HECVAT vs SOC 2: What Your Audit Report Doesn't Cover
You finished the audit. The report is signed, the trust page is live, and then a university sends over a HECVAT workbook with a tight turnaround.
Most EdTech teams assume the SOC 2 covers it. It covers part of it, and the gap is where deals stall. Here's what your report answers, what it doesn't, and how to close the difference before the questionnaire lands.
Does a SOC 2 Type II report satisfy HECVAT?
No. HECVAT and SOC 2 are complementary documents, not substitutes.
Your SOC 2 gives an institution independently verified evidence about security controls. Your HECVAT gives it a standardized answer set it can compare across vendors, covering domains SOC 2 never examines.
| Dimension | SOC 2 Type II | HECVAT 4 |
|---|---|---|
| Who asserts it | Licensed CPA firm | You, the vendor |
| Verification | Independent attestation | Self-reported |
| Scope | The Trust Services Criteria you select | Cybersecurity, privacy, IT accessibility, compliance |
| Cost to produce | Audit fees plus tooling | Free from EDUCAUSE |
| Cadence | Observation window, commonly 3 to 12 months | Complete once per year |
| Sharing | Typically under NDA, on request | Share with any institution, unchanged |
North Carolina's Department of Public Instruction shows how buyers treat the difference. Its K-12 vendor integration process requires an approved self-assessment tool, with HECVAT Lite and CoSN's K-12CVAT among the options, and a separate third-party report under twelve months old, such as a SOC 2 Type 2 executive summary, ISO 27001, FedRAMP, or HITRUST.
Not one or the other. Both.
Working on a higher ed rollout?
Talk to our team about a procurement readiness review.
Book a Readiness Review →What changed in HECVAT 4?
HECVAT is a free vendor risk questionnaire created in 2016 by higher education leaders working with EDUCAUSE, Internet2, and REN-ISAC. Version 4 arrived on February 10, 2025, and EDUCAUSE calls it a significant change from past versions. Three changes matter most for EdTech vendors:
Full, Lite, and On-Premise merged into a single file. Screener questions at the start determine which sections apply to your product.
Questions built by the EDUCAUSE Chief Privacy Officers Community Group moved into HECVAT 4, along with a tab where a privacy analyst records input on your completed workbook.
Community volunteers built questions specifically for assessing the AI components inside a solution.
Scoring runs across three tabs: Institution Evaluation, High-Risk Evaluation, and Privacy Analyst Evaluation. Institutions set their own weights and can flag any item as non-negotiable.
One detail worth checking today: EDUCAUSE currently publishes version 4.1.6. Plenty of guidance still circulating online names 4.1.5. Submit the wrong workbook and you've handed a reviewer an easy reason to send it back.
The Silent Four: where SOC 2 stops and HECVAT keeps going
EDUCAUSE describes HECVAT as covering four areas, and your SOC 2 speaks fluently to one of them. We call the rest the Silent Four: the domains where a clean audit earns close to nothing on a HECVAT scorecard.
| Domain | What SOC 2 gives you | What actually closes it |
|---|---|---|
| IT accessibility | Nothing. There is no accessibility criterion. | Current VPAT or ACR, WCAG 2.1 AA conformance, contractual commitment |
| Privacy | Only if you scoped the optional Privacy criterion | Privacy criterion in scope, plus documented consent and deletion workflows |
| AI | Nothing directly | Documented data flows for any AI feature, and terms covering training use |
| Regulatory compliance | Security evidence that supports it, not the answer itself | FERPA-specific handling, retention, and deletion terms |
1. IT accessibility
This is the widest gap and the costliest to close late. SOC 2 has no accessibility criterion. HECVAT 4 gives accessibility a dedicated tab and weights four questions above the others by default:
- ITAC-06: Has a VPAT or ACR been created or updated for this solution and version in the past 12 months?
- ITAC-07: Will you agree to meet your stated accessibility standard, or WCAG 2.1 AA, as part of the contract?
- ITAC-08: Does the solution substantially conform to WCAG 2.1 AA?
- ITAC-09: Do you have a documented, working process for reporting and tracking accessibility issues?
The regulatory clock behind these questions moved recently. DOJ's 2024 ADA Title II rule made WCAG 2.1 AA the enforceable standard for public entities.
On April 20, 2026, the department published an interim final rule pushing compliance to April 26, 2027 for entities serving 50,000 or more people, and April 26, 2028 for smaller ones. HHS extended its parallel Section 504 date to May 11, 2027.
You gained a year. So did the institutions buying your product, and they're writing accessibility into contracts now.
2. Privacy
Only the Security criterion is required in a SOC 2 audit. Privacy is one of four optional criteria, and scoping it in adds cost, so plenty of vendors leave it out.
HECVAT 4 treats privacy as first-class regardless. A privacy analyst reviews your answers on a dedicated tab, even when the security team drove the request.
3. AI
If your platform has an AI feature, expect the screener to route you into the AI question set. A SOC 2 Processing Integrity opinion covers whether your system processes data completely and accurately.
It says nothing about where a model runs or what happens to the data you send it. Document those flows before you open the workbook, because retrofitting the answer under deadline is how vendors end up guessing.
