Score a vendor's ACR: a 12-flag rubric for procurement reviewers
Where federal guidance stops
You are holding two vendor ACRs for the same product category, the award schedule has not moved, and you have to write down a decision that survives a debrief if the unsuccessful offeror protests. Federal guidance tells you the report has to be complete. It does not tell you how to rank two complete reports against each other.
GSA runs a 30-minute course on soliciting and evaluating ACRs, written for purchase card holders, contracting officers and CORs, requiring officials and approving officials, and for the vendors on the other side of the buy. Its five stated objectives run from describing why an ACR matters, through determining when to request one and writing one, to judging whether one is complete. Judging completeness is where they stop. Scoring and ranking are not on the list, and the course page does not publish the criteria behind the completeness judgment. One commercial service sells an ACR evaluator that scores completeness, consistency, credibility and standards alignment, and does not publish the rubric behind those four words.
What follows is a rubric published in full, weights included, so a reviewer can apply it to the report in front of them and defend it line by line. The weights are ADACP’s. Nothing in the Revised 508 Standards, FAR part 39, or Section508.gov’s buy-side guidance assigns points to an ACR, so when you use these weights, say in the file that they are a firm’s instrument applied consistently across offerors and not a federal scoring scheme.
The decision you are actually making
Four outcomes, and the evidence in the report has to pick one.
Accept the ACR as adequate evidence of conformance. Section508.gov’s buy-side guidance tells agencies to require a written ACR for each standard COTS or GOTS ICT item, and states that to be considered for award, the ACR must be complete and submitted according to the instructions. Completeness is an award condition, not a quality observation.
Return it as incomplete. Same lever, used the other way. An incomplete report is not a weak proposal, it is a proposal that has not met a stated condition.
Accept with documented risk and a dated remediation commitment in the contract. The same guidance treats remediation plans for features that do not fully conform, and broader accessibility improvement plans, as items an agency can require in the solicitation. That is the legitimate route to a dated commitment.
Escalate to hands-on testing. Agencies are advised to state in the solicitation that they reserve the right, before an award decision, to test some or all of an offeror’s proposed ICT items to ensure the accuracy of their response, and to require final commercially available release versions plus an accessibility test plan when they do. An ACR is a vendor claim you may verify, not a finding you must accept.

View the data as a list
Four outcomes for one ACR: Four outcomes, and the evidence in the report has to pick one
- Accept as adequate evidence: Complete and submitted per the instructions is an award condition
- Return it as incomplete: Not a weak proposal, a proposal that has not met a stated condition
- Accept with documented risk: A remediation plan the solicitation can require, with a dated commitment
- Escalate to hands-on testing: Reserve the right to test the offered ICT items before the award decision
Underneath all four sits FAR 39.203(a): “Unless an exception at 39.204 or an exemption at 39.205 applies, acquisitions for ICT supplies and services shall meet the applicable ICT accessibility standards at 36 CFR 1194.1.” The exceptions at 39.204(a) are three and they are narrow: national security systems, ICT a contractor acquires incidental to a contract for its own in-house use in performing that contract, and operable parts or status indicators located in spaces frequented only by service personnel. None of them covers the deliverable itself.
The edition check that comes first
Score nothing until the edition clears. Section508.gov tells vendors that if they are selling to the US federal government they must use the Revised Section 508 edition or the INT International edition of the template, which includes all Revised Section 508 requirements. An EU-edition or WCAG-edition ACR submitted against a federal solicitation is the wrong instrument regardless of how carefully it was filled in.
Do not read the WCAG version off the edition name. Only the 508 edition pins a single version. In VPAT 2.5Rev, published by ITI in April 2025, the Revised Section 508 edition covers WCAG 2.0 and the Revised Section 508 standards published January 18, 2017 and corrected January 22, 2018. The WCAG edition carries WCAG 2.0, 2.1 and 2.2 tables. The EU edition carries WCAG 2.0 and 2.1. The INT edition carries all three WCAG versions plus Revised Section 508 plus EN 301 549 at V3.1.1 (2019-11) and V3.2.1 (2021-03). ITI’s summary line that WCAG 2.2 is incorporated into the WCAG and INT editions names the newest version present, not the only one.

