In 2024 the U.S. Department of Justice finalized a rule that, for the first time, sets a specific, enforceable technical standard for state and local government websites and mobile apps. If you work for a government agency, city, county, school district, or special district, this rule almost certainly applies to you — and the clock is running.
What the rule actually requires
The standard is WCAG 2.1 Level AA. That means your web content and mobile applications must satisfy every Level A and Level AA success criterion — covering color contrast, keyboard operability, text alternatives, captions, form labels, consistent navigation, and dozens of other testable requirements. This is not “make a reasonable effort”; it is a specific, measurable conformance target.
Who is covered, and by when
- Entities serving 50,000+ population: compliance by April 26, 2027.
- Entities serving fewer than 50,000, plus special district governments: compliance by April 26, 2028.
“State and local government” is broad: state agencies, counties, cities, towns, public school districts, public colleges and universities, courts, transit authorities, water and library districts, and other special-purpose districts are all Title II entities.
What content is included
The rule reaches further than most people expect:
- Your public website and every page on it.
- Mobile apps you offer to the public.
- PDFs and other documents — benefit forms, agendas, policies, permits, and reports are all “web content.” This is where most agencies have the largest backlog.
- Third-party content that is used to provide a government service (for example, an online payment or permitting portal).
The limited exceptions
There are narrow exceptions — do not treat them as loopholes. They include certain archived web content (kept only for reference, not currently used), pre-existing electronic documents that are not used to apply for or access a service, content posted by third parties who are not under the entity's control, and individualized documents about a specific person that are password-protected. Everything that helps a member of the public access a program, service, or activity is in scope.
Have thousands of PDFs and no inventory of which ones fail? We remediate and tag document libraries at scale and document the work so it stands up as evidence of good-faith progress toward the deadline.
Where to start (a five-step plan)
- Inventory. List your websites, apps, and document libraries. You cannot remediate what you have not counted.
- Audit. Run automated scans, then manual keyboard and screen-reader testing, and map every finding to a WCAG 2.1 AA criterion.
- Prioritize. Fix the content that gates access to services first — the online forms, benefit applications, and high-traffic pages — then work down by impact.
- Remediate. Fix the site, tag the documents, caption the video, and re-test.
- Document. Keep records of your audit, your plan, and your progress. If a complaint arrives, that paper trail is your strongest defense.
Why documentation matters as much as the fixes
Enforcement rarely punishes an organization that is demonstrably working the problem. It targets the ones with no plan, no audit, and no records. Even a documented automated scan paired with a written remediation schedule shows good-faith effort. Start the paper trail now — well before April 26, 2027.