Third-party and embedded content in a conformance claim
The page you have to write a conformance claim about is not entirely yours. There is a payment iframe from a processor, a chat widget from a SaaS vendor, an embedded map, a syndicated video, and a comment thread the public writes into. Somebody has to decide what the claim covers, and the decision has to hold when a buyer’s reviewer reads it.
Two bodies of text answer, and they answer different questions. WCAG section 5.4, the statement of partial conformance, governs what you may claim. The third-party exception in the ADA title II web rule at 28 CFR 35.201(c), and its near-identical counterpart in the HHS Section 504 web rule at 45 CFR 84.85(c), governs what you must fix. An Accessibility Conformance Report that blurs the two answers neither question cleanly.
The two mechanisms are not two versions of the same rule
A WCAG conformance claim is voluntary. WCAG 2.2 says so at 5.3.1: “Conformance claims are not required. Authors can conform to WCAG 2.2 without making a claim.” Section 5.4 is a disclosure device inside that voluntary act, and its consequence is a narrower claim. A regulatory exception is not a disclosure device at all. It removes content from the scope of a legal duty, and nothing about it depends on how you describe your own page.
Three regimes reach the same organization, and only two of them contain a third-party exception.

View the data as a table
| WCAG 2.x | ADA title II and Section 504 | Revised Section 508 | |
|---|---|---|---|
| What it governs | What you may claim | What you must fix | What a Federal agency must make conform in the ICT it procures, develops or uses |
| Scope unit | The full web page, including embedded resources | Web content the entity provides, directly or through contractual, licensing, or other arrangements | Public-facing electronic content, plus nine categories of agency official communication |
| Third-party carve-out | None. Instead, monitor and repair within two business days, or state partial conformance | Yes, but only where the third party posts with no arrangement with the entity | None |
| Reaches embedded vendor widgets | Yes. They are part of the page | Yes. They must conform | Yes |
| WCAG version named | 2.2, current version dated 12 December 2024 | 2.1 Level A and AA, incorporated by reference | 2.0 Level A and AA |
| Where to cite it | WCAG 2.2 sections 5.2 to 5.4 | 28 CFR 35.200(b), 35.201(c); 45 CFR 84.84(b), 84.85(c) | 36 CFR part 1194, appendix A, E201.1, E202 and E205.2 to E205.4 |
The WCAG version each regime names matters more than it looks. Title II and Section 504 both incorporate WCAG 2.1, W3C Recommendation 05 June 2018, not 2.2. A partial conformance statement written for a public entity or an HHS-funded recipient names WCAG 2.1, because that is the standard the buyer is measured against. One naming 2.2 answers a question the regulator did not ask.
An embedded widget is inside your page. A linked site is not.
The line is drawn by the WCAG glossary definition of web page, and it is short enough to settle arguments:
a non-embedded resource obtained from a single URI using HTTP plus any other resources that are used in the rendering or intended to be rendered together with it by a user agent
with the note: “For the purposes of conformance with these guidelines, a resource must be ‘non-embedded’ within the scope of conformance to be considered a web page.”
An iframe is embedded. It renders together with the containing document, so it is part of that page rather than a separate page with its own claim. The same goes for a script-injected chat launcher, a map canvas and an ad slot. Conformance requirement 5.2.2 then closes the door on carving them out: “Conformance (and conformance level) is for full web page(s) only, and cannot be achieved if part of a web page is excluded.” Its note points straight at this subject: “Authors of web pages that cannot conform due to content outside of the author’s control may consider a Statement of Partial Conformance.”
A payment iframe is not only inside a page, though. It is inside a process, and WCAG scopes that separately. Requirement 5.2.3 Complete processes reads: “When a web page is one of a series of web pages presenting a process (i.e., a sequence of steps that need to be completed in order to accomplish an activity), all web pages in the process conform at the specified level or better. (Conformance is not possible at a particular level if any page in the process does not conform at that level or better.)” WCAG’s worked example is a store: “All pages in the series from start to finish (checkout) conform in order for any page that is part of the process to conform.” A failing component at one checkout step does not cost you that page alone. It costs conformance for every page in the flow.

