Charter schools added 111,349 students last year — the same year district schools lost 221,729. More than 8,100 charter schools now serve nearly 4 million students, according to the National Alliance for Public Charter Schools. All that growth means more devices on the network and more risk riding on them. It almost never means more IT staff. So the first thing to know about building a K-12 IT staffing plan for 2026 is that it shouldn't start with a job posting.
It should start with coverage. In CoSN's 2026 State of EdTech survey, 78% of the smallest operators, those under 1,750 students, run all of IT on one to three people. That's the enrollment bucket most charter schools sit in. That headcount isn't moving in 2026, but the workload is. The schools that get next year right will do something quieter than hiring: decide, task by task, what stays in-house, what gets shared, and what gets automated or retired. Here's how to build that plan before the 2026-27 year starts.
The first step in any K-12 IT staffing plan is a workload inventory: write down everything the 2026-27 year will demand from IT before you think about who does it. Skip the job titles for now. You want tasks, with rough hours attached.
Some of that list is familiar, like tickets and the August login flood. Security adds new weight: U.S. schools and colleges took 130 ransomware attacks in 2025, more than any other country, per Comparitech's end-of-year roundup. Safety mandates add more. Twelve states have now passed Alyssa's Law, which requires silent panic alarms tied directly to 911. Virginia and West Virginia joined in April 2026, according to the advocacy tracker at Make Our Schools Safe. If your state is on that list, or on the longer list with bills in progress, someone owns that compliance work. Then there's the device fleet: most student devices turn over on roughly a four-year cycle, so a slice of your fleet needs replacing and redeploying every single year, whether or not anyone put it on a calendar.
Write it all down, with honest hour estimates. The list will be longer than your team. Expect that. The whole next step exists to close the gap.
Every task on that inventory goes into one of three buckets: keep in-house, share with a partner, or automate and retire. That sort is your staffing plan. Not the org chart. The sort.
Keep in-house the work that depends on being in the building and knowing the people: classroom-floor support, teacher relationships, the triage judgment on day one when three things break at once. Share the work that needs depth more than presence: after-hours monitoring, network engineering, security response, E-Rate paperwork. No one- to three-person team can hold senior-level depth in all of those, and pretending otherwise is how small schools burn out good people. Automate or retire the rest: manual device imaging, password resets that eat an hour a day, that aging one-off system nobody remembers buying.
That middle bucket is exactly what a co-managed IT partner exists for. More on that below. For now, just do the sort honestly. If a task lands in "keep" only because it's always been in-house, move it and see if the plan gets better.
Your in-house person's job description should be built straight from the "keep" bucket. If a problem lives in a hallway or a classroom, it's theirs. A 2 a.m. alert or a firewall rebuild shouldn't be.
Then ask the uncomfortable question every small-school plan skips: what happens when that person is out sick during state testing week? On a team of one to three, every individual is a single point of failure. That's fine, as long as the plan says out loud who covers what when they're gone instead of assuming it away.
This lands hardest on charter schools, because there's no district office to borrow a tech from. A district school with a sick technician calls central IT. A charter school with a sick technician has a decision it should have made last spring. Your backup plan has to be explicit, not assumed: a named partner who already knows your environment, and credentials that don't live in one person's head.
Cybersecurity needs its own line in your staffing plan, with a named owner and defined hours. It cannot be a side duty for whoever's free that week. In CoSN's 2026 survey, 65% of district tech leaders said they don't have the staff to cover cybersecurity, and 58% said the same about classroom technology support. Those two gaps feed each other. When one small team owns both, every hour spent chasing a phishing report is an hour a teacher waits, and every busy support week is a week nobody's watching the logs.
You can separate the coverage lines without hiring a security analyst. The plan just has to state who monitors, who responds, and on what schedule, even if the honest 2026 answer is "a partner does, because our person is spread across everything else." An unowned risk is still a risk. It's just one you'll meet on its schedule instead of yours.
Fund the plan you wrote, not the one you wish you had. Two realities frame the money conversation for 2026. The pandemic-era federal funds are fully spent as of the final ESSER deadline this past March, and across the sector the current story is cuts, not hires. Meanwhile, budget constraints have topped CoSN's list of challenges for school technology leaders year after year. Nobody's budget is rescuing their staffing plan this year. The plan has to fit the budget.
E-Rate is where a small school finds room. The charter math is simple: E-Rate funds eligible services and equipment, not staff. But every eligible dollar you claim frees operating budget you can spend on people. For a school leaning on E-Rate with no district grants office behind it, disciplined filing is a staffing strategy wearing a paperwork costume.
