VPAT and ACR: what they are and how to fill one in

A VPAT® is a free template from the Information Technology Industry Council (ITI). Test a product against each criterion and record the results in it, and the finished document is an Accessibility Conformance Report (ACR). Buyers use ACRs to compare products against standards such as WCAG, Section 508 and EN 301 549. Testing comes first; the template only records it.

Published . Last reviewed .

ITI describes the VPAT® as a free template that translates accessibility requirements and standards into testing criteria, and says users should test their products and services against each section and use the template to document the results. The result is the report a buyer asks for. This guide covers the editions, the five conformance terms as ITI defines them, who asks for a report, how to fill one in and the mistakes that make a report worthless.

VPAT is a registered service mark of ITI, which asks that the name and report form not be altered without its written permission. GotAlt is not affiliated with ITI, and we link to ITI for the template rather than reproduce it.

VPAT and ACR: the difference

The VPAT is the blank template. An Accessibility Conformance Report is the VPAT with documented testing results: ITI's FAQ puts it as "a version of the VPAT which has been completed for a specific product". A VPAT is a template, not a certificate. What a company has is a report its product's owner produced, and the report is only as good as the testing behind it.

ITI is clear about what the format is not. It does not review or approve VPATs, there is no submission process, and there is no VPAT certification. It adds that there is no pass/fail scale for deciding whether a product is accessible: the criteria give a picture of the accessible features the product provides. The current template is VPAT 2.5Rev, dated April 2025.

The four editions

ITI publishes four editions so a report can follow the standard a buyer names. Pick the edition that matches the buyer's request, not the one that looks easiest.

The four VPAT 2.5Rev editions, the standard each reports against and the WCAG version it incorporates
EditionStandard reported againstWCAG version incorporated
508The Revised Section 508 standards, the U.S. federal accessibility standard (see Section 508 and WCAG)WCAG 2.0
EUEN 301 549, the European standard for ICT accessibility. ITI describes it as the EU's "Accessibility requirements suitable for public procurement of ICT products and services in Europe"; the current V3.2.1 is titled "Accessibility requirements for ICT products and services" (see EN 301 549)WCAG 2.1
WCAGWCAG 2.0 (also published as ISO/IEC 40500:2012), WCAG 2.1 and WCAG 2.2WCAG 2.2
INTAll three of the above in one reportWCAG 2.2

For U.S. federal sales, Section508.gov's guide to creating an ACR says vendors must use the Revised Section 508 or INT edition. That guide still describes version 2.4 of the VPAT as current and says any VPAT 2.x is acceptable (its FAQ says 2.x or later), while ITI's current release is 2.5Rev (April 2025). Use the current ITI release unless a buyer names a version. It also points vendors to its ACR Editor for building reports in a machine-readable format.

ITI's EU edition links EN 301 549 version 3.2.1. ETSI published version 4.1.1 on 2 September 2026; the European Commission's AccessibleEU Centre reported on 7 September 2026 that it had not been cited in the Official Journal, so version 3.2.1 still applied. Our EN 301 549 page tracks the dates. For help choosing a WCAG version in the WCAG edition, see which WCAG version the law requires.

The five conformance terms

Each criterion in the report gets one entry in the Conformance Level column. ITI's template requires the report to list the definitions of the terms it uses and recommends five. A vendor that changes the definitions must say so in the Notes. These are ITI's terms, summarized from the Terms section of the VPAT 2.5Rev WCAG edition; Section508.gov's guide restates the first four. ITI's web page lists four levels; the WCAG edition of the template adds Not Evaluated, for Level AAA criteria only. The remarks rules in the last column come from two sources, named in each row.

The five conformance level terms in ITI's VPAT 2.5Rev, with notes on use
TermWhat it meansNotes on use
SupportsThe product has at least one method that meets the criterion without known defects, or meets it with equivalent facilitation.Section508.gov: remarks are encouraged but not required. ITI's template says detailed remarks should justify each answer.
Partially SupportsSome functionality of the product does not meet the criterion.Remarks are required for federal ACRs (Section508.gov), and ITI's template says they should name the functions or features with issues and how they do not fully support the criterion.
Does Not SupportThe majority of the product's functionality does not meet the criterion.The same remarks rule as Partially Supports.
Not ApplicableThe criterion is not relevant to the product.Explain why in the remarks. A note in the WCAG tables says Supports may be used where you might otherwise write Not Applicable, because when there is no content a criterion applies to, the criterion is satisfied.
Not EvaluatedThe product has not been evaluated against the criterion.Allowed only for WCAG Level AAA criteria.

