WCAG

Which WCAG version each US rule requires: 508, Title II and 504

David LoPresti By David LoPresti July 13, 2026

The solicitation says “WCAG 2.1 Level AA.” The Accessibility Conformance Report your team published fourteen months ago says “WCAG 2.0 Level A and AA, Revised Section 508 Standards.” Response is due Friday, and somebody has to decide whether that is a labeling problem or a re-test.

It is usually neither, and the reason nobody can resolve it quickly is that the market talks about WCAG as one moving target when US law treats it as several frozen ones. Three separate decisions run into that wall:

  1. A software vendor picks a VPAT edition before testing starts. The edition fixes the WCAG version, the version fixes the test scope, and the scope fixes what the audit costs. Pick the 508 edition, then lose a state university deal because the buyer wanted WCAG 2.1, and the audit gets paid for twice.
  2. A capture or contracts lead drafts an accessibility clause on a contract that will still be running in 2031, and has to choose between “WCAG 2.0 Level A and AA per 36 CFR part 1194,” “WCAG 2.1 Level A and AA per 28 CFR 35.200(b),” both, or a rolling “or a subsequent version” formulation.
  3. A public sector or higher education buyer holds a supplier’s ACR and has to decide whether a WCAG 2.0 report discharges the WCAG 2.1 obligation their own agency is about to be measured against.

The short answer to all three: a federal agency and a state university are bound to different WCAG versions, and a vendor selling to both owes both. Our Section 508 website compliance work starts with that split, because getting it wrong is what produces a rejected report rather than a remediated product.

Here is every rule that names a WCAG version, what it requires, who it binds, and the citation form to write into a document.

The matrix

Three-column comparison of the Revised Section 508 Standards, the ADA Title II web and mobile app rule and the HHS Section 504 web and mobile app rule. Section 508 requires WCAG 2.0 Level A and AA, binds federal agencies and their ICT suppliers through FAR subpart 39.2, is in force now, and is cited as 36 CFR part 1194 appendices A and C, provisions E205.4, E207.2 and 602.3. Title II requires WCAG 2.1 Level A and AA, binds state and local government public entities including content provided under contract or licensing, applies from 26 April 2027 at a population of 50,000 or more and 26 April 2028 below that, and is cited as 28 CFR 35.200(b) with WCAG 2.1 defined at 28 CFR 35.104. HHS Section 504 requires WCAG 2.1 Level A and AA, binds every program or activity receiving HHS federal financial assistance, applies from 11 May 2027 with 15 or more employees and 10 May 2028 with fewer, and is cited as 45 CFR 84.84(b) with the definition at 45 CFR 84.10.
The three US rules a vendor is most likely to meet at once. Section 508 sits on WCAG 2.0. Title II and HHS Section 504 sit on WCAG 2.1. Every other rule that names a version is in the table below.
View the data as a table
Revised Section 508ADA Title II web ruleHHS Section 504 web rule
WCAG version and levelWCAG 2.0 Level A and AAWCAG 2.1 Level A and AAWCAG 2.1 Level A and AA
Who is coveredFederal agencies; their ICT suppliers via FAR subpart 39.2State and local government public entities, including content provided under contract or licensingEvery program or activity receiving HHS federal financial assistance
In force fromIn force now26 April 2027 at population 50,000+; 26 April 2028 below that11 May 2027 with 15 or more employees; 10 May 2028 with fewer
Citation form to use36 CFR part 1194, appendices A and C; provisions E205.4, E207.2, 602.328 CFR 35.200(b); WCAG 2.1 defined at 28 CFR 35.10445 CFR 84.84(b); definition at 45 CFR 84.10
Rule or standardWCAG version and levelWho is coveredIn force fromCitation form to use
Revised Section 508 StandardsWCAG 2.0 Level A and AAFederal agencies; their ICT suppliers via FAR subpart 39.2In force now36 CFR part 1194, appendices A and C; provisions E205.4, E207.2, 602.3; IBR at 702.10.1 (WCAG 2.0, W3C Recommendation, December 11, 2008)
ADA Title II web and mobile app ruleWCAG 2.1 Level A and AAState and local government “public entities,” including content provided through contractual or licensing arrangements26 April 2027 (population 50,000+); 26 April 2028 (under 50,000 or special district government)28 CFR 35.200(b); WCAG 2.1 defined at 28 CFR 35.104 (W3C Recommendation 05 June 2018)
HHS Section 504 web and mobile app ruleWCAG 2.1 Level A and AAEvery program or activity receiving HHS federal financial assistance11 May 2027 (15 or more employees); 10 May 2028 (fewer than 15)45 CFR 84.84(b); definition at 45 CFR 84.10
Air Carrier Access Act website ruleWCAG 2.0 Level AAUS and foreign carriers operating at least one aircraft with a designed seating capacity over 60 passengers, for a primary website marketing air transportation to the general public in the United StatesIn force now14 CFR 382.43(c)(1), which names the “World Wide Web Consortium (W3C) Recommendation 11 December 2008” in the rule text
Certified health IT, view/download/transmit criterionWCAG 2.0 Level A, with Level AA available as an alternative demonstrationHealth IT Modules certifying to § 170.315(e)(1)In force now45 CFR 170.315(e)(1), citing the standards adopted at 45 CFR 170.204(a)(1) and (a)(2); IBR at 45 CFR 170.299
Medicaid managed careWCAG 2.0 AA “and successor versions,” inside the definition of “readily accessible”Enrollee information from states, MCOs, PIHPs, PAHPs, PCCMs and PCCM entitiesIn force now42 CFR 438.10(a) for the definition; operative at 438.10(c)(1) and (d)(6)
Department of Labor acquisition clauseWCAG 2.0 Level A and AA, tested by the DHS Trusted Tester harmonized processDOL ICT contractorsIn force now48 CFR 2952.239-70(b)(1)
WIOA Title I nondiscrimination”Consistent with” WCAG 2.0 AA, offered as an example. Not an incorporation by referenceWIOA Title I recipientsIn force now29 CFR 38.15(a)(5)(ii)
OFCCP Section 503Encouragement in a footnote. No conformance obligationFederal contractorsNot applicable41 CFR 60-741.44, footnote 3
California state entitiesWCAG 2.0 A and AA through Section 508, plus WCAG 2.0 “or a subsequent version” at minimum Level AA for the public certificationCalifornia state agencies and state entitiesIn force now; certification due before 1 July bienniallyCal. Gov. Code §§ 7405(a) and 11546.7(a)
EN 301 549 V3.2.1 (2021-03)WCAG 2.1 Level AA for web contentICT covered by the EU Web Accessibility DirectiveVersion cited in the Official JournalEN 301 549 V3.2.1, clause 9.0
ISO/IEC 40500:2025WCAG 2.2Nothing in US law. A citation label, not an obligationPublished 24 September 2025ISO/IEC 40500:2025, Edition 2

