Skip to content
Back to blog
VPATSection 508WCAGprocurement

What is a VPAT and how to fill one out

What a VPAT is, who publishes it, and how to fill one out: the four conformance levels, the three-column format, and what a scanner can't do.

P

Pavel Charkasau

A VPAT is a Voluntary Product Accessibility Template: a standard form you fill in to document how accessible your product is, criterion by criterion. It is published and maintained by the Information Technology Industry Council (ITI), and the current version is VPAT 2.5 Rev, released in April 2025 (ITI). Once you complete it for a specific product, the filled-in document has a different name: an Accessibility Conformance Report, or ACR (Section508.gov). Buyers, especially US federal agencies and universities, ask for that ACR during procurement to check what your product supports before they purchase it.

Filling one out is mechanical once you know the shape. You download the right edition, complete the title page, then work down a three-column table: the success criterion, your conformance level, and a remarks column that explains anything that isn't a clean pass (Section508.gov). The hard part is not the form. It is testing honestly enough that the four conformance levels you write down are true, because a scanner cannot judge most of them for you.

What is a VPAT?

The VPAT is a template, not a law and not a certification. ITI created it so vendors could report accessibility in a consistent format that procurement teams recognize on sight (ITI). Before it existed, every vendor described accessibility their own way, and buyers had no way to compare two products on the same terms.

It started life tied to US federal procurement under Section 508 of the Rehabilitation Act, which requires federal agencies to buy accessible information and communication technology. It has since spread well beyond the US government. Private companies, state agencies, and universities now ask for a VPAT as a matter of routine, and the same template covers European requirements too.

One thing the VPAT is not: proof that your product is accessible. It is your documented account of how the product measures against a standard. An honest VPAT that reports real gaps is worth more than a spotless one nobody can back up, and I will come back to why that distinction matters legally.

What is the difference between a VPAT and an ACR?

The VPAT is the blank template. The ACR is what you get after you fill it in. Section508.gov puts it plainly: "the VPAT® with documented testing results is referred to as an Accessibility Conformance Report (ACR)" (Section508.gov).

In everyday conversation people say "send me your VPAT" when they mean "send me your completed ACR." The distinction still matters when a buyer is precise, because an empty template proves nothing. What a contracting officer actually evaluates is the ACR: the version with your product's name on the title page and a conformance level filled in on every applicable row.

Which VPAT edition should you use?

VPAT 2.5 comes in four editions, and picking the wrong one is the most common mistake I see. Each edition maps to a different legal or regional standard (ITI):

  • 508 edition — the Revised Section 508 standards, which incorporate WCAG 2.0 Level A and AA. Use this for US federal sales.
  • EU editionEN 301 549, the European standard that underpins the European Accessibility Act, built on WCAG 2.1.
  • WCAG edition — WCAG on its own, covering 2.0, 2.1, and 2.2, with no regional law attached.
  • INT edition — the international one, which folds all three of the above into a single report.

For a US government contract, Section508.gov says vendors must use the Revised Section 508 edition or the INT edition (Section508.gov). If you sell into both the US and the EU, the INT edition saves you from maintaining two separate reports; you fill in one document and it answers both markets. If your buyer is a European public body, the EU edition is what they expect.

How do you fill out a VPAT?

Section508.gov breaks the process into six steps, and they are worth following in order (Section508.gov):

  1. Download the current template from ITI in the edition your buyer needs.
  2. Complete the title page. Product name, version, your company and contact details, the report date, and the evaluation methods you used. This last field matters: a buyer reads "tested with NVDA and VoiceOver, plus axe-core" very differently from a blank.
  3. Learn the three columns. Every criterion row has the criterion itself, a Conformance Level, and a Remarks and Explanations column.
  4. Fill in the success criteria tables. For web content, that means the WCAG Level A and AA rows that apply to your product.
  5. Work through the other applicable chapters. The Section 508 standards cover more than web pages, so if you ship software, hardware, or documentation, those chapters apply too.
  6. Run the final checklist to confirm nothing applicable was left blank.

