VPAT ACR

Why clients ask for a VPAT, and what happens if you send nothing

David LoPresti By David LoPresti September 3, 2022

The email is four lines long. It asks you to “provide your VPAT” before the renewal can be processed, it does not say which standard, it does not say which version, and it does not say what happens if you send nothing. The person who sent it may not know either, because in most organisations the request is generated by a procurement checklist rather than by an accessibility team.

What follows is how to read that request: who is asking and under what authority, what the requester will actually do with the document, which of the four templates applies to them, what to send when your product does not fully conform, and why the answer to the last question is not the one most vendors assume.

Nobody requires you to produce one

Start with the thing the request implies and never states.

There is no federal statute that obliges a vendor to produce a Voluntary Product Accessibility Template. The word in the middle of the name is doing exactly what it says. The template is published by the Information Technology Industry Council, which describes it as “a free template that translates accessibility requirements and standards into actionable testing criteria” for products and services. It is a reporting format, not a licence.

The government’s own guidance to vendors uses the same register. Section508.gov “recommends that vendors generate an ACR for any ICT that’s intended to be marketed” to the federal government. Recommends. A page written by the people who buy this technology, addressed to the people who sell it, chose that verb deliberately.

So the honest framing of the ask is commercial rather than legal. Nothing compels you to file. Something does prevent you from winning the contract if you do not, and that something sits in the buyer’s rulebook rather than in yours.

The rule behind the ask names the buyer, not you

The obligation is real, and it belongs to your customer.

For a federal buyer it lives in the Federal Acquisition Regulation, and FAR 39.203 states it in one sentence:

Unless an exception at 39.204 or an exemption at 39.205 applies, acquisitions for ICT supplies and services shall meet the applicable ICT accessibility standards at 36 CFR 1194.1.

That is a duty on the acquisition, discharged by the contracting officer, and the only way that officer can discharge it is with information from you.

The mechanism tightens at the order stage. Where an agency buys through an indefinite-quantity vehicle, the same subpart provides that at issuance of each task or delivery order the requiring and ordering activities “shall ensure compliance with the ICT accessibility standards and document an exception or exemption” where one applies. A vendor already on a schedule can therefore be asked again, per order, by someone who has never seen the original file.

Read the ask through that lens and its shape makes sense. Your customer is not auditing you. Your customer is assembling a record that has to exist before money moves, and you are the only source for one field in it.

Four buyers, four reasons the ask arrived this year

The request has become common recently because four different rulebooks reached their enforcement phase at roughly the same time, and each one produces the same email for a different reason.

Who is askingWhat binds themStandard they need you againstTheir date
A federal agencyRevised 508 Standards, through FAR Subpart 39.2WCAG 2.0 Level A and AA, plus the hardware and software chaptersIn force since January 2018
A state or local governmentThe ADA Title II web ruleWCAG 2.1 Level AA26 April 2027, or 2028 for smaller entities
A recipient of HHS financial assistanceThe Section 504 web ruleWCAG 2.1 Level AA11 May 2027 at fifteen or more employees, 10 May 2028 below that
A European customerEN 301 549, under the European Accessibility ActWCAG 2.1 Level AA plus the non-web clausesIn force since June 2025

Two of those rows changed inside the last eighteen months, which is why your inbox changed. The Title II rule adopts “WCAG 2.1, Level AA” and sets 26 April 2027 for entities serving populations of 50,000 or more. The Section 504 dates moved out by a year, and recipients with “fifteen (15) or more employees must comply with the success criteria of WCAG 2.1” from 11 May 2027.

The extension is worth reading carefully rather than celebrating, because the same rule says the delay “does not relieve recipients of their other obligations” under Section 504. A hospital with a 2027 date still has a present duty, which is precisely why its procurement team is asking you now instead of in 2027.

How each of those obligations actually reaches a vendor is a separate question with a separate answer, and the route matters when you negotiate the clause. For state and local buyers, how Title II and Section 504 reach a vendor sets out what the rules do and do not say about you. For the handful of states with their own statutes, which state laws name government vendors is the shorter list than people expect.

Sometimes the standards do not apply, and you can say so

Before you build a report, check whether the acquisition needed one. The regulation carries two escape routes, and a vendor who knows them can shorten a conversation instead of prolonging it.

