October 1 is Approaching, and This Year is Different. Is Your 2026 Annual Security Report Ready?

CriticalArc Consulting
Share this blog:
executives around a table

The Annual Security Report deadline is virtually here. A final review should include more than updating crime statistics and changing the date on the cover. For colleges and universities subject to the Clery Act, October 1 is a familiar date. Each year, as required by federal requirements, institutions must distribute their Annual Security Report (ASR) to current students and employees while making the report available to prospective students and employees. But the 2026 publication cycle deserves particular attention.

The Stop Campus Hazing Act (SCHA) added hazing to the Clery Act’s crime-reporting framework and created new requirements related to institutional hazing policies, prevention and awareness programs, and the Campus Hazing Transparency Report. The Department of Education’s 2026-27 Federal Student Aid Handbook has now been updated throughout its Clery guidance to reflect those requirements.

For institutions preparing to publish their 2026 ASR, the remaining weeks before October 1 offer an important opportunity to conduct a final quality-control review. And for institutions that have already published? There is still value in reviewing the report now. An ASR should not be treated as a once-a-year compliance exercise or a document that disappears after publication. It is a reflection of an institution’s year-round commitment to campus safety and serves as an important reference for students, employees, families, and other stakeholders when questions arise about safety policies, reporting, response, and institutional responsibilities. Treating it as routine paperwork can allow outdated or inaccurate information to persist, increasing both compliance and operational risk. Finding a problem after publication is preferable to carrying it forward for another year.

Here are several areas your institution should consider before October 1, immediately after publication, and as they prepare for the next reporting cycle.

  1. Make sure 2026’s SCHA requirements have made it into the ASR. This is perhaps the most consequential change for this year’s reporting cycle. Under the SCHA, hazing is now among the Clery Act crimes/incidents institutions must include within their Clery statistics. The U.S. Department of Education’s (ED) current guidance also identifies two additional categories of required ASR content:
    • A statement of the institution’s current policies relating to hazing, including how hazing is defined by the institution, how incidents can be reported, the process used to investigate them, and information regarding applicable local, state, and Tribal hazing laws.
    • A statement of policy regarding hazing prevention and awareness programs, including research-informed, campus-wide prevention programming designed to reach students, staff, and faculty and primary prevention strategies intended to stop hazing before it occurs.

The 2026 ASR is the first annual report in which institutions must disclose hazing statistics, covering reportable incidents occurring during calendar year 2025.

That makes this year’s review more than a matter of inserting a new policy section. Institutions should ask whether the operational structures and processes behind those disclosures are genuinely in place. Consider these examples:

  • Who receives reports of potential hazing?
  • Who determines whether an incident meets the federal Clery definition?
  • Are the appropriate individuals and offices identified as Campus Security Authorities (CSA)?
  • Are reports flowing to the office responsible for Clery classification?
  • Can an institution substantiate the statistics ultimately appearing in its ASR?

The ASR is the output of those processes, not where an institution discovers they do not exist, typically after-the-fact.

  1. Do not confuse the ASR hazing requirements with the Campus Hazing Transparency Report. One area ripe for confusion is the relationship between the ASR and the Campus Hazing Transparency Report (CHTR). They are related requirements, but not the same report not do they use the same framework.
    • The ASR requires institutions to disclose Clery crime statistics for hazing incidents reported within the applicable Clery framework, along with required hazing policy and prevention disclosures.
    • The CHTR, by contrast, focuses on student organizations found responsible for hazing violations under the institution’s standards of conduct. When applicable, it must identify the organization, provide a general description of the violation and sanctions imposed, and provide the date of the incident. The report must be updated at least twice each year when there are findings requiring an update.
    • That distinction matters. A reportable Clery hazing incident does not depend upon an institutional disciplinary finding against a student organization. Conversely, the CHTR is specifically tied to findings of responsibility involving student organizations. Institutions should therefore review whether they have established two distinct but coordinated processes for satisfying these requirements. 
  1. Reconcile your statistics one more time. The ASR must disclose statistics for the three most recent calendar years for reportable crimes occurring within the institution’s Clery geography and reported to a CSA or local law enforcement agency. Hazing has now joined the categories that must be reported. Before publication, institutions should consider conducting a final reconciliation across the sources that feed those statistics. That may include:
    • Campus police or public safety records
    • Reports received from other Campus Security Authorities
    • Student conduct and Title IX/sexual misconduct records
    • Hazing reports received outside traditional public safety channels
    • Local law enforcement requests and responses
    • Records involving recognized student organizations
    • Relevant noncampus locations and institutional programs

The question is not simply whether the spreadsheet totals correctly. Institutions should be comfortable that incidents were identified, classified, counted, and geographically assigned consistently and that the documentation supporting those decisions is sufficient to reconstruct how your institution arrived at its published statistics.