View the data as a table
| Revised 508 edition | WCAG edition | EU edition | INT edition | |
|---|---|---|---|---|
| WCAG versions in its tables | WCAG 2.0 | WCAG 2.0, 2.1 and 2.2 | WCAG 2.0 and 2.1 | All three WCAG versions |
| Pins one WCAG version | Yes, WCAG 2.0 | No, three versions in one edition | No, two versions in one edition | No, three versions in one edition |
| Accepted for a US federal solicitation | Yes | No, the wrong instrument | No, the wrong instrument | Yes |
To learn what a vendor actually claimed, read the report’s own Applicable Standards/Guidelines statement and check it against the tables the document contains. The template requires a clear indication of which standards the report covers, and it lets the vendor put that indication in a table at the top of the report or in the introductory text instead. Prose is not a defect.
Edition mismatch is a gate, not a scored flag. If it fails, the twelve flags below are moot and the remedy is trigger 1 in the tree.
The twelve flags, with weights
Award the full weight when the flag is clean, half when it is partly satisfied, zero when it fires. A clean report totals 100. The weights reflect how much each defect degrades the report as evidence, not how hard it is to fix.
| # | Flag | What to ask the vendor | Weight |
|---|---|---|---|
| 1 | Applicable Standards/Guidelines indication absent, or inconsistent with the edition used | Restate, in a table or in the report’s introductory text, which standards and which WCAG version and level this report covers | 8 |
| 2 | Federal 508 obligations not reported (a WCAG-only claim against a 508 buy) | Supply the applicable Revised 508 tables, Chapter 4 for hardware, Chapter 5 for software, Chapter 6 for support documentation and services, rather than a newer WCAG version in their place | 10 |
| 3 | Report date or product version does not match the release being offered | An ACR for the exact final commercially available release proposed, or a written statement that the tested build and the offered build are identical | 8 |
| 4 | ”Not Evaluated” appearing on a Level A or Level AA success criterion | Test the criterion and report a conformance level; “Not Evaluated” is restricted to Level AAA | 8 |
| 5 | A “Supports” row whose own remark leaves no conforming method standing | Ask which is wrong, the level or the remark, and require a corrected report | 12 |
| 6 | Thin or missing remarks on “Partially Supports” and “Does Not Support” rows | Name the function or feature with the issue, how it fails, and any accessible alternative in use | 12 |
| 7 | ”Evaluation Methods Used” absent or non-responsive | Populate the required element with a description of how the product was tested | 12 |
| 8 | Assistive technologies and testing tools not named | List the assistive technologies and tools used, with versions, through the Supplemental Accessibility Report | 4 |
| 9 | Chapter 3 Functional Performance Criteria not answered where Chapters 4 and 5 leave a function uncovered | Complete the Chapter 3 table, 302.1 through 302.9, for the functions Chapters 4 and 5 do not address | 10 |
| 10 | No Supplemental Accessibility Report | Supply the SAR: evaluation methods, accessibility features, core functions that cannot be used by persons with disabilities, and configuration and installation guidance | 8 |
| 11 | No contact information for follow-up questions | Give a route to someone who can answer questions about the data in the report | 4 |
| 12 | Material deviation from the template’s essential requirements | Reissue on an unaltered template; deviating from the Essential Requirements precludes the vendor from referencing the template by name or the VPAT acronym | 4 |
Seven of these need explaining before you can defend a zero.
Flag 4 is a template violation, not a judgment call. The template’s Terms section restricts “Not Evaluated” to WCAG Level AAA criteria, and Section508.gov’s sell-side guidance says the same thing for the same reason: the Level AAA table is the only success criteria table that is not required to be completed. A Level A or AA row carrying it means the vendor did not test something the report is supposed to answer.
Flag 5 turns on the definitions the report itself states. The template requires every ACR to list the definitions used in its Conformance Level column, and it recommends ITI’s: “Supports” means the functionality of the product has at least one method that meets the criterion without known defects, or meets it with equivalent facilitation. A vendor may deviate from those definitions provided the deviation is declared in the heading Notes, so read the report’s own Terms section and Notes before you reach for ITI’s wording.
Applied to that definition, the flag is narrower than it first looks. A remark naming a defect in one of several methods, or a documented workaround alongside a path that still conforms, is not a contradiction, and ITI’s best-practice guidance tells authors to put known workarounds in the remarks. Fire the flag only when no conforming method survives the remark: a defect in the only method available, or a fix scheduled for a future release, is describing “Partially Supports” while the level column says “Supports”. That is the one defect where the vendor’s own document supplies both sides of the argument. It does not tell you why the two disagree, so ask rather than assume.
