Questionnaire standards

HECVAT, and what universities are actually checking

The Higher Education Community Vendor Assessment Toolkit is the assessment that colleges and universities send to software vendors. If you sell into education, it will reach you sooner or later.

In short

HECVAT is a community-maintained questionnaire coordinated through EDUCAUSE, designed so that a vendor can answer once and have many institutions accept the same file. It ships in a Full and a shortened version, plus a variant for on-premise products. Completed HECVATs are often published in a shared community broker, which means a good one can pre-empt the next request entirely.

HECVAT at a glance

Maintained throughEDUCAUSE, with the higher-education security community
VersionsA Full version, a shortened version for lower-risk purchases, and a variant for on-premise software
Typical sizeThe Full version runs to a few hundred questions; the shortened one is a fraction of that
FormatExcel workbook, multiple sheets
Who asks for itUniversities, colleges and their procurement or IT security offices
NotableCompleted HECVATs are commonly shared through a community listing, so one careful answer can serve many institutions

How the file is put together

HECVAT workbooks are built for reuse, which shows in how much of the file is guidance rather than questions.

Early tabs carry instructions, a version history and reference material for the vendor completing the file.
The question tab groups controls by area — general, data handling, access, continuity, and so on — with a question ID column first.
Answers are typically a structured response plus an explanation field.
Institutions sometimes append their own supplementary questions at the end of the sheet.

What Compliance Concierge does with a HECVAT

Instructions and version-history tabs are skipped automatically; the question tab is chosen on content.
Question IDs and grouping columns are ignored in favour of the actual question text.
Drafts cite the policy, report or certificate they came from, so the institution's reviewer can check the claim rather than take it on trust.
Controls your documents do not cover are flagged as needing evidence — which is also a useful to-do list for what to write next.
Because HECVATs are shared and reused, reviewed answers are worth keeping: the library reapplies them to the next institution's copy.

None of this certifies you. The tool drafts answers from the documents you upload, shows the evidence behind each one, and refuses to export anything a person has not signed off. Where your documents do not cover a control, it says so instead of filling the cell.

Frequently asked

Which HECVAT version should I complete?+

The one you were sent. If you are completing one proactively to publish, the Full version covers the most ground and is the most likely to be accepted without follow-up questions.

Is HECVAT only for cloud products?+

No. There is a variant intended for software installed on the institution's own infrastructure, which drops the questions about your hosting and adds ones about what you require from theirs.

Do I need to redo it for every university?+

Usually not from scratch. HECVAT exists precisely so one completed file can satisfy multiple institutions, and many are shared through a community listing. Expect to refresh anything dated — audit reports, test dates, subprocessors — rather than rewrite the whole thing.

What if a question does not apply to us?+

Say so, and say why in the explanation field. Institutions are used to seeing not-applicable answers; what generates a follow-up email is a blank cell or a bare "N/A" with nothing behind it.

Other assessments we cover: CAIQ v4, SIG & SIG Lite, VSA. For the process itself, see the guide to answering security questionnaires.

Answer your HECVAT with evidence

Upload your policies and the workbook. Every draft is cited from your own documents, and nothing leaves until you approve it. The first questionnaire is free.