There is no official body that certifies websites or software for accessibility compliance. No seal, no stamp, no certificate you can frame. What exists instead is the Voluntary Product Accessibility Template (VPAT), a standardized document maintained by the Information Technology Industry Council (ITI) that reports how well a digital product conforms to accessibility standards. Once a VPAT is completed based on testing results, the finished document is called an Accessibility Conformance Report (ACR). The VPAT is the template. The ACR is your evidence.
The current version is VPAT 2.5, published by ITI in November 2023 to align with WCAG 2.2. It comes in four editions depending on which standards your buyers require. If you sell software or digital services to government, education, healthcare, or enterprise buyers, you almost certainly need one.
How VPATs and ACRs Actually Work
The VPAT is a structured Word document with tables that map directly to accessibility success criteria defined in the Web Content Accessibility Guidelines (WCAG). An evaluator tests your product against those criteria, then fills in each row with a conformance level and an explanation of what was found.
The conformance levels in VPAT 2.5 are:
- Supports – the product fully meets the criterion
- Partially Supports – some functionality meets the criterion, some does not
- Does Not Support – the product fails the criterion
- Not Applicable – the criterion does not apply to the product
VPAT 2.5 replaced the old “Supports with Exceptions” language from version 2.4 with “Partially Supports.” It also added a dedicated column for detailed explanations of each conformance finding. That second change matters more than it sounds. Procurement reviewers read these line by line, and a bare “Partially Supports” with no context is a red flag. The explanation column is where credibility lives.
Once filled out, the VPAT becomes your ACR. That ACR is what procurement officers, legal teams, and accessibility reviewers actually read when deciding whether your product clears their requirements.
Which VPAT Edition Do You Need?
VPAT 2.5 comes in four editions. Each one maps to a different set of standards. Pick the one that matches where your buyers are and what they’re required to evaluate against.
VPAT 2.5 WCAG Edition reports conformance against the Web Content Accessibility Guidelines (WCAG 2.0, 2.1, or 2.2). This is the most flexible edition and the right default for most commercial SaaS and private-sector products selling in the US. If your buyers aren’t specifying a particular edition, start here. (Download from ITI)
VPAT 2.5 508 Edition adds reporting tables specific to Section 508 of the Rehabilitation Act. Required when selling to US federal agencies or entities that receive federal funding, including most public universities and K-12 districts. The 508 edition includes additional functional performance criteria tables organized by disability category beyond what the WCAG edition covers. (Download from ITI)
VPAT 2.5 EU Edition reports against EN 301 549, the European accessibility standard published by ETSI and referenced by the European Accessibility Act (EAA). If you sell digital products or services to EU customers or EU public-sector entities, this is the edition that maps to their requirements. (Download from ITI)
VPAT 2.5 INT (International) Edition combines all three: WCAG, Section 508, and EN 301 549 in a single document. This is the right choice if your product is sold globally and your buyers span US federal, EU, and commercial markets. It’s the most comprehensive but also the longest. If you only operate in one market, a narrower edition is cleaner. (Download from ITI)
The decision framework is straightforward. Ask two questions: Who is the buyer? What standard does their procurement process reference? If you’re selling SaaS to US state agencies, the 508 edition covers you. If you’re responding to an RFP from a European university, the EU edition. If you’re a global platform selling to all of the above, the INT edition saves you from maintaining three separate documents.
One word of caution. Don’t fill out more editions than your buyers require. Extra tables mean extra criteria, and if your product doesn’t meet standards you weren’t actually required to report against, procurement reviewers will notice. A clean WCAG edition is better than a messy INT edition with “Does Not Support” scattered through sections nobody asked about.
What Changed from VPAT 2.4 to 2.5
The update from 2.4 to 2.5 was driven primarily by the release of WCAG 2.2 in October 2023. The changes are targeted, not sweeping.
The WCAG edition now includes tables for WCAG 2.2 alongside the existing 2.1 and 2.0 tables. In practice, most buyers are specifying WCAG 2.1 Level AA as their minimum, though procurement language is beginning to shift toward 2.2. The EU edition was updated to reflect the latest version of EN 301 549. The INT edition absorbs both updates.
The “Supports with Exceptions” conformance level was retired. “Partially Supports” replaced it. The practical difference is mostly linguistic, but it removes ambiguity. “Exceptions” implied edge cases. “Partially Supports” is blunter about the reality that some parts work and some don’t.