Flag 6 is scorable because the template makes it so. Detailed remarks are there to justify the answer in the Conformance Level column, and for “Partially Supports” or “Does Not Support” the instructions say the remarks should identify the functions or features with issues and how they do not fully support, explain why a criterion does not apply, and describe any accessible alternative in use. Section508.gov’s sell-side guidance agrees: remarks are required for those two levels and encouraged, not required, for “Supports”. A remark reading “some issues identified” satisfies neither.
Flag 7 is a missing required field, and only that. “Evaluation Methods Used, include a description of evaluation methods used to complete the VPAT for the product under test” is one of the template’s minimum content elements, sitting alongside report title, template version, product name and version, report date, product description, contact information, notes and the applicable standards indication. Its absence is a hard defect, which is why it carries a full 12. Score the field, not its richness. Naming a published test method with its publisher and URL, or a proprietary method with the vendor and the non-proprietary details, sits in Best Practices for Authors rather than the Essential Requirements. A vendor who wrote “manual and automated testing” has populated the required element. That is thin, and the place to press for more is the Supplemental Accessibility Report, which the buy-side guidance says should describe the evaluation methods used to produce the ACR, to demonstrate due diligence in supporting conformance claims.
Flag 8 is deliberately weighted low, and here is why. Naming the assistive technologies and the testing tools sits in the template’s Best Practices for Authors and is marked optional there. Your demand for it has to come from the solicitation, and the SAR is where it belongs, since the buy-side guidance already requires a SAR describing evaluation methods for each standard COTS or GOTS item. Cite the solicitation for the requirement and the ACR only for the absence. Getting that backwards is how a reviewer loses an argument with a capture manager.
Flag 9 is conditional, which is what keeps it defensible. E204.1 of the Revised 508 Standards: “Where the requirements in Chapters 4 and 5 do not address one or more functions of ICT, the functions not addressed shall conform to the Functional Performance Criteria specified in Chapter 3.” There are four Revised 508 tables in the template: Chapter 3 for Functional Performance Criteria, Chapter 4 for hardware, Chapter 5 for software, and Chapter 6 for support documentation and services. Chapter 3 holds nine criteria, 302.1 Without Vision through 302.9 With Limited Language, Cognitive, and Learning Abilities. A missing Chapter 3 answer is a gap only when the product has functions Chapters 4 and 5 do not reach. Establish that first, then fire the flag.
Flag 11 has a low bar and you should score it at that bar. Contact information is an Essential Requirement, and the template’s own words are that listing an email is sufficient. A vendor who supplied a shared accessibility inbox has met the requirement and will say so. Score zero only when the report gives no route to anyone. A named accountable owner is worth having, and like flag 8 it is a solicitation demand rather than a report defect.
Two rules on top of the total
The evidence cap. If flag 5, 6 or 7 scores zero, cap the total at 64 no matter what the arithmetic says. A report whose remarks leave its levels unsupported, or that never states how the product was tested, is not evidence of conformance. It is a set of assertions with a template around them. The template puts it plainly: it is the vendor’s responsibility to maintain the integrity of the data in the report. There is no VPAT certification to fall back on.
The gate, before the bands. If the edition gate failed, do not score. Go to trigger 1 in the rejection-remedy tree.
The bands. These are ADACP’s thresholds, offered so that your file records a rule applied consistently across offerors rather than a per-vendor impression.
| Total | Disposition |
|---|---|
| 85 to 100 | Accept as adequate evidence of the claims made |
| 65 to 84 | Accept with the gaps documented and a dated remediation commitment written into the contract |
| 40 to 64 | Return to the offeror as incomplete against the solicitation’s ACR instructions |
| Below 40 | Reject, or exercise the reserved right to test before award |
The blank score sheet
| Flag | Weight | Offeror A | Offeror B |
|---|---|---|---|
| 1 Standards indication | 8 | ||
| 2 508 obligations reported | 10 | ||
| 3 Date and version match | 8 | ||
| 4 No “Not Evaluated” below AAA | 8 | ||
| 5 Levels survive their remarks | 12 | ||
| 6 Remark specificity | 12 | ||
| 7 Evaluation methods stated | 12 | ||
| 8 AT and tools named | 4 | ||
| 9 Chapter 3 FPC answered where required | 10 | ||
| 10 SAR supplied | 8 | ||
| 11 Contact information | 4 | ||
| 12 Unaltered template | 4 | ||
| Total | 100 |
Two real reports, scored
Both of the reports below are publicly published ACRs for learning management systems, both dated March 2025, scored against the twelve flags exactly as defined above. They are described by category and date rather than by vendor, because the point is the instrument and not a verdict on a named company. Offeror A published on the VPAT 2.5 INT edition and had its report tied back by a third-party auditor. Offeror B published on the VPAT 2.5 Revised Section 508 edition and self-reported.
