Why School Leaders Should Be Paying Attention to the ASIS SSEC-2025 School Security Standard
After working across multiple areas of K-12 public education, I have learned that school safety looks very different depending on where you are sitting. I have viewed it through school policing and administration, risk management, school security, emergency preparedness, organizational leadership, and district operations. Today, as a consultant and expert witness, I also examine these issues through another important lens: the standard of care schools provide to students and how decisions made before an incident may be evaluated after one occurs.
Those different perspectives have taught me an important lesson. What sounds reasonable on paper does not always translate easily into the daily operations of America’s schools. Policies, standards, and best practices are important, but they ultimately must function in real schools, with real students and employees, finite resources, different facilities, different risks, and very different communities.
That is one reason I have been closely following the ASIS International School Security Standard.
From a Proposed Standard to an ANSI-Approved Standard
On July 26, 2024, ASIS International announced a public review period for its proposed School Security Standard. That process ultimately resulted in the publication of ASIS SSEC-2025, School Security Standard, an ANSI-approved standard, on August 27, 2025. We are now approaching the first anniversary of its publication.
The standard represents a significant effort to establish a comprehensive framework for school security. There are important security principles within it that school leaders should understand and consider. My concern is not with the concept of establishing guidance for schools, nor is this discussion about questioning whether schools should take reasonable steps to protect students and staff. They absolutely should.
The larger question is how prescriptive a voluntary national standard should become when applied to thousands of schools operating under vastly different conditions—and what happens when that standard begins influencing expectations about what schools reasonably should have done.
School Safety Is Ultimately Local
Every school exists within a community, and every community is different.
School safety does not occur in a vacuum. A school’s safety and security strategies should reflect its students, facilities, geography, surrounding neighborhood, community expectations, staffing, available resources, identified risks, and relationships with local first responders and community partners.
A large urban high school may face challenges very different from those of a small rural elementary school. A suburban district with its own school police department may have resources and response capabilities that differ significantly from a district relying upon a county sheriff whose deputies cover hundreds of square miles. A school built five years ago may have security infrastructure that is substantially different from a campus constructed 60 years ago.
Even schools within the same district may require different approaches.
That is why I have long viewed school safety as fundamentally a local issue.
National recommendations, research, professional guidance, and recognized best practices can provide tremendous value. They can help school leaders identify vulnerabilities they may not have considered and provide benchmarks against which existing practices can be evaluated. But those resources should inform local decision-making, not dictate local decisions.
The people closest to a school and its community understand their risks, know their resources, maintain relationships with their first responders, engage their employees and community partners, and determine which strategies are reasonable and appropriate for their particular environment.
Effective school safety requires both strong guidance and local professional judgment.
A Voluntary Standard Is Not the Same as a Legal Requirement
Based on my research, I have found no evidence that ASIS SSEC-2025 has been incorporated into federal law or adopted as a statewide statutory or regulatory requirement governing K-12 schools. That distinction is important. An ANSI-approved industry standard does not automatically establish the legal standard of care for every school in America.
However, school leaders should also be careful not to equate voluntary with irrelevant.
Those of us who work with school liability litigation understand that the analysis of what a school reasonably should have done does not necessarily begin and end with statutes and regulations. Attorneys and expert witnesses may also examine district policies, procedures, training materials, professional guidance, recognized practices, industry publications, accreditation requirements, and voluntary standards when developing opinions about the reasonableness of a school’s actions.
Imagine a deposition several years from now following a serious school security incident. A superintendent, principal, risk manager, or security administrator is asked whether they were aware of the nationally recognized ANSI-approved ASIS School Security Standard. The next question may be whether their district was meeting that standard. If the answer is no, the inevitable follow-up may be: Why not?
The standard may be voluntary, but those questions are entirely foreseeable.
The Importance of the Word “Shall”
One of my concerns dates back to the proposed standard. The 2024 draft reportedly contained more than 200 uses of the word “shall.” ASIS’s subsequent public-review materials distinguished requirements expressed through “shall” statements from recommendations expressed through “should” statements.
