Section 508 Remediation: What to Fix and What to Skip
You have a report with three hundred findings and a contract clause you have now read four times. The question isn’t whether the findings are real. It’s how many of them are actually yours to fix, and in what order.
That question has a written answer, and most of it is good news. Section 508 exempts more than people expect, and the exemptions are printed in the standard rather than negotiated. Across the federal government, conformance currently sits at 1.96 on a five point scale, so nobody reading this is behind some tidy norm.
Here’s what the rule requires, what it lets go, and how to sequence the work that’s left.
The short answer
- Remediation is the fixing, not the finding. An audit produces the defect list, remediation closes it, and a conformance report documents what happened.
- Unaltered legacy content is protected. Content that met the earlier standard and hasn’t been touched since January 2018 doesn’t have to be rebuilt, but editing it removes that protection.
- Internal content is mostly out of scope. Public content always conforms. Non-public content only conforms when it falls into one of nine named categories.
What Section 508 remediation actually means
Three different activities get called the same thing, and the confusion is expensive.
An audit finds problems. It produces a list of defects mapped to specific success criteria. Remediation is the work of closing that list, in your code, your templates, and your files. A conformance report describes the state of the product once that work is done.
The order matters because each step consumes the one before it. In federal practice, the fixing stage has its own document, a Defect Remediation Plan, which “documents the actions, timelines, and responsible parties for fixing accessibility defects”. It’s an execution artifact, not a diagnostic one.
Teams that treat a conformance report as a defect list end up paying for the same discovery twice. If you already have findings and need someone to work through them, you want remediation rather than another audit. If you don’t have findings yet, start with a WCAG audit instead.
The standard your work is measured against
A lot of Section 508 advice still circulating online predates the current rule, which is why you’ll see checklists referencing screen flicker rates and text-only alternate pages. Those provisions are gone.
The Access Board issued the current final rule on January 18, 2017, and it “went into effect on January 18, 2018”. Under it, electronic content must “conform to Level A and Level AA Success Criteria and Conformance Requirements in WCAG 2.0”. The old technical provisions were replaced wholesale by that reference.
Two practical consequences. First, if a checklist you’re working from doesn’t mention WCAG, it’s describing a standard that stopped applying eight years ago. Second, Section 508 incorporates WCAG 2.0, not 2.1 or 2.2. Your contract may ask for a later version, and plenty do, but that’s a contractual term rather than what the statute’s standards require. It’s worth reading what Section 508 covers before you accept a scope written by someone else.
What you do not have to remediate
This is the part that changes budgets, and almost nobody leads with it.
The Revised 508 Standards carry a safe harbor for legacy technology. Existing content or components that complied with the earlier Section 508 standard, and that “has not been altered on or after January 18, 2018, shall not be required” to be modified to meet the current rule. A twelve year old PDF that met the old standard and has sat untouched since is not a defect you owe anyone.
The condition is doing real work in that sentence, so read it twice. Two things have to be true: the content met the earlier standard, and it hasn’t been altered since the compliance date.
Alteration is the trigger, and it’s broader than a redesign. Re-exporting a document, editing a page template that renders it, migrating a library to a new platform, any of these can end the protection for what you touched. This is why safe harbor gets settled during scoping rather than after. Once your team has started editing files to fix them, arguing that those same files were exempt becomes awkward.
Which content is actually in scope
Scope splits on one question: can the public see it.
Public facing electronic content is straightforward. It “shall conform to the accessibility requirements specified in E205.4”, with no category test and no exceptions to hunt for. If it’s on your public site, it’s in.
Non-public content is narrower than most organizations assume. It only has to conform “when such content constitutes official business and is communicated by an agency” through one of nine specific channels:
- Emergency notification.
- An initial or final decision adjudicating an administrative claim or proceeding.
- Internal or external program or policy announcement.
- Notice of benefits, program eligibility, employment opportunity, or personnel action.
- Formal acknowledgement of receipt.
- Survey questionnaire.
- Template or form.
- Educational or training materials.
- Intranet content designed as a web page.
