A VPAT is a template.
The ACR is your honest answer.
A US agency, a university or an enterprise procurement team has asked for your VPAT. This guide explains what that document is, which edition to use, how to fill it in without overclaiming, and how often to update it. A practical guide, not legal advice.
Last updated Published by TryTrustableNot legal advice
A VPAT (Voluntary Product Accessibility Template) is a free template from the Information Technology Industry Council (ITI) for reporting how well a product meets accessibility standards. Once you fill it in for your product it becomes an Accessibility Conformance Report (ACR). Buyers in government, higher education and large enterprises ask for it during procurement. The current version is VPAT 2.5Rev (April 2025), in four editions: 508, EU, WCAG and INT. For most SaaS products, the WCAG or INT edition filled in after a real audit against WCAG 2.2 Level AA is what the buyer wants.
What is a VPAT?
A VPAT, short for Voluntary Product Accessibility Template, is a document template published by the Information Technology Industry Council (ITI). It turns accessibility standards into a table of criteria, and for each criterion a vendor states how well the product conforms and explains why. ITI describes it as a free template, and using it does not require ITI membership. VPAT is a registered service mark of ITI, so the template asks you to keep its required content and to write it as VPAT®.
The word is used loosely. When a buyer says "send us your VPAT", they mean your completed report, not the blank template.
VPAT vs ACR: what is the difference?
The VPAT is the blank form. The Accessibility Conformance Report (ACR) is the completed form for a specific product and version. The template's own instructions require the report title to read "[Company Name] Accessibility Conformance Report", followed by the template version, product name and version, report date, a product description, contact details, notes, the evaluation methods used, the standards covered and the definitions of the conformance terms. If a buyer asks for either name, send the ACR.
Which VPAT edition should I use? (VPAT 2.5Rev)
As of October 2026 the current release is VPAT 2.5Rev, dated April 2025. It comes in four editions, and WCAG 2.2 is included in the WCAG and INT editions.
| Edition | Standards it reports against | Use it when |
|---|---|---|
| VPAT 2.5Rev 508 | Revised Section 508 Standards (which incorporate WCAG 2.0 A and AA) | You sell only to US federal agencies and they asked for a 508 report |
| VPAT 2.5Rev EU | EN 301 549, the European standard for accessible ICT | You sell to EU public bodies or EU customers ask for EN 301 549 |
| VPAT 2.5Rev WCAG | WCAG 2.0, 2.1 and 2.2 | A web product sold to enterprises, universities or state agencies that reference WCAG |
| VPAT 2.5Rev INT | All three of the above in one report | You sell in the US and the EU and want one report that answers every buyer |
Source: ITI VPAT page, checked October 2026. Download the editions from itic.org, not from a third-party copy.
If you are unsure, the INT edition covers every buyer at the cost of a longer report. A SaaS startup selling mostly to US enterprises and universities usually starts with the WCAG edition reporting against WCAG 2.2 Level A and AA.
Who asks for a VPAT, and why?
- US federal agencies. Section 508 requires agencies to buy accessible technology, and the ACR is how they assess it. See Section 508 and the ADA.
- US state and local governments and public universities. The DOJ's ADA Title II rule adopts WCAG 2.1 Level AA for their web content and apps. After an April 2026 interim final rule, compliance dates are 26 April 2027 for entities serving 50,000 people or more and 26 April 2028 for smaller ones and special districts. Their procurement teams increasingly ask vendors for ACRs.
- Private universities and colleges, which often have their own accessibility policies for procured software.
- Enterprise procurement, especially companies with public-sector customers of their own or a published accessibility policy.
- UK public sector bodies, which must meet WCAG 2.2 AA under the Public Sector Bodies Accessibility Regulations 2018 and so ask suppliers about it.
- EU buyers, now that the European Accessibility Act applies to many consumer services, and public bodies procure against EN 301 549.
Australian government and university buyers also commonly ask for WCAG AA conformance evidence; the ACR is the usual format.
How do I create a VPAT for my product?
- Pick the edition and scope. Decide which product, version and platforms (web, iOS, Android) the report covers.
- Audit against WCAG 2.2 Level AA. Run automated scans, then test manually: keyboard only, a screen reader (for example NVDA or JAWS on Windows, VoiceOver on macOS and iOS), zoom to 200% and 400%, colour contrast, and every form and error state. Our WCAG 2.2 checklist lists what to check.
- Cover complete processes. WCAG conformance is scoped to full pages and complete processes, so test sign-up, sign-in, the core workflow, settings and billing end to end.
- Fill the template honestly. For each criterion choose a conformance level and write a remark that names what fails and where.
- List your evaluation methods. Tools, assistive technologies, browsers and who tested.
- Publish an accessible version and date it. Many vendors link it from their trust center or accessibility page.
- Fix and re-issue. Keep a remediation plan; buyers accept gaps far more readily than surprises.
