
Introduction
Your product just cleared a technical review. The demo went well. Then procurement sends back one line: "Please provide a VPAT or Accessibility Conformance Report."
Many software vendors hit this wall late in the sales cycle, especially when selling to government agencies, universities, or large enterprises with formal accessibility requirements. A rushed response usually means filling out a template based on guesses rather than evidence.
That's a problem. A credible VPAT is the output of an actual accessibility audit that tests real workflows with real tools.
This article covers what a VPAT audit evaluates, how the testing process works, how to spot a weak or padded report, and when bringing in outside testing help makes sense.
Key Takeaways
- A VPAT is the blank template; the finished, product-specific version is called an Accessibility Conformance Report (ACR).
- Credible audits combine automated scanning, manual keyboard testing, and assistive technology evaluation.
- Every claim needs a version, scope, standard, date, and honest remarks, not vague language.
- Treat a VPAT as documentation of accessibility status—not a bug fix, usability guarantee, or substitute for ongoing testing.
What Is a VPAT Audit and What Does It Produce?
The Voluntary Product Accessibility Template (VPAT) is a standardized reporting format published by the Information Technology Industry Council (ITI). It translates accessibility requirements into a structured set of criteria that a vendor tests against and reports on.
The blank template is the VPAT. The completed, tested, product-specific document is technically an Accessibility Conformance Report (ACR). In practice, most buyers and vendors still call the finished document a "VPAT." ITI itself distinguishes the two terms and notes that the naming overlap is common.
ITI currently publishes four VPAT 2.5Rev editions, each covering different standards:
| Edition | Standards Covered |
|---|---|
| 508 | Revised Section 508, which incorporates WCAG 2.0 |
| EU | EN 301 549, incorporating WCAG 2.1 |
| WCAG | WCAG 2.0, 2.1, and 2.2 |
| INT | All three standards combined |
These are four editions, not four sections of one report. Choosing the wrong one is a common early mistake.
Which edition you need usually depends on who is asking for the report.
Who Asks for a VPAT
- US federal agencies — use ACRs in market research and proposal evaluation
- State and local government — some states, such as Missouri, require a VPAT in ICT procurement solicitations
- Higher education institutions — public colleges often request a VPAT plus an accessibility roadmap
- Enterprise buyers — treat accessibility documentation as part of vendor risk review
Websites vs. Software Products
A standalone marketing site usually needs a WCAG conformance statement covering its pages. But if your website is part of a larger product, say, a customer portal tied to your SaaS platform, it likely belongs inside the product's ACR scope, not a separate document.
What a VPAT does not do:
- Act as a legal certification
- Guarantee every user's experience is accessible
- Replace fixing the barriers it documents
How Is VPAT Testing Performed?
A defensible VPAT starts long before anyone opens the template. It starts with clear scoping.
Define the Scope First
Before testing begins, document:
- Product version and release date
- Platforms, browsers, and operating systems included
- User roles (admin, standard user, guest, etc.)
- Major workflows and integrations
- Third-party components and what's excluded
Skipping this step is how vendors end up with reports that don't match what the buyer actually receives.
Combine Automated and Manual Testing
Automated scanners catch a meaningful slice of issues: missing alt text, contrast failures, and missing form labels. They still can't evaluate everything.
HHS's acquisition guidance states plainly that automated scans alone are insufficient. It recommends combining them with manual testing and assistive technology output.
Manual testing is where the real evaluation happens:
- Keyboard-only navigation — Can every function be reached and operated without a mouse?
- Focus order and visibility — Does focus move logically, and is it visible at every step?
- Screen reader testing — Does content read in a meaningful order with proper labels?
- Dynamic content review — Do modals, notifications, and live updates announce correctly?
- Error handling — Are validation messages announced and understandable?
At Yes Yes Know, this looks like pairing automated tooling with manual testing using NVDA or VoiceOver, plus dedicated keyboard-only and focus-order passes, rather than relying on scan results alone.

