VPAT ACR

VPAT certificate: what people mean and what actually exists

David LoPresti By David LoPresti January 31, 2022

The short answer

There is no VPAT certificate. Nobody issues one, nobody reviews one, and no organization awards a passing grade for a website. The Information Technology Industry Council (ITI) publishes the Voluntary Product Accessibility Template, and its own FAQ answers the question without hedging: “there is no VPAT certification.” Asked how to get VPAT certified, ITI answers, “There is no certification for VPAT.” Asked whether it checks the reports people publish, ITI answers, “No, ITI does not review or approve VPATs. ITI provides the VPAT templates as a free resource for anyone to use.”

What exists instead is a self-disclosure. You complete the template for your own product, you publish the result, and the result is called an Accessibility Conformance Report. It is a claim you make and stand behind, not a credential somebody grants you. That distinction runs through every accessibility proof on the market, and we walk through the whole set in what each accessibility certification actually is.

The rest of this page uses the words the way ITI does. Where you see “VPAT certificate” or “VPAT certification” below, it is describing what a buyer or a sales team meant by the phrase, not a document that exists.

What a VPAT actually is

A VPAT is a reporting template. It helps organizations document how information and communication technology products, such as electronic content, software, hardware, and support documentation, measure up against accessibility standards. The United States standard it was built for is the Revised Section 508 Standards, which sit at 36 CFR part 1194 and implement Section 508 of the Rehabilitation Act of 1973, not the Americans with Disabilities Act. That distinction matters when a contract cites the wrong statute. Section 508 obligates federal agencies to develop, procure, maintain, and use information and communication technology that is accessible to people with disabilities.

The template began as a way for vendors to describe their goods against Section 508, and it has since been extended to cover the European EN 301 549 standard and the W3C’s Web Content Accessibility Guidelines. ITI’s current release is VPAT 2.5Rev, dated April 2025, and it comes in four editions:

  • VPAT 2.5 508, for the Revised Section 508 Standards, the U.S. federal accessibility standard, which incorporate WCAG 2.0.
  • VPAT 2.5 EU, for EN 301 549, the accessibility requirements suitable for public procurement of ICT products and services in Europe, which incorporates WCAG 2.1.
  • VPAT 2.5 WCAG, for WCAG 2.0 or ISO/IEC 40500, WCAG 2.1, and WCAG 2.2.
  • VPAT 2.5 INT, which incorporates all three of the above.

Pick the edition your buyer actually cites. A federal solicitation points at the 508 edition. A European public sector buyer points at the EU edition. A private buyer who wrote WCAG 2.2 into a contract needs the WCAG or INT edition, because the 508 edition has no rows for the criteria added after WCAG 2.0.

The completed document is an ACR, and it is a claim

ITI is precise about the naming: “A version of the VPAT which has been completed for a specific product is an ACR.” An empty template is a VPAT. Your filled-in version, with your test results in it, is an Accessibility Conformance Report about one product at one point in time.

Two things follow from that, and they are the reason the certificate framing misleads people.

The first is authorship. You write it about yourself. ITI notes that “The Original Equipment Manufacturer (OEM) is likely the best source to conduct the testing necessary to complete the VPAT,” which is a statement about who knows the product, not about who validates the claim. A third-party evaluator can perform the testing and draft the report for you, and buyers do treat an independent evaluation as stronger evidence than an unsupported internal one. That still does not make it a certificate. The evaluator is a witness, not an awarding body.

The second is that there is no score. ITI: “There is no ‘pass/fail’ scale for determining whether a product is accessible or inaccessible.” You report each applicable provision as supports, partially supports, does not support, or not applicable, and you add remarks explaining what the verdict means in practice. There is no total, no percentage, and no badge. ITI is explicit on that last point too, saying there is no certification or conformance logo required or even available to those who have filled out the VPAT.

An honest ACR that says “does not support” on several rows, with clear remarks and a remediation timeline, is worth more to a procurement reviewer than a report claiming full support with nothing behind it. Reviewers read the remarks column first.

Why buyers ask for one anyway

The document has real value, and it survives the correction intact.

Federal buyers need accessibility information to satisfy their own Section 508 obligations, and an ACR is the standard way to hand it to them. That reach extends past agencies themselves to organizations spending federal funds, so a vendor selling into education, health care, or state programs runs into the request as well.

Buyers outside government ask for the same document because reading a report is faster than testing your product themselves. A completed ACR tells a reviewer, provision by provision, where your product works with assistive technology and where it falls short, along with any workarounds. That saves the buyer a review cycle, which is why a missing or stale report can stall a deal that had nothing else wrong with it.

There is also the plain risk argument, which stands on its own without any certification language. An inaccessible website excludes customers and invites ADA claims. Completing an ACR forces you to test, and testing is what surfaces the problems while you can still fix them cheaply.

What it means for a website’s compliance

A completed ACR for a website does not certify the site. It documents the site’s conformance, and its accessibility gaps, against WCAG, the Revised Section 508 Standards, or EN 301 549, depending on the edition you used. It is evidence a buyer can weigh, and it is only as good as the testing behind it.

Real conformance is a property of the site, not of the paperwork. A website has to work for people using screen readers, magnification, voice control, switch access, and keyboard-only navigation, across devices, with sufficient contrast, resizable text, meaningful alternative text for graphics, accessible document formats, and interactions that do not depend on a mouse. The report describes that work. It does not perform it.

Which is worth saying plainly to anyone who reads a supplier’s report as a guarantee: the ACR tells you what the vendor tested and what the vendor found. It does not tell you that an outside body agreed.

How to produce one for a website

For a website reported on the 508 edition, the applicable tables are the WCAG success criteria at Level A and AA, Chapter 3 for the functional performance criteria, and Chapter 6 for support documentation and services. The hardware chapter does not apply, and the software chapter applies only to the parts of your product that are software rather than web content. Mark the rest not applicable rather than leaving it blank, and say why.

Test before you write. Automated scanners catch a minority of accessibility issues, so an ACR built from a scanner report alone will be contradicted by the first reviewer who tries the site with a screen reader. Combine automated coverage with manual keyboard and assistive technology testing, and record the method in the evaluation methods section so a reviewer can reproduce what you did.

Publish the finished report where buyers can find it, such as a linked page in the footer or your accessibility page, so procurement teams do not have to email you for it. Then keep it current. Websites change, and a report describing last year’s build describes a site that no longer exists. Any release that changes what the report says is a reason to update it, and the date on the report is the first thing a careful reviewer checks.

Need help getting your VPAT ACR done?

Self-reported ACRs carry real risk. Automated tools catch only a fraction of accessibility issues, and procurement reviewers push back on reports with no testing method behind them. Our team prepares procurement-ready VPAT 2.5 ACRs aligned to WCAG 2.2 AA, Section 508, and EN 301 549 (EAA). Learn more about our VPAT ACR services or book a free consultation to scope your report.