A VPAT (Voluntary Product Accessibility Template) is a standardized document, published by the Information Technology Industry Council (ITI), that a vendor fills in to report how well a product meets accessibility standards, criterion by criterion. A VPAT that has been completed for a specific product is called an Accessibility Conformance Report, or ACR, and in practice people use “VPAT” for both. Buyers ask for one because United States federal agencies are required by Section 508 to consider accessibility when they purchase technology, and state governments, universities, hospitals and large enterprises have adopted the same habit. If you sell software, a web application, a platform or a digital service to any of them, you will be asked for a VPAT, and the quality of your answer affects whether you make the shortlist.

This guide explains what a VPAT contains, who asks for it, how it is completed honestly, what a good one looks like, and what to do if you have been asked for one and do not have it.

VPAT versus ACR: the terminology

  • VPAT is the blank template. The current version is VPAT 2.5Rev, dated April 2025. The name and the form are ITI registered service marks and the template is not supposed to be altered.
  • ACR (Accessibility Conformance Report) is the completed document for a specific product and version. When a procurement officer says “send us your VPAT,” they mean your ACR.
  • ITI publishes four editions of the template, and you pick the one that matches what the buyer needs: 508 (the revised Section 508 standards, for US federal buyers), EU (EN 301 549, for European public procurement), WCAG (WCAG 2.0, 2.1 and 2.2 only), and INT (all three combined, the safe choice for a vendor selling internationally).

Who asks for a VPAT, and why

  • Federal agencies. Section 508 of the Rehabilitation Act requires them to procure accessible information and communication technology, and the ACR is how vendors demonstrate it. No ACR usually means no consideration.
  • State and local governments. Most have adopted 508-style procurement rules, and the ADA Title II web rule (WCAG 2.1 AA, deadlines in 2027 and 2028) has made them more careful about the tools they buy, since a vendor’s inaccessible product becomes their compliance problem.
  • Colleges and universities. Higher education has been a target of accessibility complaints for a decade and procurement offices routinely require an ACR for any learning tool, portal or platform.
  • Healthcare organizations. The HHS Section 504 rule (deadlines May 2027 and May 2028) covers patient-facing digital tools, so hospitals and practices are starting to ask their vendors.
  • Enterprises. Large companies with their own accessibility policies ask for ACRs during vendor security and compliance review, alongside SOC 2 and privacy documentation.

If your customers are in any of those groups, an ACR is a sales document as much as a compliance one. Software companies we work with in medical imaging, telehealth and B2B SaaS get the request during procurement, often with a deadline attached.

What is in a VPAT

The template has a cover section and then one table per standard. The cover section records the product name and version, the report date, the contact for questions, the evaluation methods used (which tools, which screen readers, which browsers, who tested), and the applicable standards. It also has a legal disclaimer area and, critically, a notes area for scoping: which parts of the product were evaluated and which were not.

Each standards table lists every criterion (for WCAG, every success criterion at Level A, AA and AAA) with two columns to fill in:

  • Conformance level, one of four values: Supports (the functionality meets the criterion without known defects), Partially Supports (some functionality does not meet it), Does Not Support (most functionality does not meet it), or Not Applicable (the criterion is not relevant to the product).
  • Remarks and explanations, where you say what does and does not work, and how. For anything other than Supports, this column is mandatory in spirit and is what a knowledgeable buyer reads first.

A Level AA WCAG edition, then, is 55 rows of honest self-assessment, each backed by testing. That is why an ACR cannot be produced without an accessibility audit behind it.

How to complete a VPAT honestly

  1. Audit the product first. Automated scanning of every screen or template, then manual testing with a keyboard and at least one screen reader, against WCAG 2.2 AA (or the version the buyer names). Record which criteria pass, fail and do not apply, with locations. Our WCAG 2.2 checklist is the row-by-row list.
  2. Pick the edition and the standards. INT if you sell to government and abroad; WCAG if a buyer only asks about WCAG. Include the AAA rows even though they will mostly be Not Applicable or Does Not Support; the template expects them.
  3. Scope precisely in the notes. Name the product version, the modules covered, the platforms (web, iOS, Android) and anything excluded. An ACR for “the web app, version 4.2, excluding the legacy reporting module” is credible; one for “the product” is not.
  4. Fill in each row from the audit findings. Use Partially Supports freely and explain: “Custom date picker is not operable by keyboard; a text entry alternative is provided.” Buyers expect partial support. What they do not accept is a page of Supports followed by a screen reader that cannot get past the login.
  5. Document the evaluation methods. Tools, screen readers and versions, browsers, dates, and whether testing was internal or by a third party. Third-party testing carries more weight.
  6. Date it, version it, and set a review date. An ACR describes a product version at a point in time. Update it with each significant release, and at least annually.
  7. Publish it. Put it on an accessibility page on your site next to your accessibility statement. Buyers look there before they ask.