Those words matter because there is an important difference between a requirement, a recommendation, and a best practice. A recommendation gives school leaders guidance that can be evaluated within the context of their particular environment. A best practice provides a benchmark against which existing operations can be measured while still allowing professional judgment.
“Shall” communicates something considerably different. Within these standards, it establishes a requirement.
My concern with that language should not be mistaken as suggesting schools should somehow do less to protect students and staff. The issue is who should ultimately determine what the safety and security measures are for a particular school and community.
A nationally developed requirement may represent sound practice in many environments. But that does not necessarily mean it is the most appropriate, effective, feasible, or highest-priority security measure for every school in the country.
When a voluntary school security standard contains hundreds of requirements (“shall” statements), we should think carefully about whether all schools within a given jurisdiction can meet all the listed required standards and stay compliant.
America’s Schools Are Not Interchangeable
There are approximately 99,000 individual public schools, including charter schools, and nearly 30,000 private schools across the United States. Those schools are extraordinarily diverse.
That diversity is more than an argument about funding. Schools differ in campus design, enrollment, grade configuration, staffing, transportation, climate, surrounding land use, law enforcement response times, emergency medical capabilities, behavioral-health resources, community partnerships, and the types of hazards they are most likely to encounter.
A security measure that is a high priority for one school may be a considerably lower priority for another. This is why school safety cannot simply become an exercise in checking boxes against a national document. Schools operate as complex ecosystems. A national security standard should not unintentionally create an expectation that every school must look, operate, or secure itself in essentially the same way.
Local Decision-Making Is Not an Excuse for Inaction
There is an equally important point that needs to be made.
Arguing for local flexibility should never become an excuse for failing to address known vulnerabilities.
Schools have an obligation to take safety seriously. When risks are identified, school leaders should evaluate them. When reasonable corrective measures are available, those measures should be considered. When policies or procedures are outdated, they should be reviewed. When employees need training, that training should occur.
The strongest school safety programs are not necessarily those that can demonstrate compliance with the greatest number of checklist items. They are the programs that can demonstrate an ongoing process of identifying risks, evaluating vulnerabilities, prioritizing improvements, collaborating with stakeholders, implementing reasonable measures, training employees, and reassessing whether those measures are actually working.
That is meaningful risk management.
Would Recommendations and Best Practices Have Better Served Schools?
Like it or not, the ASIS SSEC-2025 School Security Standard is here to stay.
In my view, America’s public and private schools would have been better served if many of the ASIS’s requirements (“shall” statements) had been presented as recommendations or recognized best practices, allowing school leaders to determine applicability through a thoughtful and documented risk-based process.
That approach would not lower the expectation that schools protect students and staff. Instead, it would place responsibility where I believe it belongs, on school leaders and their local partners to understand their environment, evaluate credible guidance, identify vulnerabilities, establish priorities, and make informed decisions about what works best for their schools.
There is a significant difference between saying, “Every school shall do this,” and saying, “This is a recognized security practice that every school should evaluate.”
The second approach still creates accountability. But it also recognizes the diversity of America’s public and private schools.
A 2017 New Mexico Case Offers an Important Lesson
There is an interesting legal case worth examining when discussing security-industry standards and the standard of care in schools. In Kreutzer v. Aldo Leopold High School, a 2017 New Mexico Court of Appeals decision, an expert with an ASIS security-management certification offered opinions related to security and the standard of care at a public school.
The court pushed back on important aspects of that testimony. Among other concerns, the court questioned how the expert’s security credentials established expertise regarding the particular standard-of-care issue involving a public school. More importantly for today’s discussion, the court addressed the expert’s reliance upon what he characterized as industry standards and questioned why those standards should establish the standard of care New Mexico public schools were required to meet.
That distinction remains extremely important today. An industry standard does not automatically become the legal standard of care. Likewise, professional certification in the security industry does not necessarily establish expertise regarding every aspect of K-12 school operations.
But Kreutzer also demonstrates something else. An attorney and expert witness were attempting to bring security-industry concepts and standards into school litigation years before ASIS SSEC-2025 existed.