Watch the federal signal, too. The FCC's E-Rate Cybersecurity Pilot set aside $200 million over three years for school and library cybersecurity, and as of late January 2026 only about 14% of it had been committed: $28.1 million across 191 schools and libraries, per Funds For Learning's analysis. That pilot is closed to new applicants, so there's nothing to apply for. Read it as two lessons instead: federal money is moving toward school cybersecurity, slowly, and the schools that win funding rounds are the ones with their E-Rate discipline already in order when a window opens.
A staffing plan without a calendar is a wish. Work backward from day one of school and put a date on every dependency, starting with board or authorizer approval. Then date the contract signatures and the summer setup that lets teachers walk into working classrooms.
The backward math is unforgiving. Board and authorizer meetings happen on their schedule, not yours. Miss a cycle and you lose a month. Contracts and procurement have lead times. Summer setup needs the summer, not the last ten days of it. If the plan isn't approved by late spring, day-one readiness is already at risk.
For charter leaders, the calendar carries one more job. You answer to a board and an authorizer, and an IT outage or a security incident becomes a board agenda item fast. A dated, board-approved coverage plan changes that conversation. Instead of explaining a surprise, you're pointing to a plan the board already endorsed. It's also a renewal-file asset: documented evidence that the school runs its operations deliberately.
Because for most small schools in 2026, the money isn't there, and the labor market doesn't serve one-person departments well. The pandemic funds that padded budgets are gone as of this spring, and sector-wide budgets are tightening. A single mid-level IT salary can be the entire technology budget line of a small school. Even when the money exists, the market fights you: a generalist strong enough to run both your network and your security program is exactly the person larger employers are hunting too, at salaries a small school can't match. And when your one tech leaves, everything they knew leaves with them.
Sometimes hiring is the right answer. If your Step 1 inventory shows 40-plus weekly hours of work that genuinely requires a person in your building, that's a job, and you should post it. The mistake is treating a job posting as the default answer to every gap, including the overnight monitoring and specialist depth that a single hire was never going to cover anyway.
Managed IT means an outside partner runs your school's technology operation; co-managed IT means your in-house person and a partner split the work deliberately. With fully managed IT, the partner is the IT department, from the helpdesk to the firewall. That fits schools with no technical staff at all.
Co-managed IT maps directly onto the three buckets from Step 2. Your person keeps the in-house bucket, the hallway-and-classroom work only someone on-site can do. The partner takes the share bucket, the deep technical work like security monitoring and network engineering. You keep ownership and building knowledge, and you stop paying the price of one person pretending to be five.
Veeya is built to be the "share" bucket for schools like yours. We've spent over a decade working inside school buildings, so we know what a lean budget forces you to trade off and how fast an E-Rate deadline arrives. We also know what August looks like when the whole IT department is one person and a cart of Chromebooks.
With a co-managed setup, your one-to-three-person team stops being a set of single points of failure without giving up ownership. Your person stays out front as the name teachers know and the first call when something breaks. We carry the depth behind them, from security monitoring and network engineering to E-Rate support and day-one readiness. That includes emergency communications, with Alyssa's Law panic alerts where your state requires them. The buckets you sorted in Step 2 become the working agreement between your team and ours.
If you're building your 2026 plan now, don't start from a blank page. Bring your task list to a working session with our team, not a pitch, and leave with a draft coverage model for 2026.
There's no reliable magic ratio. Most very small schools run IT on one to three people, and the right number depends on workload, not enrollment math. Plan by coverage instead of chasing a headcount formula: list what the year demands, then decide what your team owns and what a partner covers.
Six things: a workload inventory for the year ahead, a three-bucket sort of every task (keep in-house, share, or automate/retire), a clear definition of the on-site role, a dedicated cybersecurity coverage line, a budget and E-Rate match, and a calendar with board approval and contract lead times built in.
Yes, plenty do. It works when the plan is explicit about what that person does not own, and who covers those things instead. One person can't be the on-site technician and the security analyst at once, so the plan has to name who covers each gap before someone's out sick during testing week.
Co-managed IT means your in-house tech and an outside partner split the work deliberately: your person stays the face of IT in the building, and the partner covers the depth, like security monitoring and after-hours coverage. It differs from fully managed IT, where the partner runs the whole operation.
No. E-Rate funds eligible services and equipment, not salaries. But every eligible dollar you claim through E-Rate frees operating budget you can spend on people, which is why disciplined E-Rate filing belongs inside a staffing plan.
Now. Work backward from day one of school: board or authorizer approval runs on its own calendar, and contracts have lead times that eat the summer. A plan finished in August is a plan for October.