Buyers read the terms with caution. Section508.gov's guidance for understanding vendor claims tells buyers to review partially supported and not applicable entries in detail, says Not Evaluated gives no assurance of accessibility, and recommends independent conformance testing where possible. Write the report assuming someone will check it.

Who asks for a VPAT

  • U.S. federal buyers. Section508.gov's ACR and VPAT FAQ says the government asks vendors to submit an Accessibility Conformance Report so the accessibility of a product can be evaluated, and that without one the government may not proceed with the purchase unless it claims a special exception. A product that does not meet every standard is still considered and compared with similar products. The ITI template itself is voluntary; the report is what the buyer needs.
  • Buyers that name EN 301 549. ITI publishes an EU edition so a report can follow EN 301 549, which ITI describes as the EU's accessibility requirements for public procurement of ICT. Whether a European buyer asks for a report, and which edition, is the buyer's decision, so read the tender. Our EU law overview explains where the standard sits in EU law.
  • Other buyers. ITI says that if you are completing a VPAT in response to a government or other solicitation, you should follow the directions in the solicitation, which may require a third-party audit or review. Whether a buyer asks for a report, which edition and which WCAG level is the buyer's decision, so read the request before you start.

Who completes the report is the product's owner in the first instance. ITI says the original equipment manufacturer is likely the best source for the testing, and that either a reseller or the vendor can complete it. Section508.gov says that if your product is an add-on to another company's, you complete the report for the part you developed.

This guide is not legal advice

Whether you must supply a report, and against which standard, depends on the contract or solicitation and the law that applies to you. Our laws checker and laws overview are a starting point, and a lawyer or your contracting officer can answer for your situation.

What goes in an ACR

ITI's template sets a minimum for every report. In summary it must contain:

  • A title in the form "[Company Name] Accessibility Conformance Report", and the template version it is based on.
  • The name and version of the product, a short description of it, the report date (at least month and year) and contact details.
  • Notes, for anything a reader needs to know about the product or the report.
  • The evaluation methods used. ITI suggests saying whether the testers knew the product's functionality, which assistive technologies were used, which manual and automated tools were used, and the name, publisher and link of any published test method.
  • The applicable standards or guidelines, listing only the WCAG versions actually used.
  • The definitions of the conformance terms.
  • The tables: one entry per criterion for the conformance level, and remarks that justify it.

When a report covers a WCAG level, every criterion at that level must be answered for the WCAG version reported. Section508.gov adds that only Levels A and AA are required in an ACR meant for federal procurement, and Level AAA is optional. The final report must itself be accessible, which matters when it is published as a PDF: see our guide to accessible PDFs.

How to fill one in

  1. Pick the edition and the target

    Ask the buyer which standard, which WCAG version and which level it wants. A report against the wrong edition or version may not answer what the buyer asked.

  2. Define exactly what is being reported

    Name the product and version. For a website, say how the pages were chosen. W3C's evaluation methodology states that a sample alone cannot support a WCAG 2 conformance claim for a whole website, so the Notes should say what was and was not tested. Our website accessibility audit guide explains sampling.

  3. Test every criterion before you record anything

    Section508.gov says the product owner must first test the product against the standards to complete a report. Combine automated checks, manual testing and assistive technology. Our testing guide, the keyboard test and the WCAG 2.2 checklist cover the routine.

  4. Choose a conformance level for each criterion

    Use the definitions above and keep your evidence: which page, which tool or assistive technology, what you observed.

  5. Write remarks a buyer can use

    For Partially Supports and Does Not Support, name the functions or features with issues and how they fall short. If a criterion does not apply, say why. If an accessible alternative exists, describe it. Known workarounds and a way to get more information help the buyer.

  6. Finish the document

    Complete the title information, remove ITI's instruction pages, check that the result is accessible, and send it on request or publish it. There is no submission process. Use the registered mark ("VPAT®") wherever the name appears in the report.

  7. Date it and keep it current

    The Section508.gov FAQ says an updated report may be required every time the product changes, such as a version change or bug fix. If you revise a report, change its date and say what changed.

Example rows

These three rows are invented, for a fictional web application, to show the level and the remarks that go with it. They are not from a real report.

Three invented example rows from a report on a fictional web application
CriterionConformance levelRemarks and explanations
1.1.1 Non-text Content (Level A)Partially SupportsProduct photos and icons have text alternatives. The charts on the Reports screen have none, and their data is not available as text. Workaround: the Export button downloads the same data as a CSV file.
3.1.1 Language of Page (Level A)SupportsEvery page sets its language in the html element, and the language switcher updates it. Checked on each sampled page with a browser inspector and a screen reader.
1.2.1 Audio-only and Video-only (Prerecorded) (Level A)Not ApplicableThe product has no prerecorded audio-only or video-only content, so the criterion has nothing to apply to. ITI's note allows Supports here instead; whichever you choose, say why.