View the data as a list
- An iframe renders inside your page: Not a separate page with its own claim
- 5.2.2 allows no exclusions: No part of a page can be left out
- That page is one step in a process: 5.2.3 scopes checkout flows separately
- The whole flow loses conformance: One component costs more than its own page
A plain link is the opposite case. The destination is a different non-embedded resource at a different URI, so it is a different web page and outside your claim, provided the claim says which pages it covers. That is required component 4: “A concise description of the web pages, such as a list of URIs for which the claim is made, including whether subdomains are included in the claim.”
DOJ landed in the same place. Its proposed title II rule carried an exception for linked third-party content and the final rule dropped it in favor of a coverage test: “when public entities link to third-party websites, unless the public entity has a contractual, licensing, or other arrangement with the website to provide or make available content, those third-party websites are not covered by title II of the ADA.”
WCAG offers two options, and the first one is not a statement
WCAG 2.2 opens section 5.4 with “Web pages that will later have additional content added can use a ‘statement of partial conformance’.” WCAG 2.1 words that first sentence differently: “Sometimes, Web pages are created that will later have additional content added to them.” The rest of the section is identical apart from the version number inside the model sentence. Both then give the same examples, “an email program, a blog, an article that allows users to add comments, or applications supporting user-contributed content,” and “a page, such as a portal or news site, composed of content aggregated from multiple contributors, or sites that automatically insert content from other sources over time, such as when advertisements are inserted dynamically.” Both warn that “the uncontrolled content can affect the accessibility of the controlled content as well,” then offer two options.
Option 1 is monitor and repair, and it preserves a full claim.
A determination of conformance can be made based on best knowledge. If a page of this type is monitored and repaired (non-conforming content is removed or brought into conformance) within two business days, then a determination or claim of conformance can be made since, except for errors in externally contributed content which are corrected or removed when encountered, the page conforms. No conformance claim can be made if it is not possible to monitor or correct non-conforming content;
Two business days is the only repair window in this subject and it belongs to WCAG. Neither 28 CFR part 35 subpart H, nor 45 CFR part 84 subpart I, nor the Revised 508 Standards states any timeframe for repairing third-party content. The last sentence is the one people skip: if you cannot monitor and cannot correct, this option yields no claim at all.
Option 2 is the statement, and it carries two conditions.
A “statement of partial conformance” may be made that the page does not conform, but could conform if certain parts were removed. The form of that statement would be, “This page does not conform, but would conform to WCAG 2.2 at level X if the following parts from uncontrolled sources were removed.” In addition, the following would also be true of uncontrolled content that is described in the statement of partial conformance:
- It is not content that is under the author’s control.
- It is described in a way that users can identify (e.g., they cannot be described as “all parts that we do not control” unless they are clearly marked as such.)
Condition 2 disqualifies careless drafting on its face. A blanket sentence about unspecified third-party components fails it, because the reader cannot tell which parts of the page are disclaimed.

View the data as a table
| Option 1: monitor and repair | Option 2: partial conformance | |
|---|---|---|
| What it is | Monitoring the page and repairing non-conforming content | A statement that the page does not conform, but would conform if certain parts were removed |
| What you end up with | A determination or claim of conformance can be made | A statement of non-conformance |
| Repair window | Within two business days | None. The disclosed parts stay on the page |
| Conditions | It must be possible to monitor and to correct | Parts are not under the author’s control and are described so users can identify them |
| How it fails | No claim at all if you cannot monitor or correct | A blanket sentence about unspecified components fails condition 2 |
W3C’s non-normative Understanding Conformance is blunt about the instrument: “It is important to recognize that this is a statement of non-conformance and there are users who may not be able to access some of the content this page.” It also pushes back on treating procured components as uncontrolled, telling authors who choose a third party implementation to “choose products that meet WCAG requirements,” and listing “third party libraries, plugins, or widgets” among the content to monitor rather than the content to excuse.