Two things in that table are worth stating flat.

Section 508 has never required anything other than WCAG 2.0. Extract the plain text of the full published standard at the Access Board’s ICT page, which carries the Revised 508 Standards, the Section 255 Guidelines, the preamble and Appendix D, and on 27 July 2026 it contains 155 occurrences of “WCAG 2.0,” zero occurrences of “WCAG 2.1” and zero occurrences of “WCAG 2.2.” The two zeros are the load-bearing numbers, and they hold under any counting method.

No provision of the Code of Federal Regulations requires WCAG 2.2. An exact-phrase full-text search of the eCFR on 27 July 2026 returns two hits for “WCAG 2.2,” both inside the appendix guidance to the DOJ Title II rule, neither in operative regulatory text. That claim is scoped to the CFR. State statutes, state IT policies, university standards and contract terms sit outside it and were not searched exhaustively.

The CFR census, which you can re-run yourself

The eCFR exposes a search API. Query it for each exact phrase and the version landscape resolves into something a contracts lead can actually reason about.

Exact phraseHitsWhere it appears in the CFR (27 July 2026)
“WCAG 2.2”2Both in 28 CFR part 35 Appendix D, the DOJ Title II guidance appendix. Nothing operative
”WCAG 2.1”1228 CFR 35.104, 35.200, 35.202 and part 35 Appendix D; 45 CFR 84.10, 84.84, 84.86
”WCAG 2.0”4936 CFR part 1194 appendices A, B and C; 14 CFR 382.3 and 382.43; 45 CFR 170.204 and 170.299; 48 CFR 2952.239-70; 29 CFR 38.15; 41 CFR 60-741.44; 42 CFR 438.10; 28 CFR part 35 Appendix D

Eight parts across eight titles carry the phrase “WCAG 2.0.” Drop 28 CFR part 35 Appendix D, which is guidance rather than operative text, and it is seven parts across seven titles. Two parts carry “WCAG 2.1.” Nothing operative carries “WCAG 2.2.” If your internal position is “WCAG is basically 2.2 now,” the regulatory record disagrees by a wide margin.

Section 508: WCAG 2.0 Level A and AA, and only for federal agencies

The Access Board is explicit about scope at E101.1: “Compliance with these standards is mandatory for Federal agencies subject to Section 508 of the Rehabilitation Act of 1973, as amended (29 U.S.C. 794d).” Section508.gov puts the statutory reach the same way: “The law 29 U.S.C § 794d applies to all federal agencies when they develop, procure, maintain, or use electronic and information technology.”

Three provisions carry the WCAG obligation, and a vendor’s ACR should account for all three rather than the first one.

  • E205.4 Accessibility Standard covers electronic content: “Electronic content shall conform to Level A and Level AA Success Criteria and Conformance Requirements in WCAG 2.0 (incorporated by reference, see 702.10.1).”
  • E207.2 WCAG Conformance covers software: “User interface components, as well as the content of platforms and applications, shall conform to Level A and Level AA Success Criteria and Conformance Requirements in WCAG 2.0 (incorporated by reference, see 702.10.1).”
  • 602.3 Electronic Support Documentation covers documentation, and it is easy to leave out when scoping: “Documentation in electronic format, including Web-based self-service support, shall conform to Level A and Level AA Success Criteria and Conformance Requirements in WCAG 2.0 (incorporated by reference, see 702.10.1).” Your help center is in scope.
Hub-and-spoke breakdown of the Revised Section 508 WCAG 2.0 Level A and AA obligation, incorporated by reference at provision 702.10.1 as the W3C Recommendation of December 11, 2008. Three provisions carry it: E205.4, under which electronic content shall conform to Level A and Level AA; E207.2, which covers user interface components and the content of platforms and applications; and 602.3, which covers documentation in electronic format, including web-based self-service support, so a help center is in scope.
Three provisions carry the Section 508 WCAG obligation. An ACR that accounts for only the first one has left content or documentation unreported.
View the data as a list

Revised 508: WCAG 2.0 Level A and AA: Incorporated by reference at 702.10.1, W3C Recommendation December 11, 2008

  • E205.4 Electronic content: Electronic content shall conform to Level A and Level AA
  • E207.2 Software: User interface components, platforms and applications
  • 602.3 Support documentation: Documentation in electronic format. Your help center is in scope

The incorporation is dated, and it is a closed list. Provision 702.10.1 names “Web Content Accessibility Guidelines (WCAG) 2.0, W3C Recommendation, December 11, 2008” and then enumerates exactly which provisions the incorporation reaches: in Appendix A, E205.4, E205.4 Exception, E205.4.1, E207.2, E207.2 Exception 2, E207.2 Exception 3, E207.2.1 and E207.3; in Appendix B, the Section 255 Communications Act scoping at C203.1, C203.1 Exception, C203.1.1, C205.2, C205.2 Exception 2, C205.2 Exception 3, C205.2.1 and C205.3; and in Appendix C, 408.3 Exception, 501.1 Exception, 504.2, 504.3, 504.4 and 602.3. Anything not on that list is not carrying WCAG by reference.

