Two vendors bid on your accessibility audit. Both say “Section 508 compliant.” One hands you a 60-page export from an automated scanner. The other hands you a conformance report produced by a certified tester following a documented federal process, with each finding traced to a specific test procedure. Those are not the same deliverable, and only one of them will hold up when someone files a complaint.
What Trusted Tester actually is
The Department of Homeland Security maintains the Trusted Tester Conformance Test Process, a step-by-step manual inspection method for deciding whether web content conforms to the Revised Section 508 Standards. It grew out of the U.S. Access Board’s ICT Testing Baseline for Web, which defines the minimum set of checks a credible 508 test has to perform.
The point of the program is repeatability. Give the same page to five accessibility consultants using five different toolkits and you can get five different answers. Trusted Tester constrains the method — which tools, which keystrokes, which decision rules — so that two testers reach the same verdict on the same page. That is what makes a report defensible rather than merely opinionated.
Certification is earned through DHS training that ends in an exam; enrollment is free and a passing score is 85% or better. One detail worth knowing before you write requirements: a certification is tied to the version of the process the tester trained under. DHS published Trusted Tester for Web v5.1.3 in April 2024, and each new release can require supplemental training — so confirm the current version on section508.gov instead of freezing a number into a template solicitation.
Is it legally required?
No. Section 508 requires that federal ICT be accessible; it does not mandate any particular testing credential. What has happened instead is a practical convergence: because the process is standardized and free, many federal agencies have adopted it internally, and an agency that has adopted it will typically accept conformance results only from certified testers — including results submitted by contractors.
So the honest framing for a buyer is this. Trusted Tester is not a legal requirement. It is the closest thing the federal market has to a common yardstick, which means requiring it costs you nothing and removes an entire category of argument about whether the testing was real.
The version trap: 508 points at WCAG 2.0, Title II points at 2.1
This is the mistake we see most often, and it bites state agencies and school districts hardest.
The Revised Section 508 Standards incorporate WCAG 2.0 Level A and AA by reference, and the Trusted Tester process tests against those standards. But the DOJ’s ADA Title II web rule sets WCAG 2.1 Level AA as the technical standard for state and local government web content and mobile apps, with compliance dates of April 26, 2027 for larger public entities and April 26, 2028 for smaller ones.
WCAG 2.1 added success criteria that a strictly 2.0-scoped test will not evaluate — orientation, reflow, non-text contrast, text spacing, content on hover or focus, and the pointer and label criteria that matter most on phones. A clean Trusted Tester report is genuinely strong evidence, but it is not a Title II conformance statement. Ask your vendor in writing whether the scope includes the WCAG 2.1 AA criteria added after 2.0, and require the report to say so on its face.
Need a conformance report that covers both standards? We test to the Section 508 baseline and the WCAG 2.1 AA criteria the ADA Title II rule requires, then remediate what we find — websites, PDFs, Word, PowerPoint, and video.
What to put in the solicitation
Five clauses do most of the work. Adapt the wording to your own template:
- Named, certified testers. Require that manual conformance testing be performed by personnel holding current DHS Trusted Tester for Web certification, and require the proposal to name them — not just the firm. Certifications belong to people, and people leave.
- Method disclosure. Require the process and version used, plus a statement of how automated and manual testing were combined. Automated tooling alone inspects only a portion of the applicable requirements; the remainder has to be checked by a human, and the report should show which findings came from where.
- Standard and version, spelled out. State the target explicitly: Revised Section 508 Standards, WCAG 2.1 Level AA, or both. Do not write “508 compliant” and hope.
- Defined test scope. Name the page templates, the service-critical user flows (application, payment, enrollment, records request), the mobile breakpoints, and the document and video samples. An unscoped audit becomes a vendor’s choice of the easiest pages on your site.
- Findings mapped to criteria, with severity. Every issue tied to a specific success criterion, located, rated by user impact, and paired with a remediation recommendation — plus a re-test of the fixes. A prioritized findings list is what turns an audit into a schedule someone can execute.
Four questions that separate the bidders
- “Who specifically will test, and what version are they certified on?” Vague answers here predict vague deliverables.
- “Which findings will be manual and which automated?” A vendor who cannot describe the split is probably selling you a scanner export with a cover page.
- “Does your scope include the WCAG 2.1 AA criteria beyond 2.0?” The answer decides whether the report touches your Title II obligation at all.
- “Do you remediate, or only report?” Both models are legitimate. Knowing which one you bought before the report lands prevents a second procurement you did not budget for.
What Trusted Tester does not cover
Scope discipline matters. Trusted Tester for Web is exactly that — a process for web content. It is not a PDF or Office document remediation methodology, and a page-level test will not tell you whether the 900 untagged PDFs in your document library have a sensible reading order. It also will not judge whether your video captions are accurate, or whether audio description exists where visuals carry meaning that is never spoken aloud.
Those lanes are usually the larger share of the actual work. Under the Title II rule the PDFs and Word files you publish are web content, and document libraries are where most public entities discover the real size of the project. Plan your audit scope around all three lanes — pages, documents, and media — and treat the tester credential as the quality floor for the first one, not as coverage of all three.
The bottom line
Requiring Trusted Tester certification is cheap insurance: it costs a qualified vendor nothing to hold, it makes results comparable across bids, and it forecloses the “we ran a scan and it passed” deliverable. Then add one sentence naming WCAG 2.1 Level AA, and one defining scope across pages, documents, and video. Those three moves turn an accessibility procurement from a leap of faith into something you can actually evaluate — and, when a complaint arrives, something you can hand over.