Non-interference is about the live page, not about the claim
Conformance requirement 5.2.5 makes four success criteria apply to everything rendered on the page, including content nobody relies on:
In addition, the following success criteria apply to all content on the page, including content that is not otherwise relied upon to meet conformance, because failure to meet them could interfere with any use of the page:
- 1.4.2 - Audio Control,
- 2.1.2 - No Keyboard Trap,
- 2.3.1 - Three Flashes or Below Threshold, and
- 2.2.2 - Pause, Stop, Hide.
WCAG does not say how 5.2.5 interacts with section 5.4, and the model sentence in 5.4 is counterfactual by construction: it asks what would be true “if the following parts from uncontrolled sources were removed.” What is not in doubt is the status of the document you end up with. A statement of partial conformance is, in W3C’s own words, “a statement of non-conformance.” The page does not conform either way. On the live page a chat widget that traps keyboard focus still traps it, an ad that autoplays audio still autoplays, a video that flashes still flashes, and a carousel with no pause control still runs. Disclosure changes the claim, not the experience.
So test every embedded component against those four criteria before you write anything else about it. WCAG singles them out as the failures capable of interfering with any use of the page.
Writing a statement that survives review
The base sentence is WCAG’s own, with the version matched to the standard the reader is regulated under. Around it sit the five required components of any conformance claim: date of the claim; guidelines title, version and URI; conformance level satisfied; a concise description of the pages, including whether subdomains are in scope; and the web content technologies relied upon.

View the data as a list
Statement of partial conformance: WCAG section 5.4, in the version the reader is regulated under
- Admits non-conformance: It begins This page does not conform
- Names version and level: Would conform to WCAG 2.1 at level AA
- Lists parts individually: Each one named so a user can find it
- Only uncontrolled parts: Not a component you chose and configured
- Four criteria still apply: Audio, keyboard trap, flashing and pause
A defensible statement does five things.
- Admits non-conformance. It begins “This page does not conform.” A report presenting it as a softened pass has misread the instrument.
- Names the version and level: “would conform to WCAG 2.1 at level AA,” the level the rest of the page genuinely meets.
- Lists the parts individually, each named so a user can find it on the page.
- Restricts the list to genuinely uncontrolled parts. A component you selected, contracted for and configured is a poor candidate.
- Does not treat the four non-interference criteria as disclosed away. Audio control, keyboard trap, flashing and pause or stop apply “to all content on the page,” disclosed parts included.
One limit belongs here rather than in a footnote. A statement of partial conformance has no regulatory standing. The phrase appears nowhere in 28 CFR part 35 subpart H, 45 CFR part 84 subpart I or 36 CFR part 1194, and the structural reason is stronger than the absence of a string. All three regulations incorporate a defined slice of WCAG, not the whole document. 28 CFR 35.200(b)(1) requires web content to “comply with Level A and Level AA success criteria and conformance requirements specified in WCAG 2.1,” 45 CFR 84.84(b)(1) uses the same words, and E205.4 of the Revised 508 Standards requires conformance to the “Success Criteria and Conformance Requirements in WCAG 2.0.” In WCAG’s own structure, “Conformance Requirements” is section 5.2 and its five numbered requirements. Conformance claims are section 5.3, and the statement of partial conformance is section 5.4. Neither sits inside what the regulations pull in. The closest analogue in regulatory text is 28 CFR 35.205, whose test is whether noncompliance “has such a minimal impact on access that it would not affect the ability of individuals with disabilities” to use the content: a question about effect, not about disclosure.
The regulatory exception turns on who posted, not on what the content is
Here is the whole exception, from 28 CFR 35.201(c):
(c) Content posted by a third party. Content posted by a third party, unless the third party is posting due to contractual, licensing, or other arrangements with the public entity.
And 45 CFR 84.85(c), which substitutes “recipient” for “public entity”:
(c) Content posted by a third party. Content posted by a third party, unless the third party is posting due to contractual, licensing, or other arrangements with the recipient.
