VerifyFiltering — home VerifyFiltering — home
Learn / Compliance

What Each Compliance Standard Actually Checks

When you run a scan, the first choice you make is which standard to test against. That choice isn't cosmetic — each standard checks a different, fixed set of content categories. Picking the wrong one means the categories tested may not match what you're actually trying to show.

The four options

The scanner offers three named standards, plus a custom option:

StandardCategories tested
CIPAAdult & Pornography, CSAM, Proxy & VPNs, Malicious domains
UK Safer InternetAdult & Pornography, CSAM, Terrorism, IWF, Malicious domains
Friendly WiFiAdult & Pornography, CSAM, Terrorism
CustomWhichever categories you pick yourself

CIPA, UK Safer Internet, and Friendly WiFi each map to a fixed bundle of categories — you don't choose the categories individually, you choose the standard and the right categories come with it. Custom is different: instead of a predefined bundle, you pick the categories yourself. That's useful if you're testing against your own acceptable-use policy rather than an external regulation, or if you only care about one or two categories rather than a full standard's worth.

What each category actually means

CategoryWhat it tests
Adult & PornographyWhether pornographic websites are blocked on your network.
CSAMWhether sites on the IWF child abuse content URL list are blocked.
IWFThe same IWF child abuse content URL list, tested as its own category under UK Safer Internet.
TerrorismWhether known terrorist-affiliated sites are blocked.
Proxy & VPNsWhether proxies and VPNs that can be used to bypass a filter are themselves blocked.
Malicious domainsWhether known malicious and malware domains are blocked.

Notice CSAM and IWF share the same description in the product's category config. CIPA and Friendly WiFi fold that check into the general CSAM category, while UK Safer Internet breaks it out as its own line item.

We don't test every domain, and not the same ones twice

Each category has a larger list of test domains behind it than any single scan actually uses — a scan checks a random sample from each category rather than the full list, and which domains get picked varies scan to scan. We don't publish the exact test list. A fixed, public list of exactly what gets checked would let anyone configure their filter to pass the scan specifically, rather than to actually block the category it represents.

How results get scored

Once a scan runs, each category comes back as its own result, and the standard's pass or fail comes from combining all of them — see how the scanner works for exactly what "blocked," "partially blocked," and "not blocked" mean, and how they roll up into one overall result.

Not sure which standard applies to you? See how the scanner works for a breakdown of who each standard is for, then run a free scan — you can always switch standards and re-run if the first one doesn't match your situation.

Compliance & Filtering

Guides on network content filtering, the standards that regulate it, and how to verify your own network actually meets them.

Standards We Test

  • CIPA
  • UK Safer Internet
  • Friendly WiFi
  • Custom Profiles

VerifyFiltering Monitoring

Move past a one-time scan — scheduled, ongoing checks across every device you manage, with alerts when something changes.

See plans →

CleanBrowsing

VerifyFiltering is a CleanBrowsing service. CleanBrowsing itself offers fast, privacy-first DNS filtering you can deploy directly.

Explore CleanBrowsing →

Contact Us

Have an idea for an article, or see something missing? Email support@noc.org.