| Flag | Weight | Offeror A | Offeror B |
|---|---|---|---|
| 1 Standards indication | 8 | 8 | 4 |
| 2 508 obligations reported | 10 | 5 | 5 |
| 3 Date and version match | 8 | 8 | 4 |
| 4 No “Not Evaluated” below AAA | 8 | 8 | 8 |
| 5 Levels survive their remarks | 12 | 6 | 0 |
| 6 Remark specificity | 12 | 12 | 6 |
| 7 Evaluation methods stated | 12 | 12 | 12 |
| 8 AT and tools named | 4 | 2 | 0 |
| 9 Chapter 3 FPC answered where required | 10 | 10 | 10 |
| 10 SAR supplied | 8 | 4 | 0 |
| 11 Contact information | 4 | 4 | 4 |
| 12 Unaltered template | 4 | 4 | 2 |
| Total | 100 | 83 | 55 |
Offeror A lands in the 65 to 84 band: accept, with the gaps documented and a dated remediation commitment written into the contract. Offeror B lands in 40 to 64: return as incomplete against the solicitation’s ACR instructions. Twenty-eight points separate two reports for the same class of product in the same month, and none of that gap is about how accessible the two products are. It is about how much of each report a reviewer can rely on.
Four of the rows are worth walking through, because they are where a reviewer’s judgment actually gets tested.
Flag 5 fires on B and only halves A, and that asymmetry is the rule working correctly. B has three “Supports” rows whose own remarks describe a defect in the only method available, with no alternative path documented anywhere in the report. That is the narrow fire condition. A has two rows where a defect appears under a “Supports” level, but its Features block documents a surviving conforming path, so the flag does not fire. A still loses half, for a different and more interesting reason: the same underlying defects are reported as “Partially Supports” at 1.3.1, 4.1.2 and 3.3.3 while appearing as mere exceptions under 302.7 and 302.9. The document supplies both sides of the argument on an identical fact. That is unanswerable except by a corrected report, and the affected functions are page-scoped rather than absent, which is why it costs six points and not twelve.
Flag 2 is a half on both, for the same structural reason. Neither report displaces its 508 obligations with a WCAG-only claim: both answer Chapter 3 and Chapter 6 and both cross-walk 501.1, 504.2 and 602.3 into their WCAG rows. What neither supplies is a standalone non-web software table. Both dismiss it with the same sentence, that the platform is a web app, and in A’s case that sits awkwardly beside a scope line that includes a mobile app and beside its own exception rows describing missing keyboard access inside that app on iOS. A half is right. A zero would overstate it.
Flag 4 is clean on both, and that is worth stating because it is easy to get wrong. “Not Evaluated” appears in both documents, but only inside the Terms definitions, never in a Level A or AA row. The flag tests where the string lands, not whether it appears.
Flag 10 separates them even though neither report has a Supplemental Accessibility Report. The word “Supplemental” appears in neither document. What differs is how much of the SAR’s content survives elsewhere. A carries three of the four elements inside the ACR itself, including a described evaluation method and a route to feature documentation, so it loses half. B carries only the evaluation-methods element and affirmatively reports its support documentation as non-existent, so the flag fires. Score the content, not the heading.
B’s missing Level A row costs points at flag 12, not flag 4. B omits 3.3.2 Labels or Instructions entirely from a table it declares it covers, and seventeen of its twenty-three Level AAA rows still carry the raw template placeholder in both the conformance and remarks columns. Both defects are deviations from the template’s essential requirements, which is flag 12’s job. Counting the missing row at flag 4 as well would charge the same omission twice.