It is one of five exceptions in each rule, alongside archived web content, preexisting conventional electronic documents, individualized or secured conventional electronic documents, and preexisting social media posts. DOJ called it “the only exception in Sec. 35.201 that applies solely based upon the identity of the poster (whereas the other exceptions identify the type of content at issue),” and declined to define “third party” at all, “because the critical factor in determining whether this exception applies is whether the third party is posting due to contractual, licensing, or other arrangements with the public entity …” Its fact sheet puts it plainly: “Third parties are members of the public or others who are not controlled by or acting for state or local governments.” The worked examples are a member of the public commenting on a government social media post, and an attorney independently filing through a court e-filing portal.
Now the passage that decides the widget question, from the title II rule preamble:
Sometimes a public entity itself chooses to post content created by a third party on its website. The exception in Sec. 35.201(c) does not apply to content posted by the public entity itself, or posted on behalf of the public entity due to contractual, licensing, or other arrangements, even if the content was originally created by a third party. For example, many public entities post third-party content on their websites, such as calendars, scheduling tools, maps, reservations systems, and payment systems that were developed by an outside technology company. Sometimes a third party might even build a public entity’s website template on the public entity’s behalf. To the extent a public entity chooses to rely on third-party content on its website in these ways, it must select third-party content that meets the requirements of Sec. 35.200. This is because a public entity may not delegate away its obligations under the ADA.
And embedded content by name:
The Department wishes to clarify that while the exception for third-party posted content applies to that content which is posted by an independent third party, the exception does not apply to the authoring tools and embedded content provided by the public entity, directly or through contractual, licensing, or other arrangements. Because of this, authoring tools, embedded content, and other similar functions provided by the public entity that facilitate third-party postings are not covered by this exception and must be made accessible in accordance with subpart H of this part.
HHS carried the same clarification into its Section 504 rule preamble, swapping “recipient” for “public entity” and “the rule” for “subpart H of this part.” The platform and the posts sit on opposite sides of the line, and DOJ’s fact sheet gives the split in one example: a message board platform “would not fall under the exception, and it would usually need to meet WCAG 2.1, Level AA,” while “the exception would probably apply to posts by third parties on that platform.”
The exception does not switch off the underlying statute either: “even if certain content does not have to conform to the technical standard, public entities still need to ensure that their services, programs, and activities offered using web content and mobile apps are accessible to individuals with disabilities on a case-by-case basis in accordance with their existing obligations under title II of the ADA.” DOJ then draws the line for content the exception does cover: “Independent third-party content should still be made accessible upon request when required under the existing obligations within title II of the ADA. However, public entities are not required to ensure the accessibility at the outset of independent third-party content.”
Read the columns below as three different questions, because that separation is the whole point.
| Content on the page | Inside the WCAG claim? | Reached by the title II or 504 third-party exception? | Statement of partial conformance available? |
|---|---|---|---|
| Payment iframe supplied under contract | Yes. Embedded, so part of the page | No. Posted under a contractual arrangement; DOJ names payment systems by example | Not settled. See the note below |
| Chat or support widget from a SaaS vendor | Yes. Embedded | No. Same arrangement test | Not settled. See the note below |
| Embedded map from an outside technology company | Yes. Embedded | No. DOJ names maps by example | Not settled. See the note below |
| Calendar, scheduling or reservations tool from a vendor | Yes. Embedded | No. All three named in the preamble | Not settled. See the note below |
| Site template built by an outside firm | Yes | No. Addressed directly in the preamble | Not settled. See the note below |
| The comment platform or message board itself | Yes | No. Tools and platforms sit outside the exception | Not settled. See the note below |
| Comments posted by members of the public | Yes. They render in the page | Yes, where the poster has no arrangement with the entity | Yes. Section 5.4 is written for pages that later take contributed content |
| Filings submitted independently through an e-filing portal | Yes, where they render in the entity’s page | Yes for the filings. The portal itself is not covered | Yes for the filings |
| Advertisement inserted dynamically by an ad network | Yes. Rendered together with the page | Not addressed by any rule text or preamble passage found for this article | Yes. Section 5.4 names dynamically inserted advertisements in its own example |
| Syndicated video the entity chose to embed | Yes. Embedded | No, where the entity chose to post it | Not settled, on the same reasoning as the vendor rows |
| A third-party website reached by a plain link | No. A different non-embedded resource at a different URI | Not reached. The question is whether the entity provides or makes it available | Not applicable. Exclude it in the claim’s scope statement |
The third column stops short on every vendor row, and that is deliberate. WCAG condition 1 asks whether a part is “content that is under the author’s control,” and WCAG has no glossary entry for the phrase. Understanding Conformance leans against disclaiming a component you chose, as quoted above, but that document is non-normative and says so. Nothing normative resolves it. The regulatory column is different, and that is why its cells read “No” without hedging: DOJ’s rule text and preamble decide the arrangement question outright.
