The question almost always arrives at the worst possible moment. A contracting officer emails asking for “your VPAT” three days before award. Or an agency’s acquisition team is told the software they already selected cannot be purchased, because nobody documented whether it is accessible. Either way, the thing being asked for is an accessibility conformance report — and the confusion over what that is, who writes it, and which version to use derails more purchases than the accessibility gaps themselves.
A VPAT and an ACR are not the same thing
People use the two terms interchangeably and then talk past each other. The distinction is simple. The VPAT — Voluntary Product Accessibility Template — is the empty form. The ACR is the completed, tested, dated document. So when a solicitation asks for “a VPAT,” it is asking for a finished ACR; a blank template attached to a bid is not a response.
The current template version is VPAT 2.5, published by ITI in November 2023 and free to download from their site. It is what federal reviewers expect to see. If your report is still built on the 2001-era Section 508 structure, it needs to be rebuilt against the Revised Standards — those became the benchmark for altered ICT on January 18, 2018, and a report citing the superseded standards reads as expired rather than merely dated.
Pick the right edition — this is the most common rejection
VPAT 2.5 ships in four editions, and they are not interchangeable:
- Revised Section 508 edition — for U.S. federal procurement. This is the one for a federal agency, and in practice for the many state agencies and school districts that mirror the federal standard.
- WCAG edition — reports against WCAG 2.0, 2.1, and 2.2 only. Useful commercially, but it omits the 508-specific requirements a federal reviewer is checking.
- EN 301 549 edition — for the European Union.
- INT (International) edition — all of the above in one document. Longer, but it satisfies every audience at once.
The failure mode is predictable: a vendor hands a federal buyer a WCAG-edition report, the buyer needs 508 conformance documented, and the submission comes back incomplete with the clock running. If you are only going to maintain one report, the INT edition is the safest single artifact.
Need a conformance report you can defend — or need the gaps it will find fixed first? We test documents, websites, and video against the Revised 508 Standards and hand back a prioritized remediation plan with the evidence behind it.
What the Revised 508 Standards actually measure
Section 508 does not invent its own web rules. The Revised Standards, issued by the U.S. Access Board and codified at 36 CFR Part 1194, incorporate the WCAG 2.0 Level A and Level AA success criteria by reference and apply them to web content, electronic documents, and software. Note the version carefully: 508 points at WCAG 2.0, not 2.1. Because the guidelines are backward compatible, building to a newer version satisfies the older one — but the row you are being scored against is 2.0 A and AA.
Around that core, the 508 edition also asks about hardware, functional performance criteria, support documentation, and support services. That last pair catches a surprising number of otherwise-clean products: the application itself passes, and then the PDF user guide has no tags and the training video has no captions.
Four conformance terms — and where reports lose credibility
Every criterion gets one of four labels: Supports, Partially Supports, Does Not Support, or Not Applicable. The temptation is to write “Supports” down the entire column. Resist it. An experienced 508 program office reads a flawless report as an untested one, and a report that overstates conformance is worse than an honest one — it converts an accessibility gap into a misrepresentation sitting in your proposal file.
The credibility lives in the Remarks and Explanations column. “Partially Supports — three legacy report exports lack table headers; scheduled for the next quarterly release” is far stronger than a bare “Supports.” It shows the product was genuinely tested, it tells the buyer what to expect, and it gives them something they can put in their own acquisition file.
The exceptions agencies can use — and their limits
FAR Subpart 39.2 implements Section 508 in acquisition and carries a short list of carve-outs. The requirements do not reach national security systems, or incidental contract items — ICT a contractor acquires for its own in-house use in performing the contract. An agency may also grant an undue burden exemption, in which case conformance is required only to the extent it would not impose that burden.
Two things are worth knowing about these. First, they are the agency’s determinations to make and document, not a vendor’s to assert in a cover letter. Second, an undue-burden finding does not make the obligation vanish — the agency still has to provide comparable access by an alternative means. Planning to lean on an exception is rarely cheaper than fixing the product.
How long is an ACR good for?
Until the product changes. Any meaningful update to the ICT can change the answers, so the report should be revisited on roughly the same cadence as your release schedule. Buyers increasingly ask for the test date, the tooling and assistive technology used, and who performed the evaluation. A two-year-old report on a quarterly-release product invites exactly the question you do not want asked in the middle of an evaluation.
State and local buyers are heading the same direction
If you sell to cities, counties, or school districts, this conversation is arriving on their side too. The Department of Justice’s ADA Title II web and mobile rule sets WCAG 2.1 Level AA as the standard for state and local government digital content, with compliance dates of April 26, 2027 for larger public entities and April 26, 2028 for smaller ones. Procurement teams there are already starting to ask vendors for conformance documentation, for a straightforward reason: anything they buy becomes part of what they are on the hook to make accessible.
If the honest answer is “Partially Supports”
That is a normal place to be, and it is not disqualifying. An accurate report with a dated remediation roadmap beats a spotless report nobody believes. The work itself is finite: test against the criteria that actually apply, fix what fails, re-test, and document what you did. Tagging the PDFs, captioning the video, and repairing the templates that generate your document exports usually accounts for most of the column.
The reports that win business are the ones a reviewer can trust — real testing, specific remarks, the correct edition, and a date recent enough to mean something.