HECVAT Explained

What is HECVAT?

The Higher Education Community Vendor Assessment Toolkit (HECVAT) provides a comprehensive framework for assessing vendor security and compliance. Explore the different assessment areas that help institutions evaluate vendor risk.

Explore the framework

Explore the areas of the HECVAT assessment

Organization

This tab focuses on the vendor organization's governance, documentation, and operational maturity.

It covers business continuity planning, disaster recovery capabilities, and compliance with audit standards like SOC 2.

Questions examine security framework conformance, architecture documentation, privacy policies, and employee onboarding/offboarding procedures.

The tab also addresses third-party risk management, including security assessments and contractual protections.

Product

This tab evaluates the security features and data handling capabilities built into the product itself.

It focuses on authentication methods including SSO support, password policies, and participation in trust federations like InCommon.

Questions address authorization controls, audit logging, and whether passwords are securely stored rather than hard-coded or in plaintext.

The tab examines how the product manages user accounts, enforces access controls, and maintains security audit trails.

Infrastructure

This tab examines the technical security architecture and infrastructure controls of the solution.

It covers cloud-based offerings, network security components like web application firewalls and intrusion detection systems, and vulnerability management practices.

Questions address access controls, operating system currency, code security testing, and datacenter security measures.

The tab also explores incident handling procedures and separation of duties for security administration.

IT Accessibility

This tab evaluates the accessibility features and compliance of the solution's interface for users with disabilities.

It focuses on adherence to WCAG 2.1 AA standards and the availability of Voluntary Product Accessibility Templates (VPAT) or Accessibility Conformance Reports (ACR).

Questions address the vendor's commitment to maintaining accessibility standards through contractual agreements.

The tab also covers the vendor's processes for reporting, tracking, and resolving accessibility issues.

Case-Specific

This tab addresses specialized compliance requirements and deployment scenarios specific to particular use cases.

It covers HIPAA compliance for protected health information, PCI DSS standards for payment card data, and consulting services arrangements.

Questions examine whether the solution requires on-premises appliances, consultant access to institutional networks, and data handling training for sensitive information.

AI

This tab focuses on artificial intelligence features and capabilities within the solution, including machine learning and large language models.

It covers AI risk management, responsible AI training, and governance policies for AI implementation.

Questions address how AI features can be controlled, disabled, and monitored for security risks.

The tab also examines data protection measures to prevent sensitive information from being ingested by AI models.

Privacy

This tab comprehensively addresses data privacy requirements across multiple regulatory frameworks including FERPA, GDPR, PIPL, CCPA, and HIPAA.

It examines how the solution processes personal and institutional data, including AI-related privacy considerations.

Questions cover employee work locations, data residency, privacy notices, and privacy-specific policies and procedures.

The tab also addresses privacy change management and the handling of sensitive data by third parties.

What you need to know

Community-Developed by Higher Education Leaders

HECVAT was created by leaders in higher education in collaboration with EDUCAUSE, Internet2, and REN-ISAC . EDUCAUSE serves as the hosting organization with copyright ownership , but the questionnaire content is developed and maintained by security professionals from participating colleges and universities through volunteer working groups, making it truly community-driven.

Major Evolution from Version 3 to Version 4

HECVAT 4 rolls Full, Lite, and On-Prem into one unified file , streamlining vendor assessments. Version 4 includes new AI-specific questions and privacy questions developed by a higher education privacy working group . The redesign eliminates redundant questions and introduces customizable institution evaluation tabs, allowing schools to tailor assessments to their specific risk requirements.

Nine Years of Continuous Improvement Since 2016

First released in 2016 , HECVAT has evolved significantly. In 2019, "Cloud" became "Community" to reflect its broader scope . Version 3.0 in 2021 brought major question revisions and accessibility focus. HECVAT 4, launched in early 2025 , represents the most comprehensive update with enhanced privacy frameworks and AI evaluation capabilities addressing modern security challenges.

Expanding Beyond Higher Education

While designed specifically for colleges and universities, K-12 school districts have adapted HECVAT through the K-12CVAT tool based on HECVAT Lite . Research institutions and some educational nonprofits have also adopted it. The standardized framework appeals to educational organizations needing efficient vendor risk management without developing custom questionnaires from scratch.

Complementary to SOC 2 and ISO 27001

HECVAT covers many of the same security questions as SOC 2, NIST, and ISO frameworks about encryption, backups, and security controls . While SOC 2 requires third-party validation and ISO 27001 provides certification, HECVAT is a self-assessment focused on higher education requirements. Vendors with these certifications still complete HECVAT to address institution-specific concerns like FERPA compliance.

Free and Openly Available to All

EDUCAUSE makes HECVAT 4 available to colleges and universities at no cost without further license . Institutions may modify it to suit their nonprofit needs and missions. Vendors may use HECVAT 4 in connection with their college and university business relationships at no cost . This free, open approach has driven widespread adoption with over 180 institutions and nearly 200 vendor products assessed.