Skip to main content

Compliance & Regulation

HECVAT Explained: What Universities Ask Software Vendors, and How to Answer It

Eduspera Team
11 min read
A person working through a printed questionnaire with a pen at a tidy desk
Share this article

Before a university buys a piece of software, someone in information security has to decide whether it can be trusted with student data. For years every institution asked its own questions, which meant vendors answered hundreds of near-identical questionnaires and reviewers had no way to compare the answers. The HECVAT — the Higher Education Community Vendor Assessment Toolkit, maintained by EDUCAUSE with REN-ISAC — exists to end that. It is a standardised set of security, privacy and accessibility questions that institutions send to cloud vendors, and it has become the de facto gate in higher-education procurement. This guide explains what it covers, which version applies when, how buyers actually use it, and — for vendors — what separates an answer that clears review quickly from one that stalls for a month.

What the HECVAT is, and what it is not

The HECVAT is a questionnaire, not a certification. Nobody issues a HECVAT badge, there is no auditor, and completing one confers no status. Its value is standardisation: because every institution asks the same questions in the same order, a security reviewer can read a completed HECVAT from an unfamiliar vendor and reach a judgement in an afternoon rather than a fortnight.

It covers the ground you would expect — company and product overview, documentation, third-party assessments, consulting, application and database security, data handling, disaster recovery, firewalls and IDS, policies, quality assurance, systems management, vulnerability scanning, and business continuity — plus two areas that matter especially in education: accessibility and privacy of student records.

It is not a substitute for a SOC 2 report, and reviewers know the difference. A SOC 2 is an independent auditor’s opinion on operating controls; a HECVAT is the vendor’s own account of them. Institutions ask for both when the data is sensitive enough, and a vendor without SOC 2 is not automatically disqualified — but the HECVAT answer has to be markedly more specific to compensate.

Full, Lite, On-Premise: which one applies

The toolkit comes in variants, and being sent the wrong one wastes everybody’s time:

  • HECVAT Full — several hundred questions. Used where the vendor will hold sensitive institutional or student data at scale, or where the service is critical to operations.
  • HECVAT Lite — a substantially shorter subset for lower-risk engagements, smaller deployments and initial qualification. In practice this is where most first conversations start.
  • HECVAT On-Premise — for software the institution hosts itself, where the security questions shift from the vendor’s infrastructure to the code and its update path.

Completed HECVATs are shared through the Cloud Broker Index, a community repository. When a vendor already appears there, a reviewer at another institution can often accept the existing assessment instead of running their own — which is why getting listed is worth more to a vendor than the effort suggests. Listing follows a first institutional assessment rather than preceding it.

How reviewers actually read it

Buyers rarely read a HECVAT front to back. They triage. In practice a reviewer goes straight to a handful of areas and forms a judgement there:

  • Where does the data live, and who else can reach it? Hosting region, sub-processors, and how tenants are isolated from one another.
  • What happens when something goes wrong? Incident response, notification windows, backup and recovery objectives.
  • Can we get our data out? Export, retention and deletion — asked with an eye on the end of the contract, not the start.
  • Does it work with our identity system? SAML and InCommon, SCIM provisioning and de-provisioning, multi-factor authentication for administrators.
  • Student records. Whether the vendor will sign a FERPA “school official” clause and confine processing to the institution’s instructions.
  • Accessibility. Increasingly the section that stalls a review, now that Title II and Section 504 have put institutions on a clock. Expect the HECVAT accessibility answer to be cross-checked against the vendor’s ACR.

A reviewer’s instinct is calibrated for evasion. Vague answers, unexplained “yes” responses and marketing language all slow a review down, because each one generates a follow-up email.

Two people reviewing documents across a meeting table in a bright office
Accessibility-first design lets every learner complete your courses — by keyboard, with captions, and with a screen reader.

What a good answer looks like

Three principles separate a HECVAT that clears in days from one that takes six weeks.

Be specific. “Data is encrypted” invites a follow-up; “TLS 1.2+ in transit, AES-256 at rest at the database and object-storage layer, keys managed by the platform provider” does not. Specificity is not just faster — it is itself evidence that someone technical wrote the answer.

Disclose gaps with a plan. The instinct is to soften. Resist it. “No SOC 2 report today; policies published, controls operating, Type I commissioned on contract with the first institution requiring it” is a respected answer. An implied attestation that unravels in a follow-up call ends the conversation entirely, and reviewers talk to each other.

Publish what you can. The strongest move available to a vendor is to put the substance of the answers on a public page, as Atlassian, Zoom and Google Cloud do, so a reviewer can qualify you before the questionnaire is even sent. It shortens the cycle, it filters out institutions you cannot serve, and it signals that the answers are stable enough to stand in public. Ours are at /trust/hecvat.

The accessibility questions, and why they now stall reviews

For most of the toolkit’s life, the accessibility questions were a formality: a reviewer confirmed a conformance report existed and moved on. That has changed. Since ADA Title II and Section 504 attached dates to WCAG conformance, an institution that approves an inaccessible product has created its own liability — so the accessibility answers are now read properly, and increasingly by someone from the digital accessibility office rather than from information security.

