common language and practical structure for assessing cybersecurity maturity. It helps leaders move beyond the question, “What security product should we buy next?” toward a more strategic conversation:
But completing an assessment isn’t the finish line. It is the starting point. The real value of the CCRE Rubric is what you do with what you learn. More than an assessment, it is a strategic planning tool designed to make cybersecurity readiness understandable and actionable.
Many commonly used cybersecurity frameworks and assessment approaches were not designed specifically for K-12 education, requiring education leaders to translate highly technical requirements into the realities of a school system. The CCRE Rubric provides a K-12-specific, common language that technology leaders can use with superintendents, executive teams, and other stakeholders to understand where the organization stands, establish priorities, and determine where investments of time, people, and resources can make the greatest difference.
Once you know where you are, the next question is: Where do we go from here? CoSN’s practical three-stage cybersecurity readiness roadmap connects assessment to action.
CoSN’s practical three-stage cybersecurity readiness roadmap
Build Your Foundation. Start with the CCRE Cybersecurity Rubric and CR Sidekick (AI-enabled version) to assess current maturity, identify strengths and gaps, and translate what you learn into a prioritized cybersecurity readiness roadmap.
Strengthen Your Team. Readiness requires more than technology. Build internal capability through professional learning, targeted training, practical tools, authentication strategies, third-party risk assessment, and opportunities to learn with other K–12 practitioners.
Lead with Resilience. Cybersecurity ultimately becomes an organizational leadership responsibility. Policy, governance, funding, advocacy, incident response, recovery, and continuous improvement all contribute to a school system’s ability to withstand and recover from disruption.
This is where the real opportunity lies.
The vision for CCRE is to build the nation’s leading cybersecurity readiness ecosystem for K-12 education, connecting districts, practitioners, professional learning, implementation resources, AI-enabled tools, state chapters, partners, and community around a shared framework.
But a framework creates value only when we use it.
So, if your district has never completed the CCRE Cybersecurity Rubric, start there. If you completed it previously, perhaps it is time to revisit it. Look at what has changed. Celebrate where you have improved. Identify where gaps remain. Then use what you learn to determine what comes next.
Cybersecurity readiness isn’t a destination or a one-time assessment. It is a cycle of assessing, prioritizing, building capacity, implementing, and improving.
And you don’t have to do it alone. October is a call to action for Cybersecurity Awareness Month:
If you do one thing for cybersecurity readiness this month, complete or revisit the CCRE Cybersecurity Rubric.
Published: Sept 29, 2206
AUTHOR: Frankie J. Jackson, CETL®, CCRE,
CoSN Cybersecurity Readiness for Education (CCRE) Project Director
CoSN Cybersecurity Committee
CoSN is vendor neutral and does not endorse products or services. Any mention of a specific solution is for contextual purposes.