FAR 39.204 lists three exceptions, where the standards do not reach the ICT at all. The first is ICT operated as part of “a national security system, as defined by 40 U.S.C 11103(a)”. The second is ICT “acquired by a contractor incidental to a contract”, meaning tools the contractor uses in-house to perform the work rather than anything delivered. The third is narrow and physical: operable parts or status indicators “located in spaces frequented only by service personnel for maintenance, repair, or occasional monitoring of equipment”.

That second one matters more than it looks. A build server, an internal ticketing tool or a licence your delivery team uses to do the work is not what the agency is buying, and the exception exists precisely for that case.

FAR 39.205 lists three exemptions, which are different: the standards apply, and the agency documents a decision not to meet them. Undue burden on the agency. A fundamental alteration in the nature of the ICT. And nonavailability, “where there are no commercial products and commercial services that fully conform to the ICT accessibility standards”.

Nonavailability is the exemption that intersects with your report, and it runs on the same evidence as Best Meets. It is the buyer’s finding rather than yours, and the way you help them reach it is a report that says clearly which provisions your product does not meet.

View the data as a table
RouteWhat it doesWho decidesWhat your report contributes
Exception, 39.204The standards do not apply to this ICTContracting officerUsually nothing, the ask was unnecessary
Undue burden, 39.205Standards apply, agency documents reliefAgency officialLittle, this is about agency resources
Fundamental alteration, 39.205Standards apply, conformance would change the product’s natureAgency officialContext on what conformance would require
Nonavailability, 39.205No conforming product exists in the marketAgency official, on market researchThe specific gaps, named
Best Meets, E202.7Buy the closest available productAgency official, documentedEverything, this is the memo your remarks feed

Which edition they need, and the version their own page gets wrong

There is not one template. There are four, and sending the wrong one reads as carelessness to a reviewer who handles these daily.

The publisher’s current release is “VPAT® Version 2.5Rev (April 2025)”, issued in four editions: the 508 edition for United States federal standards, the EU edition for EN 301 549, the WCAG edition for the W3C guidelines alone, and the INT edition, which carries all three.

EditionBuyer it fitsWhat it reports against
VPAT 2.5 508Federal agencies and their primesRevised Section 508 Standards
VPAT 2.5 EUCustomers inside the European UnionEN 301 549
VPAT 2.5 WCAGCommercial buyers with no statutory hookWCAG only
VPAT 2.5 INTAnyone selling into more than one of the aboveAll three, one document

For a federal sale the choice narrows to two. The government’s how-to guidance states that if you are selling to the federal government “you must use the Revised Section 508 or the INT International Editions of the template”.

Now the detail worth knowing before you follow that page to the letter. The same guidance recommends VPAT version 2.4, or any 2.x version, while the publisher’s current template is 2.5Rev of April 2025. Following the government page will not get your report rejected, and using the current edition is still the better answer, because a reviewer comparing three bidders notices which one is working from the newest template. Where a solicitation names a version, the solicitation wins.

If you sell into both federal and European markets, the INT edition removes a recurring problem: two reports drift apart the moment one of them is updated and the other is not.

What the requester actually does with the file

This is the part that changes how you write it, and almost no vendor is told.

The report is a screening instrument. Section508.gov says ACRs help contracting officials and buyers “assess ICT for accessibility when doing market research and evaluating proposals”. Market research happens before a solicitation exists. Proposal evaluation happens against other bidders. In neither case is anyone reading your document for pleasure.

What the reviewer is doing is looking for specific things and marking them off. Guidance to federal buyers tells them to require a report for each item, and to “Advise offerors that each requirement must be fully addressed in order to be considered” for award. The same guidance sets a bar that is procedural rather than technical: “the ACR must be complete, and submitted according to the instructions”.

Read those two sentences together and the failure mode becomes obvious. A report loses on completeness far more often than on the accessibility of the product. Blank rows, a missing edition, no version number, no date, remarks columns left empty next to a “Partially Supports” are all defects in the document rather than defects in the software, and all of them are cheap to avoid.