A 508 obligation is close to a plain WCAG 2.0 AA obligation but is not identical, and the difference is testable. E205.4 carries an exception: “Non-Web documents shall not be required to conform to the following four WCAG 2.0 Success Criteria: 2.4.1 Bypass Blocks, 2.4.5 Multiple Ways, 3.2.3 Consistent Navigation, and 3.2.4 Consistent Identification.” E207.2 releases non-web software from the same four, and separately from “Conformance Requirement 3 Complete Processes in WCAG 2.0.” E205.4.1 and E207.2.1 then substitute “document” or “software” for “Web page” throughout, and swap “in a document” or “in software” for “on a Web page” inside Success Criterion 1.4.2.

Section 508 also reaches hardware in Chapter 4, non-electronic support documentation at 602.4 and support services at 603, none of which WCAG addresses at all. Where the technical chapters run out, the standard says what fills the gap. E204.1 General: “Where the requirements in Chapters 4 and 5 do not address one or more functions of ICT, the functions not addressed shall conform to the Functional Performance Criteria specified in Chapter 3.” That is a conformance route, and it is a different mechanism from marking a row Not Applicable. The Chapter 3 functional performance criteria are where it lands on the report.

For web content the applicable set has a number attached to it. Section508.gov states: “A page that fails to meet even one of the 38 applicable WCAG success criteria does not conform to the standards. A set of pages in a sequence, e.g., identifying, selecting, and paying for a ticket to a public event, does not conform if any of those steps fails to conform fully.” Thirty-eight is WCAG 2.0 Level A and AA counted together: 25 criteria at Level A and 13 at Level AA. All or nothing, at the page level and across the process.

Vendors are reached through the acquisition regulation rather than by the statute. FAR 39.203(a) provides that “Unless an exception at 39.204 or an exemption at 39.205 applies, acquisitions for ICT supplies and services shall meet the applicable ICT accessibility standards at 36 CFR 1194.1,” and FAR 39.201(a) states that the subpart “implements section 508 of the Rehabilitation Act of 1973 (29 U.S.C. 794d)” and the Access Board’s standards at the same citation. That is why a supplier who has never read the Rehabilitation Act still ends up with WCAG 2.0 in a statement of work.

One relief valve worth knowing before you scope a remediation budget. E202.2 Legacy ICT provides that “Any component or portion of existing ICT that complies with an earlier standard issued pursuant to Section 508 of the Rehabilitation Act of 1973, as amended (as republished in Appendix D), and that has not been altered on or after January 18, 2018, shall not be required to be modified to conform to the Revised 508 Standards.” It operates component by component, not product by product, which is why an old report does not automatically become worthless.

ADA Title II: WCAG 2.1 Level A and AA, for state and local government

This is a costly misreading, and it turns up regularly in solicitation language. Federal agencies are not Title II entities.

“Public entity” at 28 CFR 35.104 means “(1) Any State or local government; (2) Any department, agency, special purpose district, or other instrumentality of a State or States or local government; and (3) The National Railroad Passenger Corporation, and any commuter authority (as defined in section 103(8) of the Rail Passenger Service Act).” The federal government appears nowhere in that definition. A federal agency asking you for a WCAG 2.1 ACR “because of the DOJ rule” is asking for something that rule does not impose on it.

The obligation itself, at 28 CFR 35.200(b), requires a covered entity to ensure web content and mobile apps “comply with Level A and Level AA success criteria and conformance requirements specified in WCAG 2.1.” Level A and Level AA, not Level AA alone. WCAG 2.1 has 30 success criteria at Level A and 20 at Level AA, 50 in total for the obligation. Anyone writing “Title II requires 2.1 AA” is describing 20 of the 50 and dropping the other 30.

The reach into your contract is at 35.200(a), which covers web content and mobile apps a public entity “provides or makes available, directly or through contractual, licensing, or other arrangements.” That single clause is what puts a supplier’s ACR inside the buyer’s own compliance file.

The dates now codified are the extended ones. An interim final rule published 20 April 2026 moved them: “The compliance date for State and local government entities with a total population of 50,000 or more is extended from April 24, 2026, to April 26, 2027. The compliance date for public entities with a total population of less than 50,000, or any special district government, is extended from April 26, 2027, to April 26, 2028.” Sources that have not been refreshed since the 2024 final rule still print 24 April 2026. If a solicitation you are answering quotes that date, the drafter has not refreshed since spring.

Three points from DOJ’s own preamble are worth quoting back to anyone who insists the versions must converge.

DOJ considered WCAG 2.2 and declined it: “The Department believes that adopting WCAG 2.1 as the technical standard rather than WCAG 2.2 is the most prudent approach at this time. W3C, while recommending the use of the most recent recommended standard, has made clear that WCAG 2.2 does not ‘deprecate or supersede’ WCAG 2.1 and has stated that WCAG 2.1 is still an existing standard.”

