The HECVAT (Higher Education Community Vendor Assessment Toolkit) is a free, standardized security questionnaire that colleges and universities send to technology vendors. Created in 2016 by the higher education community with EDUCAUSE, Internet2, and REN-ISAC, it covers cybersecurity, privacy, IT accessibility, and compliance in a single workbook a vendor completes once a year.
Higher education runs on shared trust. A single university may buy from hundreds of software vendors, and each one touches student records, research data, or payment systems. Rather than have every campus write its own questionnaire, the community agreed on one. If you sell into colleges and universities, a HECVAT will land in your inbox, and how quickly you return it shapes how quickly the deal moves.

HECVAT vs SIG vs CAIQ: how the questionnaires differ
Most vendors selling into regulated buyers eventually field all three. They overlap heavily on controls but differ on who maintains them, who sends them, and how portable a completed response is.
| DIMENSION | HECVAT | SIG | CAIQ |
|---|---|---|---|
| Maintained by | EDUCAUSE with Internet2 and REN-ISAC | Shared Assessments | Cloud Security Alliance |
| Who sends it | Colleges and universities | Enterprise third-party risk teams | Cloud service buyers |
| Scope | Security, privacy, IT accessibility, and AI | Broad risk domains across the vendor lifecycle | Cloud controls mapped to the CCM |
| Current format | One Excel workbook with scoping questions that route you | Excel workbook, Core and Lite versions | Excel workbook aligned to CCM domains |
| Cost to the vendor | Free, no license required | Access through Shared Assessments | Free download from CSA |
| Reuse across buyers | Complete once a year and share unchanged | Usually re-scoped per buyer | Publishable to the STAR Registry |
The practical difference is reuse. EDUCAUSE designs the HECVAT so a vendor fills it out once a year and shares the same file with any institution that asks, without edits. That makes it closer to a published trust artifact than a one-off buyer request. If you already maintain answers for the SIG questionnaire or the CAIQ, most of the underlying evidence carries over. The work is mapping it, not rewriting it.
What changed in HECVAT 4
HECVAT 4 launched in February 2025 and is the version institutions now expect. EDUCAUSE maintains the current file and publishes an issue tracker of changes between releases. Three changes from the HECVAT 4 announcement matter most to a response team:
- One file instead of three. Full, Lite, and On-Premise were rolled into a single workbook. Vendors answer a short set of scoping questions first, and the workbook routes them to the sections that actually apply.
- AI and privacy questions. Community volunteers added a dedicated AI question set so institutions can assess how a product uses machine learning and generative models, alongside privacy questions originally built by the Chief Privacy Officers Community Group and a tab for a privacy analyst to weigh in.
- Institution-side scoring controls. Reviewers can choose which categories count toward a score, flag individual items as non-negotiable, and run a lighter high-risk-only evaluation instead of scoring the whole file.
The AI section is the one most likely to catch a vendor out. Questions about model training data, retention inside AI features, and whether a human reviews model output are now standard, and answering them well takes input from engineering and legal, not just the security team. Teams that have already built defensible positions on private AI architecture will find this section far less painful than teams improvising it.
What a HECVAT response actually has to prove
Reviewers are not scoring your prose. They are checking whether documented controls exist and whether your answers hold up against the evidence you attach. Expect to cover:
- Data handling: where institutional data lives, how tenants are segregated, encryption in transit and at rest, retention, and deletion on termination
- Access control and authentication, including federated single sign-on, which higher education cares about more than most buyer segments
- Subprocessors and fourth-party dependencies, named rather than described in general terms
- Business continuity, disaster recovery, and incident response, including your breach notification timeline
- Independent assurance: a SOC 2 Type II report, ISO 27001 certificate, or a recent penetration test summary
- IT accessibility, typically evidenced with a VPAT or a WCAG conformance statement
- How artificial intelligence is used in the product, and what institutional data it touches
How to respond to a HECVAT faster

- Scope honestly at the start. The routing questions decide which sections you inherit. Over-scoping buries you in questions that do not apply. Under-scoping gets the file returned.
- Assign by section, not by file. Infrastructure, application security, privacy, accessibility, and AI belong to different owners. One person holding the whole workbook is the single biggest cause of a stalled response.
- Answer from an approved library, not from memory. Every control question you face has almost certainly been answered before, in a SIG, a CAIQ, or a customer security review.
- Attach current evidence, and version it. An expired SOC 2 or a two-year-old pen test undermines otherwise strong answers.
- Review across tabs before you send. Contradictions between the privacy section and the data handling section are what trigger follow-up rounds.
- Refresh on a calendar, not on request. A HECVAT is good for a year and shareable across institutions, so treat it as a maintained artifact with named review owners.
When a HECVAT drags on, the cause is usually structural rather than technical. These are the patterns worth watching for:
| SYMPTOM | ROOT CAUSE | FIX |
|---|---|---|
| The same question is answered differently across deals | Answers live in old email threads and past files | Keep one approved answer per control in a central library |
| The response sits for weeks waiting on experts | The whole workbook is assigned to one owner | Assign by section, with named owners and due dates |
| The reviewer sends the file back for clarification | Answers assert a control but attach no evidence | Link each control answer to the current policy or report |
| Answers go stale between renewals | Refresh only happens when a buyer asks | Schedule an annual refresh with review owners |
| The AI section takes longer than everything else | No agreed position on model training and data use | Draft and approve AI answers once, before the next request |
Treat your HECVAT answers as institutional knowledge
The vendors who answer fastest are not the ones with the best writers. They are the ones who stopped treating each questionnaire as a writing project and started treating approved answers as a knowledge base. That idea is not new. The Consortium for Service Innovation formalized it as Knowledge-Centered Service (KCS), a methodology built on a simple loop: capture knowledge inside the workflow that uses it, reuse it, and improve it as you go rather than rebuilding it each time. The consortium's knowledge base practices describe how organizations structure that loop in practice.

Applied to security questionnaires, that means every HECVAT answer you approve should land back in a content library where it is owned, dated, and reusable. Do that consistently and the next HECVAT, SIG, or CAIQ starts mostly complete instead of blank. The first one is a project. The tenth should be a review.
RocketDocs was built for exactly this work: multi-tab Excel questionnaires, routing to the right experts, approval trails an auditor can follow, and an answer library that keeps the same claim consistent across every buyer. See how the platform handles security questionnaires, or book a demo to walk a HECVAT through it end to end.
Looking for the platform behind this? See the RocketDocs platform or book a demo.