The advertisement row is unresolved on the regulatory side only. WCAG names the case in its own example for section 5.4, “sites that automatically insert content from other sources over time, such as when advertisements are inserted dynamically.” The “contractual, licensing, or other arrangements” language could plainly reach a publisher’s agreement with an ad network, and neither DOJ nor HHS addressed advertising in the third-party passages.
One scope correction. This exception is not a public-sector-only device. It appears in title II and in the HHS Section 504 rule, which under 45 CFR 84.2(a) “applies to each recipient of Federal financial assistance from the Department”: a set that includes private hospitals, health systems, community health centers and nonprofits that take HHS money. Federal funding from a different agency does not pull an organization into 84.85(c), because part 84 is HHS’s own Section 504 regulation. Neither rule reaches ADA title III. DOJ’s April 2024 web rule amends 28 CFR part 35, the title II regulation, and HHS said of its own rulemaking that it “only addresses recipients’ obligations under section 504.” A private retailer’s embedded checkout has no third-party exception to point at, which is why our e-commerce accessibility work treats vendor components as in scope by default.
Section 508 has no third-party exception at all
The Revised 508 Standards frame their general exceptions in one sentence at E202.1: “ICT shall be exempt from compliance with the Revised 508 Standards to the extent specified by E202.” The six that follow are Legacy ICT, National Security Systems, Federal Contracts, ICT Functions Located in Maintenance or Monitoring Spaces, Undue Burden or Fundamental Alteration, and Best Meets. None is a third-party-content exception. The nearest neighbor, E202.4, is about procurement rather than page content: “ICT acquired by a contractor incidental to a contract shall not be required to conform to the Revised 508 Standards.”
Two further exceptions sit inside the electronic content chapter itself, and neither is about third parties. E205.3 carves out records the National Archives and Records Administration maintains under Federal recordkeeping statutes, unless they are public facing. E205.4 relieves non-Web documents from four success criteria, 2.4.1, 2.4.5, 3.2.3 and 3.2.4. What E205.4 requires is everything else: “Electronic content shall conform to Level A and Level AA Success Criteria and Conformance Requirements in WCAG 2.0 (incorporated by reference, see 702.10.1).” Scope comes from E205.2 and E205.3: electronic content that is public facing, plus nine listed categories of agency official communication when it is not public facing. Inside that scope, an embedded component is covered content like any other.
GSA fills the gap with procurement instructions rather than exceptions. Its ICT Product Lifecycle Overview tells agencies to “Require Accessibility Conformance Reports (ACRs) for any third-party libraries, platforms, or other components” in planning, and at launch to “Verify all third-party integrations are Section 508 conformant or have alternative means of access.” Its guidance on test reports asks testers to “Specify the test scope, including what was tested, how many pages, what may have been omitted in test scope, or any other details to provide additional context of the results.” Whether an agency may accept an ACR that silently excludes an embedded component is not addressed in the standard.
