ADA Title II has been a very hot topic in the past year. The DOJ had set its enactment deadline to April 2026 for cities over 50K and April 2027 for those under 50K, but pushed those dates out a year. While some may see that as a sign of lack of support for the law, the reality is that the scale of this task is so large that few, if any, were compliant. This was a good move.
Quick context: April 2024 the DOJ issued a final rule on ADA Title II, which affects state and local government entities. This is in contrast to ADA Title III which applies to all businesses and organizations. And in further contrast to Section 508 of the Rehabilitation Act, which applies to US federal institutions.
Most of the conversation around this deadline has focused on the government entities themselves – cities, counties, transit agencies, school districts. Fair enough. But the real lift comes from all the digital providers – particularly SaaS providers – who serve those entities and through them, you and I.
This is no small task. The thousands of applications with millions of lines of code out there, which span from the local library, to the elementary school, to the emergency response call center, to the governors office must all meet WCAG standards for accessibility. And at no time has there been more demand for accessibility to digital resources. Not only for the 20% of the population with some form of disability, plus our digital boomers – our first digital seniors, but also for our non-human users as well. This comes at a time of convergence between what humans, assistive technology, and now AI agents all need to access the digital world. We have entered the Agentic Web Era, and the good news is that what works for screen readers and assistive technology also works for AI agents, improving the user experience for humans and machines.
What ADA Title II Requires
ADA Title II covers web content and mobile apps that state and local governments use to deliver services to the public. Permitting portals, payment systems, court filing, transit apps – the stuff residents actually depend on to get things done.
The standard is WCAG 2.1 Level AA – that’s what the DOJ adopted when it finalized the rule. In practice though, WCAG 2.2 only adds nine new success criteria on top of 2.1, so there’s no real reason not to target 2.2. It’s the current spec and where auditors and procurement reviewers are heading anyway.
The rule does carve out some exceptions. Archived content that’s been properly labeled and isn’t actively used. Certain pre-existing documents. Third-party content the entity doesn’t control. Individualized password-protected records. These are narrower than people tend to assume, so if you’re advising a government client banking on one of those exceptions, read the fine print carefully.
Larger cities – population over 50K have until April 26, 2027.
Smaller cities and towns – under 50K have an extra year – April 26, 2028. That may seem like a lot of time… but it isn’t.
Your Customers’ Deadline Is Your Deadline
Most SaaS vendors selling into government haven’t fully connected the dots yet. When a city needs its permitting portal to conform to WCAG 2.1 AA and that portal runs on your platform, their compliance obligation becomes your procurement requirement.
Procurement language around accessibility has tightened a lot over the past couple of years. More agencies now have people involved in vendor evaluation who actually know what a VPAT is supposed to say – and can tell when one was put together by running a scanner and filling in the template.
Deals stall over this. A sales cycle that looked clean hits procurement, the accessibility review comes back with questions nobody can answer, and now you’re sitting in a lengthy delay trying to produce documentation that should have existed a year ago. Getting ahead of it doesn’t just reduce risk – it removes a redline from contracts and shortens sales cycles. That’s a competitive advantage.
VPAT/ACR: Ticket to Procurement Access
A Voluntary Product Accessibility Template – better known as a VPAT – is what procurement teams use to evaluate your product’s accessibility. When a vendor completes one, it becomes an Accessibility Conformance Report, or ACR. Worth knowing because procurement offices will often ask for a VPAT, but what they actually need is a completed ACR. If you hand them a blank template or a partially filled document, you’re not done.
Where things typically go wrong is the self-reporting part. When someone internally runs axe or WAVE and calls it done, the results overstate conformance. Automated tools are useful but they catch somewhere between 30% and 57% of WCAG issues depending on the application. Dynamic interfaces – modal dialogs, custom form controls, sortable data tables, toast notifications, anything that manipulates the DOM – those often look clean on a scan and fail badly under manual testing with a screen reader.
Government procurement specialists have seen enough VPATs to recognize a scanner-only report. When your document claims “Supports” on criteria your product doesn’t actually support, it doesn’t slide through. It flags. And then you’re in a conversation you weren’t ready for.
A VPAT built on real manual testing reads differently. Where conformance is partial it says so, with a specific technical explanation and a remediation path. That kind of honesty moves procurement forward faster than a polished document that falls apart under scrutiny.
There’s Still Time to Get This Right
Audit to VPAT delivery doesn’t have to be a linear process. The common assumption is you audit, remediate, verify, then write the VPAT. That sequence can take months. A smarter approach is to get the audit done now and start the ACR immediately based on current conformance – then update it after remediation is complete.
A VPAT isn’t a pass/fail document. There’s no grade. Where your product doesn’t conform, the ACR has room to explain what doesn’t meet the standard and why, along with your remediation timeline. A well-documented “Does Not Support” or “Partially Supports” entry with a clear technical explanation and a roadmap is far more credible to a serious procurement reviewer than a document that claims full conformance on everything.
That said, don’t read too much into the low bar. Some procurement offices just want to see that a VPAT exists – checking the box is enough to move forward. But that’s changing. More agencies now have accessibility-literate reviewers who read these documents carefully. A VPAT that’s honest, specific, and backed by a real audit will always outperform one that isn’t.
The sooner the audit starts, the more options you have.
Frequently Asked Questions
The ADA Title II final rule sets April 24, 2026 as the compliance date for state and local government entities with populations over 50,000. Those entities must ensure their web content and mobile apps conform to WCAG 2.1 Level AA. Smaller entities and special districts have until April 26, 2027.
The rule directly covers government entities. But government procurement requirements flow down through contracts. Vendors selling into the public sector are increasingly required to document their product’s accessibility through a VPAT/ACR as a condition of contract award. A government entity’s compliance deadline creates real procurement pressure for every vendor in their technology stack.
The DOJ adopted WCAG 2.1 Level AA when it finalized the rule in April 2024. WCAG 2.2 wasn’t incorporated. For VPAT documentation you report against WCAG 2.1 for government procurement purposes, though targeting 2.2 is the smarter move – it only adds nine new success criteria and it’s where the industry is heading.
A VPAT is the blank template. An ACR – Accessibility Conformance Report – is what you get when a vendor actually completes it. Procurement offices often ask for a VPAT but what they’re expecting to receive is a completed ACR. Handing over an incomplete or unfilled document won’t get you through the review.
No. Automated tools catch somewhere between 30% and 57% of WCAG issues. Dynamic interfaces – SPAs, modal dialogs, custom interactive components, real-time data tables – are routinely missed by scanners and routinely failed under manual testing. A VPAT based only on automated scan output tends to overstate conformance in ways experienced procurement reviewers recognize. A defensible ACR requires manual testing.