DOJ also considered WCAG 2.0 and rejected it, and in doing so put the federal split on the record: “Alternatively, the Department considered adopting WCAG 2.0. This change was suggested by the Small Business Administration, which argued that public entities should not have to comply with a more rigorous standard for online accessibility than the Federal Government, which is required to conform to WCAG 2.0 under section 508 of the Rehabilitation Act.” A federal regulator describing the two-version split is a stronger citation than any consultant’s summary.

And nothing drifts upward on its own: “The Department notes that when W3C publishes new versions of WCAG, those versions will not be automatically incorporated into this rule. Federal agencies do not incorporate by reference into published regulations future versions of standards developed by bodies like W3C.”

“WCAG 2.1” in this rule also means one frozen document. 28 CFR 35.104 defines it as “the Web Content Accessibility Guidelines (‘WCAG’) 2.1, W3C Recommendation 05 June 2018,” and pins the URL of that dated edition. W3C has since republished WCAG 2.1 three times, on 21 September 2023, 12 December 2024 and 6 May 2025, and the current Recommendation is the 6 May 2025 one. Those are not the same document as the one the rule incorporates, and an audit report that says only “WCAG 2.1” has not told the reviewer which one it tested against.

HHS Section 504: same version, same level, different population, different dates

45 CFR 84.84(b) uses the same operative wording as Title II: recipients shall ensure web content and mobile apps “comply with Level A and Level AA success criteria and conformance requirements specified in WCAG 2.1.” Same version, same level, same frozen 5 June 2018 edition, defined at 45 CFR 84.10 with the same dated URL DOJ used. If you see the two rules described as sitting at different levels, that description is wrong.

What differs is who is covered and when. 45 CFR 84.82 states the scope in one sentence: “This subpart applies to all programs or activities that receive Federal financial assistance from the Department.” That is the university, hospital and health plan population, and it overlaps with Title II without being the same set. A private nonprofit hospital taking HHS funds is a 504 recipient and not a Title II public entity. A state university is frequently both.

The dates were also extended by a year, by an interim final rule published 11 May 2026: “The compliance date for recipients with fifteen (15) or more employees is extended from May 11, 2026, to May 11, 2027. The compliance date for recipients with fewer than fifteen (15) employees is extended from May 10, 2027, to May 10, 2028.”

Cite § 84.84(b) for the requirement, not the subpart range. Subpart I does run from § 84.82 to § 84.89, but citing the range tells a reviewer you have not read to the subsection, and WCAG 2.1 also appears at § 84.86 for conforming alternate versions, which is a different obligation with its own trigger: a recipient may use them “only where it is not possible to make web content directly accessible due to technical or legal limitations.”

One scoping note that matters if you sell hardware. Subpart I is titled “Web, Mobile, and Kiosk Accessibility,” and the kiosk provision is a general nondiscrimination duty with no version attached. 45 CFR 84.83 reads in full: “No qualified individual with a disability shall, on the basis of disability, be excluded from participation in, be denied the benefits of, or otherwise be subjected to discrimination under any program or activity of a recipient provided through kiosks.” No WCAG citation, no level. A kiosk deployed by an HHS recipient is covered by the subpart and is not measured against WCAG 2.1 by § 84.84(b), which reaches web content and mobile apps.

The weaker instruments, and the one strong one

Three of the WCAG 2.0 appearances in the CFR are not conformance requirements, and treating them as such damages your credibility with a reviewer who has read them. A fourth is the strongest version clause in the CFR, and it is worth reading for the opposite reason.

41 CFR 60-741.44 (OFCCP, Section 503) mentions WCAG only in a footnote hanging off the personnel-processes paragraph, in hortatory form. Footnote 3: “Contractors are encouraged to make their information and communication technology accessible.” It then lists WCAG 2.0 among “a variety of resources that may assist contractors.” No obligation, no version lock. Do not cite it as a requirement.

29 CFR 38.15(a)(5)(ii) (WIOA) requires technology that is “consistent with modern accessibility standards, such as Section 508 Standards (36 CFR part 1194) and W3C’s Web Content Accessibility Guidelines (WCAG) 2.0 AA.” “Consistent with” and “such as” are illustrative wording, not incorporation by reference.

42 CFR 438.10 (Medicaid managed care) defines “readily accessible” as “electronic information and services which comply with modern accessibility standards such as section 508 guidelines, section 504 of the Rehabilitation Act, and W3C’s Web Content Accessibility Guidelines (WCAG) 2.0 AA and successor versions.” The definition feeds real duties: 438.10(c)(1) requires all information in the section to be provided “in a manner and format that may be easily understood and is readily accessible,” and 438.10(d)(6) forbids electronic delivery of enrollee information unless “The format is readily accessible” and the information sits somewhere on the website “that is prominent and readily accessible.” So it is an operative requirement with a rolling definition, which is the opposite drafting choice from DOJ’s frozen edition. The target can move without any rulemaking.

48 CFR 2952.239-70 (Department of Labor) is the model for what a version requirement looks like once it reaches a contract file. Paragraph (b) requires the contractor to “test and validate the ICT for conformance to the Revised 508 Standards (36 CFR part 1194, appendices A and C), in accordance with the required testing methods and provide test results to verify conformance of the Voluntary Product Assessment Template (VPAT).” Paragraph (b)(1) then names the method: “For web and software, WCAG 2.0 Level A and AA Conformance test results shall be based on the Accessibility Tests for Software and Web, Harmonized Testing Process for Section 508 Compliance from the DHS Trusted Tester program.” Paragraph (b)(2) does the same for documents, pointing at “the Harmonized Testing Guidance from the Accessible Electronic Documents Community of Practice.” Paragraph (a)(4) reaches the supplier’s own capability: its processes must be “at a maturity level at least equivalent to the DHS Trusted Tester methodology.”