Most internal estates shrink sharply against that filter. Meeting notes, drafts, working spreadsheets and internal reference material generally don’t appear on the list. Forms and training materials almost always do. If you’re unsure which side of the line your organization sits on, who has to comply with Section 508 is the shorter version of that question.
The four criteria that do not apply to documents
Section 508 measures documents against WCAG, a standard written for web pages, so it carves out the criteria that don’t translate. “Non-Web documents shall not be required to conform to the following four WCAG 2.0” success criteria: 2.4.1 Bypass Blocks, 2.4.5 Multiple Ways, 3.2.3 Consistent Navigation, and 3.2.4 Consistent Identification.
That’s four categories of finding you can legitimately close on a PDF without doing any work. A tool that scans documents with a web ruleset will report all four, because it doesn’t know what it’s looking at.
Documents are also the most systematically tested content type in federal use, with “72% of agencies reported standardized testing” for them. Buyers see a lot of document reports, which means they notice when yours closes findings it shouldn’t or leaves open ones it needn’t. If files are the bulk of your estate, document and PDF remediation is a different workflow from site work and worth scoping separately.
How to decide what gets fixed first
Once scope is settled, sequence beats speed.
Fix blocking defects before appearance defects. A form field with no programmatic label stops a task completely, while insufficient contrast on a footer link makes one harder. Both are AA failures and they are not the same emergency.
Then weight by use. The pages and documents people actually reach carry more of your risk than the archive, and fewer than half of federal agencies could say “their most viewed or used ICT assets were fully conformant”. Start where the traffic is.
Risk-based ordering is still not universal practice. For public web pages and documents it’s used by “55% of agencies”, which leaves a large share working through findings in whatever order the report printed them. Report order is alphabetical or by page. It has nothing to do with user impact. If you’d rather not build the ranking yourself, how remediation work gets prioritized describes one way to structure it.
What a remediation plan has to contain
Federal practice recognizes two documents, and knowing both by name is worth something in a procurement conversation.
The Defect Remediation Plan. It “documents the actions, timelines, and responsible parties for fixing accessibility defects”. Each defect, the criterion it violates, who owns it, when it closes, and how the fix gets verified.
The Alternative Means Plan. It “documents the actions, timelines, responsible parties, and methods for alternative access”. This is the one people forget. It covers the gap while remediation runs, and it also covers content that will never be fixed: a legacy system scheduled for retirement, an exception already granted, a vendor product you don’t control.
Having both is a stronger position than promising everything will be fixed. The first says what you’re doing. The second says what happens to a user who needs the thing you haven’t done yet. A buyer who has read a hundred accessibility responses can tell the difference between a plan and a reassurance.
Where federal remediation actually stands
The FY 2025 assessment measured this directly, and the picture is useful for calibrating your own expectations.
Testing and remediation scored an “average Testing and Remediation factor outcome of 2.00 (Low) on a 5-point scale”, making it the weakest area measured across the federal enterprise. The reason is not that the work is unusually hard.
It’s that nobody sets a date. “Approximately 70 percent of agencies reported no required timelines across ICT types”. Where timelines do exist, “80 percent to 90 percent of agencies reported remediating within those timelines”.
Read those two numbers together and the lesson transfers to any organization. Teams given a deadline hit it most of the time. Teams given a backlog and no deadline don’t finish. The single highest value thing you can add to a remediation effort costs nothing and takes an afternoon, which is a date next to each item.
If you sell to an agency rather than run one
Section 508 binds federal agencies. It doesn’t reach into your company on its own, which surprises vendors who’ve been told they must “be 508 compliant” as though the statute named them.
The obligation arrives through the contract. The Federal Acquisition Regulation was amended to carry the Revised Standards into federal procurement, and those updates “went into effect on September 10, 2021”. What you owe is whatever your contract’s accessibility clause says, which is usually conformance plus a current conformance report.
Enforcement is uneven right now, with “less than 30% of agencies almost always verifying ICT deliverables for Section 508 conformance”. That’s a description of the present, not a strategy. The agencies that do check tend to check at renewal, at protest, or after a complaint, which are the three worst moments to discover your report was optimistic.
