Which WCAG version each US rule requires: 508, Title II and 504
The solicitation says “WCAG 2.1 Level AA.” The Accessibility Conformance Report your team published fourteen months ago says “WCAG 2.0 Level A and AA, Revised Section 508 Standards.” Response is due Friday, and somebody has to decide whether that is a labeling problem or a re-test.
It is usually neither, and the reason nobody can resolve it quickly is that the market talks about WCAG as one moving target when US law treats it as several frozen ones. Three separate decisions run into that wall:
- A software vendor picks a VPAT edition before testing starts. The edition fixes the WCAG version, the version fixes the test scope, and the scope fixes what the audit costs. Pick the 508 edition, then lose a state university deal because the buyer wanted WCAG 2.1, and the audit gets paid for twice.
- A capture or contracts lead drafts an accessibility clause on a contract that will still be running in 2031, and has to choose between “WCAG 2.0 Level A and AA per 36 CFR part 1194,” “WCAG 2.1 Level A and AA per 28 CFR 35.200(b),” both, or a rolling “or a subsequent version” formulation.
- A public sector or higher education buyer holds a supplier’s ACR and has to decide whether a WCAG 2.0 report discharges the WCAG 2.1 obligation their own agency is about to be measured against.
The short answer to all three: a federal agency and a state university are bound to different WCAG versions, and a vendor selling to both owes both. Our Section 508 website compliance work starts with that split, because getting it wrong is what produces a rejected report rather than a remediated product.
Here is every rule that names a WCAG version, what it requires, who it binds, and the citation form to write into a document.
The matrix

View the data as a table
| Revised Section 508 | ADA Title II web rule | HHS Section 504 web rule | |
|---|---|---|---|
| WCAG version and level | WCAG 2.0 Level A and AA | WCAG 2.1 Level A and AA | WCAG 2.1 Level A and AA |
| Who is covered | Federal agencies; their ICT suppliers via FAR subpart 39.2 | State and local government public entities, including content provided under contract or licensing | Every program or activity receiving HHS federal financial assistance |
| In force from | In force now | 26 April 2027 at population 50,000+; 26 April 2028 below that | 11 May 2027 with 15 or more employees; 10 May 2028 with fewer |
| Citation form to use | 36 CFR part 1194, appendices A and C; provisions E205.4, E207.2, 602.3 | 28 CFR 35.200(b); WCAG 2.1 defined at 28 CFR 35.104 | 45 CFR 84.84(b); definition at 45 CFR 84.10 |
| Rule or standard | WCAG version and level | Who is covered | In force from | Citation form to use |
|---|---|---|---|---|
| Revised Section 508 Standards | WCAG 2.0 Level A and AA | Federal agencies; their ICT suppliers via FAR subpart 39.2 | In force now | 36 CFR part 1194, appendices A and C; provisions E205.4, E207.2, 602.3; IBR at 702.10.1 (WCAG 2.0, W3C Recommendation, December 11, 2008) |
| ADA Title II web and mobile app rule | WCAG 2.1 Level A and AA | State and local government “public entities,” including content provided through contractual or licensing arrangements | 26 April 2027 (population 50,000+); 26 April 2028 (under 50,000 or special district government) | 28 CFR 35.200(b); WCAG 2.1 defined at 28 CFR 35.104 (W3C Recommendation 05 June 2018) |
| HHS Section 504 web and mobile app rule | WCAG 2.1 Level A and AA | Every program or activity receiving HHS federal financial assistance | 11 May 2027 (15 or more employees); 10 May 2028 (fewer than 15) | 45 CFR 84.84(b); definition at 45 CFR 84.10 |
| Air Carrier Access Act website rule | WCAG 2.0 Level AA | US and foreign carriers operating at least one aircraft with a designed seating capacity over 60 passengers, for a primary website marketing air transportation to the general public in the United States | In force now | 14 CFR 382.43(c)(1), which names the “World Wide Web Consortium (W3C) Recommendation 11 December 2008” in the rule text |
| Certified health IT, view/download/transmit criterion | WCAG 2.0 Level A, with Level AA available as an alternative demonstration | Health IT Modules certifying to § 170.315(e)(1) | In force now | 45 CFR 170.315(e)(1), citing the standards adopted at 45 CFR 170.204(a)(1) and (a)(2); IBR at 45 CFR 170.299 |
| Medicaid managed care | WCAG 2.0 AA “and successor versions,” inside the definition of “readily accessible” | Enrollee information from states, MCOs, PIHPs, PAHPs, PCCMs and PCCM entities | In force now | 42 CFR 438.10(a) for the definition; operative at 438.10(c)(1) and (d)(6) |
| Department of Labor acquisition clause | WCAG 2.0 Level A and AA, tested by the DHS Trusted Tester harmonized process | DOL ICT contractors | In force now | 48 CFR 2952.239-70(b)(1) |
| WIOA Title I nondiscrimination | ”Consistent with” WCAG 2.0 AA, offered as an example. Not an incorporation by reference | WIOA Title I recipients | In force now | 29 CFR 38.15(a)(5)(ii) |
| OFCCP Section 503 | Encouragement in a footnote. No conformance obligation | Federal contractors | Not applicable | 41 CFR 60-741.44, footnote 3 |
| California state entities | WCAG 2.0 A and AA through Section 508, plus WCAG 2.0 “or a subsequent version” at minimum Level AA for the public certification | California state agencies and state entities | In force now; certification due before 1 July biennially | Cal. Gov. Code §§ 7405(a) and 11546.7(a) |
| EN 301 549 V3.2.1 (2021-03) | WCAG 2.1 Level AA for web content | ICT covered by the EU Web Accessibility Directive | Version cited in the Official Journal | EN 301 549 V3.2.1, clause 9.0 |
| ISO/IEC 40500:2025 | WCAG 2.2 | Nothing in US law. A citation label, not an obligation | Published 24 September 2025 | ISO/IEC 40500:2025, Edition 2 |
Two things in that table are worth stating flat.