Test Assistive Technology, Not Just Code
Representative testing typically covers:
- Desktop screen readers (JAWS, NVDA)
- Mobile screen readers (VoiceOver on iOS, TalkBack on Android)
- Keyboard-only navigation
- Browser zoom or magnification
Which combination matters depends on your actual user base, not a generic checklist.
Evaluate Full Workflows, Not Isolated Screens
Testing one page in isolation misses how accessibility barriers stack up across a real task. A thorough audit walks through complete flows: login, search and filtering, form submission, data tables, dashboards, and error recovery.
Every finding should document:
- Affected feature
- Specific requirement failed
- Reproduction steps and environment
- Severity
- Recommended fix
Vague notes like "some issues found" don't help a remediation team or a procurement reviewer. Clear, reproducible findings are what make a VPAT defensible.
What Makes a VPAT Credible and Procurement-Ready?
Not all VPATs are created equal. Some are backed by real testing evidence. Others are filled out optimistically in an afternoon. Here's how to tell the difference.
Start With the Basics
A credible report opens with clear identifying information:
- Product name and specific version tested
- Evaluation date
- Report author or organization
- Standards and edition used (508, EU, WCAG, or INT)
- Evaluation methods (automated tools, manual testing, assistive tech used)
If any of these are missing or vague, treat the rest of the document with caution.
Watch for Suspiciously Clean Reports
A complex product, especially one with dashboards, data tables, and multiple user roles, rarely earns "Supports" across every single criterion. Section508.gov's ACR guidance requires remarks whenever a criterion Partially Supports or Does Not Support, and encourages them even for full support.
Strong remarks look like this:
"Supports with exceptions. Data table sorting controls are keyboard-operable, but the sort-direction announcement to screen readers is inconsistent in Firefox. Affects the reporting dashboard only."
Weak remarks look like this:
"Generally compliant. No known issues."
The second version tells a buyer nothing. It should raise questions, not close them.

A Quick Review Checklist
Before trusting a VPAT, check for:
- Report date and product version match what you're buying
- Test environments and assistive technologies are named
- Major workflows, not just pages, are addressed
- Excluded components are disclosed, not hidden
- Remarks explain why, not just what
Reports should be revisited after major interface, framework, or platform changes, not left untouched for years while the product evolves underneath it.
When Should You Hire VPAT Audit and Testing Services?
Internal teams know their product best. But that familiarity can work against objectivity. An outside evaluator brings structured methodology, no assumptions about "how it's supposed to work," and the bandwidth to test thoroughly when a deadline is looming.
Situations That Call for Outside Help
- A government or education RFP requires a VPAT you don't currently have
- An enterprise buyer's security or procurement review flags accessibility gaps
- Your product has multiple user roles, complex integrations, or a data-heavy interface
- Internal stakeholders disagree on what "Partially Supports" should mean
- Your last VPAT predates several major feature releases
Questions to Ask Before Hiring a Provider
- What's their experience with software similar to yours?
- Which standards do they test against (WCAG 2.2, Section 508, EN 301 549)?
- What assistive technologies and devices are included?
- What does the deliverable actually contain: findings only, or remediation guidance too?
- How are conformance ratings validated before the report ships?
How Yes Yes Know Approaches This Work
Yes Yes Know works with B2B software, SaaS, cybersecurity, fintech, and data-heavy platforms that need accessibility support tied to real product outcomes, not just a completed form.
The flat-fee accessibility audit combines automated tooling with manual testing using NVDA or VoiceOver, keyboard-only navigation checks, and focus-order review. Findings map directly to WCAG 2.2 AA criteria with critical, serious, moderate, or minor severity ratings.
Founder Jen Bullard holds the CPACC credential through the International Association of Accessibility Professionals. The team's broader Accessibility & ADA/VPAT Compliance Services extend beyond testing into strategy, design remediation, and development support, which helps when a VPAT surfaces issues that need actual fixing rather than documentation alone.
You leave with a prioritized issue list, evidence-backed findings, and a plan for keeping the report accurate as your product changes.

Conclusion
A VPAT audit is an evidence-gathering process. It exists to help buyers understand what your product actually supports, not a procurement checkbox.
The sequence that produces a credible report:
- Define scope
- Identify the applicable standard
- Test real workflows with automated and manual methods
- Document findings honestly
- Assign accurate conformance statuses
- Revisit the report as your product changes
If your B2B software, SaaS, fintech, cybersecurity, or education product team needs a VPAT, Yes Yes Know can scope the audit, run the testing, and turn findings into a remediation plan buyers will trust. Reach the team at hello@yesyesknow.co or 617.551.1191.
Frequently Asked Questions
What is a VPAT audit?
A VPAT audit is an accessibility evaluation of a software product that produces the evidence needed to complete a VPAT or ACR. It combines automated scanning, manual testing, and assistive technology evaluation.
Who fills out a VPAT?
The product vendor is responsible for the completed report. Internal accessibility staff or an independent testing provider typically perform the underlying evaluation the report is based on.
What are the four sections of a VPAT?
ITI does not publish a fixed four-section structure. The template includes product information, evaluation methods, applicable standards, and a conformance table with remarks. Always confirm the current official ITI template.
What does VPAT stand for?
VPAT stands for Voluntary Product Accessibility Template. The completed, product-specific version of that template is commonly called an Accessibility Conformance Report, or ACR.
What is the difference between a VPAT and an ACR?
The VPAT is the blank, standardized template. The ACR is the completed document, tested against a specific product version, scope, and accessibility standard.
How often should a VPAT be updated?
Update it after major product, interface, or platform changes, and whenever a buyer's requirements call for a current version. The report's date and covered product version should always be clearly stated.


