Section 508 Compliance

Section 508 compliance services for government and public sector work

Section 508 of the Rehabilitation Act requires federal agencies to make their electronic and information technology accessible to people with disabilities — and it reaches every vendor and contractor that sells them that technology. We test your ICT against the standard 508 is actually measured on, document the findings so they hold up in review, and support you through remediation and procurement.

What each Section 508 workstream involves

  • Website compliance — for most teams Section 508 starts as a website question: is this site 508 compliant, and what does it take to get there. A 508 compliant website can be operated with a keyboard alone, read with a screen reader and used at high zoom, measured against WCAG 2.0 Level A and AA. The failures we find most often are keyboard traps and focus that disappears, missing landmarks and headings, form fields without programmatic labels, contrast below the required ratios, images without meaningful alternative text, and custom components such as menus, modals and tabs that expose nothing usable to a screen reader.
  • Testing — automated tools flag part of the picture; they cannot tell you whether a screen reader announces a form error, or whether a custom component can be operated at all. Testing pairs an automated baseline with manual keyboard, screen reader and magnification passes through your real user journeys, following the federal test procedures in the ICT Testing Baseline for Web, with every finding mapped to its WCAG 2.0 criterion.
  • Procurement support — under FAR Part 39 and Subpart 39.2, federal buyers have to consider accessibility when they acquire ICT, which is why RFPs and vendor questionnaires reach you at all. We help you answer them consistently, agree the scope before work starts, and prepare the evidence and the VPAT/ACR in the correct 508 edition.

Section 508 compliance that holds up in procurement and review

A Section 508 obligation is ultimately tested by a reviewer: a contracting officer reading your VPAT, an agency compliance team examining your documentation, an auditor checking your ICT. Work that consists of an automated scan and a green checkmark does not survive that. What survives is manual testing mapped to the right success criteria, findings a reviewer can verify, and documentation in the format procurement expects.

That is what we build. Our testing pairs automated checks with manual and assistive-technology evaluation — keyboard navigation, screen readers (JAWS, NVDA, VoiceOver), and screen magnification — and every finding is tied to the specific WCAG 2.0 Level A or AA criterion it fails, with its location and evidence.

Who must comply with Section 508

  • Federal agencies — required to build, buy, and maintain accessible ICT, and to show documentation that withstands oversight.
  • Vendors and contractors selling software, hardware, or digital services to federal agencies — accessibility is a condition of the purchase, checked during procurement.
  • Organizations receiving federal funding whose obligations flow down through contracts and grants.
  • State and local government entities are covered by a different rule — ADA Title II, measured against WCAG 2.1 Level AA. We confirm which framework applies to you before recommending any work, so you never buy an audit against the wrong law.

What Section 508 covers: WCAG 2.0 A/AA and the Revised Standards

Section 508 applies to websites and web applications, software, digital documents, and hardware that federal agencies use or procure. The Revised 508 Standards incorporate WCAG 2.0 Level A and AA by reference — so Section 508 conformance is measured against WCAG 2.0, not the later 2.1 or 2.2 versions that belong to other obligations.

This version question is where budgets get wasted — not on the testing itself, but on remediating 2.1-only criteria your contract never asked for while the reviewer scores you against 2.0. We test against the exact standard your obligation is based on, and we confirm it with you before the engagement starts.

Section 508 vs ADA vs WCAG

These three get used interchangeably, and mixing them up is how accessibility work ends up scoped against the wrong standard:

  • Section 508 — federal procurement law under the Rehabilitation Act. Applies to federal agencies and their vendors; measured against WCAG 2.0 Level A and AA.
  • ADA — a civil rights law with no technical checklist. Courts and the Department of Justice use WCAG as the benchmark, and its Title II rule adopts WCAG 2.1 Level AA for state and local government.
  • WCAG — the technical standard both point to, and what our testing maps every finding against. WCAG conformance is the evidence; compliance is the legal or contractual state that evidence supports.

For the private-sector side, see ADA website compliance. And if you tell us your situation — who is asking, under what contract — we will tell you plainly which framework applies and what evidence it requires. That conversation costs you nothing and prevents scoping the work against the wrong law.

A practical path to Section 508 compliance

Section 508 pays off most when it is a standard part of your delivery process, not a scramble after a complaint or ahead of a deadline. We take your team through a defined path.

Scope

We identify the products, templates, user flows, and documents that carry the obligation and the risk.

Test

Automated checks first to clear the machine-detectable issues, then manual and assistive-technology testing against WCAG 2.0 A and AA.

Prioritize

We rank findings by user impact and by what fails a federal review, so fixes land in the order that de-risks the contract fastest.

Document

Criteria-mapped findings, remediation guidance your developers can execute, and VPAT/ACR-ready evidence.