Section 508 has never required anything other than WCAG 2.0. Extract the plain text of the full published standard at the Access Board’s ICT page, which carries the Revised 508 Standards, the Section 255 Guidelines, the preamble and Appendix D, and on 27 July 2026 it contains 155 occurrences of “WCAG 2.0,” zero occurrences of “WCAG 2.1” and zero occurrences of “WCAG 2.2.” The two zeros are the load-bearing numbers, and they hold under any counting method.
No provision of the Code of Federal Regulations requires WCAG 2.2. An exact-phrase full-text search of the eCFR on 27 July 2026 returns two hits for “WCAG 2.2,” both inside the appendix guidance to the DOJ Title II rule, neither in operative regulatory text. That claim is scoped to the CFR. State statutes, state IT policies, university standards and contract terms sit outside it and were not searched exhaustively.
The CFR census, which you can re-run yourself
The eCFR exposes a search API. Query it for each exact phrase and the version landscape resolves into something a contracts lead can actually reason about.
| Exact phrase | Hits | Where it appears in the CFR (27 July 2026) |
|---|---|---|
| “WCAG 2.2” | 2 | Both in 28 CFR part 35 Appendix D, the DOJ Title II guidance appendix. Nothing operative |
| ”WCAG 2.1” | 12 | 28 CFR 35.104, 35.200, 35.202 and part 35 Appendix D; 45 CFR 84.10, 84.84, 84.86 |
| ”WCAG 2.0” | 49 | 36 CFR part 1194 appendices A, B and C; 14 CFR 382.3 and 382.43; 45 CFR 170.204 and 170.299; 48 CFR 2952.239-70; 29 CFR 38.15; 41 CFR 60-741.44; 42 CFR 438.10; 28 CFR part 35 Appendix D |
Eight parts across eight titles carry the phrase “WCAG 2.0.” Drop 28 CFR part 35 Appendix D, which is guidance rather than operative text, and it is seven parts across seven titles. Two parts carry “WCAG 2.1.” Nothing operative carries “WCAG 2.2.” If your internal position is “WCAG is basically 2.2 now,” the regulatory record disagrees by a wide margin.
Section 508: WCAG 2.0 Level A and AA, and only for federal agencies
The Access Board is explicit about scope at E101.1: “Compliance with these standards is mandatory for Federal agencies subject to Section 508 of the Rehabilitation Act of 1973, as amended (29 U.S.C. 794d).” Section508.gov puts the statutory reach the same way: “The law 29 U.S.C § 794d applies to all federal agencies when they develop, procure, maintain, or use electronic and information technology.”
Three provisions carry the WCAG obligation, and a vendor’s ACR should account for all three rather than the first one.
- E205.4 Accessibility Standard covers electronic content: “Electronic content shall conform to Level A and Level AA Success Criteria and Conformance Requirements in WCAG 2.0 (incorporated by reference, see 702.10.1).”
- E207.2 WCAG Conformance covers software: “User interface components, as well as the content of platforms and applications, shall conform to Level A and Level AA Success Criteria and Conformance Requirements in WCAG 2.0 (incorporated by reference, see 702.10.1).”
- 602.3 Electronic Support Documentation covers documentation, and it is easy to leave out when scoping: “Documentation in electronic format, including Web-based self-service support, shall conform to Level A and Level AA Success Criteria and Conformance Requirements in WCAG 2.0 (incorporated by reference, see 702.10.1).” Your help center is in scope.

View the data as a list
Revised 508: WCAG 2.0 Level A and AA: Incorporated by reference at 702.10.1, W3C Recommendation December 11, 2008
- E205.4 Electronic content: Electronic content shall conform to Level A and Level AA
- E207.2 Software: User interface components, platforms and applications
- 602.3 Support documentation: Documentation in electronic format. Your help center is in scope
The incorporation is dated, and it is a closed list. Provision 702.10.1 names “Web Content Accessibility Guidelines (WCAG) 2.0, W3C Recommendation, December 11, 2008” and then enumerates exactly which provisions the incorporation reaches: in Appendix A, E205.4, E205.4 Exception, E205.4.1, E207.2, E207.2 Exception 2, E207.2 Exception 3, E207.2.1 and E207.3; in Appendix B, the Section 255 Communications Act scoping at C203.1, C203.1 Exception, C203.1.1, C205.2, C205.2 Exception 2, C205.2 Exception 3, C205.2.1 and C205.3; and in Appendix C, 408.3 Exception, 501.1 Exception, 504.2, 504.3, 504.4 and 602.3. Anything not on that list is not carrying WCAG by reference.