Standard, version, level, test process and tester competence, all in one clause. If you are drafting, that is the shape to copy, and the companion piece on Section 508 contract clauses and QASPs works through the acceptance and surveillance language that has to sit around it.

Two details in the same clause are worth noticing, because they show how easily version and artifact drift apart even in well-drafted text. DOL writes “Voluntary Product Assessment Template,” where ITI’s template is the Voluntary Product Accessibility Template. And paragraph (c)(1) asks for an ACR “based on the most recent version of the Voluntary Product Assessment Template (VPAT) provided by the Information Technology Industry Council (ITI).” Most recent version of the template is not the same instruction as a WCAG version, and the two have not moved in step since 2023.

The state layer, and the one public artifact somebody has to sign

California is the cleanest illustration that “which version” is not a single-answer question for a single website.

Cal. Gov. Code § 7405(a) routes state entities to the federal standard: state governmental entities, “in developing, procuring, maintaining, or using electronic or information technology, either indirectly or through the use of state funds by other entities, shall comply with the accessibility requirements of Section 508 of the federal Rehabilitation Act of 1973, as amended (29 U.S.C. Sec. 794d), and regulations implementing that act as set forth in Part 1194 of Title 36 of the Federal Code of Regulations.” That lands on WCAG 2.0 Level A and AA.

Cal. Gov. Code § 11546.7(a) then adds a separate, public, dated artifact with named signatories. Before 1 July biennially, “the director of each state agency or state entity … and each chief information officer … shall post on the home page of the state agency’s or state entity’s Internet Web site a signed certification from the state agency’s or state entity’s director and chief information officer that they have determined that the Internet Web site is in compliance with Sections 7405 and 11135, and the Web Content Accessibility Guidelines 2.0, or a subsequent version, published by the Web Accessibility Initiative of the World Wide Web Consortium at a minimum Level AA success criteria.”

Read the drafting: “or a subsequent version.” California wrote a rolling reference while DOJ wrote a frozen one. And from 26 April 2027 the same California state agency website is also subject to 28 CFR 35.200(b) at WCAG 2.1 Level A and AA. Three instruments, two version families, one website, and one of the three produces a public certification with two named people’s signatures on it.

If you supply that agency, your evidence has to survive all three readings, and the certification is the one a journalist or a plaintiff can pull up in a browser.

Europe: V3.2.1 carries WCAG 2.1, and the WCAG 2.2 edition is a draft

EN 301 549 V3.2.1 (2021-03) states its own equivalence in clause 9.0: “Conformance with W3C Web Content Accessibility Guidelines (WCAG 2.1) [5] Level AA is equivalent to conforming with all of clauses 9.1 to 9.4 and the conformance requirements of clause 9.6 of the present document.” The same clause records the older mapping separately, since WCAG 2.0 Level AA reaches only an enumerated subset of clause 9.

The presumption of conformity is conditional, and the standard says so itself: “Once the present document is cited in the Official Journal of the European Union under Directive 2016/2102 [i.28], conformance with the normative clauses of the present document given in Tables A.1 and A.2 confers, within the limits of the scope of the present document, a presumption of conformity with the corresponding essential requirements of that Directive and associated EFTA regulations.” A version number alone confers nothing.

The European Commission’s own published pages state that V3.2.1 is the harmonized version cited in the Official Journal for the Web Accessibility Directive, having replaced V2.1.2 in August 2021 with an overlap period running to February 2022. The Commission puts the general rule plainly: only once a modified standard is harmonized through a reference in the Official Journal does it have legal significance.

A WCAG 2.2 edition does exist. ETSI publishes it as Draft EN 301 549 V4.1.0 (2025-11), prepared “under the Commission’s standardisation request C(2022) 6456 final [i.28] to provide one voluntary means of conforming to the essential requirements of Directive 2019/882 on the accessibility requirements for products and services,” and its own list of significant changes includes that “the requirements of clauses 9, 10 and 11 have all been updated to align with the WCAG 2.2 recommendation.” The word on the cover page is Draft, and the foreword states the document “is now submitted for the combined Public Enquiry and Vote phase.” Anyone telling you V4.1.x is the current European requirement, or quoting a date when it will be cited in the Official Journal, is ahead of the published record.

What an ISO/IEC 40500 citation obliges in a five-year contract

For years, “ISO/IEC 40500” was treated as a tidy, version-neutral way to write a WCAG requirement into a long contract. That stopped being true in September 2025, and a template drafted before then has not caught up.

EN 301 549 records the original equivalence in a note to clause 9.0: “WCAG 2.0 is identical to ISO/IEC 40500:2012: ‘Information technology - W3C Web Content Accessibility Guidelines (WCAG) 2.0’.” That equivalence is now historical. ISO/IEC 40500:2025 is Edition 2.0, published 24 September 2025, 72 pages, and its title is “Information technology - W3C Web Content Accessibility Guidelines (WCAG) 2.2.” The standards catalogues record it as a replacement rather than an addition: DIN Media’s entry states “This document replaces ISO/IEC 40500:2012-10.” W3C announced the approval on 21 October 2025, which is the date to attach to W3C’s announcement rather than to ISO’s act of publication.