The rejection-remedy tree
Five triggers, and for each one the remedy, the evidence that goes in the file, and the language to fall back on if the vendor will not move. Nothing here renegotiates a conformance level. A level is a reported test result and the vendor owns it. What is negotiable is remark accuracy, stated test scope, disclosed methods, named assistive technologies, and a dated commitment.
| Trigger | Remedy | Evidence to file | Fallback commitment |
|---|---|---|---|
| 1. Wrong edition for a federal solicitation | Request reissue on the Revised 508 or INT edition | The edition statement and the Applicable Standards/Guidelines indication from the submitted report, with the solicitation’s ACR instruction | Offeror reissues on a 508 or INT edition before award; the reissued report replaces the submitted one as the conformance record |
| 2. Chapter 3 FPC not answered where Chapters 4 and 5 leave functions uncovered | Identify the uncovered functions, request the Chapter 3 table for 302.1 through 302.9 | Your written finding of which product functions Chapters 4 and 5 do not address, cited to E204.1 | Offeror supplies the Chapter 3 table within the exchange period; unanswered criteria are treated as unreported, not as conforming |
| 3. A “Supports” row left unsupported by its own remark | Ask which is wrong, the level or the remark, and require a corrected report | The row itself, the definitions the report states in its Terms section, and the vendor’s reply | Corrected ACR supersedes the submitted version; where the level moves, the remediation date moves into the contract with it |
| 4. No test method stated | Require the SAR’s description of evaluation methods | The blank or generic “Evaluation Methods Used” section, which is a missing minimum element, plus the solicitation’s SAR requirement if one was included | Offeror supplies the SAR before award, or the agency exercises its reserved right to test the offered release |
| 5. Assistive technologies and tools not named | Request them through the SAR, not as a template requirement | The SAR clause and the vendor’s response | Offeror names the assistive technologies and tools used, and the agency records which claims were never exercised against real AT |
If your solicitation never asked for a Supplemental Accessibility Report, triggers 4 and 5 are your office’s gap rather than the vendor’s, and the fix belongs in the next solicitation. On what gets tested: the buy-side guidance tells agencies to require final commercially available release versions for hands-on testing, and suggests stating in the solicitation that trial versions will not be considered, since features may not yet be present and the results would not be accurate.
Three things reviewers over-flag
An empty or absent Level AAA table. Section508.gov tells vendors to skip the Level AAA tables because Section 508 does not require testing against them, while noting a vendor may include them voluntarily to show a higher level of accessibility. Flagging their absence penalizes a vendor for following federal guidance.
A template version number below 2.5Rev. Section508.gov’s sell-side guidance states that any VPAT 2.x is acceptable, and that page still names 2.4 as the current version while ITI publishes 2.5Rev. The page lags ITI, which is exactly why “reject anything not on the newest template” is indefensible in a debrief. Score the edition and the report date instead. Treat the version number as informational.
A WCAG 2.2 claim, where the question is whether 508 was answered. This one is a half-flag rather than a non-flag. The Revised 508 Standards incorporate WCAG 2.0 by reference at E205.4: “Electronic content shall conform to Level A and Level AA Success Criteria and Conformance Requirements in WCAG 2.0.” A vendor reporting WCAG 2.2 has done more than 508 asks for electronic content and may still not have answered your solicitation. In the 508 edition, the WCAG tables answer 501.1 and 504.2 in Chapter 5 and 602.3 in Chapter 6, and nothing else. The platform accessibility services at 502.3, the caption and audio description controls at 503.4, the alternate-format duty at 602.4, and the whole of Chapter 4 hardware have no WCAG counterpart at any version. For a hardware or kiosk buy, Chapter 4 is the primary obligation. Score whether the 508 obligations were reported, not whether the newest WCAG version was used.

View the data as a table
| Do | Don’t |
|---|---|
| Recognize that Section 508 does not require testing against the Level AAA criteria, which vendors are told to skip | Flag an empty or absent Level AAA table, which federal guidance tells vendors to skip |
| Score the edition and the report date instead, and treat the version number as informational | Reject anything not on the newest template, when the sell-side guidance accepts any VPAT 2.x |
| Score whether the 508 obligations were reported, not whether the newest WCAG version was used | Score the report on which WCAG version it used rather than on what it answered |
When every offeror fails the same criterion
Sometimes the field is the problem, not the vendor. E202.7 of the Revised 508 Standards: “Where ICT conforming to one or more requirements in the Revised 508 Standards is not commercially available, the agency shall procure the ICT that best meets the Revised 508 Standards consistent with the agency’s business needs.”