A 508 obligation is close to a plain WCAG 2.0 AA obligation but is not identical, and the difference is testable. E205.4 carries an exception: “Non-Web documents shall not be required to conform to the following four WCAG 2.0 Success Criteria: 2.4.1 Bypass Blocks, 2.4.5 Multiple Ways, 3.2.3 Consistent Navigation, and 3.2.4 Consistent Identification.” E207.2 releases non-web software from the same four, and separately from “Conformance Requirement 3 Complete Processes in WCAG 2.0.” E205.4.1 and E207.2.1 then substitute “document” or “software” for “Web page” throughout, and swap “in a document” or “in software” for “on a Web page” inside Success Criterion 1.4.2.
Section 508 also reaches hardware in Chapter 4, non-electronic support documentation at 602.4 and support services at 603, none of which WCAG addresses at all. Where the technical chapters run out, the standard says what fills the gap. E204.1 General: “Where the requirements in Chapters 4 and 5 do not address one or more functions of ICT, the functions not addressed shall conform to the Functional Performance Criteria specified in Chapter 3.” That is a conformance route, and it is a different mechanism from marking a row Not Applicable. The Chapter 3 functional performance criteria are where it lands on the report.
For web content the applicable set has a number attached to it. Section508.gov states: “A page that fails to meet even one of the 38 applicable WCAG success criteria does not conform to the standards. A set of pages in a sequence, e.g., identifying, selecting, and paying for a ticket to a public event, does not conform if any of those steps fails to conform fully.” Thirty-eight is WCAG 2.0 Level A and AA counted together: 25 criteria at Level A and 13 at Level AA. All or nothing, at the page level and across the process.
Vendors are reached through the acquisition regulation rather than by the statute. FAR 39.203(a) provides that “Unless an exception at 39.204 or an exemption at 39.205 applies, acquisitions for ICT supplies and services shall meet the applicable ICT accessibility standards at 36 CFR 1194.1,” and FAR 39.201(a) states that the subpart “implements section 508 of the Rehabilitation Act of 1973 (29 U.S.C. 794d)” and the Access Board’s standards at the same citation. That is why a supplier who has never read the Rehabilitation Act still ends up with WCAG 2.0 in a statement of work.
One relief valve worth knowing before you scope a remediation budget. E202.2 Legacy ICT provides that “Any component or portion of existing ICT that complies with an earlier standard issued pursuant to Section 508 of the Rehabilitation Act of 1973, as amended (as republished in Appendix D), and that has not been altered on or after January 18, 2018, shall not be required to be modified to conform to the Revised 508 Standards.” It operates component by component, not product by product, which is why an old report does not automatically become worthless.
ADA Title II: WCAG 2.1 Level A and AA, for state and local government
This is a costly misreading, and it turns up regularly in solicitation language. Federal agencies are not Title II entities.
“Public entity” at 28 CFR 35.104 means “(1) Any State or local government; (2) Any department, agency, special purpose district, or other instrumentality of a State or States or local government; and (3) The National Railroad Passenger Corporation, and any commuter authority (as defined in section 103(8) of the Rail Passenger Service Act).” The federal government appears nowhere in that definition. A federal agency asking you for a WCAG 2.1 ACR “because of the DOJ rule” is asking for something that rule does not impose on it.
The obligation itself, at 28 CFR 35.200(b), requires a covered entity to ensure web content and mobile apps “comply with Level A and Level AA success criteria and conformance requirements specified in WCAG 2.1.” Level A and Level AA, not Level AA alone. WCAG 2.1 has 30 success criteria at Level A and 20 at Level AA, 50 in total for the obligation. Anyone writing “Title II requires 2.1 AA” is describing 20 of the 50 and dropping the other 30.
The reach into your contract is at 35.200(a), which covers web content and mobile apps a public entity “provides or makes available, directly or through contractual, licensing, or other arrangements.” That single clause is what puts a supplier’s ACR inside the buyer’s own compliance file.
The dates now codified are the extended ones. An interim final rule published 20 April 2026 moved them: “The compliance date for State and local government entities with a total population of 50,000 or more is extended from April 24, 2026, to April 26, 2027. The compliance date for public entities with a total population of less than 50,000, or any special district government, is extended from April 26, 2027, to April 26, 2028.” Sources that have not been refreshed since the 2024 final rule still print 24 April 2026. If a solicitation you are answering quotes that date, the drafter has not refreshed since spring.
Three points from DOJ’s own preamble are worth quoting back to anyone who insists the versions must converge.
DOJ considered WCAG 2.2 and declined it: “The Department believes that adopting WCAG 2.1 as the technical standard rather than WCAG 2.2 is the most prudent approach at this time. W3C, while recommending the use of the most recent recommended standard, has made clear that WCAG 2.2 does not ‘deprecate or supersede’ WCAG 2.1 and has stated that WCAG 2.1 is still an existing standard.”