The ACR has nowhere obvious to put any of this
The VPAT 2.5Rev WCAG edition carries a scoping note directly above the success criteria tables: “When reporting on conformance with the WCAG 2.x Success Criteria, they are scoped for full pages, complete processes, and accessibility-supported ways of using technology as documented in the WCAG 2.0 Conformance Requirements.” The other three editions carry the same note with the standard version swapped: the Revised Section 508 edition names WCAG 2.0 in both places, and the EN 301 549 and International editions point at the WCAG 2.1 Conformance Requirements. Full pages and complete processes, which is where the argument started.
The conformance terms are per success criterion, not per component. At Level A and AA there are four of them, Supports, Partially Supports, Does Not Support and Not Applicable, plus a fifth, Not Evaluated, that ITI restricts to Level AAA criteria. ITI defines Partially Supports as “Some functionality of the product does not meet the criterion.” That does not distinguish your code from your vendor’s. The only hooks for the distinction are free text. ITI’s instruction for the Remarks and Explanations column is that where the level is Partially Supports or Does Not Support, the remarks should identify the functions or features with issues and how they do not fully support the criterion. The Notes field is the other hook, and it invites “Additional information about what the document does or does not cover.” ITI reviews nothing, and says so: “No, ITI does not review or approve VPATs.”
The workable form is a scope paragraph plus per-criterion remarks that name the component. If a payment iframe fails 1.4.3, the remark says which component and which page state, not “third-party content.” Our VPAT and ACR testing treats that naming as part of the deliverable, because a remark a reviewer cannot reproduce gives them nothing to check.
A conforming alternate version is a narrow instrument
The instrument exists and it is narrow. Both rules permit one, at 28 CFR 35.202(a) and 45 CFR 84.86(a), “only where it is not possible to make web content directly accessible due to technical or legal limitations.” The WCAG definition adds four conditions, and condition 3 ends the discussion for dynamic content: the alternate version must be “as up to date as the non-conforming content.” A parallel page can be kept as current as a static document. It cannot be kept as current as a live chat session or a dynamically inserted advertisement.
What the sources do not settle
- “Under the author’s control” is undefined. Condition 1 turns on the phrase and WCAG has no glossary entry for it, while Understanding Conformance treats a chosen third-party implementation as the author’s decision. Where a procured widget falls is unresolved in the normative text, which is why the third column of the grid above stops where it does.
- No published decision or enforcement action applying 28 CFR 35.201(c) or 45 CFR 84.85(c) turned up in the research for this article. The title II compliance dates are 26 April 2027 and 26 April 2028; the Section 504 dates are 11 May 2027 and 10 May 2028. Both sets were extended by a year in 2026, title II by a DOJ interim final rule published 20 April 2026 and Section 504 by an HHS interim final rule published 11 May 2026, so a source quoting 2026 dates is describing the superseded schedule. Nobody is yet in breach of the technical standard, so the preambles are the whole body of interpretation.
- Advertising networks are unaddressed by both rules, as the grid above says.
- The withdrawn linked-content exception left no worked examples for federated login, a checkout embedded from another origin, or a widget that is an iframe to a different domain.
- Whether the two business day window is achievable for a vendor-hosted widget is addressed by nobody. The only lever an author has over a vendor iframe is removal or replacement, which reads oddly for a payment component.
Where this stops
Whether a specific arrangement with a vendor is a “contractual, licensing, or other arrangement” within 35.201(c) is a question about that contract, and it belongs to your counsel. So does whether a given noncompliance has the minimal impact 35.205 describes, whether an organization is a recipient of Federal financial assistance from HHS, and what a statement of partial conformance is worth to a title III defendant, where no exception exists to invoke. What an accessibility practice can tell you is what the text says, which components sit inside the page, and which of them a claim can honestly exclude.
Next step
Open the last conformance claim or ACR you published. List every third-party component that renders on a covered page and sort each one by one question: did we select it, or did somebody else post it. The first pile is yours to fix under title II, Section 504 and Section 508 alike. The second pile needs either monitoring with a two business day repair window or a statement of partial conformance naming each part. Send us the report and the inventory and we will mark the rows that will not survive a reviewer’s read.