What is ICT?
ICT is defined as information technology and other equipment, systems, technologies, or processes, for which the principal function is the creation, manipulation, storage, display, receipt, or transmission of electronic data and information, as well as any associated content.
EIR -Electronic Information Resources, DIR – Digital Information Resources, EIT – Electronic Information Technology are all referencing the same thing as ICT.
What is this process?
The Information and Communication Technology (ICT) Acquisition Process helps ensure CSU hardware, software, and other digital content (all ICT) purchases, as well as renewals, align with state, federal, and University compliance requirements, including accessibility, cybersecurity, data governance, AI, and procurement standards.
The soft launch for this process began March 31, 2026 for Student Affairs, College of Liberal Arts, and College of Engineering at CSU in Fort Collins, as well as the Division of IT. It will become mandatory for all CSU System units in fall 2026.
When do I need to complete it?
Any time ICT is being purchased or renewed.
Why is it required?
The review helps CSU:
- Meet state, federal, and University compliance requirements
- Improve security, accessibility, identify the usage of AI and responsible data management
- Reduce duplicate technology purchases
- Increase visibility into technology across the CSU System
- Identify opportunities for cost savings and standardization
How does the process work?

What Documentation Do I Need?
When you submit an ICT Acquisition request, please attach any documentation you have available, such as:
- A quote
- Scope of work (SOW)
- Vendor contract or agreement
- Completed Voluntary Product Accessibility Template® (VPAT)
Depending on the technology, data involved, total cost, and review requirements, additional documentation may be requested during the ICT review process. If a vendor will access, store, process, or transmit Level 3 or Level 4 institutional data, a Vendor Risk Assessment (VRA) is required. To complete that assessment, one of the following is needed from the vendor:
- A current SOC 2 Type II report (preferred)
- A completed HECVAT (alternative)
- A completed cybersecurity questionnaire. A vendor contact email will be needed.
The appropriate data steward(s) must be notified and engaged when a vendor will access, process, store, or otherwise handle Level 2 or higher data. Data steward approval is also required for any use of Level 2 or higher data that involves AI technologies.
- If AI is used in the product, then a Privacy Policy may be required.
What’s next?
Submit an ICT Acquisition Process request. Requests received by Thursday at 5:00PM will be reviewed at the following week’s committee meeting. Once your ICT request is approved, you may submit a purchase requisition to Procurement with a PDF copy of the approval email.
Get Support
Visit the Procurement Website.
Email [email protected] for help or questions about this process.
Software Catalog
Explore the software inventory for licenses already available.
FAQ
Find answers to common questions about the acquisition process.