DOJ also considered WCAG 2.0 and rejected it, and in doing so put the federal split on the record: “Alternatively, the Department considered adopting WCAG 2.0. This change was suggested by the Small Business Administration, which argued that public entities should not have to comply with a more rigorous standard for online accessibility than the Federal Government, which is required to conform to WCAG 2.0 under section 508 of the Rehabilitation Act.” A federal regulator describing the two-version split is a stronger citation than any consultant’s summary.
And nothing drifts upward on its own: “The Department notes that when W3C publishes new versions of WCAG, those versions will not be automatically incorporated into this rule. Federal agencies do not incorporate by reference into published regulations future versions of standards developed by bodies like W3C.”
“WCAG 2.1” in this rule also means one frozen document. 28 CFR 35.104 defines it as “the Web Content Accessibility Guidelines (‘WCAG’) 2.1, W3C Recommendation 05 June 2018,” and pins the URL of that dated edition. W3C has since republished WCAG 2.1 three times, on 21 September 2023, 12 December 2024 and 6 May 2025, and the current Recommendation is the 6 May 2025 one. Those are not the same document as the one the rule incorporates, and an audit report that says only “WCAG 2.1” has not told the reviewer which one it tested against.
HHS Section 504: same version, same level, different population, different dates
45 CFR 84.84(b) uses the same operative wording as Title II: recipients shall ensure web content and mobile apps “comply with Level A and Level AA success criteria and conformance requirements specified in WCAG 2.1.” Same version, same level, same frozen 5 June 2018 edition, defined at 45 CFR 84.10 with the same dated URL DOJ used. If you see the two rules described as sitting at different levels, that description is wrong.
What differs is who is covered and when. 45 CFR 84.82 states the scope in one sentence: “This subpart applies to all programs or activities that receive Federal financial assistance from the Department.” That is the university, hospital and health plan population, and it overlaps with Title II without being the same set. A private nonprofit hospital taking HHS funds is a 504 recipient and not a Title II public entity. A state university is frequently both.
The dates were also extended by a year, by an interim final rule published 11 May 2026: “The compliance date for recipients with fifteen (15) or more employees is extended from May 11, 2026, to May 11, 2027. The compliance date for recipients with fewer than fifteen (15) employees is extended from May 10, 2027, to May 10, 2028.”
Cite § 84.84(b) for the requirement, not the subpart range. Subpart I does run from § 84.82 to § 84.89, but citing the range tells a reviewer you have not read to the subsection, and WCAG 2.1 also appears at § 84.86 for conforming alternate versions, which is a different obligation with its own trigger: a recipient may use them “only where it is not possible to make web content directly accessible due to technical or legal limitations.”
One scoping note that matters if you sell hardware. Subpart I is titled “Web, Mobile, and Kiosk Accessibility,” and the kiosk provision is a general nondiscrimination duty with no version attached. 45 CFR 84.83 reads in full: “No qualified individual with a disability shall, on the basis of disability, be excluded from participation in, be denied the benefits of, or otherwise be subjected to discrimination under any program or activity of a recipient provided through kiosks.” No WCAG citation, no level. A kiosk deployed by an HHS recipient is covered by the subpart and is not measured against WCAG 2.1 by § 84.84(b), which reaches web content and mobile apps.
The weaker instruments, and the one strong one
Three of the WCAG 2.0 appearances in the CFR are not conformance requirements, and treating them as such damages your credibility with a reviewer who has read them. A fourth is the strongest version clause in the CFR, and it is worth reading for the opposite reason.
41 CFR 60-741.44 (OFCCP, Section 503) mentions WCAG only in a footnote hanging off the personnel-processes paragraph, in hortatory form. Footnote 3: “Contractors are encouraged to make their information and communication technology accessible.” It then lists WCAG 2.0 among “a variety of resources that may assist contractors.” No obligation, no version lock. Do not cite it as a requirement.
29 CFR 38.15(a)(5)(ii) (WIOA) requires technology that is “consistent with modern accessibility standards, such as Section 508 Standards (36 CFR part 1194) and W3C’s Web Content Accessibility Guidelines (WCAG) 2.0 AA.” “Consistent with” and “such as” are illustrative wording, not incorporation by reference.
42 CFR 438.10 (Medicaid managed care) defines “readily accessible” as “electronic information and services which comply with modern accessibility standards such as section 508 guidelines, section 504 of the Rehabilitation Act, and W3C’s Web Content Accessibility Guidelines (WCAG) 2.0 AA and successor versions.” The definition feeds real duties: 438.10(c)(1) requires all information in the section to be provided “in a manner and format that may be easily understood and is readily accessible,” and 438.10(d)(6) forbids electronic delivery of enrollee information unless “The format is readily accessible” and the information sits somewhere on the website “that is prominent and readily accessible.” So it is an operative requirement with a rolling definition, which is the opposite drafting choice from DOJ’s frozen edition. The target can move without any rulemaking.
