This RFP is currently open for proposals.
Sign up for an account to get RFPs matching your business in your inbox.
Higher Education Community Vendor Assessment Toolkit Implementation
7/10/2025
-
-
Educause
Buyer provides a toolkit for higher education institutions to assess vendor security and privacy controls. The Higher Education Community Vendor Assessment Toolkit (HECVAT) standardizes security assessments for cloud services used by educational institutions. It helps institutions ensure vendor services are appropriately assessed for security and privacy requirements while reducing the burden on service providers responding to multiple assessment requests. The toolkit includes various assessment types including Full, Lite, and On-Premise versions.
- 7/10/2025 - Proposal Due Date
Refer to RFP
- Complete HECVAT-Lite questionnaire for higher education institutions
- Document information security policies and procedures
- Provide evidence of SOC 2 compliance
- Demonstrate secure data handling practices
- Provide system architecture diagrams with data flow
- Implement single sign-on capabilities
- Submit accessibility documentation including VPAT
- Detail business continuity and disaster recovery plans
- Document third-party security assessment procedures
- Provide incident response plan documentation
- Implement role-based access controls
- Demonstrate data encryption capabilities in transit and at rest
- Document security vulnerability scanning processes
- Detail physical security controls for data centers
- Provide network segmentation implementation details
- Document employee onboarding and offboarding procedures
- Detail software supply chain management procedures
- Demonstrate multi-factor authentication capabilities
- Document data backup and recovery procedures
- Provide audit logging capabilities