View the data as a list
  1. The edition and version, stated on the document. A reviewer should not have to infer which standard you reported against.
  2. A date. An undated report cannot be assessed for currency, and a reviewer comparing bidders will assume the worst.
  3. The product name and the version tested. Not the product family. The thing being bought.
  4. Every applicable row filled. A blank is read as an omission, not as a pass.
  5. Remarks wherever conformance is not full. These are mandatory for two of the four phrases and they are the only place a reviewer learns what the gap is.
  6. The evaluation method. How you tested, with what, against which pages or screens or components.
  7. A document that is itself accessible. An inaccessible PDF reporting on accessibility is the one own goal a reviewer will remember.
View the data as a table
What the request saysWhat it usually meansWhat to ask back
”Send us your VPAT”Any completed template, edition unspecifiedWhich standard and version, and which product version
”We need your Section 508 compliance documentation”The 508 or INT edition, plus possibly a Supplemental Accessibility ReportWhether they want the SAR and Issue Detail Supplement too
”Provide your accessibility conformance report”The same document, named correctlyWhether a named solicitation instruction applies
”Are you WCAG compliant?”A yes or no is not answerable, they want the reportWhich WCAG version and level
”We need certification”They mean the report, no certification existsConfirm the report satisfies the requirement
”Fill in our accessibility questionnaire”Their own form, often derived from the templateWhether your existing report can be attached instead

Partial conformance is not disqualification

Here is the misconception that costs vendors the most, and correcting it is the most useful thing on this page.

Vendors assume that a report showing anything other than full conformance loses the deal, so they either delay the report until the product is perfect, which is never, or they file something flattering. Both are worse than the honest document, because the standards anticipate imperfect products and say what happens.

The Revised 508 Standards contain a provision called Best Meets:

Where ICT conforming to one or more requirements in the Revised 508 Standards is not commercially available, the agency shall procure the ICT that best meets the Revised 508 Standards consistent with the agency’s business needs.

Not “shall cancel the acquisition.” Shall procure the best available.

That provision comes with paperwork, and the paperwork is where your honest report earns its place. The responsible agency official has to document in writing the non-availability of conforming ICT, including “a description of market research performed and which provisions cannot be met”, and the basis for concluding that the chosen product best meets the standards. A clear list of your gaps, with remarks explaining each one, is the raw material for that memo. A vague report is not, and a reviewer who cannot write the memo from your document will find a bidder whose document lets them.

There is a second obligation attached, and it is worth knowing because it affects what your customer will ask you next. Where fully conforming ICT is not available, the agency has to provide access “by an alternative means” that meets identified needs. Expect a follow-up question about workarounds, documented alternatives, and your roadmap. A vendor who has that answer ready is competing on a different level from one who does not.

The four phrases, and the two that oblige you to write

The conformance column is not free text. Four phrases are permitted, and the guidance defines each one.

PhraseWhat it meansRemarks required
SupportsAt least one method meets the criterion without known defects, or meets with equivalent facilitationNo
Partially SupportsSome functionality of the product does not meet the criterionYes
Does Not SupportThe majority of product functionality does not meet the criterionYes
Not ApplicableThe criterion is not relevant to the productNo

The definitions are narrower than they look. “Partially Supports: Some functionality of the product does not meet the criterion” is not a hedge for “mostly fine.” It is a statement that a specific thing fails, and the next column has to say which.

That obligation is explicit. The remarks column carries “remarks, which are required if the product either partially supports or does not support” the criterion. A row marked Partially Supports with an empty remark is an incomplete report by the buyer’s own test, and completeness is the bar you are being measured against.

The temptation runs the other way. Marking everything Supports produces a document that reads well and fails on contact, because a reviewer with a screen reader and ten minutes can disprove it, and because a report that survives evaluation and then falls apart at acceptance is a contract problem rather than a sales problem.

View the data as a table
What the row saysWhat a reviewer infersWhat it costs you
Supports, everywhere, no remarksNobody tested thisCredibility, at the first spot check
Partially Supports, remark emptyIncomplete submissionRemoved from consideration on process
Partially Supports, remark naming the gapTested, honest, usable in a Best Meets memoNothing
Not Applicable on a criterion that clearly appliesEither an error or an evasionA clarification request at best
Does Not Support, remark with a roadmap dateA known gap with an ownerRarely the deal, sometimes the schedule

What to send when you have nothing yet

The request has a deadline and your product has never been tested. This is the common case and it has a sequence.

Do not send a template filled from a scan. An automated tool reports a fraction of the criteria and reports nothing at all about keyboard operation, focus order, screen reader output or whether an error message is announced. A report built that way is wrong in ways a reviewer finds quickly.

