VPAT Explained: What It Is and When You Need One
Sooner or later, a big customer asks for “your VPAT.” For a lot of software teams that's the first time they've ever heard the acronym, and it usually shows up attached to a deal they don't want to lose. Here's the honest version of what a VPAT is, what it isn't, and why the document is only as trustworthy as the testing behind it.
What a VPAT Actually Is
VPAT stands for Voluntary Product Accessibility Template. It's a standardized form, published and maintained by the Information Technology Industry Council (ITI) (opens in new tab), that a vendor fills out to describe how accessible their product is. You go through each accessibility requirement — a WCAG success criterion, a Section 508 provision — and state whether your product meets it, with a note explaining how.
The key word is the one people skip: voluntary. A VPAT is a self-report. Nobody hands it to you and nobody signs off on it. You write it about your own product, and it's exactly as accurate as you choose to make it. That's worth internalizing before you either request one from a supplier or produce one for a customer, because it changes how much weight the document actually deserves.
Buyers ask for VPATs because accessibility has become a purchasing requirement. Federal agencies are bound by Section 508, and universities, hospitals, banks, and large enterprises have adopted the same expectation in their procurement rules. The VPAT is how they compare vendors on paper before anyone signs. If you sell software, SaaS, or hardware into any of those markets, this document is a gate on your pipeline.
VPAT vs. ACR vs. “Certified”
Three terms get used interchangeably and shouldn't be:
- VPATis the blank template — the empty form before anyone has filled it in.
- ACR (Accessibility Conformance Report)is the completed document. Technically, the thing you send a customer is an ACR; “VPAT” is just what everyone calls it in practice. If a buyer asks for your VPAT, they want your filled-out ACR.
- “Certified”is a word that has no official meaning here. There is no governing body that certifies a VPAT, and there is no such thing as being “VPAT certified.” Any vendor who tells you their product is certified compliant because they have a VPAT is either confused or selling you something — the same way no overlay widget makes anyone “lawsuit-proof.”
A VPAT is a disclosure, not a certification. Its value comes entirely from being honest and being backed by real testing. A glowing ACR that says “Supports” on every line, with no evidence behind it, is worse than useless — it's a written record of claims a plaintiff or a procurement officer can later hold you to.
The Four Editions (Pick the Right One)
The current template is VPAT 2.x, and it ships in four editions depending on which standards your buyer cares about. Choosing the wrong one is the most common way a first VPAT gets bounced back:
- WCAG edition— reports conformance against the Web Content Accessibility Guidelines only. Best for a purely web-based product with no U.S. federal or EU angle.
- 508 edition— covers WCAG plus the U.S. Section 508 requirements. This is the one you need to sell to federal agencies and most U.S. public institutions.
- EU edition— maps to EN 301 549, the European standard referenced by the European Accessibility Act. Ask for this when your buyer is in the EU.
- INT (international) edition— combines all three. It's the most work to complete and the most flexible to hand out, which is why larger vendors default to it.
All four are built on the same underlying WCAG success criteria, so the bulk of the testing work carries across editions. If you're not sure which your customer wants, ask — it's a one-line email that saves a rewrite.
Want to know where your site stands?
Run a free scan →Who Actually Needs a VPAT
Not every website needs one. A VPAT is a procurement artifact, so you need it when someone is buying your product and their rules require it. In practice that means:
- You sell software, SaaS, hardware, or digital content to a U.S. federal agency— Section 508 effectively requires it.
- You sell to state or local government, public universities, or K–12 districts, which usually inherit 508-style rules.
- You're going through enterprise procurement or a security/vendor review at a large company, where accessibility is now a standard line item.
- You're a vendor to a regulated industry — healthcare, finance, education — where the buyer is managing their own compliance exposure.
If you run a small-business marketing site or a local e-commerce store, you almost certainly don't need a VPAT — but you do still need an accessible site. Your risk lives in ADA lawsuits and demand letters, not procurement forms, and the fix is the same underlying work either way: meet WCAG.