This is a time to reality-check and search for anomalies. A category suddenly showing zero incidents, an unexplained variance from prior years, or discrepancies between offices do not necessarily indicate an error, but they warrant a second look before publication.

  1. Review the words, not just the numbers. One of the most common traps in the annual ASR process is treating the report primarily as a statistical exercise. It isn’t.

The ASR contains extensive required policy statements describing how the institution addresses crime reporting, timely warnings, emergency notifications, security and access, law enforcement authority, crime prevention, alcohol and drugs, sexual assault and other VAWA offenses, emergency response and evacuation, and now hazing, among other requirements. Those statements should describe current institutional policies and practices.

Say what you do, do what you say. That makes September a final useful time to ask operational owners to review the portions of the ASR that describe what they actually do. Has the organizational structure changed? Have titles changed? Has responsibility for issuing emergency notifications moved? Has the institution implemented a new mass-notification platform? Have reporting mechanisms changed? Are listed telephone numbers, websites and office names current? Has a policy been revised since last year’s ASR? Most importantly: Does the institution operate the way the ASR says it does?

Bottom line: even a compliant ASR does not mean an institution is compliant with the Clery Act. ED has reminded institutions that the Clery Act requires an implemented system of campus safety policies, procedures and programs, not merely written disclosures, and that institutions must advise their campus communities when covered safety policies or procedures are revised before the next annual ASR distribution. A beautifully written ASR describing a process that no longer exists can create more risk, not less.

  1. Revisit Clery geography… always. Statistics are only as accurate as the geography underlying them. The final ASR review is a useful opportunity to ask whether anything changed during the reporting period that could affect the institution’s Clery geography. Consider new or discontinued facilities, leased spaces, athletics locations, study-away or study-abroad arrangements, recurring instructional locations, student organization property, and other properties the institution may own or control.

The current FSA Handbook defines Clery geography for statistical purposes to include campus property, qualifying non-campus buildings and property, and public property within or immediately adjacent to and accessible from campus.

This should not be a once-a-year conversation confined to the Clery coordinator. Real estate, facilities, athletics, academic affairs, global programs, student affairs and other institutional offices may know about changes long before the individual compiling the ASR does. If geography was difficult to reconstruct this September, that is an excellent process-improvement item for next year.

  1. Take a fresh look at Timely Warning and Emergency Notification language. The beginning of an academic year is an appropriate time to revisit the institution’s Timely Warning and Emergency Notification procedures. The ASR must accurately describe these processes, including relevant institutional policies and responsibilities. Emergency response disclosures include the processes used to confirm a significant emergency or dangerous situation, determine who should receive notification, determine notification content, and initiate the notification system. Ask practical questions:
    • Who has authority to make the decision?
    • Who can draft and send the message?
    • Is there backup authority at 2 a.m.?
    • Do the people identified in the ASR know that they have that responsibility?
    • Have staffing or leadership changes altered the approval chain?
    • Do the written procedures match what actually happens during an incident?
    • Is your institution 100% clear about the different standards and purposes associated with a Timely Warning and an Emergency Notification?

These are not simply ASR drafting questions. They are proactive operational readiness questions any manager should ask and any executive should oversee.

  1. Don’t overlook distribution. Finishing the PDF is not the finish line. By October 1, institutions must distribute the ASR, and Annual Fire Safety Report where applicable, to all enrolled students and current employees. Institutions may use electronic distribution, but simply placing the report somewhere on a website does not, by itself, satisfy the notice requirement.

When using web-based distribution, the notice must include the report’s availability, its exact electronic address, a brief description of its contents, and information regarding obtaining a paper copy. Requirements also apply to making the reports available to prospective students and prospective employees. Before October 1, institutions should therefore test the entire publication process:

  1. Does the URL always work?
  2. Is it accessible without institutional credentials (where appropriate)?
  3. Does the distribution notice contain all required elements?
  4. Are both students and employees included?
  5. Has responsibility for sending the notice been clearly assigned?
  6. Is there a process for prospective students and employees?
  7. And, if the Annual Security Report and Annual Fire Safety Report are published separately, does each provide information on how to directly access the other?