The most operationally useful change is the dedicated explanation column added to each conformance row. Previous versions had a remarks column, but 2.5 formalizes the expectation that every finding gets a written explanation. This is where a skilled VPAT author earns their fee. A product that “Partially Supports” a criterion with a clear explanation of which workflows are affected, what the workaround is, and what the remediation timeline looks like reads very differently to a procurement reviewer than one that just says “Partially Supports.”
There is no timeline from ITI for a VPAT 2.6. The next version would likely be triggered by WCAG 3.0 or a major update to EN 301 549 or Section 508. Neither is imminent. Plan around VPAT 2.5 as the standard for at least the next 18 to 24 months.
Who Needs a VPAT and Why
Government and Public Sector
Federal agencies have required VPATs for ICT procurement under Section 508 for years. That requirement has expanded significantly.
The Department of Justice (DOJ) published final rules in April 2024 requiring state and local government websites and mobile apps to conform to WCAG 2.1 Level AA under ADA Title II. In April 2026, the DOJ extended those compliance deadlines by one year: entities serving populations of 50,000 or more now have until April 26, 2027, and smaller entities until April 26, 2028. The substantive requirements are unchanged. WCAG 2.1 Level AA is still the technical standard.
For vendors selling to these entities, the implication is direct. Government procurement teams are asking for ACRs as part of the evaluation process. If you sell a learning management system to a public university, a case management platform to a state agency, or a scheduling tool to a city government, a current ACR is a prerequisite, not a differentiator.
SaaS and B2B Software
This is where the VPAT has shifted from a government-only document to a mainstream commercial requirement. Enterprise buyers, particularly those in regulated industries, now include accessibility requirements in their procurement processes. A B2B SaaS company selling to healthcare systems, financial institutions, or Fortune 500 companies will encounter VPAT requests during the RFP stage.
For SaaS product teams, the ACR functions as a sales document. A strong ACR that demonstrates genuine conformance testing accelerates procurement cycles. A weak one, or no ACR at all, creates redlines that slow deals or kill them.
The person requesting the VPAT is usually someone in procurement, legal, or IT governance. The person who will read it closely is often an accessibility subject matter expert embedded in the buyer’s evaluation team. The ACR needs to satisfy both: the checklist-driven procurement officer and the technical evaluator who knows what “Partially Supports” actually means.
Ecommerce and Consumer-Facing Websites
The VPAT was originally designed for software procurement, not consumer websites. But ecommerce operators increasingly use ACRs as evidence of accessibility investment, particularly as ADA Title III lawsuits against commercial websites continue to rise. An ACR won’t prevent a lawsuit, but it demonstrates a documented, systematic approach to accessibility that carries weight in legal defense and settlement negotiations.
International Markets
The European Accessibility Act (EAA) took effect in June 2025, requiring companies that serve EU citizens to meet EN 301 549 standards for websites, mobile applications, and digital content. Canada’s Accessible Canada Act and accessibility regulations in Australia, Japan, and elsewhere establish similar requirements.
The practical reality is that WCAG is the single global standard underpinning all of these laws. The specific law varies by jurisdiction, but the technical standard is the same. A WCAG-based ACR serves as your evidence of conformance regardless of which regulatory body is asking.
Why Most Organizations Outsource VPAT Authoring
VPAT authoring requires two things that rarely coexist inside a single organization: deep WCAG technical expertise and experience writing documentation that survives procurement scrutiny.
Filling out the template requires testing each success criterion against the actual product. Not scanning it with an automated tool and copying the output into the template. Automated accessibility scanners catch roughly 30% of WCAG issues. They identify missing alt attributes, color contrast failures, and malformed heading structures. They cannot evaluate whether a modal dialog traps keyboard focus correctly, whether a dynamic data table announces row and column headers to screen readers, or whether a multi-step checkout flow maintains accessible state across page transitions. Those are manual testing tasks that require both assistive technology expertise and front-end development knowledge.
A VPAT based on automated scan results alone will collapse under review. Procurement evaluators at government agencies and large enterprises know what a scan-generated VPAT looks like. The explanations are generic, the “Supports” claims are overconfident, and the gaps in coverage are obvious to anyone who has read more than a few of these documents.
Third-party authoring also adds credibility. An ACR produced by an independent accessibility consultancy carries more weight than a self-assessment. The same way a financial audit conducted by an external firm is more credible than an internal review, a VPAT authored by a team that didn’t build the product signals objectivity.