What makes a good ACR (and what makes a bad one)

Procurement officers and accessibility reviewers read many of these, and the patterns are well known.

  • Good: specific scope, named testing methods, a realistic mix of Supports and Partially Supports, remarks that describe the actual defect and any workaround, a roadmap note for known gaps, a recent date, a real contact.
  • Bad: Supports in every row; remarks left blank; no evaluation method; no version or date; an ACR that describes a marketing website rather than the product being bought; an ACR produced by a sales team without testing.
  • Disqualifying: relying on an accessibility overlay to claim conformance. In April 2025 the Federal Trade Commission finalized a $1 million order against the overlay vendor accessiBe for claiming its widget could make any website WCAG compliant, and barred it from making such claims without evidence. An ACR that rests on a widget rests on a claim the FTC has already rejected.

Does a website need a VPAT?

Usually not, and the distinction matters. A VPAT describes a product a buyer is acquiring: software, a platform, an app, a device, a digital service. A company’s marketing website is not something a buyer procures, so nobody asks for a VPAT for it; they expect it to be accessible under the ADA, and they may ask for an accessibility statement. If you sell a web-based product, the product needs the ACR, and the product’s own accessibility is what gets tested.

The exception is when the website is the product: a portal, a learning platform, a patient-facing scheduling tool, an e-commerce system sold to others. In those cases the ACR covers the application, and the same audit that produces it also proves the site’s ADA conformance. Our ADA compliance services cover both.

How long it takes and what it costs

The ACR itself is a few hours of writing once the audit exists. The audit is the work, and its cost depends on the number of screens, templates and flows in the product, the number of platforms, and how deep the manual testing goes, not on page count. For a typical web application, expect the audit to take one to three weeks and the ACR to follow within days of it. Budget for a re-test and an updated ACR after the fixes, because the first ACR for a product that has never been audited will contain more Partially Supports than anyone would like to publish, and the second one is the one you want buyers to see.

If a buyer has given you a deadline you cannot meet, an honest interim ACR with clear remarks and a dated remediation roadmap is far better received than a rushed one full of Supports.

Frequently asked questions

Is a VPAT legally required?

No law requires a vendor to produce one. Section 508 requires federal buyers to procure accessible technology, and the ACR is the accepted way to show it, so in practice it is required to sell to them. State, education, healthcare and enterprise buyers require it by policy rather than by statute.

Who should complete the VPAT: us or a third party?

ITI’s own guidance is that the manufacturer is usually the best source to run the testing, because it knows the product. Many vendors have a third party run or verify the audit and then complete the ACR themselves, and note the third-party involvement in the evaluation methods. Independent testing is what buyers weight most.

What is the difference between Supports and Partially Supports?

Supports means the functionality meets the criterion with no known defects, or with defects so minor they do not affect use. Partially Supports means some functionality meets it and some does not; the remarks must say which. Does Not Support means most of the functionality fails. Not Applicable means the criterion does not apply (for example, captions when the product contains no video).

Which WCAG version should the VPAT reference?

Test and report against WCAG 2.2, which the 2.5Rev template supports. Because 2.2 includes all of 2.1 and 2.0, a buyer whose policy names 2.1 or 2.0 can read it directly. If a buyer’s template or policy names a specific version, match it.

How often should an ACR be updated?

With every major release, whenever a reported defect is fixed, and at least once a year regardless. Include the product version and the report date on the cover so a buyer can see at a glance whether it describes what they are buying.

Need an ACR you can send to procurement?

We audit web applications against WCAG 2.2 AA with automated and manual testing, fix what we build, and produce the conformance report your buyers are asking for, with the evaluation methods and scope stated the way reviewers expect.

Book a Discovery Call →

or call 919-200-0201

Sources