Do not send nothing either, silently. Where the deadline cannot be met, the answer is a dated reply saying what exists, what is being tested, and when the report will arrive. Procurement teams work with schedules constantly. What they cannot work with is silence, and the guidance they follow tells them to treat an incomplete submission as ineligible rather than to chase it.

The sequence that produces a usable document is short. Establish scope, which means the product and version being bought rather than the whole catalogue. Test against the standard the buyer named, manually, including assistive technology. Record each result in the correct phrase with a remark wherever conformance is not full. Then publish it with a date and a version, and keep the evaluation notes, because the first clarification question will ask how you tested.

If the gap is the testing rather than the paperwork, that is what a VPAT and ACR engagement is for, and the report is the deliverable rather than a by-product.

The request is often three documents, not one

Vendors treat “send your VPAT” as a single deliverable. Federal buyer guidance treats it as a set, and the other two items are the ones nobody prepares for.

Alongside the report, buyers are told to request a Supplemental Accessibility Report for each standard commercial item. A written SAR carries a “Description of evaluation methods used to produce the ACR”, documentation of features that help achieve accessibility, and information on core functions that cannot be used by people with disabilities. For an authoring tool it also covers how the product enables the creation of accessible content.

Read that list against your own report. The evaluation method is the field most vendors leave implicit, and it is the field a reviewer uses to decide whether the conformance column means anything. A report saying Supports on forty criteria with no statement of how anything was tested is a claim rather than a finding.

The third document is the Issue Detail Supplement, which “provides additional product details needed by government agencies to better understand the severity and user impact” of the accessibility issues already identified. Where the report says a criterion is partially supported, this is where the buyer learns whether that means a cosmetic defect or a blocked task.

DocumentQuestion it answersWhat it needs from you
ACRDoes the product conform, criterion by criterionTest results in the four permitted phrases
Supplemental Accessibility ReportHow was this tested, and what is unusableEvaluation method, accessibility features, unusable core functions
Issue Detail SupplementHow bad is each gap for a real userSeverity and user impact for each identified issue

Three consequences for a vendor. The evaluation method is worth writing down while the testing is happening rather than reconstructing later. Severity is a judgement your team can make and a reviewer cannot, so leaving it out transfers the judgement to someone with less information and more bidders. And where a solicitation names only the ACR, offering the other two unprompted is cheap differentiation, because most competitors will not.

For customers outside federal procurement none of this is required, and the same three questions still arrive in a less organised form. A vendor who has the answers written down answers a commercial security questionnaire faster too.

Who may sign it

The template is a self-disclosure, and this surprises people in both directions.

ITI’s position is that “the Original Equipment Manufacturer (OEM) is likely the best source to conduct the testing” necessary to complete the template. Nobody has to countersign it. There is no register, and the publisher is explicit that “ITI does not review or approve VPATs”.

Which means the credibility of your report comes entirely from its internal quality. A reviewer judges a self-disclosure by whether the remarks are specific, whether the evaluation method is stated, whether the results are plausible against a five-minute check, and whether the version and date line up with the product being sold.

Independent testing is not required and is frequently worth buying anyway, for a reason that has nothing to do with rules. A team that built the product knows where not to look. Where the buyer is a large agency or the contract is material, a report produced by someone with no stake in the answer holds up better under a clarification request.

Anyone offering to certify the result is describing something that does not exist. What accessibility certification actually exists covers the badges, seals and letters that circulate in this market and what each one attests.

What a report cannot do for you

Two claims attach themselves to this document and neither survives contact.

The first is legal protection. A completed template is a statement about your product at a date. It is not a defence, not a safe harbour, and not a filing that any regulator accepts or acknowledges. Where it helps in a dispute is evidentiary and indirect: a dated, specific, honest report supports a story about diligence, and an inflated one supplies the other side with a written misstatement. That asymmetry is a good reason to be accurate and a poor reason to claim immunity.

The second is currency. A report describes the version you tested. Ship a redesigned checkout and the document now describes software that no longer exists, which a reviewer discovers by comparing your report date to your release notes. The practical rule is to re-test on the cadence at which your interface actually changes, and to date every revision rather than quietly replacing the file at the same URL.

What the document does well is narrow and valuable. It gets you through screening, it gives a buyer the material to justify choosing you, and it converts a vague conversation about accessibility into a list that somebody can act on.

What nobody has published

Several things a reader might expect to find do not exist, and saying so is more useful than filling the gap with inference.