The three-column row is where the real work lives. For WCAG 1.4.3 Contrast (Minimum), you write the conformance level in the middle column and, if it is anything short of a clean pass, explain the gap in the remarks. Remarks are required when you report Partially Supports or Does Not Support, and encouraged even when you report Supports (Section508.gov). A row that says "Partially Supports" with an empty remarks cell is not finished.

What do the four conformance levels mean?

You describe each criterion using one of exactly four phrases. The definitions come straight from Section508.gov (Section508.gov):

  • Supports — the product has at least one method that meets the criterion without known defects, or meets it with equivalent facilitation.
  • Partially Supports — some functionality of the product does not meet the criterion.
  • Does Not Support — the majority of product functionality does not meet the criterion.
  • Not Applicable — the criterion is not relevant to the product.

The temptation is to round everything up to Supports. Resist it. A contracting officer who finds one obviously broken thing that your ACR marked "Supports" now has a reason to distrust the whole document. "Partially Supports, remediation planned for Q2" is a defensible sentence. An inflated "Supports" that a five-minute keyboard test disproves is not.

Can a scanner fill out a VPAT for you?

No, and this is the honest limit worth stating before you promise a buyer anything. Automated tools find a real share of accessibility issues, but not most of them. Deque's analysis of more than 2,000 audits found automation identified about 57% of issues by volume, while estimates based on the share of success criteria a tool can even evaluate put the figure closer to 30% (Deque). Whichever number you use, a large part of WCAG can only be confirmed by a person with a keyboard and a screen reader: whether alt text is meaningful, whether focus order makes sense, whether an error message actually tells a screen-reader user what went wrong.

That gap is the whole reason a VPAT asks a human to attest to each criterion instead of pasting a tool's score. It is also why overpromising here carries real risk. In 2025 the Federal Trade Commission approved a final order requiring the overlay vendor accessiBe to pay $1 million over claims that its product could make websites WCAG compliant (FTC). A VPAT you send to a federal agency is a representation to the government, so an inflated conformance claim is worse than a marketing overstatement.

The method that holds up is unglamorous. Run a scanner to clear the machine-detectable issues fast, test the rest by hand, and write each conformance level to match what you actually found. Our WCAG checklist tracks the Level A and AA criteria and marks which ones are new in 2.1 and 2.2, so you can see exactly which rows still need a human check before you sign the report. If you are also documenting where your public site stands under the ADA or the EAA, the same evidence feeds both.

Frequently asked questions

What is a VPAT?

A VPAT, or Voluntary Product Accessibility Template, is a standard form published by the Information Technology Industry Council (ITI) that documents how a product conforms to accessibility standards such as WCAG and Section 508. Once completed for a specific product, it becomes an Accessibility Conformance Report (ACR).

What is the difference between a VPAT and an ACR?

The VPAT is the blank template; the ACR is the completed version with your product's testing results filled in. Section508.gov defines the VPAT with documented testing results as an Accessibility Conformance Report. Buyers evaluate the ACR, not the empty template.

Which VPAT edition do I need?

For US federal sales, use the Revised Section 508 edition or the INT (international) edition. Use the EU edition for European buyers who follow EN 301 549, the WCAG edition when no regional law applies, and the INT edition when you want one report to cover the US, the EU, and WCAG at once.

What are the four VPAT conformance levels?

Supports, Partially Supports, Does Not Support, and Not Applicable. You assign one to each applicable success criterion, and you must add a remark explaining any criterion you mark Partially Supports or Does Not Support.

Can a tool generate a VPAT automatically?

Not a trustworthy one. Automated testing catches roughly 30 to 57% of WCAG issues, so the rest of the report needs a human to test and attest. A VPAT is a signed representation of conformance, and an inflated one sent to a federal buyer creates real legal exposure.

Start with a real baseline

A VPAT is only as good as the testing behind it, so start by measuring your product against the standard instead of guessing. Run a free scan to surface the machine-detectable issues on your key pages, then work through the manual checks a scanner cannot judge. You will have honest evidence to fill in each conformance level from, rather than a number you cannot defend to a contracting officer.


Pavel Charkasau, founder, wcagc.com. Last updated 12 August 2026.

Sources