The DOJ just pushed the ADA Title II web accessibility compliance deadlines out by one year. Larger government entities now have until April 2027. Smaller entities and special districts move to April 2028. The technical standard – WCAG 2.1 Level AA – didn’t change. The scope didn’t change. The vendor flow-down language that reaches SaaS products through government procurement contracts didn’t change.
Here’s what a lot of people in government IT and higher ed may not fully appreciate: Title II has teeth that Title III doesn’t. For the past decade, most of the attention around web accessibility litigation has focused on Title III – private businesses getting demand letters, settling for attorney’s fees, dealing with injunctive relief. Title II is a different animal. Compensatory damages. DOJ enforcement with civil penalties exceeding $100,000 per violation. No requirement to exhaust administrative remedies before suing. Any citizen who encounters an inaccessible government website or an inaccessible SaaS product used by a government entity can go straight to federal court.
This isn’t the enforcement environment most government web teams have been planning around. It should be.
The good news is that the extension creates space to do this right. Not rush it. Not patch it. Actually build accessible digital infrastructure that holds up under scrutiny – and that happens to position your web properties for where the internet is headed.
Who This Applies To
ADA Title II covers state and local government entities. Cities, counties, state agencies, public universities, community colleges, K-12 districts, transit agencies, libraries, courts, special-purpose districts. No size threshold. No revenue floor.
ADA Title III covers private businesses that operate as public accommodations – private universities, retailers, healthcare, financial services. The enforcement exposure is meaningfully different. Under Title III, private plaintiffs get injunctive relief only – a court order to fix the problem – plus attorney’s fees. No compensatory damages. Under Title II, plaintiffs recover compensatory damages including actual harm and emotional distress, with attorney’s fees on top. DOJ can pursue its own enforcement actions with civil penalties up to $107,506 for a first violation and $214,514 for subsequent ones.
SaaS vendors aren’t directly covered under either title. But if your product is delivered to a Title II entity through a contract or license, the entity’s compliance obligation reaches you through procurement. The rule covers content a public entity provides “through contractual, licensing, or other arrangements.” An LMS at a state university, a permitting system at a county, a student information system at a community college. If it delivers public services on behalf of a covered entity, the obligation is in your contract. DOJ’s preamble and published guidance are explicit about this.
What Actually Changed
The Interim Final Rule (91 Fed. Reg. 20902) amends exactly two compliance dates. Every substantive requirement stays in place. The WCAG 2.1 AA standard. The scope. The exceptions. The vendor language.
A 60-day public comment window closes June 22, 2026. DOJ signaled it may issue a Notice of Proposed Rulemaking during the extension to revisit certain provisions. But the preamble says directly: if no NPRM comes, the rule implements at the new dates.
Why This Extension Is Actually Good News
I’ve spent a decade working in accessibility. The pattern with compliance deadlines is painfully consistent. Organizations discover the requirement. They scope the work. They realize the budget and internal capacity aren’t there. And because the deadline is bearing down, the impulse is to find a shortcut.
For many government entities and public universities, that’s exactly where the original April 2026 timeline was headed. Not because people were ignoring accessibility. Because the scale of the work – auditing web properties, testing with assistive technology, remediating application code, retagging years of PDFs, renegotiating vendor contracts – is genuinely large. And most organizations only fully understood that scope in the last year or so.
That creates a rush toward automated scan reports and overlay widgets. Neither holds up.
Automated scanning catches roughly 30% of WCAG issues. It cannot test whether a screen reader user can actually complete a form, navigate a dynamic interface, or use a data table. And overlays – products like accessiBe and UserWay that inject JavaScript onto your site and claim compliance – have a documented record of failure. The FTC ordered accessiBe to pay $1 million in April 2025 for deceptive claims about its product. Both companies are currently facing class action lawsuits from businesses that were sued for accessibility failures while running the widgets.
The extension removes the pressure to take shortcuts. Organizations now have room to budget properly in the next fiscal cycle, scope a real audit, and build a remediation plan that their teams can execute. That’s a better outcome for accessibility than anything a rushed last-quarter push was going to produce.
This Is Bigger Than Compliance
There’s a version of this work that treats accessibility as a box to check and a version that recognizes it for what it actually is: a structural upgrade to your digital infrastructure that pays dividends well beyond ADA compliance.
We’re in the early stages of the Agentic Web Era. AI agents, answer engines, and large language models are rapidly changing how people find, consume, and interact with web content. Google’s AI Overviews, ChatGPT’s browsing, Perplexity, Microsoft Copilot – these systems don’t just index your pages. They parse them, extract structured answers, and cite or discard content based on how well it’s built.