Supports, Partially Supports, Does Not Support: how to choose
| Term | What it means (ITI definition, summarised) | When to use it |
|---|---|---|
| Supports | The functionality meets the criterion without known defects, or meets it with equivalent facilitation | Only when you tested it and found no known defect |
| Partially Supports | Some functionality does not meet the criterion | The honest answer for most criteria in a young product; say what fails in Remarks |
| Does Not Support | The majority of functionality does not meet the criterion | Say so, and give your plan |
| Not Applicable | The criterion is not relevant to the product | For example, no audio or video means no captions criteria |
| Not Evaluated | The product has not been evaluated against the criterion | Only for WCAG Level AAA criteria, per the template instructions |
The template asks you to list the definitions of the terms you use. If you change them, say so in Notes.
Good remarks are specific: "Partially Supports. Data tables on the Reports page have header cells; the drag-and-drop board on the Planning page has no keyboard alternative (fix scheduled for Q1)." Vague remarks such as "mostly accessible" tell the buyer nothing and invite their own testing.
Self-assessed vs third-party VPAT
Nothing in the template requires an outside auditor. ITI says the manufacturer is likely the best source to do the testing. A self-assessed ACR is acceptable to many buyers if the evaluation methods are clear and the answers are honest.
A third-party audit by an accessibility firm adds credibility, catches issues an in-house team without screen reader experience will miss, and is often expected by large federal and university buyers. Cost and time depend on the number of screens and workflows in scope, how many platforms (web and native apps), how much assistive technology testing is required, and whether re-testing after fixes is included. Ask for quotes with the scope written down; we do not quote price ranges because no reliable public source exists.
How often should a VPAT be updated?
There is no fixed rule in the template. Treat the ACR as describing a version: re-test and re-issue when you ship a significant UI change or a new major module, and at least once a year. The report date must be visible, so buyers will notice an old one.
Common VPAT mistakes
| Mistake | Why it hurts | Do this instead |
|---|---|---|
| Marking everything Supports | Reviewers test a few criteria themselves; one obvious failure discredits the whole report | Use Partially Supports with specific remarks |
| No evaluation methods listed | The template requires them, and buyers cannot judge a report without them | Name the tools, browsers, screen readers and manual checks you used |
| Reporting the marketing site, not the product | Buyers procure the application their staff and students will use | Scope the report to the product and version being sold |
| A stale report | A report dated two years ago does not describe today's product | Re-test and re-issue on major releases, at least yearly |
| An inaccessible PDF | The template says the final report must itself be accessible | Publish as accessible HTML or a tagged PDF |
| Editing the template structure | Deviating from ITI's essential requirements means you may not call it a VPAT | Keep the required sections; add detail in Remarks and Notes |
Where TryTrustable fits, and where it does not
TryTrustable scans your public pages against the WCAG 2.2 Level A and AA rules with axe-core, the open-source accessibility engine, and maps each failure to its success criterion with the element and how to fix it. It then gives your team a worksheet of all 55 A and AA criteria to set the conformance level and remarks for each, and issues a sealed Accessibility Conformance Report based on the VPAT® 2.5 WCAG edition. Automated rules find only some failures, so the product never marks a criterion "Supports" by itself: that needs manual testing with a keyboard, a screen reader and zoom, by your team or a specialist. It does not yet scan pages behind a login or produce the 508, EU or INT editions. For the 508, EU or INT editions, use the official ITI VPAT template.
The same procurement review that asks for a VPAT usually asks for security and reliability evidence too, and that is where we help: SOC 2 and ISO 27001 evidence, a trust center to share it, and performance test results for uptime and latency questions. The enterprise readiness guide lists everything buyers ask for.
The things people ask us
Is a VPAT legally required?
No law requires a vendor to publish one. Buyers covered by Section 508, the ADA Title II rule or public procurement rules ask for it because they must assess the accessibility of what they buy, and an ACR is the accepted format.
What is the latest VPAT version?
VPAT 2.5Rev, released by ITI in April 2025, in 508, EU, WCAG and INT editions. Check itic.org before you start, as ITI revises the template from time to time.
Can I write my own VPAT?
Yes. ITI says the manufacturer is likely the best source for the testing. You need real testing, including keyboard and screen reader checks, and an honest description of your evaluation methods.
Does a VPAT mean my product is accessible?
No. It is a report of conformance, which can say Partially Supports or Does Not Support. A good ACR with known gaps and a fix plan is better received than a report claiming full support that a buyer can disprove.
Should my VPAT report WCAG 2.1 or 2.2?
Report WCAG 2.2 if you can, using the WCAG or INT edition. It includes the 2.1 criteria (except the removed 4.1.1 Parsing), so it answers buyers on either version.
Does TryTrustable create VPATs?
It produces an Accessibility Conformance Report based on the VPAT 2.5 WCAG edition. An automated WCAG 2.2 scan finds failures and maps them to success criteria; your team sets the conformance level and remarks for each criterion after manual testing. The 508, EU and INT editions are not produced yet.
Accessibility is one row of the buyer's checklist. Make the others easy.
Thirty minutes on the security, privacy and reliability evidence your enterprise and public-sector buyers ask for, and how to share it from one trust center.