Vendor guide
How to complete a HECVAT
A university sent you the Higher Education Community Vendor Assessment Toolkit and someone on your side has to fill it in. This is the order to do it in, written for the solution provider rather than for the institution scoring you. If you want the background first, start with what HECVAT is and who asks for it.The workbook itself comes from EDUCAUSE, which publishes and owns it. Download it from the EDUCAUSE toolkit page if the institution did not attach a copy.The eight steps, in order
- Step 1
Confirm you were sent the current workbook
Open the file before you plan anything. EDUCAUSE announced that HECVAT 4 launched in January 2025 and rolls the HECVAT Full, Lite and On-Prem into one file, so a request that still asks you to pick Lite or Full is running on older guidance. If the workbook you received is one of the retired editions, ask the institution whether it wants HECVAT 4 instead of quietly answering the old one, because your answers will not transfer cleanly later. - Step 2
Answer the scoping questions before anything else
HECVAT 4 opens with questions that decide the rest of the assessment. EDUCAUSE describes solution providers starting by answering questions that guide them to the questions that apply to their solution, which alleviates the confusion about which version to complete. Get these wrong and you either answer hundreds of rows that never applied to you, or you hide the rows the reviewer was waiting for. This is the highest-leverage ten minutes in the whole file. - Step 3
Split the workbook by who actually knows the answer
EDUCAUSE advises that HECVAT questions be answered by whoever has the most complete knowledge of the product, and notes the questionnaire may pass between several people to accurately answer the cybersecurity, infrastructure, privacy and IT accessibility questions. Assign those four areas by name on day one. The delay on a HECVAT is almost never the typing, it is a row sitting unowned while everyone assumes someone else has it. - Step 4
Answer from a document you can hand over
Every claim you make is a claim a security reviewer can ask you to evidence. Answer from the policy, the audit report or the architecture note that already says it, and keep the pointer next to the answer while you write. If a question asks for something you have not built yet, say so plainly and say what you do instead, rather than writing a sentence that reads like a yes. - Step 5
Treat the non-negotiable rows as the real exam
The workbook scores you. EDUCAUSE describes Institution Evaluation tabs that let a reviewer choose which categories to include in a score, mark items as non-negotiable so they collect into their own tab, and see a high risk score for a lighter evaluation. You will not know which rows the institution marked, so the safe assumption is that any answer you would be embarrassed to defend on a call is one of them. - Step 6
Return it as Excel, and only as Excel
EDUCAUSE is explicit that a completed assessment should always be shared as an Excel file, because saving it in another format renders it inoperable by the institution. Exporting to PDF, pasting the answers into an email, or rebuilding the workbook in another tool all break the tabs the reviewer scores you in. Send back the same file, filled in. - Step 7
Read the Analyst Notes when it comes back
A returned HECVAT is not a rejection, it is a worklist. EDUCAUSE describes an Analyst Notes column whose entries populate back to the appropriate solution provider tab, so the institution can send the workbook back for more information and you can see exactly which rows it wants improved. Answer those rows in the same file rather than starting a new thread. - Step 8
Plan the refresh before you close the file
EDUCAUSE advises solution providers to update their HECVAT at least once per year. Write the answers somewhere reusable now, while the reasoning is fresh, so the annual refresh and the next institution are both a review rather than a rebuild. Wolfia exists because that step is the one everybody skips.
Doing it with Wolfia instead
Steps three through five are the ones that consume a week. Wolfia reads the workbook, drafts an answer for every applicable row from the documentation you already have, and cites the source behind each answer so the person reviewing it can check the claim instead of re-deriving it. The file that comes out is the same Excel file that went in, which is what the institution needs.The Questionnaire Agent handles the workbook, the Knowledge Base Agent keeps the underlying answers current for the annual refresh, and the Chrome Extension Agent covers the institutions that route their assessment through a procurement portal rather than an attachment.Questions that come up mid-workbook
Do I still choose between HECVAT Lite and HECVAT Full?
No. EDUCAUSE announced that HECVAT 4, which launched in January 2025, rolls the HECVAT Full, Lite and On-Prem into one file, and that solution providers start by answering questions that guide them to the questions that apply to their solution. The scoping questions at the front of the workbook do the job that choosing a version used to do.Who inside my company should answer the HECVAT?
EDUCAUSE advises that the questions be answered by whoever has the most complete knowledge of the product, and notes that this may mean the questionnaire passes between several people to accurately answer the cybersecurity, infrastructure, privacy and IT accessibility questions. In practice that is security, infrastructure or platform engineering, privacy or legal, and whoever owns accessibility conformance.Can I send the completed HECVAT back as a PDF?
No. EDUCAUSE states that when sharing completed assessments the file should always be shared as an Excel file, because saving it in another format renders it inoperable by the institution. Return the workbook in the format you received it.What happens if the institution sends the workbook back?
It is asking for more detail on specific rows. EDUCAUSE describes an Analyst Notes column that populates back to the appropriate solution provider tab, so a returned HECVAT shows you the reviewer notes inline and you can add the information they asked for in the same file.How often do I have to redo it?
EDUCAUSE advises solution providers to update their HECVAT at least once per year. Treat the completed workbook as a snapshot of a knowledge base you keep current, not as the record of truth itself.Related reading
Security questionnaires: the complete guide
Where HECVAT sits next to SIG, CAIQ and the custom assessments a buyer writes itself, and the general response playbook HECVAT is one instance of.How long a 200-question security questionnaire takes
Where the calendar time actually goes on an assessment the size of a HECVAT, and which parts compress.When a questionnaire asks for evidence you lack
How to answer a row you cannot evidence yet without writing something the reviewer will later call a misrepresentation.Build a questionnaire knowledge base that maintains itself
The step that turns the annual HECVAT refresh into a review instead of a rewrite.What an inaccurate questionnaire answer costs
Why a HECVAT row answered from memory rather than from evidence is the one a buyer comes back to.Sources
Every instruction above that describes the toolkit itself comes from EDUCAUSE, which publishes and owns HECVAT. The workbook is downloaded from EDUCAUSE, not from this page.Get started
Ready to automate?
Upload your documentation. AI does the work.
Respond 10x faster with unlimited seats and outcome-based pricing.