VPAT and HECVAT Documentation Requirements

VPAT and HECVAT Documentation Requirements

Quick Access: Vendor Request Template

If you are requesting software that is not already approved for use at ACC, you must request accessibility and security documentation from the vendor before the request can move forward.

Use the vendor request template link below to contact your vendor:

  • HECVAT and VPAT vendor request template

  • Follow the instructions before contacting the vendor.

Overview

ACC reviews new software for accessibility and information security before it can be approved for use.

When software is not already approved, vendors are asked to provide documentation that helps the college understand:

  • how the product supports accessibility standards

  • how the vendor manages security and data protection

This documentation includes a VPAT and, when applicable, a HECVAT.

What Is a VPAT?

A VPAT (Voluntary Product Accessibility Template) is a standardized document completed by a software vendor that explains how a product aligns with recognized accessibility standards such as WCAG and Section 508.

At ACC, VPATs are used as part of the accessibility review process to:

  • understand how a product supports users with disabilities

  • identify known accessibility limitations or gaps

  • determine whether accommodations or alternate accessible solutions may be necessary based on how the software will be used

A VPAT does not certify that a product is fully accessible. It provides vendor-reported information that supports the college’s review and decision-making process.

Because Colorado public institutions are expected to ensure digital technology is accessible, VPATs are one of the primary tools ACC uses to evaluate whether a product can reasonably support those expectations.

Reference links:

What Is a HECVAT?

The HECVAT (Higher Education Community Vendor Assessment Toolkit) is a standardized security assessment used across higher education. It is completed by vendors to describe their:

  • information security practices

  • data protection and privacy controls

  • approaches to managing security risk

At ACC, a HECVAT is typically required when software:

  • stores, processes, or transmits institutional data

  • integrates with campus systems or services

A completed HECVAT does not automatically indicate approval. It provides information that supports security review and helps determine whether additional questions, safeguards, or conditions are needed.

Reference links:

Why This Documentation Is Required

Software used at ACC may support instruction, services, or job duties and may interact with institutional systems or data. Because of this, accessibility and security review is required before software can be approved.

VPAT and HECVAT documentation helps the college:

  • review accessibility alignment using recognized standards

  • understand vendor security and data protection practices

  • identify potential risks early

  • make informed procurement decisions that balance business needs with accessibility and security expectations

Requiring this documentation before approval reduces avoidable risk and helps ensure technology is appropriate for campus use.

Why Requestors Are Asked to Request the Documentation

Vendors are the authoritative source for VPAT and HECVAT documentation. For that reason, software requestors are asked to contact the vendor directly and request the documents.

Most vendors serving higher education are familiar with these requests. The provided email templates are designed to clearly explain what documentation is needed and reduce follow-up questions.

When you receive the completed VPAT and/or HECVAT documentation from the vendor, return to the Software procurement request form and upload the documents so the request can proceed.

You are not responsible for reviewing the documents. Your responsibility is to request and submit them for review.

If a Vendor Cannot Provide VPAT or HECVAT

In some cases, a vendor may be unable or unwilling to provide the required documentation. In these situations:

  • requests will not proceed without required documentation.

  • you may be required to identify alternative software options that meet accessibility and security expectations

These situations are reviewed carefully and may include conditions or limitations if approved.

What Happens After the Documents Are Submitted

Once the VPAT and/or HECVAT documentation is uploaded to the Software procurement request form:

  • the documentation is reviewed for completeness and relevance

  • accessibility and security reviewers evaluate the information provided

  • additional clarification may be requested if needed

  • a decision is made to approve, conditionally approve or deny

Important Timeline Consideration

The software procurement process involves several required reviews and approvals. Depending on the nature of the request and vendor responsiveness, the full review process may take up to 6–8 weeks after submission of complete and accurate information. Processing time may be extended if additional information or revisions are needed.

Key Takeaway

If software is not already approved for use at ACC, VPAT and HECVAT documentation is required before the request can move forward. These documents support accessibility, security, and responsible technology use across the college.