48 CFR 2952.239-70 (Department of Labor) is the model for what a version requirement looks like once it reaches a contract file. Paragraph (b) requires the contractor to “test and validate the ICT for conformance to the Revised 508 Standards (36 CFR part 1194, appendices A and C), in accordance with the required testing methods and provide test results to verify conformance of the Voluntary Product Assessment Template (VPAT).” Paragraph (b)(1) then names the method: “For web and software, WCAG 2.0 Level A and AA Conformance test results shall be based on the Accessibility Tests for Software and Web, Harmonized Testing Process for Section 508 Compliance from the DHS Trusted Tester program.” Paragraph (b)(2) does the same for documents, pointing at “the Harmonized Testing Guidance from the Accessible Electronic Documents Community of Practice.” Paragraph (a)(4) reaches the supplier’s own capability: its processes must be “at a maturity level at least equivalent to the DHS Trusted Tester methodology.”
Standard, version, level, test process and tester competence, all in one clause. If you are drafting, that is the shape to copy, and the companion piece on Section 508 contract clauses and QASPs works through the acceptance and surveillance language that has to sit around it.
Two details in the same clause are worth noticing, because they show how easily version and artifact drift apart even in well-drafted text. DOL writes “Voluntary Product Assessment Template,” where ITI’s template is the Voluntary Product Accessibility Template. And paragraph (c)(1) asks for an ACR “based on the most recent version of the Voluntary Product Assessment Template (VPAT) provided by the Information Technology Industry Council (ITI).” Most recent version of the template is not the same instruction as a WCAG version, and the two have not moved in step since 2023.
The state layer, and the one public artifact somebody has to sign
California is the cleanest illustration that “which version” is not a single-answer question for a single website.
Cal. Gov. Code § 7405(a) routes state entities to the federal standard: state governmental entities, “in developing, procuring, maintaining, or using electronic or information technology, either indirectly or through the use of state funds by other entities, shall comply with the accessibility requirements of Section 508 of the federal Rehabilitation Act of 1973, as amended (29 U.S.C. Sec. 794d), and regulations implementing that act as set forth in Part 1194 of Title 36 of the Federal Code of Regulations.” That lands on WCAG 2.0 Level A and AA.
Cal. Gov. Code § 11546.7(a) then adds a separate, public, dated artifact with named signatories. Before 1 July biennially, “the director of each state agency or state entity … and each chief information officer … shall post on the home page of the state agency’s or state entity’s Internet Web site a signed certification from the state agency’s or state entity’s director and chief information officer that they have determined that the Internet Web site is in compliance with Sections 7405 and 11135, and the Web Content Accessibility Guidelines 2.0, or a subsequent version, published by the Web Accessibility Initiative of the World Wide Web Consortium at a minimum Level AA success criteria.”
Read the drafting: “or a subsequent version.” California wrote a rolling reference while DOJ wrote a frozen one. And from 26 April 2027 the same California state agency website is also subject to 28 CFR 35.200(b) at WCAG 2.1 Level A and AA. Three instruments, two version families, one website, and one of the three produces a public certification with two named people’s signatures on it.
If you supply that agency, your evidence has to survive all three readings, and the certification is the one a journalist or a plaintiff can pull up in a browser.
Europe: V3.2.1 carries WCAG 2.1, and the WCAG 2.2 edition is a draft
EN 301 549 V3.2.1 (2021-03) states its own equivalence in clause 9.0: “Conformance with W3C Web Content Accessibility Guidelines (WCAG 2.1) [5] Level AA is equivalent to conforming with all of clauses 9.1 to 9.4 and the conformance requirements of clause 9.6 of the present document.” The same clause records the older mapping separately, since WCAG 2.0 Level AA reaches only an enumerated subset of clause 9.
The presumption of conformity is conditional, and the standard says so itself: “Once the present document is cited in the Official Journal of the European Union under Directive 2016/2102 [i.28], conformance with the normative clauses of the present document given in Tables A.1 and A.2 confers, within the limits of the scope of the present document, a presumption of conformity with the corresponding essential requirements of that Directive and associated EFTA regulations.” A version number alone confers nothing.
The European Commission’s own published pages state that V3.2.1 is the harmonized version cited in the Official Journal for the Web Accessibility Directive, having replaced V2.1.2 in August 2021 with an overlap period running to February 2022. The Commission puts the general rule plainly: only once a modified standard is harmonized through a reference in the Official Journal does it have legal significance.
A WCAG 2.2 edition does exist. ETSI publishes it as Draft EN 301 549 V4.1.0 (2025-11), prepared “under the Commission’s standardisation request C(2022) 6456 final [i.28] to provide one voluntary means of conforming to the essential requirements of Directive 2019/882 on the accessibility requirements for products and services,” and its own list of significant changes includes that “the requirements of clauses 9, 10 and 11 have all been updated to align with the WCAG 2.2 recommendation.” The word on the cover page is Draft, and the foreword states the document “is now submitted for the combined Public Enquiry and Vote phase.” Anyone telling you V4.1.x is the current European requirement, or quoting a date when it will be cited in the Official Journal, is ahead of the published record.
