( VPAT )

What is a VPAT and who needs one?

What does a VPAT actually contain?

A VPAT contains one row per success criterion of the standard you are reporting against, and each row states one of four conformance levels plus a written remark explaining it. That is the whole structure: a criterion, a rating, and your explanation.

The four ratings are:

  • Supports: the product meets the criterion.
  • Partially Supports: some functionality fails it.
  • Does Not Support: most functionality fails it.
  • Not Applicable: the criterion doesn’t apply to the product.

Each row carries remarks explaining the rating: which components fail, what the impact is, and ideally what’s planned. Honest, specific remarks make a report credible. Blanket “Supports” down the page makes reviewers suspicious, because virtually no real product supports everything.

Is a VPAT a certification?

No, and this is the most common misunderstanding about the document. There is no issuing body, no audit sign-off and no pass mark. A completed ACR is a self-representation by the vendor, or an evaluation commissioned from a third party, and its credibility rests entirely on the evidence behind the ratings rather than on any external stamp.

That has a practical consequence. Nobody is going to award you the report, so nobody can take it away either. What a reviewer can do is read your remarks, notice that every criterion says “Supports” with no detail, and decide the document was written rather than tested. The absence of a certifying authority is exactly why the specificity of your remarks carries the weight.

It also means you should be sceptical of any tool that offers to make you “VPAT certified”. The phrase describes something that does not exist.

Is a VPAT the same as WCAG?

No. WCAG is the standard; the VPAT is the reporting format you use to describe your product against it. One is the ruler, the other is the measurement written down.

The relationship runs one way. WCAG defines the success criteria, each with a conformance level of A, AA or AAA. A VPAT reproduces those criteria as rows and asks you to state where your product stands on each. That is why the VPAT WCAG edition and the Section 508 edition look so similar underneath: Section 508 incorporates WCAG by reference, so the criteria being reported are largely the same ones.

Which VPAT edition do I need?

There are four, and the one you need is decided by your buyer rather than by you.

Edition Standard covered Who asks for it
VPAT WCAG WCAG 2.x Most private-sector buyers
VPAT 508 US Section 508 US federal agencies and contractors
VPAT EU EN 301 549 European public sector
VPAT INT All of the above Vendors selling internationally

If you’re unsure, WCAG edition covers the majority of requests, and the others incorporate WCAG by reference.

Who needs a VPAT?

You need a VPAT if you sell software or digital services to government, education or large enterprise. Those three buyer types either require conformance information by law or have made it standard in their procurement process, and they ask for it during evaluation rather than after.

  • Vendors selling to the US government: Section 508 makes accessibility conformance information part of federal procurement.
  • Vendors selling to education: universities are frequent requesters, driven by their own legal obligations.
  • Vendors selling to enterprise: accessibility clauses are now standard in large RFPs; no ACR often means no shortlist.
  • Public-sector suppliers elsewhere: the EU (EN 301 549), UK, Canada and Australia all have procurement accessibility requirements that an ACR answers.

The pattern: you don’t need a VPAT until a deal depends on it, and then you need it in days, not months.

Who completes a VPAT?

The vendor, in most cases. You test your own product, rate each criterion and sign the report, which is what “voluntary” and “self-representation” mean in practice.

The alternative is commissioning an accessibility consultancy to test and write it for you. That buys independence and costs accordingly, and some buyers in regulated sectors ask for it specifically. Most do not. What almost every buyer does care about is whether the ratings are traceable to real testing, which is a question about your evidence rather than about who typed the document.

What happens if you don’t have a VPAT?

Usually nothing dramatic. You lose the deal, quietly, at the evaluation stage, and often without being told that was the reason.

Accessibility questions increasingly sit in the standard RFP template rather than in a specialist annex, so the request arrives as one line among fifty and gets scored the same way. “We don’t have one” reads as “we have not thought about this” at exactly the moment the buyer is deciding whether you are a serious vendor. There is rarely a penalty and rarely an argument. You simply do not make the shortlist.

How do I create a VPAT?

In five steps, and the order matters, because you cannot honestly rate a criterion you have not tested.

  1. Pick the edition and standard your buyers reference (WCAG 2.1 AA or 2.2 AA covers most).
  2. Test the product. Automated scanning finds the structural failures across your pages fast; manual review covers keyboard access, focus behaviour and screen reader flows that automation can’t judge.
  3. Rate each criterion honestly and write specific remarks. “Partially Supports: date-picker cannot be operated by keyboard; fix scheduled Q3” is exactly what reviewers want to see.
  4. Date and version the report. An ACR describes one product version at one moment.
  5. Regenerate on change. Material UI changes invalidate the report; stale ACRs get rejected.

Will admitting failures in a VPAT cost me the deal?

Usually the opposite. Procurement reviewers read these reports all day and know that a wall of “Supports” is fiction, so an honest report with dated remediation plans reads as competence while a perfect one reads as a vendor who has not looked.

Teams sometimes fear that admitting failures will cost them deals. A report that documents real gaps with remediation dates signals a vendor who actually understands their conformance position, which is what the buyer is really assessing.

RedFlag generates ACRs from live scan data: every criterion rating is backed by the findings for your actual pages, with manual checks layered on where human judgement is required. When the product changes, rescan and export again. The report stays current because the evidence does. It is not a certification and it does not replace a human audit, for the reasons set out above, and the export page says so as plainly as this one does.

If you want to see what a completed report actually looks like before you write one, an annotated ACR example walks through a single criterion row and the remark underneath it.

Frequently asked questions

What does VPAT stand for?

Voluntary Product Accessibility Template. It's a standardised template from the Information Technology Industry Council (ITI) that vendors fill in to report how their product conforms to accessibility standards such as WCAG, Section 508 and EN 301 549.

What is the difference between a VPAT and an ACR?

The VPAT is the empty template; the Accessibility Conformance Report (ACR) is the completed document you actually give buyers. In practice people say "VPAT" for both, but what a procurement team receives is an ACR.

Is a VPAT legally required?

The template itself is voluntary, but many buyers make it effectively mandatory. US federal agencies require Section 508 conformance information during procurement, and many enterprises and universities won't shortlist software without a current ACR.

How often should a VPAT be updated?

Whenever your product changes materially, and at least annually. An ACR describes a specific version at a specific date. Procurement teams routinely reject reports older than 12 months.

Can accessibility conformance be fully automated for a VPAT?

No. Automated scanning covers a meaningful slice of WCAG criteria and provides the evidence base, but several criteria require human judgement, including keyboard flows, focus order and screen reader behaviour. A credible ACR combines both.

VPATVPAT example: what a completed ACR row looks likeGovernmentAccessibility requirements: Australian government websitesAccessibilityHow to fix the most common accessibility issues