Skip to content

HECVAT Penetration Testing: What EdTech Vendors Need

What the HECVAT asks about penetration testing, how EdTech vendors answer it with a current third-party test, and the evidence to send university reviewers.

Invadel TeamReviewed by Omar Khandaker, Senior Security Consultant7 min read

If you sell software to colleges and universities, expect the HECVAT before the contract. Several of its questions ask whether your product has been tested, by whom and when. A current third-party penetration test with an attestation letter answers them in one attachment. At Invadel that test is a fixed price agreed before work starts: web applications from $5,200, APIs from $4,000, with a free retest so the letter can say the serious findings are closed.

What the HECVAT is

The HECVAT (Higher Education Community Vendor Assessment Toolkit) is the security questionnaire universities send to technology vendors. It was built by the higher education security community with EDUCAUSE, Internet2 and REN-ISAC, and EDUCAUSE publishes it free of charge. Instead of writing its own questionnaire, a university sends the HECVAT, and a vendor can answer it once and reuse it.

Three recent changes matter to vendors:

  • One version. HECVAT 4, released in February 2025, rolled the old Full, Lite and On-Premise versions into a single workbook that shows the questions relevant to your product.
  • Privacy and AI. HECVAT 4 gives privacy and AI their own sections, alongside the security and accessibility questions.
  • No central library. The Community Broker Index, where vendors posted completed HECVATs for any institution to download, was retired on July 31, 2025 (REN-ISAC). Each institution now gets your current copy from you, so keep one up-to-date copy ready to send.

Download the current version from EDUCAUSE rather than reusing an old file. Question wording changes between versions.

The questions that ask about testing

The wording has changed across versions. The substance has not. HECVAT 3 Lite, for example, asked vendors:

  • whether systems and applications are scanned for vulnerabilities, and the findings fixed, before new releases;
  • whether systems and applications had a third-party security assessment completed in the last year, with the results attached if possible and the date of the last assessment;
  • whether the company has a SOC 2 (SSAE 18) audit report;
  • whether a web application firewall protects the application.

Question numbers and wording differ in HECVAT 4, so answer from the current file. Expect the same topics: vulnerability scanning, an independent assessment in the last year, and how you protect the application. Have the date of your last test and the letter ready before the questionnaire arrives.

What a scan answers, and what it does not

A vulnerability scan answers the scanning question. It is weak evidence for the third-party assessment question. A scanner export lists software versions and known vulnerabilities. It says nothing about whether a student can open another student’s records, or whether one university’s data is walled off from another’s. That is what the reviewer is worried about.

A penetration test answers the question the reviewer is actually asking: has someone independent tried to break this product? The report shows what was tested and what was found. The attestation letter proves it happened without handing over exploit detail. If you also run static analysis in your pipeline, mention it where the questionnaire asks how you build and protect the application; our guide to SAST vs DAST explains what each tool covers.

Scope the test around what universities care about

A university reviewer reads your HECVAT with its own risks in mind: single sign-on, the learning management system, and student records. Scope the test so the report speaks to those.

  • Single sign-on. Your SAML or OpenID Connect integration with the university’s identity provider. We test account linking, just-in-time provisioning and role mapping: can a student end up with instructor or administrator rights, and can one institution’s users reach another’s?
  • LTI integrations. If your tool launches from Canvas, Blackboard, Moodle or Brightspace, we test whether each launch is validated properly and whether platform roles map to the right permissions in your product.
  • Student data. Authorization between students, courses, departments and institutions, tested with accounts in every role. Student records are protected by FERPA, and universities hold vendors to that.
  • APIs. The API behind your web app and mobile apps, roster sync, grade passback and any integration endpoint. These often enforce authorization differently from the interface. See API penetration testing.
  • Admin and support tooling. The consoles your own staff use to manage customer institutions are often the most powerful and least tested part of the product.

A standard web application penetration test covers the product with accounts in every role, and a second tenant where the product serves many institutions.

What to attach to the HECVAT

  1. The attestation letter. It states what was tested, when, by whom, against which standards, and the status of the findings after the retest.
  2. The date of the last test, stated in the answer itself. The question asks for it.
  3. A shareable summary instead of the full report. Our third-party penetration testing deliverables include one written for exactly this.
  4. Retest results showing the serious findings were fixed.
  5. The full report, under NDA, only if a reviewer insists. It contains exploit detail that should not sit in a procurement inbox.

If you do not have a SOC 2 report, say so plainly. A penetration test does not replace one. It is, however, evidence your SOC 2 auditor will want later, so the work counts twice. Our SOC 2 page covers what auditors expect.

Timing against a procurement deadline

The security review is often the last step before a university signs. Plan backward from that date.

  • Onboarding begins within 24 hours of a signed proposal.
  • Testing typically starts within a week of scoping, and a standard scope takes about a week of hands-on testing, followed by the report.
  • Fixes are on your side. The free retest follows as soon as they ship.
  • The attestation letter comes with the report and is updated after the retest to show the serious findings closed.

Tell us the deadline during scoping and we will schedule around it, with room for your fixes and the retest before the date.

Why SSO matters on campus

Single sign-on is the key to almost everything on a campus. In a credential-harvesting phishing engagement for a private university, our campaign reached inboxes and captured staff SSO credentials, including those of several senior staff. The full write-up is on our case studies page. A vendor integration that trusts SSO assertions loosely makes a stolen campus login worth even more, which is why the SSO section of your test matters.

If you are the institution

Colleges and universities that take part in federal student aid programs agree to comply with the FTC Safeguards Rule (16 CFR Part 314). That is a separate duty from reviewing vendors. Our FTC Safeguards Rule page covers what it asks of the institution itself.

Frequently asked questions

Does the HECVAT require a penetration test? It asks whether your product had a third-party security assessment in the last year and asks for the results and the date. A current penetration test is the clearest way to answer yes.

Is a vulnerability scan enough for the HECVAT? It answers the scanning question. For the third-party assessment question, a scan shows known vulnerabilities, not whether your access controls hold. A penetration test answers the question a reviewer is actually asking.

What is the difference between HECVAT Lite and Full? In HECVAT 4 there is no longer a separate Lite or Full version. One workbook replaced the Full, Lite and On-Premise versions.

How often should an EdTech vendor test? At least once a year, so the “last year” answer stays true, and again after major releases or new integrations.

What does a HECVAT-ready test cost? At Invadel, web application testing starts at $5,200 and API testing at $4,000, each at a fixed price with a free retest and an attestation letter.

Fixed price, fixed scope, free retest. Our sample report shows the deliverable. Scope your test and get a written price within one business day.

Written by

Invadel Team

Senior penetration testers writing from real engagements, the same team that scopes, tests, and reports for our clients. About Invadel →

Find out what an attacker sees.

Tell us what to test and see your fixed price.

Prefer the full scoping questionnaire? 
Start the conversation