What an ISO/IEC 40500 citation obliges in a five-year contract
For years, “ISO/IEC 40500” was treated as a tidy, version-neutral way to write a WCAG requirement into a long contract. That stopped being true in September 2025, and a template drafted before then has not caught up.
EN 301 549 records the original equivalence in a note to clause 9.0: “WCAG 2.0 is identical to ISO/IEC 40500:2012: ‘Information technology - W3C Web Content Accessibility Guidelines (WCAG) 2.0’.” That equivalence is now historical. ISO/IEC 40500:2025 is Edition 2.0, published 24 September 2025, 72 pages, and its title is “Information technology - W3C Web Content Accessibility Guidelines (WCAG) 2.2.” The standards catalogues record it as a replacement rather than an addition: DIN Media’s entry states “This document replaces ISO/IEC 40500:2012-10.” W3C announced the approval on 21 October 2025, which is the date to attach to W3C’s announcement rather than to ISO’s act of publication.
| If your clause says | Before 24 September 2025 it meant | Signed today it resolves to | What it does not do |
|---|---|---|---|
| ”ISO/IEC 40500” (undated) | WCAG 2.0, via the 2012 edition | WCAG 2.2, via the 2025 edition, and it will move again at the next edition | Satisfy a Section 508 obligation on its own terms, since 36 CFR part 1194 incorporates WCAG 2.0 dated 11 December 2008, not an ISO designation |
| ”ISO/IEC 40500:2012” | WCAG 2.0 | WCAG 2.0, but pointing at an edition the catalogues record as replaced | Give the supplier a currently published document to buy or test against |
| ”ISO/IEC 40500:2025” | Did not exist | WCAG 2.2 | Discharge Title II or Section 504, which require the 5 June 2018 WCAG 2.1 edition, unless routed through equivalent facilitation |
| ”WCAG 2.0 Level A and Level AA, W3C Recommendation 11 December 2008, per 36 CFR part 1194 appendices A and C” | The same thing it means today | The same thing it means today | Nothing. This is the wording to use |
The ambiguity is already sitting inside the ITI template itself. The VPAT 2.5Rev 508 edition Word file lists its applicable standards as “Web Content Accessibility Guidelines 2.0 or WCAG 2.0 (ISO/IEC 40500)” and the Revised Section 508 standards. Undated ISO reference, in the artifact your suppliers fill in.
Name version, level and dated edition. Do not rely on the ISO designation alone, and do not write a rolling “or a subsequent version” clause unless you have actually decided that you want your supplier’s obligation to change without your signature.

View the data as a table
| Do | Don’t |
|---|---|
| Name version, level and dated edition in the clause itself | Do not rely on the ISO designation alone: undated, it now resolves to WCAG 2.2 via the 2025 edition |
| For federal ICT: WCAG 2.0 Level A and Level AA, W3C Recommendation 11 December 2008, per 36 CFR part 1194 | Do not treat ISO/IEC 40500:2012 as current; the catalogues record that edition as replaced |
| For a Title II or Section 504 buyer, name the 5 June 2018 WCAG 2.1 edition | Do not assume ISO/IEC 40500:2025 discharges Title II or Section 504, which require the 5 June 2018 WCAG 2.1 edition |
| Check which ISO reference your supplier’s VPAT edition carries; the 508 edition names ISO/IEC 40500 undated | Do not write a rolling ‘or a subsequent version’ clause unless you want the obligation to change without your signature |
When you owe two versions at once
One product, two buyers, two obligations, two evidence sets. It is entirely ordinary for a SaaS vendor selling into both federal and state or local government.

View the data as a list
- One product, two buyers: Federal agency and state university
- Two rules bind it: FAR subpart 39.2; 28 CFR 35.200(b)
- Two WCAG versions: 2.0 from 2008; 2.1 from 2018
- Two evidence sets: Two ACRs, or one INT edition
| Buyer | Their rule | Version and level they are measured against | The artifact that speaks to it |
|---|---|---|---|
| Federal agency | Section 508 via FAR subpart 39.2 | WCAG 2.0 Level A and AA, 11 December 2008 edition, plus 508 provisions WCAG does not cover | ACR on the VPAT 508 edition, plus Chapter 3 and Chapter 4/5 rows as applicable |
| State university or state agency | ADA Title II, 28 CFR 35.200(b), from 26 April 2027, or 26 April 2028 for a population under 50,000 or a special district government | WCAG 2.1 Level A and AA, 5 June 2018 edition | An ACR reporting WCAG 2.1, which the 508 edition template cannot produce |
| Hospital, health plan or HHS-funded program | Section 504, 45 CFR 84.84(b), from 11 May 2027, or 10 May 2028 under 15 employees | WCAG 2.1 Level A and AA, 5 June 2018 edition | Same as above |
| Health IT Module certifying to § 170.315(e)(1) | 45 CFR 170.315(e)(1), citing 170.204(a)(1) and (a)(2) | WCAG 2.0 Level A, with Level AA as an alternative demonstration | 508-edition style WCAG 2.0 reporting |
| EU public sector customer | Web Accessibility Directive via EN 301 549 V3.2.1 | WCAG 2.1 Level AA, plus the EN’s non-web clauses | ACR on the VPAT EU edition |
The template is the mechanism that makes this concrete. ITI is clear on terminology: the VPAT is the free template, and “Once completed, the VPAT® with documented testing results is referred to as an Accessibility Conformance Report (ACR).” The current template is Version 2.5Rev, dated April 2025, and it ships in four editions with different WCAG versions baked in. ITI’s summary reads: “WCAG 2.0 is incorporated into the 508 edition; WCAG 2.1 is incorporated into the EU edition; WCAG 2.2 is incorporated into the WCAG and INT editions.” The 508 edition also instructs, in its author instructions rather than its About section, “If other Standards/Guidelines are reported, then use the appropriate VPAT edition.”
