Event Technology

How to Get Your Event Tech Through IT Security Review

How to Get Your Event Tech Through IT Security Review

In this article, we'll cover:

  • What an IT security review is and why your event tech has to pass one
  • The four documents reviewers ask for most
  • What to gather before you submit anything
  • How much time to build into your event timeline
  • The questions that separate a prepared vendor from a risky one

The Approval Nobody Put on the Timeline

You picked the platform. The demo went well, the budget's approved, and registration opens in six weeks. Then IT sends a 300-question spreadsheet and says nothing gets signed until it's reviewed.

This is the moment a lot of event tech purchases stall. The cause is rarely a bad product. It's that nobody planned for the review. The good news is that security review is predictable, and a planner who knows what's coming can keep it from eating the calendar.

What an IT Security Review Is (and Why Events Get One)

Your registration platform holds names, emails, employers, and often payment details. Add dietary needs, accessibility requests, or student records, and you're holding attendee data your organization is legally responsible for.

A security review is how IT confirms a vendor will protect that data. At a university, an association, or a larger company, expect up to four groups to weigh in:

  • IT security checks how the vendor stores and protects data
  • Privacy or legal checks who owns the data and when it's deleted
  • Procurement checks contract terms and insurance
  • Accessibility checks that every attendee can use the product

None of them are trying to block your event. They're answering one question: if something goes wrong with this vendor, are we covered?

The Four Documents Reviewers Ask For Most

Most reviews come down to the same short list. Knowing the names puts you ahead of most buyers.

DocumentWhat it isWho usually asks
Security questionnaireA long list of questions about how the vendor handles security, privacy, and riskIT security
SOC 2 reportAn independent auditor's report on the vendor's security controlsIT security, procurement
Accessibility conformance report (often called a VPAT)A statement of how the product meets accessibility standardsAccessibility office
Data processing agreementContract terms covering data ownership, retention, and deletionPrivacy, legal

In higher education, the questionnaire is almost always the HECVAT, the Higher Education Community Vendor Assessment Toolkit. It was built by higher ed leaders with EDUCAUSE, Internet2, and REN-ISAC so schools could stop writing their own questionnaires.

Version 4 arrived in February 2025. It combined the old Full, Lite, and On-Prem versions into one file and added questions on privacy and AI. If your vendor hands you a HECVAT from an older version, expect IT to ask for an update.

💡 Pro tip: Ask the vendor for a completed HECVAT before you contact IT. A prepared vendor sends it the same day. Top event technology providers, like Expo Pass, keep one on file so the reviewer's first request is already answered.

What to Gather Before You Submit Anything

The fastest reviews happen when IT gets a complete packet on day one. Every missing document adds another round of email.

  1. Ask IT how intake works. Find the request form, ask what triggers a full review, and ask how long the queue is right now.
  2. List the data you'll collect. Write down every registration field, and flag anything sensitive. Fewer sensitive fields means a shorter review.
  3. Request the vendor's security packet in one email. Ask for the completed questionnaire, the SOC 2 report or equivalent, the accessibility report, the data processing agreement, and a list of subprocessors.
  4. Know how payments flow. Find out whether the vendor touches card numbers or whether a processor like Stripe handles them. This is one of the first things IT asks.
  5. Map the integrations. Note any single sign-on, CRM, or membership system connections, plus on-site hardware. Check-in iPads and badge printers on a venue network count.
  6. Connect IT to the vendor's security contact. Don't relay technical questions yourself. A direct line between the two saves days.

That packet does most of the work for you. It also tells you something about the vendor. One who can't produce these documents quickly hasn't been through many reviews.

How Much Time to Build Into Your Timeline

Review times vary too much to quote one number. A vendor with a complete packet and a short IT queue can clear in days. A large university or enterprise with a backlog can take weeks.

So don't guess. Ask IT for their current turnaround, then put the review on your event timeline as its own milestone, ahead of contract signature. Three habits keep it from becoming the bottleneck:

  • Start at the shortlist, not the selection. Send packets for your top two vendors, and the review is finished when you decide.
  • Run it alongside contract review. Security and legal can work at the same time.
  • Expect it at renewal. Many organizations review vendors again each year, so keep your packet where you can find it.

If approvals are a recurring headache, our guide to getting event tech through procurement covers the budget side of the same process.

⚡ Practical Advice: Registration can't open until the platform is approved. Count backward from your registration launch date, not your event date.

Questions That Separate a Prepared Vendor From a Risky One

You don't need a security background to ask good questions. These six tell you most of what IT wants to know:

  • Do you have a completed security questionnaire, and when was it last updated?
  • Who is your security contact, and how quickly do they answer follow-up questions?
  • Where is attendee data stored, and when is it deleted after my event?
  • Which subprocessors handle our data?
  • Does your product use AI on attendee data, and can we turn it off?
  • What happens at check-in if the venue internet drops?

Clear, fast answers are a good sign. Vague ones are worth raising with IT before the review starts, not after.

Final Takeaway

Security review isn't a hurdle between you and your event tech. It's a step in the timeline, and it rewards the planner who treats it like one. Ask IT how the process works, collect the vendor's packet before you submit, and start while you still have two vendors on the shortlist. Do that and the review becomes one more milestone you hit on schedule.

Frequently Asked Questions

What is a HECVAT?

The HECVAT is the Higher Education Community Vendor Assessment Toolkit, a standard questionnaire colleges and universities use to measure vendor risk. It covers cybersecurity, privacy, accessibility, and compliance. The vendor fills it out, and your IT team reviews the answers.

Who fills out the security questionnaire, me or the vendor?

The vendor does. Your job is to request it, pass it to IT, and connect the two teams for follow-up questions. If a vendor asks you to complete it for them, treat that as a warning sign.

Does a small event still need a security review?

It depends on your organization's policy and the data you collect, not the size of the event. A 150-person meeting that collects payments and personal details can trigger the same review as a 5,000-person conference. Ask IT what the threshold is before you assume you're exempt.

What's the difference between a SOC 2 report and a security questionnaire?

A questionnaire is the vendor's own description of their security practices. A SOC 2 report is an independent auditor's assessment of those practices. Some organizations require both, and some accept one, so ask IT which they need.

What is a VPAT?

A VPAT is the template vendors use to report how their product meets accessibility standards. The completed version is called an accessibility conformance report. Universities and public sector organizations ask for it most often.

Will we have to repeat the review next year?

Often, yes. Many organizations review vendors again at renewal or when the product changes in a meaningful way. Save your packet and ask the vendor for updated documents each year.

This article was written with the help of AI and edited by humans. Graphics were generated with the assistance of AI.

Keep reading

Bring your next event to life.

See how Expo Pass powers registration, check-in, and engagement from start to finish.

Get a demo