No public data quantifies how often an ACR decides a federal award. Section 508 reporting measures agency conformance rather than procurement outcomes, so the claim that a report wins or loses contracts at some rate is not supported by anything published.

There is no published federal decision interpreting the “complete, and submitted according to the instructions” condition, so how much incompleteness is fatal is a matter of contracting officer discretion rather than settled rule. Research for this article found guidance and no adjudication.

Nothing published states how many vendors respond to these requests, refuse, or go quiet. The buyer’s side of the same problem is documented in where to find a vendor’s ACR, and even there the answer is that the reports are scattered rather than counted.

And the commercial question stays open. Whether a buyer outside government has any leverage beyond declining to buy is a matter of the contract in front of you. There is no rule that reaches a private-sector purchase, which is why a commercial customer asking for a VPAT is making a purchasing decision rather than enforcing a standard.

Questions vendors ask when the request lands

Is a VPAT legally required?

No. There is no statute or regulation that requires a vendor to produce one, and the template’s publisher describes it as a free reporting format rather than a compliance filing. The obligation belongs to your buyer: a federal acquisition has to meet the accessibility standards unless an exception applies, and the contracting officer needs your information to show that it does. Nothing compels you to file. Not filing can remove you from consideration.

Can I write my own, or does it need a third party?

You can write your own. ITI treats the manufacturer as the party best placed to do the testing, and no countersignature exists because the publisher does not review or approve completed templates. Independent testing is worth buying where the contract is material, not because a rule demands it, but because a report produced by the team that built the product tends to miss the same things the product misses.

Which edition and version should I send?

Match the buyer. Federal buyers require either the Revised Section 508 edition or the INT edition. European customers need the EU edition or INT. A commercial buyer with no statutory hook is usually served by the WCAG edition. Use the publisher’s current release, 2.5Rev of April 2025, unless the solicitation names a specific version, in which case follow the solicitation.

What do I send if my product does not fully conform?

The honest report. The standards contain a Best Meets provision: where no conforming product is commercially available the agency buys the one that best meets the standards, and the official has to document which provisions cannot be met. Your specific remarks are what makes that memo writable. A report claiming full support that a reviewer disproves in ten minutes is worse than a report with named gaps and dates against them.

What happens if I ignore the request?

Usually you stop being considered rather than hearing a refusal. Federal buyers are advised to tell bidders that every requirement must be fully addressed to be considered for award, and that a report has to be complete and submitted according to instructions. Silence is read as an incomplete submission. Where the deadline is genuinely impossible, a dated reply with a delivery date keeps you in the conversation.

How often does it need updating?

On the cadence at which your interface changes, not on a calendar. The report describes a specific version, so a release that changes navigation, forms or components makes the previous document stale. Date each revision and keep the old ones rather than overwriting the file, because a buyer comparing your report date against your release notes is a routine check rather than a hostile one.

Does having a VPAT protect me from a lawsuit?

Not directly. It is a statement about a product at a point in time, not a filing that confers protection, and no regulator reviews or accepts it. An accurate, dated, specific report can support an account of diligence. An inflated one gives an opponent a written misstatement in your own words. That is a reason for accuracy rather than a reason to expect immunity.

My customer is a hospital, not a government agency. Why are they asking?

Because a recipient of HHS financial assistance has its own web accessibility rule, with WCAG 2.1 Level AA and a compliance date of 11 May 2027 for recipients with fifteen or more employees. The rule reaches content delivered through third-party arrangements, which includes the software the hospital licenses from you. The date moved out by a year, and the extension explicitly did not relieve recipients of their other obligations, which is why the question arrived early.

Your next step

Take the request that is actually in your inbox and do three things in order.

First, reply asking two questions rather than guessing: which standard and version they need you reported against, and whether they want the report for a named product version or a product family. Both answers change the document, and asking makes you look like a vendor who has done this before rather than one stalling.

Second, decide honestly whether you have test results or only a product. If nothing has been tested manually against the named standard, the report cannot be written this week and pretending otherwise creates a document that fails at acceptance instead of at screening. Send a dated schedule.

Third, fix the scope before the testing starts. Name the product and version, name the standard and its version, and name the edition of the template. Those three decisions determine whether the finished report answers the buyer’s question or a different one.

Where the testing itself is the gap, ADACP’s VPAT and ACR reporting produces the evaluation and the completed report together, and its accessibility audit work is where a product with no test history usually has to start.