Open the templates and the mapping is finer than that summary, which matters when you are choosing one. Each edition’s Applicable Standards/Guidelines table is the authoritative list of what that file can report:
- 508 edition. One WCAG row, “Web Content Accessibility Guidelines 2.0 or WCAG 2.0 (ISO/IEC 40500),” plus the Revised Section 508 standards. Its report sections are a WCAG 2.0 Report and a Revised Section 508 Report. It cannot produce a WCAG 2.1 row.
- EU edition. WCAG 2.0 and WCAG 2.1, plus EN 301 549 V3.1.1 (2019-11) and V3.2.1 (2021-03). No WCAG 2.2, and no Revised Section 508 report section.
- WCAG edition. WCAG 2.0, 2.1 and 2.2, and nothing else.
- INT edition. WCAG 2.0, WCAG 2.1 and WCAG 2.2, each with its own Level A, Level AA and Level AAA row, plus the Revised Section 508 standards and the two EN 301 549 versions. Its report sections are a WCAG 2.x Report, a Revised Section 508 Report and an EN 301 549 Report.
So a supplier handing a Title II buyer a 508-edition ACR is handing them a WCAG 2.0 report against a WCAG 2.1 obligation. Both documents are honest. They do not meet. And a supplier owing both federal and state buyers has exactly two workable answers: two reports on two editions, or one INT-edition report with the WCAG 2.0, 2.1 and 2.2 rows and the Section 508 tables all populated.
The failure has a published example that needs no client data to demonstrate. University of Washington Procurement Services procedure 7.2.15 sets WCAG 2.1 Level AA as its Minimum Digital Accessibility Standard and asks suppliers for “a current Accessibility Conformance Report (ACR) based on the most current version of the ITI Voluntary Product Accessibility Template (VPAT),” with an ACR from an independent third-party consultancy preferred. Its contract insert states UW’s own basis: “UW is a public entity.” Read that instruction against ITI’s edition table. The most current VPAT is 2.5Rev; its 508 edition carries WCAG 2.0 and its WCAG edition carries 2.0, 2.1 and 2.2. A supplier can satisfy the sentence exactly and still deliver evidence against a version the buyer did not ask for. The requirement and the artifact are specified in two different vocabularies, which is the same drift the DOL clause shows at (c)(1).
What a version-literate ACR header looks like is also public. Salesforce’s Accessibility Conformance Report for Sales Innovations for Prospect Management, International Edition, VPAT version 2.5, report date May 2025, lists WCAG 2.0, 2.1 and 2.2 separately in its Applicable Standards/Guidelines table, each with Level A “Yes,” Level AA “Yes,” Level AAA “No,” alongside “Yes” against the Revised Section 508 standards row and “Yes” against the combined EN 301 549 V3.1.1 (2019-11) and V3.2.1 (2021-03) row. It states which 508 provisions its WCAG tables carry (501.1 Scope, 504.2 Content Creation or Editing, 602.3 Electronic Support Documentation), and it names its evaluation methods and assistive technology pairings, including JAWS with Chrome, NVDA with Firefox and VoiceOver with Safari. If you are wondering what to demand from a supplier, demand that header. Our guidance on scoring a supplier’s ACR works through the rest of the rows.
Your existing test evidence probably speaks to WCAG 2.0
This is the part that turns a version question into a budget question.
The Access Board’s ICT Testing Baseline is the coverage definition behind most credible federal test packages, and it states its own version scope plainly: “While Section 508 requires WCAG 2.0 Level A and AA, Baseline tests with applicable WCAG success criteria (SC) reference the latest version (2.2) of WCAG Understanding SC articles. These updated Understanding SC articles provided improved clarity and explanations and informed the development of the Baseline tests. However, the Baselines are mapped only to Section 508 (and WCAG 2.0) requirements.” Baseline for Web version 3.1 was published 1 April 2024; Baseline for Electronic Documents version 1.0 followed on 30 September 2024.
The Baseline is a coverage definition, not a procedure. It describes itself as “a comprehensive set of test components that a Section 508 conformance test process should include to ensure full coverage of all requirements,” and explicitly not “a step-by-step testing procedure or methodology” and not “a specific testing tool or software.”
The consequence for a vendor with a federal test history: a Baseline-scoped package, including a DHS Trusted Tester package built on it, is WCAG 2.0 evidence. It does not by itself discharge a WCAG 2.1 obligation under Title II or Section 504. That is not a criticism of the method, which is rigorous. It is a scope fact, and it is the one that turns into a re-test. The question of whether a reviewer will accept your test evidence turns on three things: coverage, tester competence and version.
