2026’s Definitive Guide to VPAT for Product Accessibility Compliance (Free Template)

vpat template to reach vpat compliance

Table of Contents

A VPAT looks like paperwork: a form you fill in to show a buyer your product is accessible. The form is the easy part. What a procurement reviewer actually checks is whether the conformance claims survive contact with a screen reader, and a template completed in-house to look good rarely does. That is the difference between a document that wins the contract and one that gets your bid set aside.

At TestPros, an independent accessibility assessment firm, we have prepared and reviewed VPATs since long before procurement teams started demanding them, and the pattern we see most is a template filled out by a vendor’s marketing team that marks “Supports” on criteria a screen reader fails in the first thirty seconds. Because we sell assessment and not accessibility scanners or overlays, the conformance levels in a report we produce reflect what assistive technology actually does, not what a tool we profit from reported.

What is a VPAT?

A VPAT (Voluntary Product Accessibility Template) is a standardized document, created by the Information Technology Industry Council (ITI), that reports how well a digital product meets accessibility standards such as WCAG, Section 508, and EN 301 549. A completed VPAT is called an Accessibility Conformance Report (ACR).
Preview of the TestPros VPAT template, a Voluntary Product Accessibility Template ready to complete

Free download

Download Our Free VPAT Template

You can complete the template on your own, but we recommend working with accessibility experts so your conformance claims hold up in procurement review.

Download the VPAT template

The template covers information and communication technology (ICT) of every kind: software, web applications, hardware, electronic documents, and the support materials that ship with them. The ITI publishes and maintains the VPAT, and the current version is VPAT 2.5.

A completed VPAT does three things. It lists the accessibility requirements that apply to the product, states the product’s level of conformance with each one, and explains how the product meets the requirement, or where it falls short. That last column is where a credible report is separated from a hopeful one.

What is the difference between a VPAT and an ACR?

The VPAT is the blank template. An Accessibility Conformance Report (ACR) is the finished document you produce by completing it. People use the two words interchangeably, but the distinction matters in procurement: a buyer will ask for a “VPAT,” and what they actually need is your completed ACR for the specific standard they buy against.

That is why “send us your VPAT” is really a request for evidence. An empty template proves nothing. A completed ACR, backed by real testing, is the thing that lets a buyer compare your product against a competitor’s and defend the choice to their own compliance team.

Who needs a VPAT, and when?

Any organization that sells ICT to a buyer who has an accessibility obligation needs a VPAT, and that circle is widening. It starts with software vendors, web and application developers, and hardware manufacturers selling into procurement.

The clearest trigger is selling to government. To contract with a U.S. federal agency, a product generally has to meet Section 508 of the Rehabilitation Act, and agencies request an ACR as the evidence. The General Services Administration and Section508.gov spell out that a completed ACR is expected for ICT in federal procurement. State and local governments, which often reference WCAG directly, ask for the same thing.

The requirement no longer stops at government. Enterprise buyers in higher education, healthcare, and finance increasingly attach a VPAT request to their RFPs, because their own compliance and legal teams now treat accessibility as a purchasing condition. If your largest prospect makes an ACR a requirement to sign, the VPAT stops being optional the moment that RFP lands.

What are the different types of VPAT?

VPAT 2.5 comes in four editions, each matched to the standard a given market enforces. Picking the wrong one is a common and avoidable mistake: hand a federal buyer a WCAG-edition ACR when they need the 508 edition, and the report can be bounced before anyone reads the findings. For the version history behind 2.5, see our breakdown of what changed in VPAT 2.5.

The four editions of VPAT 2.5 and who asks for each
VPAT 2.5 edition Standard it documents Who typically requests it
508 editionRevised Section 508, which incorporates WCAG 2.0 Level A and AAU.S. federal agencies and their contractors
WCAG editionWCAG 2.0, 2.1, and 2.2 (Level A and AA)U.S. private sector and state and local government buyers
EU editionEN 301 549, the European standard that references WCAGEuropean Union public-sector procurement
INT editionSection 508, EN 301 549, and WCAG combined in one reportGlobal vendors selling across multiple markets

Choose the edition that matches the buyer in front of you. If you sell into more than one market, the INT edition covers the combinations in a single report.

What do the conformance levels mean?

A VPAT records conformance against each requirement using four terms, and using them honestly is the whole game. A reviewer trusts a report that says “Partially Supports” with a clear explanation far more than one that claims “Supports” everywhere, because the second reads as marketing and invites a closer look.

