817-625-2700

GSFT School Safety Certification

ISDs: a new three-year audit cycle begins September 1, 2026

See all cycle deadlines →

The 2026–2029 school safety audit, done the way the new cycle demands

Texas Education Code §37.108 requires every district, charter school, and public junior college to audit the safety and security of its facilities at least once every three years. For the new cycle, the TxSSC replaced the old single checklist with a full instrument suite — and we rebuilt our audit practice on it, item for item. We plan, conduct, and document the audit to the current methodology, and deliver a report your board can act on.

Listed on the Texas School Safety and Security Consultant Registry, as required by Texas Education Code §37.2091.
Your audit is led by Bryan Proctor, GSFT’s lead auditor, with Donnie Camp as registered auditor — practitioners you can verify by name.
Verify our listing on the official registry → Registry listing is verified registration under state law — it is not a state endorsement.

This cycle’s audit is a different audit

For 2026–2029, the Texas School Safety Center restructured how audits are conducted. The familiar single checklist is retired; in its place is a coordinated set of official instruments — nearly 300 assessment items spanning records, climate, interviews, and physical inspection. Our audit system implements the official tool set directly, so every criterion your district is measured against is the state’s current criterion, not last cycle’s.

Audit Plan

Scope, campuses, facility inventory, schedule, and team — signed before fieldwork begins.

Records Review Assessment

140 criteria across your policies, plans, drill logs, and compliance records — completed before anyone walks a campus.

Safety Climate Assessment

Staff and stakeholder climate input through a digital survey instrument, documented and referenced in findings.

On-Site Interview Tool

84 structured interview items with campus leadership, staff, and safety personnel.

On-Site Assessment

71 physical criteria per facility — access control, exterior and interior, communications — with photo evidence tied to each observation.

Trackers & Final Report

Improvement, Commendation, and Justification Trackers feeding a board-ready report on the official TxSSC Final Report Template.

Official source: TxSSC School Safety and Security Audit Toolkit.

The 2025 laws are now audit criteria

The 89th Legislature’s school-safety bills are not future obligations — they are built into the new cycle’s assessment items. Your audit now checks, among others:

AuthorityWhat the audit now verifies
SB 838 (Alyssa’s Law)Silent panic alert technology in every classroom
HB 33 (Uvalde Strong Act)Breaching tool and ballistic shield at each campus; standard response protocol terminology
TEC §37.1087 (HB 33)Security reviews for facilities constructed, acquired, renovated, or improved
HB 121Six-phase emergency operations plan — including reunification and recovery
HB 121Annual renewal documentation for armed-security good-cause exceptions
HB 121Emergency response maps provided to every applicable emergency services district
SB 57Drill accommodations for students with IEPs and 504 plans; special-education representation on the safety committee
TEC §37.108(b-1)Certification that school safety allotment funds (§48.160) were used for allowed purposes

And the criteria keep moving: each September the TxSSC publishes an Annual Supplemental capturing laws amended after audit resources were published — the first of this cycle arrives September 7, 2026. Every GSFT engagement records which supplemental version it was conducted under and reconciles against the current one.

What the law requires

Under TEC §37.108(b), the audit may be conducted by the district itself or by “a person included in the registry established by the Texas School Safety Center under Section 37.2091.” Either way, it must follow TxSSC audit procedures, cover every facility, and be reported to the TxSSC during your cycle’s reporting window and to your local board of trustees — with the district retaining a report copy signed by the board and superintendent. The audit must also certify that school safety allotment funds (TEC §48.160) were used only for allowed purposes.

Outside auditors must be registered — it’s the law

Two statutes protect districts here. TEC §37.108(b) recognizes only two lawful performers of the audit: the district itself, or a person on the Texas School Safety and Security Consultant Registry. And TEC §37.2091(b-1) goes further — a district must confirm a person is on the registry before engaging them for any school safety or security consulting service, paid or unpaid.

So before you sign with anyone — including us — look them up: registry.txssc.txstate.edu. GSFT’s audits are led by Bryan Proctor with Donnie Camp as registered auditor, and we link our listing because that check should take you two minutes, not an open-records request. If a vendor you’re considering isn’t on the registry, the engagement itself would put your district out of compliance.

What your district receives

One discipline runs through all of it: anything an auditor observes is entered once, tied to a criterion and its evidence, and flows to the trackers and the report. Nothing is re-keyed from memory, and any immediate safety concern is escalated to your superintendent the same day — not saved for the report.

Discretion is part of the method

Audit documents are confidential under TEC §37.108(c-1), and we operate accordingly: access-restricted workspaces, no published findings, no district-identifiable examples in our marketing — and exact on-site dates disclosed only to your superintendent and local law enforcement.

After the audit: Annual Compliance Maintenance

An audit is current the day it’s delivered — then the Legislature meets and the TxSSC updates the questions. Our Annual Compliance Maintenance program keeps your audit alive through the cycle: each September we reconcile your completed audit against the new Annual Supplemental by September 30 and re-complete any affected items by October 30, with a short memo your safety committee can file. Three years of a current audit posture — not one audit year and two stale ones.