What conforming to WCAG 2.2 does and does not solve
Partly, and not on paper.
W3C’s position is that the versions coexist: “WCAG 2.0, WCAG 2.1, and WCAG 2.2 are all existing standards. WCAG 2.2 does not deprecate or supersede WCAG 2.1, and WCAG 2.1 does not deprecate or supersede WCAG 2.0.” The three were first published on 11 December 2008, 5 June 2018 and 5 October 2023, and the current WCAG 2.2 Recommendation is dated 12 December 2024.
W3C also says content conforming to 2.2 conforms to the earlier two: “Content that conforms to WCAG 2.2 also conforms to WCAG 2.0 and WCAG 2.1. The WG intends that for policies requiring conformance to WCAG 2.0 or WCAG 2.1, WCAG 2.2 can provide an alternate means of conformance.”
Two qualifications keep that from being a clean substitution.
First, WCAG 2.2 removed success criterion 4.1.1 Parsing, and W3C notes that authors “required by policy to conform with WCAG 2.0 or 2.1 will be able to update content to WCAG 2.2, but may need to continue to test and report 4.1.1.” A 2.2-only report has a hole in it where a 508 or Title II reviewer expects a row.
Second, under Title II the 2.2 route runs through equivalent facilitation at 28 CFR 35.203. DOJ accepted that “Public entities could also choose to comply with subpart H by conforming their web content to WCAG 2.2 Level AA … because WCAG 2.2 Level AA provides substantially equivalent or greater accessibility and usability to WCAG 2.1 Level AA,” and then said who carries the argument: “The responsibility for demonstrating equivalent facilitation rests with the public entity.” A supplier handing a public entity a WCAG 2.2 ACR is handing them a demonstration burden, not a discharge. Some buyers will take it. Some will send it back. Neither reaction is unreasonable, which is exactly why you settle it before testing rather than after.

View the data as a table
| Pros | Cons |
|---|---|
| W3C treats all three as existing standards: 2.2 does not deprecate or supersede 2.1, and 2.1 does not supersede 2.0 | WCAG 2.2 removed success criterion 4.1.1 Parsing, so a 2.2-only report has a hole where a reviewer expects a row |
| Content that conforms to WCAG 2.2 also conforms to WCAG 2.0 and WCAG 2.1 | Authors required by policy to conform with 2.0 or 2.1 may need to continue to test and report 4.1.1 |
| W3C intends 2.2 as an alternate means of conformance for policies requiring 2.0 or 2.1 | Under Title II the 2.2 route runs through equivalent facilitation at 28 CFR 35.203, not through the rule’s own standard |
| DOJ accepted that WCAG 2.2 Level AA provides substantially equivalent or greater accessibility than 2.1 Level AA | The responsibility for demonstrating equivalent facilitation rests with the public entity, so it is a burden, not a discharge |
What to write today
If you are drafting a requirement, write version, level, dated edition and the rule it comes from, in one sentence:
- Federal ICT: “WCAG 2.0 Level A and Level AA, W3C Recommendation 11 December 2008, as incorporated by the Revised Section 508 Standards at 36 CFR part 1194, appendices A and C, including provisions E205.4, E207.2 and 602.3.”
- State or local government: “WCAG 2.1 Level A and Level AA, W3C Recommendation 5 June 2018, as required by 28 CFR 35.200(b).”
- HHS-funded recipient: “WCAG 2.1 Level A and Level AA, W3C Recommendation 5 June 2018, as required by 45 CFR 84.84(b).”
- Test method, if you want comparable evidence: name it in the clause, the way 48 CFR 2952.239-70(b) does, and say what tester competence you expect, the way its paragraph (a)(4) does.
If you are choosing a VPAT edition, choose by buyer, not by habit. Federal only, 508 edition. EU public sector only, EU edition. State, local or HHS-funded buyers in the pipeline, you need WCAG 2.1 reporting, which the 508 edition cannot produce and the EU and INT editions can. Federal and domestic public sector together, the honest answer is either two reports or one INT-edition report carrying the 508 tables alongside the WCAG 2.1 rows, with the 4.1.1 Parsing gap handled explicitly wherever you also report 2.2. Our VPAT and ACR testing service scopes that decision before testing starts, because reversing it afterwards means paying twice.
If you are reviewing a supplier’s ACR this week, check four things in the header before you read a single row: which VPAT edition, which WCAG version and level, which dated edition of that version, and which test method. If any of the four is missing, the rows underneath cannot be scored against your obligation, whatever they say.
Next step
Open the last ACR you published or received. Find the Applicable Standards/Guidelines table in the header block, usually within the first two pages, and read the version line. If it says “WCAG 2.0” and any buyer in your pipeline is a state agency, a public university, a school district or an HHS-funded recipient, that document does not speak to their 2027 obligation, and you have roughly nine months to decide whether you are re-testing or losing the deal. If you would like a second reader on it, send us the ACR and the solicitation language and we will mark the specific rows that will not survive the version mismatch.