If your clause saysBefore 24 September 2025 it meantSigned today it resolves toWhat it does not do
”ISO/IEC 40500” (undated)WCAG 2.0, via the 2012 editionWCAG 2.2, via the 2025 edition, and it will move again at the next editionSatisfy a Section 508 obligation on its own terms, since 36 CFR part 1194 incorporates WCAG 2.0 dated 11 December 2008, not an ISO designation
”ISO/IEC 40500:2012”WCAG 2.0WCAG 2.0, but pointing at an edition the catalogues record as replacedGive the supplier a currently published document to buy or test against
”ISO/IEC 40500:2025”Did not existWCAG 2.2Discharge Title II or Section 504, which require the 5 June 2018 WCAG 2.1 edition, unless routed through equivalent facilitation
”WCAG 2.0 Level A and Level AA, W3C Recommendation 11 December 2008, per 36 CFR part 1194 appendices A and C”The same thing it means todayThe same thing it means todayNothing. This is the wording to use

The ambiguity is already sitting inside the ITI template itself. The VPAT 2.5Rev 508 edition Word file lists its applicable standards as “Web Content Accessibility Guidelines 2.0 or WCAG 2.0 (ISO/IEC 40500)” and the Revised Section 508 standards. Undated ISO reference, in the artifact your suppliers fill in.

Name version, level and dated edition. Do not rely on the ISO designation alone, and do not write a rolling “or a subsequent version” clause unless you have actually decided that you want your supplier’s obligation to change without your signature.

Do and do not guidance for writing a WCAG version into a long contract after the ISO/IEC 40500 edition change. Do: name version, level and dated edition in the clause itself; write WCAG 2.0 Level A and Level AA, W3C Recommendation 11 December 2008, per 36 CFR part 1194 appendices A and C; for a Title II or Section 504 buyer name the 5 June 2018 WCAG 2.1 edition; and check which ISO reference your supplier's VPAT edition carries, since the 508 edition names ISO/IEC 40500 undated. Do not: rely on the ISO designation alone, because an undated ISO/IEC 40500 clause now resolves to WCAG 2.2 via the 2025 edition; treat ISO/IEC 40500:2012 as current, because the catalogues record it as replaced; assume an ISO/IEC 40500:2025 citation discharges Title II or Section 504, which require the 5 June 2018 WCAG 2.1 edition; or write a rolling or a subsequent version clause unless you want the obligation to change without your signature.
An undated ISO/IEC 40500 clause changed version on 24 September 2025 and nobody re-signed anything. This is the wording that survives a five-year contract.
View the data as a table
DoDon’t
Name version, level and dated edition in the clause itselfDo not rely on the ISO designation alone: undated, it now resolves to WCAG 2.2 via the 2025 edition
For federal ICT: WCAG 2.0 Level A and Level AA, W3C Recommendation 11 December 2008, per 36 CFR part 1194Do not treat ISO/IEC 40500:2012 as current; the catalogues record that edition as replaced
For a Title II or Section 504 buyer, name the 5 June 2018 WCAG 2.1 editionDo not assume ISO/IEC 40500:2025 discharges Title II or Section 504, which require the 5 June 2018 WCAG 2.1 edition
Check which ISO reference your supplier’s VPAT edition carries; the 508 edition names ISO/IEC 40500 undatedDo not write a rolling ‘or a subsequent version’ clause unless you want the obligation to change without your signature

When you owe two versions at once

One product, two buyers, two obligations, two evidence sets. It is entirely ordinary for a SaaS vendor selling into both federal and state or local government.

Four-step causal chain reading left to right. One product, two buyers: a federal agency and a state university. Two rules bind it: Section 508 through FAR subpart 39.2, and ADA Title II at 28 CFR 35.200(b). Two WCAG versions follow: WCAG 2.0 on the 11 December 2008 edition, and WCAG 2.1 on the 5 June 2018 edition. Two evidence sets result, because the 508 edition of the VPAT cannot produce a WCAG 2.1 row: either two ACRs on two editions, or one INT-edition report carrying both.
One product, two buyers, two evidence sets. The fork at the end is the decision that has to be made before testing starts, not after.
View the data as a list
  1. One product, two buyers: Federal agency and state university
  2. Two rules bind it: FAR subpart 39.2; 28 CFR 35.200(b)
  3. Two WCAG versions: 2.0 from 2008; 2.1 from 2018
  4. Two evidence sets: Two ACRs, or one INT edition
BuyerTheir ruleVersion and level they are measured againstThe artifact that speaks to it
Federal agencySection 508 via FAR subpart 39.2WCAG 2.0 Level A and AA, 11 December 2008 edition, plus 508 provisions WCAG does not coverACR on the VPAT 508 edition, plus Chapter 3 and Chapter 4/5 rows as applicable
State university or state agencyADA Title II, 28 CFR 35.200(b), from 26 April 2027, or 26 April 2028 for a population under 50,000 or a special district governmentWCAG 2.1 Level A and AA, 5 June 2018 editionAn ACR reporting WCAG 2.1, which the 508 edition template cannot produce
Hospital, health plan or HHS-funded programSection 504, 45 CFR 84.84(b), from 11 May 2027, or 10 May 2028 under 15 employeesWCAG 2.1 Level A and AA, 5 June 2018 editionSame as above
Health IT Module certifying to § 170.315(e)(1)45 CFR 170.315(e)(1), citing 170.204(a)(1) and (a)(2)WCAG 2.0 Level A, with Level AA as an alternative demonstration508-edition style WCAG 2.0 reporting
EU public sector customerWeb Accessibility Directive via EN 301 549 V3.2.1WCAG 2.1 Level AA, plus the EN’s non-web clausesACR on the VPAT EU edition

The template is the mechanism that makes this concrete. ITI is clear on terminology: the VPAT is the free template, and “Once completed, the VPAT® with documented testing results is referred to as an Accessibility Conformance Report (ACR).” The current template is Version 2.5Rev, dated April 2025, and it ships in four editions with different WCAG versions baked in. ITI’s summary reads: “WCAG 2.0 is incorporated into the 508 edition; WCAG 2.1 is incorporated into the EU edition; WCAG 2.2 is incorporated into the WCAG and INT editions.” The 508 edition also instructs, in its author instructions rather than its About section, “If other Standards/Guidelines are reported, then use the appropriate VPAT edition.”

