Skip to main content

Reference

HECVAT IT Accessibility

HECVAT is the security and compliance questionnaire US universities send to software vendors, developed by EDUCAUSE. Version 4 gives accessibility its own tab: 18 questions, numbered ITAC-01 to ITAC-18, asking who your accessibility contact is, whether you have a current VPAT, how conformant the product is, and whether anyone independent has checked. It usually arrives alongside a request for the VPAT itself.

Last reviewed September 2026

The questions

Four of these carry the heaviest weight in scoring — ITAC-06 through ITAC-09 — because they are the ones that reveal whether accessibility is a practice or a document.

  1. ITAC-01Solution Provider Accessibility Contact Name

  2. ITAC-02Solution Provider Accessibility Contact Title

  3. ITAC-03Solution Provider Accessibility Contact Email

  4. ITAC-04Solution Provider Accessibility Contact Phone Number

  5. ITAC-05Web Link to Accessibility Statement or VPAT

  6. ITAC-06Has a VPAT or ACR been created or updated for the solution and version under consideration within the past 12 months?

  7. ITAC-07Will your company agree to meet your stated accessibility standard or WCAG 2.1 AA as part of your contractual agreement for the solution?

    This is a contractual commitment, not a technical fact. Do not answer yes on the vendor's behalf — surface it for a human decision.

  8. ITAC-08Does the solution substantially conform to WCAG 2.1 AA?

    Answer from the conformance table. 'Substantially' is a judgement: say what the table shows, including the criteria that only partially support.

  9. ITAC-09Do you have a documented and implemented process for reporting and tracking accessibility issues?

  10. ITAC-10Do you have documentation to support the accessibility features of your solution?

  11. ITAC-11Has a third-party expert conducted an audit of the most recent version of your solution?

    Affido is not a third-party expert audit. If no independent auditor has reviewed the product, the answer is no — say so and describe what was done instead.

  12. ITAC-12Do you have a documented and implemented process for verifying accessibility conformance?

  13. ITAC-13Have you adopted a technical or legal standard of conformance for the solution?

  14. ITAC-14Can you provide a current, detailed accessibility roadmap with delivery timelines?

    Remediation items on record may support this, but timelines are the vendor's to commit to. Do not invent dates.

  15. ITAC-15Do you expect your staff to maintain a current skill set in IT accessibility?

  16. ITAC-16Do you have documented processes and procedures for implementing accessibility into your development lifecycle?

  17. ITAC-17Can all functions of the application or service be performed using only the keyboard?

    Answer from criterion 2.1.1 evidence, including any manual keyboard verification that was run.

  18. ITAC-18Does your product rely on activating a special "accessibility mode," a "lite version," or using an alternate interface for accessibility purposes?

    A yes here is a red flag to reviewers. Answer honestly from what the crawl saw.

Reproduced from the HECVAT 4 IT Accessibility section as a starting point. Institutions customise the toolkit and EDUCAUSE revises it, so check this against the copy you were sent before returning it.

The two that catch vendors out

ITAC-08 names WCAG 2.1 AA. If your conformance table was written against 2.2, you are answering a different and stricter question — six criteria exist in 2.2 that do not exist in 2.1, so a product failing only those conforms to what was actually asked. Answering from the wrong table usually makes a vendor look worse than they are.

ITAC-11 asks about a third party. Self-assessment is not a third-party audit, and claiming otherwise is the sort of thing that surfaces later at the worst possible moment. Answer no, say what you did instead, and let the evidence carry it.

ITAC-07 is a contractual commitment, not a technical fact. It belongs to whoever signs contracts, not to whoever runs the scan.

How Affido answers it

Paste the questionnaire, or start from the template. 7 of the 18 are resolved from your own records rather than inferred — whether a report exists, when it was generated, and the link to your accessibility statement — because a wrong answer to “has a VPAT been updated in the past twelve months?” is a misrepresentation in a procurement document, not a wording choice.

The rest are drafted from your conformance table and findings. ITAC-08 is computed against WCAG 2.1 AA specifically, whatever standard your report targets. Anything the evidence cannot support is flagged for a human rather than answered confidently, and the answers export as CSV keyed by question id so they paste straight back into the spreadsheet you were sent.

Answer a HECVAT from evidence rather than memory. Affido drafts the accessibility section from your own conformance report and flags what it cannot support.

Start free

Related questions

Should my VPAT cover WCAG 2.1 or WCAG 2.2?

It depends who is asking. HECVAT names WCAG 2.1 AA, as does the ADA Title II rule for state and local government. Section 508 references WCAG 2.0 AA, and EN 301 549 points at 2.1 AA for web content. Affido always evaluates against 2.2, which contains all of them, and reports against whichever standard you pick — so one scan answers every version of the question.

What is the accessibility section of the HECVAT and how do I answer it?

HECVAT is the questionnaire US universities send to software vendors, and its IT Accessibility tab has 18 questions (ITAC-01 to ITAC-18) covering your conformance status, your contact for accessibility issues, whether a VPAT exists and how recent it is, and whether a third party has audited you. Affido answers them from your evidence and resolves five of them from your own records, including the link to your accessibility statement and whether your report is less than twelve months old.

Do I need an accessibility statement as well as a VPAT?

Usually yes, and they are different documents. A VPAT is the criterion-by-criterion table procurement reviews; an accessibility statement is a public page on your own site saying how conformant you are, what is not yet fixed, and how to report a problem. HECVAT asks for a link to one, and the European Accessibility Act requires it. Affido hosts one that rebuilds itself from your current report so it cannot go stale.

HECVAT IT Accessibility: all 18 questions, and how to answer them · Affido