Ed-Tech · University Procurement
SOC 2, HECVAT, and FERPA: what university procurement actually checks
Control and Function · August 2026
Ed-tech vendors usually discover the real shape of university security review the hard way: a faculty pilot goes well, adoption talks begin, and then procurement sends a workbook the vendor has never seen. Here is what that review actually consists of, and the order of operations that gets you through it.
Three instruments, three different questions
SOC 2 is an attestation report issued by a licensed CPA firm. It answers: does this vendor have a functioning security program, and did an independent auditor verify it? A Type I report covers control design at a point in time; a Type II covers operation over a period. It is the general-purpose trust document that works across every industry.
HECVAT (the Higher Education Community Vendor Assessment Toolkit) is a questionnaire, not an audit. It answers: does this vendor meet the specific expectations of higher education, in higher education's own vocabulary? The current HECVAT 4 generation is a single workbook of over three hundred questions with conditional triage, and it goes places SOC 2 does not: a dedicated AI and machine learning section that distinguishes machine learning from large language models and asks about training data and governance, a substantial privacy section mapped to FERPA and GDPR, and accessibility questions aligned to WCAG 2.1 AA.
FERPA is federal law. It is not a certification you obtain; it is a set of obligations that attach to student education records, and they follow the data into your systems. Universities can only share student records with vendors under specific exceptions, each with conditions on use, redisclosure, and destruction, and the sharing agreement is where those conditions live.
The mistake: assuming SOC 2 covers it
It does not. At most institutions, a completed HECVAT is the procurement baseline regardless of the SOC 2 report in your data room. The efficient play is not choosing between them; it is completing the HECVAT once, well, with answers that cross-reference your SOC 2 report as evidence, so each new institution gets a consistent, current response instead of a from-scratch scramble.
Two things changed recently that make this more work, not less. First, the community exchange that used to let institutions pull a vendor's completed HECVAT from a shared index was retired in mid-2025, so each institution now asks the vendor directly, one at a time. Keeping a current, versioned response set ready to send is now a real operational task. Second, if your product uses AI in any form, HECVAT 4's AI section applies to you, and "we use a model provider" is not an answer. You need documented positions on training data, model behavior, and student privacy in AI features.
FERPA scrutiny is rising, and it is aimed at data-receiving organizations
In February 2026 the Department of Education's Student Privacy Policy Office opened investigations into a university and a national nonprofit over student data shared for research under FERPA's studies exception, and issued a Dear Colleague Letter asking institutions to review their data-sharing agreements. The signal to every organization that receives student data from universities, including ed-tech vendors and research nonprofits, is that those agreements are getting re-read by university counsel. If your data flows in under a FERPA exception, you want to know exactly which exception, what its conditions are, and whether your practices match, before someone else checks.
The enforcement risk is not only federal. State student-privacy laws now number in the hundreds, state consumer-privacy regulators have begun bringing actions involving student data, and the amended federal COPPA rule reached full enforcement in 2026 for products touching users under thirteen.
The order of operations
For an ed-tech vendor moving from pilot to institutional adoption, the sequence that works:
- Map your student-data flows first. Every inbound flow gets a documented legal basis, its conditions, and a match against your actual retention and deletion practices. This is days of work, not months, and it de-risks everything downstream.
- Build one control program, not three. SOC 2's criteria, HECVAT's questions, and FERPA's obligations overlap heavily. Map them into a single control set so every artifact serves all three masters.
- Complete the HECVAT once, properly, and keep it current. Including the AI section if your product touches AI. Cross-reference your SOC 2 evidence rather than restating it.
- Time the SOC 2 audit against your sales calendar. A Type I lands fastest when a procurement gate needs paper; a Type II follows over the next observation period. Auditor calendars fill months out, especially in the fourth quarter, so the audit firm gets engaged early, not when the deal is on the table.
Where we fit
Control and Function runs SOC 2 readiness for SaaS and ed-tech companies as a fixed-fee engagement, with dual-framework programs that fold FERPA obligations and HECVAT responses into the same control set. We are not an audit firm and we do not issue SOC 2 reports; we build the program, prepare the evidence, refer you to a licensed CPA firm, and manage the audit through report issuance. Engagements run through a client portal where you watch control status, phases, and the engagement record move in real time.
If you are somewhere between "a university just asked for our HECVAT" and "we need a SOC 2 by a deadline," a 30-minute call will tell you where you actually stand. Book a readiness call or email hello@controlandfunction.com.
Related
Complementary User Entity Controls (CUECs) Explained
University procurement asks about your subprocessors. Every vendor SOC 2 report you collect lists controls it assumes you operate, and those are the ones that get missed.