Open the templates and the mapping is finer than that summary, which matters when you are choosing one. Each edition’s Applicable Standards/Guidelines table is the authoritative list of what that file can report:

  • 508 edition. One WCAG row, “Web Content Accessibility Guidelines 2.0 or WCAG 2.0 (ISO/IEC 40500),” plus the Revised Section 508 standards. Its report sections are a WCAG 2.0 Report and a Revised Section 508 Report. It cannot produce a WCAG 2.1 row.
  • EU edition. WCAG 2.0 and WCAG 2.1, plus EN 301 549 V3.1.1 (2019-11) and V3.2.1 (2021-03). No WCAG 2.2, and no Revised Section 508 report section.
  • WCAG edition. WCAG 2.0, 2.1 and 2.2, and nothing else.
  • INT edition. WCAG 2.0, WCAG 2.1 and WCAG 2.2, each with its own Level A, Level AA and Level AAA row, plus the Revised Section 508 standards and the two EN 301 549 versions. Its report sections are a WCAG 2.x Report, a Revised Section 508 Report and an EN 301 549 Report.

So a supplier handing a Title II buyer a 508-edition ACR is handing them a WCAG 2.0 report against a WCAG 2.1 obligation. Both documents are honest. They do not meet. And a supplier owing both federal and state buyers has exactly two workable answers: two reports on two editions, or one INT-edition report with the WCAG 2.0, 2.1 and 2.2 rows and the Section 508 tables all populated.

The failure has a published example that needs no client data to demonstrate. University of Washington Procurement Services procedure 7.2.15 sets WCAG 2.1 Level AA as its Minimum Digital Accessibility Standard and asks suppliers for “a current Accessibility Conformance Report (ACR) based on the most current version of the ITI Voluntary Product Accessibility Template (VPAT),” with an ACR from an independent third-party consultancy preferred. Its contract insert states UW’s own basis: “UW is a public entity.” Read that instruction against ITI’s edition table. The most current VPAT is 2.5Rev; its 508 edition carries WCAG 2.0 and its WCAG edition carries 2.0, 2.1 and 2.2. A supplier can satisfy the sentence exactly and still deliver evidence against a version the buyer did not ask for. The requirement and the artifact are specified in two different vocabularies, which is the same drift the DOL clause shows at (c)(1).

What a version-literate ACR header looks like is also public. Salesforce’s Accessibility Conformance Report for Sales Innovations for Prospect Management, International Edition, VPAT version 2.5, report date May 2025, lists WCAG 2.0, 2.1 and 2.2 separately in its Applicable Standards/Guidelines table, each with Level A “Yes,” Level AA “Yes,” Level AAA “No,” alongside “Yes” against the Revised Section 508 standards row and “Yes” against the combined EN 301 549 V3.1.1 (2019-11) and V3.2.1 (2021-03) row. It states which 508 provisions its WCAG tables carry (501.1 Scope, 504.2 Content Creation or Editing, 602.3 Electronic Support Documentation), and it names its evaluation methods and assistive technology pairings, including JAWS with Chrome, NVDA with Firefox and VoiceOver with Safari. If you are wondering what to demand from a supplier, demand that header. Our guidance on scoring a supplier’s ACR works through the rest of the rows.

Your existing test evidence probably speaks to WCAG 2.0

This is the part that turns a version question into a budget question.

The Access Board’s ICT Testing Baseline is the coverage definition behind most credible federal test packages, and it states its own version scope plainly: “While Section 508 requires WCAG 2.0 Level A and AA, Baseline tests with applicable WCAG success criteria (SC) reference the latest version (2.2) of WCAG Understanding SC articles. These updated Understanding SC articles provided improved clarity and explanations and informed the development of the Baseline tests. However, the Baselines are mapped only to Section 508 (and WCAG 2.0) requirements.” Baseline for Web version 3.1 was published 1 April 2024; Baseline for Electronic Documents version 1.0 followed on 30 September 2024.

The Baseline is a coverage definition, not a procedure. It describes itself as “a comprehensive set of test components that a Section 508 conformance test process should include to ensure full coverage of all requirements,” and explicitly not “a step-by-step testing procedure or methodology” and not “a specific testing tool or software.”

The consequence for a vendor with a federal test history: a Baseline-scoped package, including a DHS Trusted Tester package built on it, is WCAG 2.0 evidence. It does not by itself discharge a WCAG 2.1 obligation under Title II or Section 504. That is not a criticism of the method, which is rigorous. It is a scope fact, and it is the one that turns into a re-test. The question of whether a reviewer will accept your test evidence turns on three things: coverage, tester competence and version.

What conforming to WCAG 2.2 does and does not solve

Partly, and not on paper.

W3C’s position is that the versions coexist: “WCAG 2.0, WCAG 2.1, and WCAG 2.2 are all existing standards. WCAG 2.2 does not deprecate or supersede WCAG 2.1, and WCAG 2.1 does not deprecate or supersede WCAG 2.0.” The three were first published on 11 December 2008, 5 June 2018 and 5 October 2023, and the current WCAG 2.2 Recommendation is dated 12 December 2024.