The same markup that WCAG requires – semantic HTML, properly structured headings, descriptive labels on forms and controls, meaningful alt text, logical reading order – is exactly what these systems need to understand your content. A SEMrush study of 10,000 websites found that WCAG-conformant sites received a 23% lift in organic search traffic. That wasn’t a coincidence. Accessible code and search-optimized code are converging because they both depend on the same thing: machine-readable structure.
For government websites and public university sites, this matters in a specific way. Citizens and students increasingly find public services through search and AI assistants, not by navigating to a .gov domain and clicking through menus. If your site isn’t built in a way that AI systems can parse and surface accurately, people aren’t finding your content. Accessibility work fixes that at the structural level.
And there’s a practical opportunity here that goes beyond SEO and AEO. Many of the government and higher ed web properties that need accessibility remediation are running on aging CMS installs with years of technical debt. Legacy WordPress themes. Unpatched plugins. Outdated server configurations. If you’re going to audit and remediate anyway, this is the moment to evaluate whether a broader rebuild makes more sense than patching a codebase that also carries security exposure. The accessibility audit surfaces the structural problems. A rebuild addresses them at the root while also modernizing your security posture and positioning your site for how the web works now.
How to Use This Year
Accessibility compliance at scale is a 12-to-18-month effort when done properly. The audit itself isn’t the long pole – that’s typically three to five weeks for a reasonably complex web property. The remediation is what takes time, and it’s where most organizations get surprised.
Inventory first
Before any audit begins, you need a complete picture of your digital footprint. Every website, every subdomain, every web application, every mobile app, every vendor-delivered platform, every document library. Public-facing and behind-login. Government entities and universities tend to have far more digital properties than anyone in leadership realizes until someone actually catalogs them. You can’t scope an audit without this step, and you can’t build a budget without a scope.
Then audit – and invest in the audit
Automated scanning tools are limited. Even the ones incorporating AI. They catch surface-level issues – missing alt text, color contrast failures, broken form labels – but they cannot evaluate whether a real person using assistive technology can actually complete a task on your site. An experienced auditor understands the nuances and edge cases in WCAG that no automated tool can replicate. The audit isn’t cheap, and it shouldn’t be. The quality of the audit report directly determines how fast and how affordably the remediation goes. Vague findings mean dev teams burn hours interpreting what’s actually wrong. Detailed, developer-ready findings with root cause analysis and stack-specific remediation guidance mean your team can fix things without guessing. A good audit pays for itself in remediation efficiency.
Scope the vendor layer
If your properties include third-party platforms – an LMS, a permitting system, a payment portal – those are covered too. Review vendor contracts for accessibility warranty language. Request a current Accessibility Conformance Report (ACR) from each vendor. If they can’t produce one, or if it predates their last major release, that tells you where the conversation needs to start.
Build a phased remediation plan
The audit takes weeks. Remediation can take months. The range depends entirely on how much is broken, how deeply it’s embedded in the codebase, and how many vendor dependencies are involved. A well-structured remediation plan prioritizes access-blocking issues first – a portal that fails on keyboard, a form that screen readers can’t parse, unlabeled controls on an application page. Cosmetic issues and edge cases come later. The plan needs realistic timelines and clear ownership, not a PDF that sits in a folder.
Lock in the budget now
The extension makes this conversation dramatically easier. Instead of asking leadership for emergency money, you’re presenting a scoped plan with a realistic timeline. “Here’s the inventory, here’s the audit cost, here’s what remediation will look like based on what the audit finds, and here’s the 12-month plan.” That’s a conversation that gets funded. Waiting until 2027 to have it puts you back in the scramble.
For SaaS vendors: get the ACR right
Procurement teams at government agencies and public universities are requiring a current, manually-tested ACR at proposal. Built on the VPAT 2.5 framework, tested against WCAG 2.1 AA or better, showing which criteria your product meets, which it partially supports, which it doesn’t, and what the remediation plan looks like. Stale ACRs don’t survive serious due diligence. Annual updates tied to your release cycle are the baseline expectation now.
