VPAT and HECVAT Documentation Requirements
Quick Access: Vendor Request Template
If you are requesting software that is not already approved for use at ACC, you must request accessibility and security documentation from the vendor before the request can move forward.
Use the vendor request template link below to contact your vendor:
Follow the instructions before contacting the vendor.
Overview
ACC reviews new software for accessibility and information security before it can be approved for use.
When software is not already approved, vendors are asked to provide documentation that helps the college understand:
how the product supports accessibility standards
how the vendor manages security and data protection
This documentation includes a VPAT and, when applicable, a HECVAT.
What Is a VPAT?
A VPAT (Voluntary Product Accessibility Template) is a standardized document completed by a software vendor that explains how a product aligns with recognized accessibility standards such as WCAG and Section 508.
At ACC, VPATs are used as part of the accessibility review process to:
understand how a product supports users with disabilities
identify known accessibility limitations or gaps
determine whether accommodations or alternate accessible solutions may be necessary based on how the software will be used
A VPAT does not certify that a product is fully accessible. It provides vendor-reported information that supports the college’s review and decision-making process.
Because Colorado public institutions are expected to ensure digital technology is accessible, VPATs are one of the primary tools ACC uses to evaluate whether a product can reasonably support those expectations.
Reference links:
Information Technology Industry Council (ITI) – VPAT overview and templates
Section508.gov – VPAT / Accessibility Conformance Report FAQ
What Is a HECVAT?
The HECVAT (Higher Education Community Vendor Assessment Toolkit) is a standardized security assessment used across higher education. It is completed by vendors to describe their:
information security practices
data protection and privacy controls
approaches to managing security risk
At ACC, a HECVAT is typically required when software:
stores, processes, or transmits institutional data
integrates with campus systems or services
A completed HECVAT does not automatically indicate approval. It provides information that supports security review and helps determine whether additional questions, safeguards, or conditions are needed.
Reference links:
EDUCAUSE – Higher Education Community Vendor Assessment Toolkit Official Site
EDUCAUSE – HECVAT FAQs for Higher Education
Why This Documentation Is Required
Software used at ACC may support instruction, services, or job duties and may interact with institutional systems or data. Because of this, accessibility and security review is required before software can be approved.
VPAT and HECVAT documentation helps the college:
review accessibility alignment using recognized standards
understand vendor security and data protection practices
identify potential risks early
make informed procurement decisions that balance business needs with accessibility and security expectations
Requiring this documentation before approval reduces avoidable risk and helps ensure technology is appropriate for campus use.
Why Requestors Are Asked to Request the Documentation
Vendors are the authoritative source for VPAT and HECVAT documentation. For that reason, software requestors are asked to contact the vendor directly and request the documents.
Most vendors serving higher education are familiar with these requests. The provided email templates are designed to clearly explain what documentation is needed and reduce follow-up questions.
When you receive the completed VPAT and/or HECVAT documentation from the vendor, return to the Software procurement request form and upload the documents so the request can proceed.
You are not responsible for reviewing the documents. Your responsibility is to request and submit them for review.
If a Vendor Cannot Provide VPAT or HECVAT
In some cases, a vendor may be unable or unwilling to provide the required documentation. In these situations:
requests will not proceed without required documentation.
you may be required to identify alternative software options that meet accessibility and security expectations
These situations are reviewed carefully and may include conditions or limitations if approved.
What Happens After the Documents Are Submitted
Once the VPAT and/or HECVAT documentation is uploaded to the Software procurement request form:
the documentation is reviewed for completeness and relevance
accessibility and security reviewers evaluate the information provided
additional clarification may be requested if needed
a decision is made to approve, conditionally approve or deny
Important Timeline Consideration
The software procurement process involves several required reviews and approvals. Depending on the nature of the request and vendor responsiveness, the full review process may take up to 6–8 weeks after submission of complete and accurate information. Processing time may be extended if additional information or revisions are needed.
Key Takeaway
If software is not already approved for use at ACC, VPAT and HECVAT documentation is required before the request can move forward. These documents support accessibility, security, and responsible technology use across the college.