Current cycles at a glance

The 2026–2029 ISD cycle is the first full district cycle under the new methodology. Districts that start audit work in year one absorb the still-evolving rules on their own schedule; districts that wait inherit them in a compressed final year.

EntityAudit cycleReport due to TxSSC
Independent School Districts Sep 1, 2026 – Aug 31, 2029 To be announced by TxSSC
Open-Enrollment Charter Schools Sep 1, 2025 – Aug 31, 2028 September 15, 2028
Public Junior College Districts Sep 1, 2024 – Aug 31, 2027 September 13, 2027

Full cycle details, reporting windows, and sources →

What is not in scope

TEA’s intruder detection audits (IDAs) and District Vulnerability Assessments (DVAs) are TEA’s own programs, run by state teams — no private vendor performs them. A well-documented §37.108 audit is the best preparation a district can have for both.

Why the whole exercise matters

Compliance is the frame; the point is what happens in the first minutes of an emergency. The audit is where a district measures its real response timeline honestly — before it matters. For why that timeline is the variable everything turns on, see our case study, what Parkland’s timeline teaches about campus response.

The district audit journey

Clear stages. Defined deliverables. Fewer surprises.

  1. Plan

    Signed audit plan: scope, campuses, facility inventory, schedule, and team.

  2. Records

    Tailored document checklist, secure submission, and the full records review — before fieldwork.

  3. On-site

    Physical assessment of every facility, structured interviews, and climate input — scheduled discreetly.

  4. Findings

    Every finding tied to a criterion, its evidence, and a tracker — priorities your board can budget against.

  5. Maintain

    Board-ready report, TxSSC reporting support, and annual supplemental reconciliation through the cycle.

Frequently asked questions

Is the safety and security audit required by law?
Yes. Texas Education Code §37.108(b) requires each school district and public junior college district to conduct a safety and security audit of its facilities at least once every three years, following Texas School Safety Center procedures, and to report results to the TxSSC. Open-enrollment charter schools carry the same obligation through TEC §12.104(b)(3)(V).
What changed for the 2026–2029 audit cycle?
The methodology. The single audit checklist of prior cycles is retired — the TxSSC now publishes a suite of instruments: an Audit Plan, a Records Review Assessment Tool, a Safety Climate Assessment, an On-Site Interview Tool, an On-Site Assessment Tool, Improvement/Commendation/Justification Trackers, and a Final Report Template. The 2025 legislative session is also built into the criteria — silent panic alerts, breaching tools and ballistic shields, six-phase emergency operations plans, and more. An audit run on the old checklist will not satisfy the new cycle.
Can we do the audit ourselves instead of hiring a consultant?
Yes — the statute allows the district to conduct its own audit. Keep one thing in view, though: when a district self-audits, the liability for the audit and the accuracy of its findings rest entirely on the district and the individual completing it. Many districts choose an outside auditor for exactly that reason, along with independence, capacity, and depth — the new multi-instrument methodology has made self-auditing a substantially larger project than it was last cycle. If you engage anyone outside the district, TEC §37.2091(b-1) requires you to confirm they are listed on the TxSSC Consultant Registry first.
What is the Annual Supplemental, and why does it matter?
Each September the TxSSC publishes an Annual Supplemental — a maintenance document capturing laws that changed after the cycle’s audit resources were published. Districts are expected to update their assessment questions against it, mid-cycle, every year. The first one of this cycle lands September 7, 2026. Our Annual Compliance Maintenance program exists precisely for this: we reconcile your audit against each supplemental so your program stays current across the full three years.
How disruptive is the on-site work?
Minimally, by design. On-site dates are held close — only your superintendent and local law enforcement are told the exact date — and fieldwork is scheduled around your calendar. Our auditors capture observations, photos, and interviews digitally on-site, so campuses are not asked to host repeat visits to fill gaps.
How is this different from TEA’s intruder detection audit?
They are separate programs. TEA’s regional teams conduct unannounced intruder detection audits (IDAs) at every campus each year, and TEA’s Office of School Safety and Security conducts District Vulnerability Assessments on a random basis. Those are TEA’s own programs — no vendor can perform them for you. A thorough §37.108 audit prepares your campuses to do well in them.
What does the audit cost?
Scope depends on the number of campuses, facility size, and student enrollment. Request an audit estimate with your campus count and we will return a scoped, per-campus proposal the same business day in most cases.
Is our audit information kept confidential?
Yes — and not just as a courtesy. Audit documents are confidential under TEC §37.108(c-1). Our audit workspaces are access-restricted, findings are never published or shared, exact on-site dates are disclosed only to your superintendent and local law enforcement, and nothing sensitive is ever collected through public web forms.

Get a scoped audit estimate

Tell us your entity type, campus count, and timing. We respond with a per-campus scope the same business day in most cases.

We respond to every inquiry the same business day in most cases.