State Laws That Don’t Wait
The federal extension doesn’t override state-level requirements already in effect. For organizations operating across states, or SaaS vendors selling nationally, these are the ones to track:
| State | Law | Standard | Applies To | Enforcement |
|---|---|---|---|---|
| Colorado | HB 21-1110 | WCAG 2.1 AA | State/local gov, K-12, higher ed | Private right of action, $3,500/violation/individual |
| New York | S3114A + Human Rights Law | WCAG 2.1 AA (June 2026), 2.2 AA (Jan 2027) | State agencies, contractors, consultants; private businesses (HRL) | OIT enforcement, civil litigation |
| California | Unruh Act + AB 434 | WCAG 2.1 AA / Section 508 | State agencies; private businesses (Unruh) | $4,000+ statutory damages/occurrence, biennial agency certification |
| Massachusetts | Enterprise IT Policy + Ch. 93A | Section 508 / WCAG 2.1 AA | Executive branch agencies; private businesses (93A) | Treble damages for willful violations under consumer protection |
| Florida | § 282.603 | Section 508 | All three branches of state government | Administrative compliance, vendor disqualification from procurement |
| Illinois | IITAA | WCAG 2.0 AA | State agencies, public universities | Procurement mandates, Dept. of Human Rights oversight |
| Texas | TAC Title 1, Ch. 206/213 | WCAG 2.0/2.1 | State agencies | Annual reporting, procurement vetting |
| Virginia | ITAA | WCAG 2.0 AA | State agencies | Technology procurement standards |
| Minnesota | Digital Accessibility Standard | WCAG 2.1 AA | Executive branch agencies | State policy enforcement |
This table isn’t exhaustive. Other states including Michigan, Connecticut, Iowa, Indiana, and others maintain accessibility policies or standards that may apply. We’ll be publishing a comprehensive state-by-state breakdown separately.
Colorado, New York, California, and Massachusetts carry the most immediate weight. Colorado and California expose vendors directly through private rights of action with statutory damages. New York extends obligations to contractors and platform operators. Massachusetts connects inaccessible digital experiences to consumer protection claims with treble damages for willful noncompliance. If you have public sector or commercial accounts in any of these states, the federal extension doesn’t change your exposure.
Florida is worth watching for a different reason. No private right of action, but the state enforces through procurement. A SaaS product that can’t demonstrate Section 508 conformance can be disqualified from a Florida state bid outright. That’s not a lawsuit – it’s lost revenue you never see coming.
The Enforcement Reality
Worth getting specific here, because Title II and Title III diverge in ways that matter for this audience.
Under Title III – the title covering private businesses – a private plaintiff can only get injunctive relief. That’s a court order requiring you to fix the problem. No compensatory damages from a private suit. The financial exposure comes from attorney’s fees under the ADA’s fee-shifting provision, which routinely run $30,000 to $50,000 or more in a straightforward web case. That’s why Title III generates so many demand letters.
Title II is materially different. Private citizens can sue directly in federal court with no administrative process required. If they prevail, they can recover compensatory damages – that includes actual harm from denial of services and in some cases emotional distress – with attorney’s fees on top. DOJ can also bring its own enforcement actions and seek civil penalties up to $107,506 for a first violation and $214,514 for subsequent violations.
That’s a different category of risk. A government agency or public university running inaccessible digital properties after April 2027 isn’t just facing a fix-it order. They’re exposed to damages, fees, and DOJ action with six-figure penalties.
For SaaS vendors, the exposure is indirect but follows the contract. If you warranted WCAG conformance and your product doesn’t hold up under scrutiny, that’s a breach. The suit hits your customer and then flows to you through the indemnification clause.
An overlay widget, an automated scan certificate, or a marketing page claiming compliance doesn’t constitute a good-faith effort under that standard. If a plaintiff’s attorney can show an organization knew about the requirement, claimed to have addressed it, and demonstrably didn’t – that documentation becomes evidence, not a defense.
For SaaS Product Teams
If you sell into government or higher education, your customers are covered entities. Their procurement teams know it. State and local RFPs increasingly require a current ACR at proposal, annual refreshes tied to major releases, and accessibility warranties with remediation SLAs baked into contract language. NASPO ValuePoint cooperative contracts – used across all 50 states – are actively folding these requirements into master agreements.
The federal deadline extension gave your customers more time. It didn’t change what their next RFP is going to ask of you.
If your team needs to understand what a real audit and ACR process looks like for a SaaS product, our VPAT and ACR services page lays out the methodology and deliverables.
What Twelve Months of Good Work Looks Like
By April 2027, an organization that used this time well will have a completed digital property inventory, a WCAG audit with documented findings, a remediation plan that’s been substantially executed, updated vendor contracts with accessibility warranties and ACR requirements, and an accessibility statement on their website that reflects actual testing rather than aspirational language.
That’s what defensible looks like. Not a scan report. Not a widget. A documented, ongoing practice built into how your organization publishes and maintains digital content.
The organizations and product teams that treat this extension as a planning and execution window – not a reason to delay – come out of it in a stronger position. Not just legally. Structurally. Accessible, secure, built for how people actually find and use the web in the Agentic Web Era.
That’s worth doing regardless of what any deadline says.
If your organization needs to scope what an audit and remediation roadmap looks like – whether you’re on the .gov side or the SaaS side – our WCAG compliance audit services and VPAT/ACR services pages cover the methodology and deliverables.