Today, there is a school-specific, ANSI-approved security standard.
Now, that changes the conversation.
How Voluntary Standards Can Influence Expectations Over Time
I am particularly interested in what happens over the next five to ten years. ASIS SSEC-2025 may remain primarily a voluntary resource used by security professionals and schools seeking guidance. But standards can gain influence incrementally.
Consultants may begin referencing provisions in security assessments. School districts may incorporate portions into policies or procedures. Insurance professionals may consider provisions when evaluating risk. Requests for proposals may begin referencing the standard. Training programs may incorporate its requirements. Professional presentations and publications may cite it as a recognized security benchmark.
Then, following a serious incident, an expert witness may identify a particular “shall” requirement and argue that the school failed to follow a nationally recognized security standard.
That is how a voluntary standard can potentially begin influencing expectations without a legislature ever passing a law making the entire standard mandatory. The standard becomes more widely recognized, portions become incorporated into practice, and attorneys and experts begin debating whether particular provisions represent what a reasonably prudent school should have known or done.
None of that automatically transforms ASIS SSEC-2025 into the legal standard of care. But it may make the document part of the standard-of-care conversation.
What Should School Leaders Do Now?
My recommendation is not that every school district immediately attempt to comply with every provision of ASIS SSEC-2025. At the same time, I would not recommend that school leaders ignore the standard simply because it is voluntary.
A more thoughtful approach is to understand what the standards are and compare it against the district’s existing safety and security program. Determine which provisions reflect practices already in place. Identify those recommendations that may strengthen existing operations and examine requirements that may not be appropriate, feasible, or necessary within the district’s environment.
Most importantly, involve the people who understand the local environment. School administrators, risk managers, security professionals, teachers and support staff, law enforcement, fire and emergency management partners, mental health professionals, parents, and other appropriate community stakeholders may all bring different perspectives to the discussion.
That collaboration matters because school safety should not simply be imported into a community. It should be developed with the community through ongoing interagency and intra-agency collaborative groups, each with their unique role to address school safety, security, and emergency preparedness.
When significant security decisions are made, districts should also document the process and reasoning used to make them. A school district should be able to explain not simply what it did, but why it did it, and how that decision related to identified risks, school-specific conditions, available resources, professional guidance, and local circumstances.
The goal should not simply be to answer:
“Are we ASIS compliant?”
A stronger leadership question is:
“Can we demonstrate that our district has a thoughtful, documented, locally informed, risk-based process for identifying security concerns and implementing reasonable measures appropriate for our schools and community?”
School Safety Leadership Requires More Than Compliance
School safety leadership requires judgment. It requires understanding the unique environment of each school, listening to those who work there every day, collaborating with law enforcement and emergency-response partners, evaluating available resources, understanding community expectations, and continually reassessing risk as conditions change.
National standards can provide valuable guidance. Best practices can provide important benchmarks. Professional organizations can advance the school safety profession and expose school leaders to strategies they may not otherwise have considered.
But ultimately, school safety happens locally.
It happens at a particular school, on a particular campus, serving a particular group of students, supported by a particular community and responding to a particular set of risks.
That reality should remain at the center of any national conversation about school security standards.
There is also another reality school leaders cannot overlook: security decisions that appear purely operational today may eventually become litigation questions tomorrow. A decision not to implement a particular security measure may someday be examined in a deposition. An assessment completed years earlier may become an exhibit. A district’s knowledge of a recognized standard may become relevant to an expert’s opinion.
What matters at that point should not simply be whether a school checked every box in a national standard. The more meaningful question is whether school leaders understood their risks, evaluated credible guidance, engaged their local partners, exercised reasonable professional judgment, implemented appropriate safeguards, and continually worked to improve their program.
ASIS SSEC-2025 is still relatively new. We do not yet know what influence it will ultimately have on school liability litigation or judicial interpretations of the standard of care. But I believe school leaders, risk managers, insurance professionals, attorneys, and school safety practitioners should be watching it closely.