HECVAT 4.1.6: 310 Questions, 15 Tabs, and 4 You Must Not Touch
If you sell software to a university, HECVAT is the questionnaire you will meet. It is the Higher Education Community Vendor Assessment Toolkit, it is maintained by the higher education community through EDUCAUSE, and institutions send it instead of writing their own.
The numbers below are measured from HECVAT 4.1.6 by parsing the workbook, not recalled. If you have the file open, you can check every one.
What is actually in it
310 questions, across 15 tabs. Eight of those tabs are yours to complete:
START HERE, Organization, Product, Infrastructure, IT Accessibility, Case-Specific, AI, and Privacy.
The rest are not. Institution Evaluation, High-Risk Evaluation and Privacy Analyst Evaluation are for the institution assessing you. Analyst Reference is reference material. There are also Questions, Auto Responses and a scoring tab that drive the workbook's own logic.
The instruction most vendors miss
This is not our interpretation. It is item 4 of the instructions on HECVAT's own START HERE tab:
DO NOT complete any fields in the "Evaluation" sheets or the "Analyst Notes" column.
Those sheets look exactly like the ones you are supposed to fill in. They have questions in a column and an empty column beside them. A vendor working through the file tab by tab, trying to be thorough, will fill them in, and every hour spent on them is wasted at best. At worst you have written into the space the reviewer uses to score you.
Three more things the file tells you and the covering email usually does not
A blank answer needs a reason. Item 3: "If leaving an answer blank, you must also state why in 'Additional Information'." Blank is permitted. Blank and silent is not. This matters more than it sounds, because the honest answer to a good number of HECVAT questions is that your documentation does not cover it, and the file gives you a sanctioned way to say so.
An asterisk means critical. The file says starred questions are "those deemed most important to institutions by higher education volunteers." If you are triaging 310 questions with a deadline, that is the triage, already done for you.
Not every tab applies. Item 1 points you at the "Required Questions" guidance to work out which sections your product actually needs. Answering sections that do not apply is the other common way to spend a day for nothing.
There is an accessibility tab, and it is not a mistake
IT Accessibility sits between Infrastructure and Case-Specific, inside a security questionnaire, and it catches vendors out.
It is structural rather than accidental. In higher education and government, one procurement office sends one file, so accessibility obligations ride along with the security ones. We found the same thing measuring our whole corpus: across 146 real questionnaires, accessibility appears in 56 questions, more often than DDoS protection or data subject rights, and no security policy you own can answer any of them. What answers them is a VPAT, and that is its own problem.
There is an AI tab too, which is newer and which most vendors have nothing written down about at all.
What the 310 questions are about
Counted by topic across the questions HECVAT asks you, most common first: Business Associate Agreements and HIPAA (11), single sign-on and SAML (9), backup and restore (8), AI and customer data (8), privacy notices (5).
That HIPAA sits at the top of a higher education questionnaire surprises people. Universities run medical centres, student health services and research involving human subjects, so protected health information is genuinely in scope for a great many campus purchases. It is a contract question rather than a security one, and the answer is whether you will sign a BAA.
If you want to check any of this
Open the file and count. That is the point of publishing measured numbers rather than remembered ones, and it is the same discipline we hold our product to: every answer it writes cites the passage it came from, and a question your documents do not support gets left blank with the reason beside it, which is exactly the form HECVAT asks for.
You can also drop the file into our analyser. It will tell you the question count, which tabs carry questions, which ones are for the institution rather than you, and what the whole thing is asking about. It needs no account, calls no model, and keeps nothing.