What that reviewer is checking, in order:

  1. Does a conformance report exist, and is it current? Dated within twelve months, naming the WCAG version and level. A report predating WCAG 2.2 signals when the vendor last engaged with the subject.
  2. Does its scope cover what we will actually use? Learner-facing, authoring and administrative interfaces — not just the marketing website. This is where most reports quietly narrow.
  3. How was it tested? Automated scanning alone covers an estimated 30–40% of WCAG criteria. A credible answer names screen readers, browsers and manual keyboard testing.
  4. What are the known gaps, and when are they being fixed? Disclosed exceptions with dates read as maturity. A report with no exceptions at all reads as a form somebody filled in.
  5. What happens when we report a barrier? An acknowledgement window and a severity classification, ideally written into the contract rather than promised on a call.

For vendors, the practical consequence is that the HECVAT accessibility section and the ACR are cross-checked against each other, and against the product itself during a trial. Three documents that disagree is worse than one honest one. For institutions, the consequence is that this section deserves a named reviewer with the standing to hold a purchase — accessibility findings that arrive as advisory comments at the end of a procurement are routinely overridden by the deadline that prompted the purchase.

What the HECVAT does not settle

Clearing a HECVAT is necessary and not sufficient, and institutions occasionally treat it as the whole review. Four things it does not resolve:

  • Contract terms. The questionnaire records what a vendor says it does; the contract is what obliges them to keep doing it. Notification windows, uptime commitments, remediation obligations and the consequences of failing them live in the agreement, not the assessment.
  • Accessibility conformance. The HECVAT asks whether a conformance report exists. It does not evaluate the report, and a “yes” here is compatible with an ACR that is four years old and covers a different product. Read the ACR separately — our guide to reading a VPAT covers what to look for.
  • Data protection outside the United States. The HECVAT was designed around American institutional practice. If personal data touches the EU or the UK, you still need an Article 28 processing agreement, a sub-processor list and a lawful transfer mechanism, none of which the questionnaire produces.
  • What the product is actually like to use. A vendor can clear a security review comprehensively and still ship software your staff cannot operate. The assessment runs in parallel with the evaluation; it does not substitute for it.

Used well, the HECVAT is a filter that lets a small security team assess many more vendors than it otherwise could. Used as the entire review, it produces approved software that nobody wants to use and contracts that cannot be enforced.

A vendor’s preparation checklist

If you sell into higher education and have not been asked for a HECVAT yet, you will be. Have these ready before the request arrives:

  1. HECVAT Lite completed and kept current, with the Full version available on request.
  2. A published sub-processor list with purpose, region and safeguard for each entry.
  3. A DPA with a FERPA clause ready for signature, alongside GDPR Article 28 terms and Standard Contractual Clauses if you handle EU data.
  4. A current ACR covering learner, authoring and administrative interfaces.
  5. A one-page security summary — hosting, encryption, isolation, backups, incident response, access control — for the reviewer who wants the shape of it in two minutes.
  6. An honest attestation position. If you have no SOC 2, say so, and say what would trigger starting one.

The institutions worth selling to are not looking for a vendor with no gaps. They are looking for one whose account of itself matches what they find when they check. For institutions planning a pilot alongside the review, the pilot kit runs both in parallel.

Eduspera is an accessibility-first learning platform built to sit alongside a campus LMS rather than replace it: WCAG 2.2 AA as a product requirement, a published Accessibility Conformance Report, public HECVAT answers, SAML single sign-on with InCommon metadata, SCIM provisioning and LTI 1.3 with grade passback. Institutions can start from the 12-week pilot kit, which sets out the plan, the metrics and the technical checklist your identity and data teams will work through.

Frequently asked questions

Is the HECVAT mandatory?

It is not a legal requirement, but it is close to universal practice. Most United States universities require a completed HECVAT before a cloud service can be approved, and many will not begin a contract review without one. Treat it as mandatory in practice even though no statute names it.

What is the difference between HECVAT Full and HECVAT Lite?

Scale. Full runs to several hundred questions and is used where a vendor will hold sensitive institutional or student data, or where the service is operationally critical. Lite is a much shorter subset used for lower-risk engagements and for initial qualification, and is where most first conversations start.

Does a HECVAT replace a SOC 2 report?

No. A HECVAT is the vendor’s own account of its controls; a SOC 2 is an independent auditor’s opinion on whether those controls operate. Institutions handling sensitive data often want both. A vendor without SOC 2 can still pass review, but the HECVAT answers need to be considerably more specific.

What is the Cloud Broker Index?

A community repository of completed HECVATs maintained for the higher-education sector. When a vendor is listed, a reviewer at another institution can often rely on the existing assessment rather than running a fresh one, which shortens procurement substantially for both sides.

How long does a HECVAT review take?

From a few days to a couple of months, driven almost entirely by answer quality. Specific, evidenced answers with disclosed gaps move quickly. Vague answers generate follow-up cycles, and each round trip typically costs a week. Publishing your answers publicly is the single most effective way to shorten it.