What automated fixes will not close
Automated testing finds patterns. It reports a missing alt attribute reliably because the attribute is either there or it isn’t.
It can’t tell you whether the alt text describes the image, whether the heading order matches the document’s actual structure, or whether a custom widget behaves sensibly when someone drives it from the keyboard. Those are judgments about meaning, and meaning is where most of the remaining failures live.
Testing with the people the standard exists for is still rare. “Only between 12 percent and 17 percent of agencies reported conducting usability testing” with disabled users before deployment. A clean scan and an unusable product are compatible states.
What finishing actually looks like
Remediation ends with verification, not with a closed ticket. Retest each item against the criterion it failed, on the build that’s shipping. Fixes get reverted during merges, and a fix that lives only in a branch is not a fix.
Then document what you have. The conformance report is the artifact that outlives the project and the one a buyer will ask for, so it should reflect the retested state rather than the intended one. Partial support, stated accurately with a remediation date attached, reads better than full support that a reviewer can disprove in ten minutes. This is what the conformance report that follows a remediation engagement is for, and it’s the same document as VPAT ACR reporting when the buyer is federal.
Bringing in help makes sense when three things are true at once: you have findings you didn’t generate, the estate spans both a site and a pile of documents, and there’s a date in a contract. That combination is hard to absorb into a sprint. Our accessibility remediation services cover the site, the documents, and the report at the end of it.
Conclusion
Most remediation projects go wrong at the scoping stage rather than the fixing stage. Teams count every finding as an obligation, price the whole pile, and then stall because the number is unbearable. The standard is more generous than that, and the safe harbor and the nine categories are the two places to look first. Get the real number, put dates on it, and the work stops feeling infinite.
Frequently Asked Questions About Section 508 Remediation
Is Section 508 remediation the same as an accessibility audit?
No, and they’re usually separate engagements. An audit is diagnostic: someone tests your product against the standard and produces a list of defects mapped to specific criteria. Remediation is the work of closing that list in your code, templates and files. The audit report is the input to remediation, not a substitute for it. Organizations that buy only audits tend to accumulate reports rather than fixes.
Do we have to remediate documents published before 2018?
Often not. The Revised 508 Standards include a safe harbor for existing content that complied with the earlier standard and “has not been altered on or after January 18, 2018”. If a document met the old requirements and nobody has touched it since, it doesn’t have to be rebuilt to the current rule. The protection ends the moment you alter the file, including re-exporting it or migrating it to a new platform.
Which WCAG version does Section 508 require?
WCAG 2.0, at Levels A and AA. The standard requires electronic content to “conform to Level A and Level AA Success Criteria and Conformance Requirements in WCAG 2.0”. Later versions like 2.1 and 2.2 are not what Section 508 itself incorporates, though your contract may specify one of them, and other laws that apply to you might. Check the clause before assuming which version you’re being measured against.
Do all of our PDFs need remediation?
Only the ones in scope. Public facing documents always conform. Internal documents conform only when they carry official business in one of nine named categories, which covers forms, templates, training materials and benefits notices but leaves out most working files. Non-web documents are also exempt from four success criteria that don’t apply to them, so some findings in a scan report can be closed without work.
What do we give a federal buyer if remediation is not finished?
Two documents. A Defect Remediation Plan lists each defect with an owner and a closing date. An Alternative Means Plan “documents the actions, timelines, responsible parties, and methods for alternative access” while the fixing runs and for anything that won’t be fixed at all. Together they show a buyer a schedule instead of an assurance, which is a materially stronger position than claiming conformance you can’t yet demonstrate.
Does Section 508 apply to us if we are a contractor?
Not directly. The statute binds federal agencies. Your obligation comes through the contract, because the Federal Acquisition Regulation was updated to carry the Revised Standards into procurement, with the updates effective September 10, 2021. Read the accessibility clause in your specific contract, since that language, not the statute, defines what you owe and what evidence you have to produce.