The ideal workflow is to have the same team conduct the audit and author the VPAT. When the evaluators who tested the product are also writing the conformance report, the explanations are specific, the “Partially Supports” entries include real detail about which workflows are affected, and the remediation guidance maps to actual code.
Common VPAT Mistakes
Relying on automated scan results. A VPAT populated from scan output will list dozens of criteria as “Supports” that a manual review would flag as “Partially Supports” or “Does Not Support.” When a procurement evaluator compares your ACR against their own testing, the credibility gap is immediate and hard to recover from.
Using outdated audits. A VPAT based on an audit from 18 months ago doesn’t reflect the current state of a product that ships updates regularly. Most organizations should plan on refreshing their ACR annually or whenever significant UI changes ship.
Self-assessing without the right expertise. VPAT authoring requires familiarity with WCAG success criteria at the implementation level, experience with multiple assistive technologies, and knowledge of how procurement teams read these documents. An internal team that doesn’t have all three will produce a document that either overclaims or underdocuments.
Ignoring mobile. Many VPATs cover the desktop web experience and stop there. If your product has a mobile app or responsive mobile interface, procurement reviewers will ask about it. An ACR that only covers desktop is incomplete.
Choosing the wrong edition. Filling out the INT edition when your buyer only requires the WCAG edition adds unnecessary criteria that could generate negative findings you weren’t required to report.
The Business Case Beyond Compliance
A strong ACR opens sales channels. Government agencies, public universities, and enterprise buyers with accessibility requirements represent a significant market. Without a current ACR, your product is screened out before a human even reads your proposal.
Beyond procurement, the audit process that produces the VPAT almost always identifies usability improvements that benefit all users. Accessible heading structures, keyboard navigation, clear focus indicators, and properly labeled form fields improve the experience for power users, mobile users, and users on slow connections. These aren’t accommodations. They’re product quality improvements.
The Americans with Disabilities Act (ADA) covers 61 million Americans with disabilities. Add the 71 million Baby Boomers who increasingly rely on accessibility features as vision, hearing, and motor function change with age, and you’re looking at a combined market with significant spending power. An accessible product reaches them. An inaccessible one doesn’t.
From an SEO and AI discoverability perspective, the semantic HTML that WCAG conformance requires is the same structure that search engines and AI agents parse to understand and surface content. Clean heading hierarchies, descriptive link text, proper ARIA labeling, and logical document structure serve both accessibility and findability.
Frequently Asked Questions
What is the current VPAT version?
VPAT 2.5, published by the Information Technology Industry Council (ITI) in November 2023. It aligns with WCAG 2.2 and includes updated editions for Section 508, EN 301 549, WCAG, and International reporting.
What is the difference between a VPAT and an ACR?
The VPAT is the blank template. Once it’s completed with testing results and conformance findings, the finished document is called an Accessibility Conformance Report (ACR). Buyers often ask for a “VPAT” when they mean an ACR. They want the completed report, not the empty template.
Do I need a VPAT for my website?
If you sell digital products or services to government agencies, public universities, or enterprise buyers with accessibility procurement requirements, yes. For commercial websites not involved in B2B or government sales, an ACR is less common but still useful as evidence of accessibility investment, particularly for ADA risk management.
How often should a VPAT be updated?
At minimum, annually. If your product ships significant UI updates or new features between cycles, the ACR should be refreshed to reflect the current state. An ACR older than 12 to 18 months loses credibility with procurement reviewers.
Can I write my own VPAT?
Technically, yes. The template is freely available from ITI’s website. In practice, VPAT authoring requires deep WCAG testing expertise, assistive technology proficiency, and experience writing conformance documentation that holds up under procurement and legal review. Self-assessments that lack this depth often overclaim conformance, which creates more risk than having no documentation at all.
Which VPAT edition should I choose?
Match the edition to your buyer. WCAG edition for US commercial and private-sector sales. 508 edition for US federal agencies and federally funded institutions. EU edition for European public-sector procurement. INT edition if you sell globally across all three markets. When in doubt, ask the procurement team that will receive your ACR which edition they require.
If your organization needs a VPAT based on a comprehensive WCAG audit conducted by senior accessibility practitioners, learn about our VPAT and ACR services.
Disclaimer: I am not an attorney. This content is for informational purposes only and should not be considered legal advice. Consult with a qualified attorney for guidance on specific legal issues.