What the Conformance Levels Really Mean
For every criterion, a VPAT asks you to pick one of a small set of conformance terms. This is where honest reports and marketing fiction part ways:
- Supports— the product meets the criterion with no known exceptions. Use this sparingly and only when you can prove it.
- Partially Supports— it meets the criterion in most cases but has known gaps. This is the most honest answer for a lot of real products, and a good reviewer respects it far more than a wall of “Supports.”
- Does Not Support— the product fails the criterion. Saying so plainly, with a note on your remediation plan, builds more trust than pretending.
- Not Applicable— the criterion genuinely doesn't apply (for example, a video criterion for a product with no video).
- Not Evaluated— allowed only for Level AAA criteria, which VPATs don't require you to assess.
A seasoned procurement reviewer reads a report that's all “Supports” with suspicion, not relief. Nobody's product is perfect, and a VPAT that admits its gaps — with a “Remarks and Explanations” column that actually explains — is the one that closes deals.
How to Produce a VPAT That Holds Up
Here's the part vendors most want to shortcut, and the part you can't. A credible VPAT requires you to evaluate every applicable success criterion against your real product — and you cannot get there with an automated scan alone. Automated tooling reliably catches only roughly 30–40% of WCAG criteria: missing alt text, color-contrast failures, missing form labels, empty links, and other machine-detectable issues. The rest — keyboard operability, focus order, whether your alt text is actually meaningful, screen-reader behavior, logical reading order — needs a human. That's not a knock on automation; it's the honest division of labor between automated and manual testing.
So the practical workflow looks like this:
- Establish an automated baseline. Scan your key page types and flows with a real engine — CompliaScan is built on axe-core (opens in new tab), the same open-source engine much of the industry trusts — to find and clear the machine-detectable third fast. Start with our free WCAG checker.
- Do the manual testing. Walk your product with a keyboard only, then with a screen reader, and check every applicable criterion by hand. Work the WCAG checklist criterion by criterion so nothing gets skipped.
- Record evidence per criterion. For each line, note how you tested and what you found. This is what turns a VPAT from a marketing sheet into a defensible record.
- Write the ACR, then keep it current. Fill in the template edition your buyer wants, date it, and re-issue it after meaningful releases. A VPAT dated three years and forty deploys ago describes a product that no longer exists.
If this sounds like the same work as a proper accessibility audit, that's because it largely is. The VPAT is the report; the audit is the work that earns it.
The Honest Bottom Line
A VPAT is a valuable, often deal-critical document — and a self-attestation that carries no legal guarantee. Those two things are both true. It won't make your product compliant, it won't make you immune to a lawsuit, and it isn't a certification no matter how it's marketed. What it does is communicate, honestly and in a standard format, how accessible your product really is — which is exactly why the honesty behind it matters more than the polish on it.
Get the underlying accessibility right first. Clear the machine-detectable issues with a real scan, do the manual testing for everything a scanner can't see, then write the report to match reality. A VPAT built that way protects your deals and your reputation. One built to look good protects neither. If you want to see where your product stands before you start writing, a scan and ongoing monitoring is the cheapest baseline you'll ever run.
See your lawsuit risk in 30 seconds
Over 5,100 ADA website lawsuits were filed in 2025 — a 20% year-over-year increase. Scan your site now and know exactly how exposed you are before a plaintiff's firm runs the same check.
Free scan · No signup required · Results in ~30 seconds
Keep reading
All articles →The Most Common WCAG Failures (And How to Fix Them)
A handful of the same issues cause most WCAG failures on the web. The ones automated scans catch, the ones they miss, and how to fix both — honestly.
Does Web Accessibility Help SEO? The Honest Answer
Accessibility and SEO overlap more than most marketers realize — and less than most vendors claim. Where the two genuinely line up, where they don't, and what to fix first.
How Screen Readers Work (And Why Sites Fail Them)
A plain-English guide to how screen readers turn your website into speech — the accessibility tree, the failures that break them, and how to test with one yourself.