4. Regulatory compliance
FERPA obligations sit with the institution, not with you. It has to show due diligence over any vendor touching student records, which is why retention and deletion terms get asked directly. Our FERPA and COPPA guide covers how those flow down.
How to reuse SOC 2 evidence on a HECVAT
- Answer the screeners honestly. They decide which sections you complete. Over-scoping burns weeks; under-scoping gets the workbook returned.
- Map your Common Criteria to the security questions first. Access control, encryption, incident response, and vendor management answers come straight from evidence you have.
- Attach the SOC 2 report as supporting documentation. A self-reported answer backed by an independent attestation reads differently from one standing alone.
- Close the Silent Four before you submit. Commission the VPAT, scope privacy, document AI data flows, write your deletion terms.
- Build it once, then reuse it. EDUCAUSE designed HECVAT 4 so vendors complete it annually and share the same file with every institution without edits. One workbook, built when no deal is on the clock, serves your whole higher ed pipeline for a year.
A 60-second self-check
Any hesitation here is a gap worth scheduling this quarter.
- Can you produce a VPAT or ACR for your current version, dated within 12 months?
- Would you sign a contract committing to WCAG 2.1 AA?
- Can you name every place student data touches an AI model?
- Can you state your deletion timeline on contract termination without checking?
Why does the questionnaire carry so much weight?
Because for many institutions it is the only assessment anyone runs.
An EDUCAUSE QuickPoll of 170 higher education professionals in August 2024 found 63% of institutions had no formal third-party risk management process. Respondents rated regulatory compliance important 95% of the time and data security 94%, yet only 15% said their institution regularly monitors and assesses compliance.
The implication is uncomfortable but useful. The workbook you submit during procurement is often the last word. There is rarely a second look where you correct the record.
Accessibility mattered to 78% of respondents, and 53% said their institution requires third parties to meet accessibility standards. That poll ran months before HECVAT 4 raised the default weighting on those questions.
Frequently asked questions
No law requires it. In practice, many institutions request a completed HECVAT as a standard procurement step, and some state education agencies name it in their vendor documentation requirements. Vendors without one absorb the delay of answering bespoke questionnaires from every institution instead.
Sometimes an institution accepts it for specific sections, rarely for the whole workbook. North Carolina's Department of Public Instruction requires both categories: a self-assessment tool such as HECVAT Lite, plus a third-party report such as a SOC 2 Type 2 executive summary. Ask your reviewer rather than assuming.
Plan for weeks, not days, on a first pass. Screener questions narrow the scope, and teams with a recent SOC 2 report move faster through security sections. The Silent Four stretch the timeline, and commissioning a VPAT is usually the long pole.
Yes. CoSN and SETDA publish the K-12 Community Vendor Assessment Tool, built from HECVAT Lite and aimed at districts and education service districts. It predates HECVAT 4, so it does not carry the privacy and AI question sets added in that version.
Close the gap before it costs you a quarter
A SOC 2 Type II report is worth having and worth attaching to every HECVAT you send. It was never designed to answer what a university asks about accessibility, privacy, AI, or student data rights.
Vendors who move fastest build the workbook when nothing is on the line. The ones who lose quarters start the VPAT after a reviewer asks for it.
At Hireplicity, WCAG 2.1 AA checks run inside the sprint cycle on EdTech engagements rather than at final audit, which is the difference between a VPAT you commission in weeks and a remediation project you can't.
Facing a HECVAT with gaps you can't close in time?
Talk to our team about an architecture and compliance readiness review.
Book a 30-Minute Call →- EDUCAUSE, "Higher Education Community Vendor Assessment Toolkit" (current version 4.1.6) — https://www.educause.edu/higher-education-community-vendor-assessment-toolkit
- Arbino, N. and Lewis, N., "HECVAT 4: Better than Ever," EDUCAUSE Review, February 10, 2025 — https://er.educause.edu/articles/2025/2/hecvat-4-better-than-ever
- Shachmut, K. and Struble, E., "Accessibility in Technology Acquisition with HECVAT 4," EDUCAUSE Review, April 16, 2025 — https://er.educause.edu/articles/2025/4/accessibility-in-technology-acquisition-with-hecvat-4
- Muscanell, N., "EDUCAUSE QuickPoll Results: Third-Party Risk Management Practices in Higher Education," EDUCAUSE Review, August 12, 2024 — https://er.educause.edu/articles/2024/8/educause-quickpoll-results-third-party-risk-management-practices-in-higher-education
- U.S. Department of Justice, "Extension of Compliance Dates," 91 Fed. Reg. 20902 (April 20, 2026) — https://www.federalregister.gov/documents/2026/04/20/2026-07663/
- U.S. Department of Health and Human Services, "Extension of Compliance Dates," Federal Register, May 11, 2026 — https://www.federalregister.gov/documents/2026/05/11/2026-09266/
- North Carolina Department of Public Instruction, "Third Party Data Integration" — https://www.dpi.nc.gov/about-dpi/technology-services/third-party-data-integration
- CoSN, "K-12CVAT: K-12 Community Vendor Assessment Tool" — https://www.cosn.org/tools-and-resources/resource/k-12cvat/