Archive redundant documentation demonstrating when, how, and to whom the required distribution occurred.

Already published? Review it anyway!

Some institutions may already have published their 2026 ASR ahead of October 1. That is a good thing, but publication should not prevent a final review. Use the remaining time to check the published version against the same questions above. Confirm that links work, required content appears as intended, statistics survived formatting correctly, the correct version was uploaded, and distribution requirements are completed.

If the review identifies a substantive omission or error, do not simply make a mental note to fix it next year. Determine what corrective action is appropriate, document what was identified and how it was addressed, and ensure the institution’s community has access to accurate information. Remember that the Clery Act is a campus safety, transparency, and consumer-protection law. ED describes access to accurate, complete and timely safety information as central to the act and has proven this extensively over the decades.

October 2 is the beginning of the next ASR cycle.

Perhaps the most valuable exercise this September is keeping track of everything that was harder than it should have been.

  • Did the institution spend weeks chasing CSA responses?
  • Were local law enforcement statistics difficult to obtain?
  • Was Clery geography reconstructed from old emails?
  • Did offices disagree about crime classifications?
  • Did no one know who owned a required policy statement?
  • Was hazing information housed in multiple offices without a clear reporting pathway?
  • Did it take until September to discover that an institutional practice had changed months earlier?

Those are not merely frustrations associated with producing this year’s report. They are the roadmap for improving next year’s Clery compliance program. Once the October 1 deadline passes, conduct a short after-action review. Identify gaps, assign owners, establish timelines, and move recurring tasks earlier in the calendar.

Consider maintaining a living ASR throughout the year rather than reopening last year’s document each summer. Establish mechanisms for notifying the Clery coordinator when policies, facilities, personnel, programs or reporting structures change. Review CSA lists and training processes periodically. Maintain an active Clery geography inventory. Document classification decisions as they occur. And start preparing for 2027 well before September 2027 arrives.

A final question: Can you defend what you published?

The strongest final review may be less of a checklist and more of a question. If someone asked tomorrow how your institution arrived at every statistic and every statement in its ASR, could you show them?

  • Could you identify the records supporting each statistic?
  • Could you explain classification and geography decisions?
  • Could the people named in your policies describe the processes attributed to them?
  • Could you demonstrate that required notices were distributed?
  • Could you show that the hazing requirements added by the Stop Campus Hazing Act are supported by actual institutional processes?

That is a higher standard than getting a PDF online by October 1. It is also a much better measure of whether an institution has a functioning Clery compliance program.

The U.S. Department of Education continues to describe Clery Act enforcement as a priority. The weeks leading up to October 1 provide institutions an opportunity not only to meet an annual deadline, but to assess whether the systems behind their disclosures are working as intended.

Jim Moore Quote

CriticalArc Consulting supports colleges and universities in evaluating Clery Act compliance programs, reviewing Annual Security Reports, assessing reporting and classification processes, and strengthening the policies and operational practices behind institutional disclosures. Whether your 2026 ASR is still in draft form or already published, an independent review can help identify both immediate concerns and opportunities to strengthen the next reporting cycle. Contact us anytime: consulting@criticalarc.com.

Beyond the Iceberg: Navigating the Stop Campus Hazing Act

Hazing remains one of the most persistent and complex safety challenges facing higher education. In response to bipartisan concern over institutional accountability and student protection, Congress passed the Stop Campus Hazing Act (SCHA), a significant amendment to the Jeanne Clery Campus Safety Act that reshapes executive oversight expectations. Download our white paper to learn more:

The new site provides a more seamless journey for visitors, making it easier to discover our solutions, explore our resources, and understand the value we bring to higher education, healthcare, and enterprise sectors. We believe this new website is not just a fresh look but a powerful tool that will help us connect with more organizations and continue our mission to make the world a safer place.
Your Name

Learn the unique ways SafeZone enhances campus safety

Don’t wait for the worst to happen. Join the hundreds of organizations already using SafeZone to empower their teams and safeguard their communities.

See all that you can accomplish with CriticalArc

Share this blog