Retest

We verify the fixes and confirm what is resolved, so your record shows closed issues rather than open findings.

Maintain

For teams shipping on a release cycle: accessible components and a repeatable procedure, so the next release does not reopen what you just closed.

What you receive in a Section 508 engagement

  • A findings report listing each issue, its location, the WCAG 2.0 A/AA success criterion it fails, and supporting evidence.
  • Results from manual and assistive-technology testing — screen reader, keyboard, and magnification — not automated output alone.
  • Remediation guidance ranked by user impact and compliance risk, written for implementation.
  • A clear statement of coverage: which templates, components, user flows, and documents were tested.
  • A retest after remediation confirming which issues are resolved.
  • A VPAT/ACR in the correct 508 edition where procurement requires one.
  • An executive summary your stakeholders and reviewers can read without a translation layer.
Schedule a consult

Trusted by leading brands

We are proud of our customers

Common questions about Section 508

A federal buyer asked for proof of Section 508 compliance. What do we need?
Usually two things: testing that shows where the product stands against WCAG 2.0 A and AA, and documentation in the format the buyer expects, normally a VPAT or ACR in the correct 508 edition. We scope both together so the evidence and the paperwork say the same thing.
Do you test against WCAG 2.0 or 2.1 for Section 508?
WCAG 2.0 Level A and AA. The Revised 508 Standards incorporate 2.0 by reference, so that is what your obligation is measured against. WCAG 2.1 AA belongs to ADA Title II, a different rule for state and local government. Testing against the wrong version burns remediation budget for nothing.
What do we hand to a contracting officer?
A findings report with each issue mapped to its WCAG 2.0 criterion, its location and evidence; a remediation plan with priorities; a retest confirming what is resolved; a VPAT or ACR in the right edition where procurement requires one; and an executive summary a non-technical reviewer can read.
Is a validator or a scanner enough for a 508 review?
No. Federal reviewers follow test procedures that include manual and assistive-technology checks: keyboard operation, screen reader behaviour, focus order, custom components. A validator result is a starting point, not a conformance claim, and reviewers know the difference.
We are a state or local government entity. Is Section 508 our standard?
Usually not. Section 508 binds federal agencies and their vendors. State and local government falls under ADA Title II, which the 2024 DOJ rule measures against WCAG 2.1 AA with fixed deadlines. We confirm which framework applies to you before recommending any work.
How do you scope work across websites, software and documents?
We agree what carries the obligation and the risk: the products, templates and user flows in use, plus the documents a reviewer is likely to open. Section 508 reaches all of it, but the effort belongs where the exposure is.
Do you retest and update the documentation after we remediate?
Yes. We re-check the findings, confirm what is closed, and refresh the report and the VPAT or ACR so what you hand a reviewer describes the product as it is now, not as it was at the first audit.
Do we need a VPAT as well as testing?
If a buyer or a contract asks for one, yes, and it should be built on the testing rather than filled in from memory. Agencies expect a completed VPAT or ACR during vendor review, and a self-reported one with no evidence behind it invites more scrutiny, not less.
How long does Section 508 work take?
It depends on product complexity, the number of templates and flows involved, and how many issues surface. Focused engagements run in weeks; large platforms phase remediation over months. We scope it against the deadline you are actually working to.
We have already run our own Section 508 testing. Can you work from that?
Usually yes. We review what was tested, how, and against which version, then fill the gaps rather than repeat work you have already paid for. What we cannot do is put our name on results we did not verify, so anything carried into a conformance claim gets re-checked.
How often does Section 508 testing need to be repeated?
At significant releases, after a redesign or platform migration, and whenever the documentation you hand buyers starts describing a version you no longer ship. Between those points, retesting the areas you remediated is usually enough.

Who does this work

David LoPresti

Founder and CEO, ADA Compliance Professionals

David LoPresti works directly with government contractors, technology manufacturers, and software vendors to evaluate accessibility conformance and prepare the documentation procurement and contract reviews call for. On a Section 508 engagement that means findings mapped to the WCAG 2.0 Level A and AA success criteria the Revised 508 Standards incorporate by reference, remediation planning your developers can act on, and an ACR when a buyer asks for one.

Get the Section 508 compliance 101 guide

A practical explainer covering who Section 508 applies to, how it maps to WCAG 2.0 and the Revised 508 Standards, and what federal procurement teams expect to see.

Section 508 compliance 101

Enter your email and we will send the guide to your inbox.

Ready to meet Section 508 requirements?

Tell us what you are up against — an audit, a reviewer's questions, or a VPAT a buyer is waiting on — and we will scope the testing and documentation on a call.

Schedule a consult (opens in new tab)