W3C also says content conforming to 2.2 conforms to the earlier two: “Content that conforms to WCAG 2.2 also conforms to WCAG 2.0 and WCAG 2.1. The WG intends that for policies requiring conformance to WCAG 2.0 or WCAG 2.1, WCAG 2.2 can provide an alternate means of conformance.”

Two qualifications keep that from being a clean substitution.

First, WCAG 2.2 removed success criterion 4.1.1 Parsing, and W3C notes that authors “required by policy to conform with WCAG 2.0 or 2.1 will be able to update content to WCAG 2.2, but may need to continue to test and report 4.1.1.” A 2.2-only report has a hole in it where a 508 or Title II reviewer expects a row.

Second, under Title II the 2.2 route runs through equivalent facilitation at 28 CFR 35.203. DOJ accepted that “Public entities could also choose to comply with subpart H by conforming their web content to WCAG 2.2 Level AA … because WCAG 2.2 Level AA provides substantially equivalent or greater accessibility and usability to WCAG 2.1 Level AA,” and then said who carries the argument: “The responsibility for demonstrating equivalent facilitation rests with the public entity.” A supplier handing a public entity a WCAG 2.2 ACR is handing them a demonstration burden, not a discharge. Some buyers will take it. Some will send it back. Neither reaction is unreasonable, which is exactly why you settle it before testing rather than after.

Pros and cons of conforming to WCAG 2.2 as an answer to a WCAG 2.0 or 2.1 obligation. In favor: W3C treats all three as existing standards, with 2.2 not deprecating or superseding 2.1 and 2.1 not superseding 2.0; content that conforms to WCAG 2.2 also conforms to WCAG 2.0 and WCAG 2.1; W3C intends 2.2 as an alternate means of conformance for policies requiring 2.0 or 2.1; and DOJ accepted that WCAG 2.2 Level AA provides substantially equivalent or greater accessibility than WCAG 2.1 Level AA. Against: WCAG 2.2 removed success criterion 4.1.1 Parsing, so a 2.2-only report has a hole where a 508 or Title II reviewer expects a row; authors required by policy to conform with 2.0 or 2.1 may need to continue to test and report 4.1.1; under Title II the 2.2 route runs through equivalent facilitation at 28 CFR 35.203; and the responsibility for demonstrating equivalent facilitation rests with the public entity, so a 2.2 ACR hands the buyer a demonstration burden rather than a discharge.
Conforming to WCAG 2.2 is a real answer to a 2.0 or 2.1 obligation, and it is an answer the buyer has to defend. That is why it is settled before testing.
View the data as a table
ProsCons
W3C treats all three as existing standards: 2.2 does not deprecate or supersede 2.1, and 2.1 does not supersede 2.0WCAG 2.2 removed success criterion 4.1.1 Parsing, so a 2.2-only report has a hole where a reviewer expects a row
Content that conforms to WCAG 2.2 also conforms to WCAG 2.0 and WCAG 2.1Authors required by policy to conform with 2.0 or 2.1 may need to continue to test and report 4.1.1
W3C intends 2.2 as an alternate means of conformance for policies requiring 2.0 or 2.1Under Title II the 2.2 route runs through equivalent facilitation at 28 CFR 35.203, not through the rule’s own standard
DOJ accepted that WCAG 2.2 Level AA provides substantially equivalent or greater accessibility than 2.1 Level AAThe responsibility for demonstrating equivalent facilitation rests with the public entity, so it is a burden, not a discharge

What to write today

If you are drafting a requirement, write version, level, dated edition and the rule it comes from, in one sentence:

  • Federal ICT: “WCAG 2.0 Level A and Level AA, W3C Recommendation 11 December 2008, as incorporated by the Revised Section 508 Standards at 36 CFR part 1194, appendices A and C, including provisions E205.4, E207.2 and 602.3.”
  • State or local government: “WCAG 2.1 Level A and Level AA, W3C Recommendation 5 June 2018, as required by 28 CFR 35.200(b).”
  • HHS-funded recipient: “WCAG 2.1 Level A and Level AA, W3C Recommendation 5 June 2018, as required by 45 CFR 84.84(b).”
  • Test method, if you want comparable evidence: name it in the clause, the way 48 CFR 2952.239-70(b) does, and say what tester competence you expect, the way its paragraph (a)(4) does.

If you are choosing a VPAT edition, choose by buyer, not by habit. Federal only, 508 edition. EU public sector only, EU edition. State, local or HHS-funded buyers in the pipeline, you need WCAG 2.1 reporting, which the 508 edition cannot produce and the EU and INT editions can. Federal and domestic public sector together, the honest answer is either two reports or one INT-edition report carrying the 508 tables alongside the WCAG 2.1 rows, with the 4.1.1 Parsing gap handled explicitly wherever you also report 2.2. Our VPAT and ACR testing service scopes that decision before testing starts, because reversing it afterwards means paying twice.

If you are reviewing a supplier’s ACR this week, check four things in the header before you read a single row: which VPAT edition, which WCAG version and level, which dated edition of that version, and which test method. If any of the four is missing, the rows underneath cannot be scored against your obligation, whatever they say.

Next step

Open the last ACR you published or received. Find the Applicable Standards/Guidelines table in the header block, usually within the first two pages, and read the version line. If it says “WCAG 2.0” and any buyer in your pipeline is a state agency, a public university, a school district or an HHS-funded recipient, that document does not speak to their 2027 obligation, and you have roughly nine months to decide whether you are re-testing or losing the deal. If you would like a second reader on it, send us the ACR and the solicitation language and we will mark the specific rows that will not survive the version mismatch.