Common mistakes

  • Marking Supports without testing. The template makes the vendor responsible for the integrity of the data in the report. A row marked Supports that nobody tested is a serious mistake, because a buyer relies on it.
  • Treating a scan as the test. An automated scan covers part of WCAG (see what automated testing can and cannot check). The 16 checks in GotAlt's free scan map to 11 of the 55 success criteria at Levels A and AA in WCAG 2.2, by our count from the methodology page, and each covers only part of its criterion.
  • Supports on every row, with no remarks. A report that never finds a gap gives a buyer nothing to verify and invites a test.
  • Confusing Not Applicable and Supports. Follow ITI's note for the WCAG tables, and explain the choice in the remarks.
  • Using Not Evaluated outside Level AAA. ITI allows it only there.
  • Reporting a whole site from a few pages without saying so. State the sample and its limits in the Notes.
  • Using the wrong edition, version or level. The report should match what the buyer asked for.
  • Reusing an old report. The Section508.gov FAQ says an updated report may be required whenever the product changes, and that reports built on the 2001 Section 508 standards must be redone against the 2017 revision.
  • Dropping the ®. The template, which you reach through ITI's VPAT page, requires the registered service mark with the VPAT name.
  • Changing ITI's terms or structure without saying so. The template says deviating from its essential requirements precludes referring to it by name.
  • Publishing an inaccessible report. The template requires an accessible final document.
  • Presenting the report as a certificate. ITI states that there is no certification, and a buyer can test your claims.

How the WCAG 2.2 checklist and testing guides help

A report needs an answer for every criterion at the level you report, so start from the full list: our WCAG 2.2 reference covers all 86 success criteria, and WCAG levels A, AA and AAA explains which ones belong to which level. The WCAG 2.2 checklist condenses the most common failures into 42 checks and says for each whether a scanner, a browser tool or a person has to check it, which makes it a good way to organize testing. It is not a substitute for answering each criterion.

For evaluation methods, W3C's WCAG-EM is a published method you can name in the report, and the website accessibility audit guide walks through it. The bookmarklet, the contrast checker and the deep audit can supply evidence for individual rows, such as contrast, language and alt text, and the sample report shows what that evidence looks like.

What GotAlt does not do

GotAlt does not write, review or certify accessibility conformance reports, and a GotAlt report is not one. Our scans and audits check what a machine can check and list exactly what they covered. The judgment on each criterion, and the signature on the report, belong to the product's owner.

VPAT and ACR questions

What is a VPAT?

The Voluntary Product Accessibility Template is a free template from the Information Technology Industry Council. It turns accessibility standards into testing criteria for a product, with a place to record how well the product meets each one. It comes in four editions: Revised Section 508, EU (EN 301 549), WCAG and International.

What is the difference between a VPAT and an ACR?

The VPAT is the blank template. An Accessibility Conformance Report is a VPAT that has been completed for a specific product, with documented testing results. Buyers ask for the report, not the template.

Is a VPAT required by law?

The ITI template is voluntary. Section508.gov says the U.S. federal government asks vendors for an Accessibility Conformance Report so it can evaluate a product, and that completing one is effectively needed for a product to be considered. Whether a report is required in your case depends on the contract or solicitation.

Which VPAT edition do I need?

The one that matches the standard the buyer names. U.S. federal sales call for the Revised Section 508 or International edition. A buyer that names EN 301 549 wants the EU edition. The WCAG edition suits a buyer that asks for WCAG 2.0, 2.1 or 2.2 directly.

Does ITI certify or review a VPAT?

No. ITI does not review or approve VPATs, there is no submission process, and there is no VPAT certification. The product's owner completes the report and is responsible for its accuracy. If a solicitation asks for a third-party audit or review, follow the solicitation.

Can a scanner result fill in a VPAT?

Only in part. A scan checks what a program can decide from a page, which is a fraction of WCAG, and every criterion in the report needs an answer from testing. Use scan results as evidence for the rows they cover, and test the rest manually and with assistive technology.

My site has no video. Do I mark the video criteria Not Applicable?

ITI's note for the WCAG tables says a response may use Supports where you might otherwise use Not Applicable, because if there is no content to which a criterion applies, the criterion is satisfied. Whichever you choose, explain it in the remarks, and follow any instruction from the buyer.

Start with the evidence a machine can collect

The free scan runs 16 rule-based checks on up to three pages and lists exactly what it checked, which gives you evidence for a few rows and a list of fixes. See a full report on a deliberately broken page before you decide what more you need.

Scan my site for free See a real report first