What each VPAT conformance level means
Conformance level What it tells a buyer
SupportsThe product meets the requirement across the evaluated functionality.
Partially SupportsSome parts meet the requirement, but there are known gaps or exceptions.
Does Not SupportThe requirement is largely unmet.
Not ApplicableThe requirement does not apply to this product.

Use the “Remarks and Explanations” column to say what a level does not capture on its own. Naming a gap and your plan to close it builds more trust than a clean sheet a reviewer cannot verify.

How do you complete a VPAT?

Completing a VPAT is a testing exercise first and a writing exercise second. The document is only as good as the evaluation behind it, so the real work happens before anyone opens the template.

Test the product against the right standard. Evaluate each applicable success criterion in the standard your buyer requires, whether that is WCAG 2.2 AA, Section 508, or EN 301 549. Automated scanners are a useful first pass, but they reliably detect only about 30 to 40 percent of WCAG issues. The criteria that decide most procurement outcomes, such as whether focus order makes sense or a label is meaningful, need a person operating real assistive technology.

Record conformance honestly, with evidence. For each criterion, set the level and explain how the product meets it or where it falls short. Include the functionality tested and the method used. Vague entries are the fastest way to lose a sale to a competitor whose report a reviewer can actually follow.

Have the report validated before it goes out. Compare every entry against the source standard and your test findings, then have an accessibility expert complete or review your VPAT before it reaches a procurement officer. An outside review catches the overstatements and inconsistencies that get an ACR challenged during evaluation.

Keep it current. An ACR describes one product version tested against one set of standards. Review it at least annually, and again whenever a major release, a fix, or a standards update changes what was evaluated.

What makes a VPAT credible to buyers?

Credibility comes from the testing, not the template. The two failures that sink a VPAT in review are overstated conformance and thin explanations, and both trace back to a report written to impress rather than to document. A reviewer who finds one “Supports” that does not hold up starts doubting every other line.

The strongest ACRs come from evaluation by people who do not profit from the result. That is the case for an independent assessment: we sell the testing, not a scanner or an overlay, so there is no product to make the findings flatter. Certified testers work through the product with real screen readers such as NVDA, JAWS, and VoiceOver, by keyboard alone, and with screen magnification, because those are the checks an automated tool cannot make. The report that comes out is one a buyer’s reviewer can trust, which is the only kind worth sending.

Primary source: Voluntary Product Accessibility Template (VPAT), Information Technology Industry Council (ITI). Backs the definition, the maintainer, and the four VPAT 2.5 editions: itic.org/policy/accessibility/vpat.

Additional sources:

Before your next RFP response is due

Get an ACR a procurement reviewer will trust.

A buyer’s request for a VPAT is a request for evidence, and a self-completed template rarely survives review. TestPros tests your product with real assistive technology and produces a conformance report you can defend, with no scanner or overlay to sell you off the back of it. Start before the RFP clock runs out.

Request a VPAT assessment

Frequently Asked Questions

What does VPAT stand for?

VPAT stands for Voluntary Product Accessibility Template. It is a standardized document from the Information Technology Industry Council (ITI) used to report how a product conforms to accessibility standards such as WCAG, Section 508, and EN 301 549. A completed VPAT is called an Accessibility Conformance Report, or ACR.

What is the difference between a VPAT and an ACR?

The VPAT is the blank template; the ACR is the completed report you produce from it. Buyers usually ask for a VPAT, but what they need is your finished ACR for the standard they buy against. The template alone proves nothing; the completed report, backed by testing, is the evidence.

Is a VPAT a certification?

No. A VPAT is not a pass or fail certificate. It documents the degree to which a product meets specific accessibility standards, so buyers and vendors share an evidence-based basis for discussion during procurement. TestPros does not issue certifications; it produces the independent conformance report that buyers rely on.

How often should a VPAT be updated?

Review the VPAT at least once a year, and again whenever a major product release, an accessibility fix, or a standards update changes what was evaluated. An ACR always reflects one product version tested against one defined set of standards, so keeping it current tells buyers exactly which release the findings cover.

Do I need a VPAT for a website or web app?

A website or web application usually needs a VPAT when it is part of a product you sell, and an ACR covering that web content is expected when you contract with a U.S. government entity. For private-sector buyers, a VPAT is a practical way to prove the site or app meets WCAG. Keep in mind that a VPAT documents a specific product version against a defined standard, so it is distinct from an ongoing accessibility statement published on a public website.

SHARING IS CARING

What Challenges
Are You Facing?

Recent Posts