E202.7.1 is the provision that turns that into paperwork. The responsible agency official has to document in writing “(a) the non-availability of conforming ICT, including a description of market research performed and which provisions cannot be met, and (b) the basis for determining that the ICT to be procured best meets the requirements in the Revised 508 Standards consistent with the agency’s business needs.” FAR 39.205(c)(3) carries a parallel requirement for the nonavailability exemption: a description of the market research performed, a listing of the requirements that cannot be met, and the rationale for the choice.
The twelve-flag totals are how you evidence the first half of that. A cluster of offerors landing in the same band on comparable reports, all failing the same criterion, is a market finding. One offeror alone in the bottom band is a vendor finding.
Keep the paperwork straight while you are there. Where an undue burden or fundamental alteration is claimed, E202.6.2 puts the writing duty on the responsible agency official, who “shall document in writing the basis” for the determination. That is not the vendor’s document and it does not belong in the vendor’s ACR.
The GSA ACR Repository is not a lookup you can use yet
Three separate GSA efforts get conflated, and a reviewer should know which is which before assuming a central lookup exists.
The ACR Library on Section508.gov publishes ACRs only for the tools and training GSA itself offers through Section508.gov, three tools and six training courses, three of those rows marked Pending with no report available. It contains no third-party vendor ACRs.
OpenACR is the machine-readable format behind those reports, a YAML-based data schema, with reports authored in it through the ACR Editor. GSA’s own project documentation calls it a pilot delivering a minimum viable product. The schema starts from the VPAT 2.4Rev 508 edition and builds on WCAG 2.0, so a machine-readable OpenACR encodes an older template than the one ITI currently publishes. The GSA/openacr repository has published no releases and its highest tag is v0.3.8. Building a process for vendors to submit ACRs is listed on the roadmap as an optional future phase.
The ACR Repository is the vendor-facing collection that does not exist publicly yet. GSA published a Paperwork Reduction Act notice for it on June 24, 2026: FR Doc 2026-12667, 91 FR 37982, with comments due on or before August 24, 2026 under Docket No. 2026-0232. The notice describes the repository as GSA’s response to a requirement in OMB Memorandum M-24-08 to explore a standardized accessibility conformance reporting process including a central repository of vendor ACRs. Submission would be voluntary, and the notice states there is no obligation for product owners to submit ACRs for any product. GSA’s burden estimate assumes 5,000 ACRs uploaded across 2,500 vendor administrator accounts, which is a paperwork calculation for OMB and not a forecast of adoption. The FY 2025 Section 508 Assessment records that GSA completed a beta and moved it to a staging environment. No GSA source publishes a launch date, a production URL, or an exit from beta, and a PRA notice is a prerequisite to collecting data rather than a release announcement.

View the data as a table
| ACR Library | OpenACR | ACR Repository | |
|---|---|---|---|
| What it is | GSA’s own published ACRs for its tools and training | A YAML-based machine-readable data schema | The vendor-facing collection GSA has proposed |
| What is in it | Three tools and six training courses, three rows marked Pending | Reports authored in the ACR Editor, starting from VPAT 2.4Rev and WCAG 2.0 | Nothing public yet; submission would be voluntary |
| Where it stands | Live, and it contains no third-party vendor ACRs | A pilot delivering a minimum viable product, no published releases | PRA notice published June 24, 2026, comments due August 24, 2026 |
For a reviewer working this week: there is no central federal source of truth to check a vendor’s ACR against. You evaluate what the offeror hands you.
Your next step
Pull the last ACR your office accepted and run the twelve flags against it in the next hour. If flag 5, 6 or 7 scored zero, that acceptance rests on assertions rather than evidence, and it is worth knowing now instead of in a debrief. If two or more offerors in a live competition fail on the same criterion, that is an E202.7 conversation before it is a rejection.
Where the gap is on your side of the table, ADACP’s Section 508 procurement support covers ACR review and the solicitation language that produces reviewable reports in the first place, including the Supplemental Accessibility Report clause most of these flags depend on. Where an agency exercises its reserved right to test before award, Section 508 testing is the independent evaluation that produces a defensible finding rather than a second opinion.
Vendors reading this from the other side of the table: VPAT testing and vendor guidance on ACRs apply the same twelve flags before submission rather than after.
If the ACR Repository matters to how your agency will source conformance evidence, the comment window under FR Doc 2026-12667 closes August 24, 2026.