A HECVAT is a vendor risk questionnaire that the institution evaluates against its own policies. An ACR reports your product against a named accessibility standard, criterion by criterion. An audit is the evaluation that either document can honestly be written from. Three instruments, three questions, and no one of them answers the other two.
| Instrument | The question behind it | Who judges the answer |
|---|---|---|
| HECVAT | How risky are you as a supplier to this institution, across security, privacy and accessibility? | The institution, against its own policies and risk appetite |
| ACR, from a VPAT | How does your product report against a named accessibility standard, one criterion at a time? | Nobody formally. It is a self-declaration and there is no certification |
| Accessibility audit | What did an evaluation of your product actually find, and in what scope? | The evaluator, and their report says what was covered |
The HECVAT Is a Risk Questionnaire
It comes from the higher education community and it covers far more than accessibility. Its accessibility section sits alongside security and privacy sections, which is the clue to what kind of document it is: a supplier assessment, not a product conformance report. The institution reads your answers against its own policies, and two universities can reach different conclusions from the same completed workbook without either being wrong.
That is why there is no pass mark we can tell you. There is no pass mark to tell you. What an institution does with a completed questionnaire is set by that institution.
What We Are Deliberately Not Doing Here
We are not reproducing HECVAT questions, its scoring, or any part of its workbook. The toolkit's license distinguishes use by institutions and vendors from other parties incorporating it, and we have not asked for permission to incorporate it. So this page describes what kind of instrument it is and links you to the official toolkit, which is a different thing from embedding one.
The same reason is why we have not built a HECVAT evidence mapper, which is otherwise an obvious tool for us to make. It is waiting on a permission question rather than on the work.
Read the Version Off the Toolkit Yourself
The toolkit is revised, and the version an institution wants is whichever one their request names. Our own reading of the official toolkit page on 31 August 2026 found version 4.1.6. Check it against the page rather than against us, and check what your requester asked for, because a campus may still be on the version they standardized on.
One warning about the surrounding material. Articles written about earlier versions carry legal deadlines that have since moved. Use those articles for their explanation of the toolkit and get any legal date from a current source, because a stale deadline repeated into a procurement conversation is worse than no date at all.
The ACR Reports Against a Named Standard
A VPAT is the blank template and an ACR is the completed report. Which edition you fill in decides which version of WCAG you are answering to: the Section 508 edition sits at WCAG 2.0, the EU edition at WCAG 2.1, and only the WCAG and INT editions reach WCAG 2.2.
Ask the institution which edition they want before you start. And know what the document is: ITI publishes the template, does not review or approve completed reports, and states plainly that there is no VPAT certification. Anyone offering you a certified VPAT is selling something that does not exist.
One thing that saves campus suppliers real work. You do not need a separate report for the platform, the mobile app and the documentation. Federal guidance says one report may address all the relevant standards and criteria that match your product's functionality, with separate reports available as an option rather than a duty.
The Audit Is What Either Document Rests On
Neither the questionnaire nor the conformance report generates evidence. They record it. So the sequence that works is to evaluate the product, then answer the questionnaire from the evaluation, then fill in the report from the same evaluation, and to keep the scope statement travelling with both.
Doing it the other way around is how suppliers end up with a questionnaire answer and a report row that quietly disagree, which is the thing a careful procurement officer notices. Our page on producing both documents from one audit covers the mapping, including the answer the template does not let you give at Level AA.
What the Institution Decides for Itself
Its own risk threshold. Whether it requires an independent evaluation, which ITI treats as the solicitation's call rather than a general rule. Its renewal cycle, which is institutional practice rather than any accessibility requirement. And whether an exception or an interim access plan is available, which is a decision only the institution can make and only for itself.
None of those travel between campuses. So the useful question, when a request arrives with three document names on it, is which of the three that particular office actually needs and by when. Ask it early. It is the cheapest question in the whole process.