What is HECVAT?
The Higher Education Community Vendor Assessment Toolkit (HECVAT) provides a comprehensive framework for assessing vendor security and compliance. Explore the different assessment areas that help institutions evaluate vendor risk.
How your company runs security, not just how your product does. Covers governance, business continuity, SOC 2 and audit compliance, plus how you vet and manage your own third parties.
The security built into the product itself. Covers authentication and SSO, password handling, access controls, account management and audit logging.
The technical foundations underneath the product. Covers cloud and network security, vulnerability management, code security testing, datacenter controls and how incidents get handled.
Whether the product works for users with disabilities. Covers WCAG 2.1 AA conformance, VPAT and ACR documentation, and how accessibility issues get reported and fixed.
Requirements that only apply in certain situations. Covers HIPAA for health data, PCI DSS for payment cards, on-premises deployments and consultant access to your network.
How AI features are governed and controlled. Covers AI risk management, whether features can be disabled and monitored, and how sensitive data is kept out of AI models.
How personal data is processed and protected. Covers GDPR, CCPA, FERPA and other frameworks, plus data residency, privacy notices and third-party data handling.
What you need to know
Community-Developed by Higher Education Leaders
HECVAT was created by leaders in higher education in collaboration with EDUCAUSE, Internet2, and REN-ISAC. EDUCAUSE serves as the hosting organization with copyright ownership, but the questionnaire content is developed and maintained by security professionals from participating colleges and universities through volunteer working groups, making it truly community-driven.
Major Evolution from Version 3 to Version 4
HECVAT 4 rolls Full, Lite, and On-Prem into one unified file, streamlining vendor assessments. Version 4 includes new AI-specific questions and privacy questions developed by a higher education privacy working group. The redesign eliminates redundant questions and introduces customizable institution evaluation tabs, allowing schools to tailor assessments to their specific risk requirements.
Nine Years of Continuous Improvement Since 2016
First released in 2016, HECVAT has evolved significantly. In 2019, "Cloud" became "Community" to reflect its broader scope. Version 3.0 in 2021 brought major question revisions and accessibility focus. HECVAT 4, launched in early 2025, represents the most comprehensive update with enhanced privacy frameworks and AI evaluation capabilities addressing modern security challenges.
Expanding Beyond Higher Education
While designed specifically for colleges and universities, K-12 school districts have adapted HECVAT through the K-12CVAT tool based on HECVAT Lite. Research institutions and some educational nonprofits have also adopted it. The standardized framework appeals to educational organizations needing efficient vendor risk management without developing custom questionnaires from scratch.
Complementary to SOC 2 and ISO 27001
HECVAT covers many of the same security questions as SOC 2, NIST, and ISO frameworks about encryption, backups, and security controls. While SOC 2 requires third-party validation and ISO 27001 provides certification, HECVAT is a self-assessment focused on higher education requirements. Vendors with these certifications still complete HECVAT to address institution-specific concerns like FERPA compliance.
Free and Openly Available to All
EDUCAUSE makes HECVAT 4 available to colleges and universities at no cost without further license. Institutions may modify it to suit their nonprofit needs and missions. Vendors may use HECVAT 4 in connection with their college and university business relationships at no cost. This free, open approach has driven widespread adoption with over 180 institutions and nearly 200 vendor products assessed.