How to read a VPAT: a procurement officer's guide
A vendor sent you an Accessibility Conformance Report. Here is how to tell a thorough one from a cursory one, in the order you should check.
A vendor has sent you a document called a VPAT, or an Accessibility Conformance Report, and somebody needs to decide whether it is good enough to award on. If that somebody is you and you are not an accessibility specialist, this is the order to read it in.
The short version: most of what matters is what the report does not say. Reports rarely contain outright false claims. They contain omissions — criteria left out, conformance claimed without explanation, an edition that does not match your solicitation.
First, check it is the right document for the right thing
Before reading a single conformance claim, confirm three facts. Each of these can invalidate the entire report, and each takes seconds.
Which edition is it? VPAT 2.5 comes in four: WCAG, Section 508, EU (EN 301 549), and INT, which combines them. If your solicitation names Section 508 and the report is written to WCAG only, it does not answer your question. A WCAG 2.1 report submitted against a WCAG 2.2 requirement is the most common and most avoidable mismatch we see.
Which product version does it cover? The report should name the product and version it was evaluated against. If it covers version 6 and you are buying version 9, it describes software you are not purchasing.
When was it written? An undated report is not evidence of anything. Best practice is a refresh annually or after any significant change. A report three versions behind tells you little about what you are about to buy.
Then read the remarks, not the conformance column
This is the part most people skip, and it is where the information is.
Every row in a conformance table has a criterion, a conformance level, and a remarks field. The conformance level is the vendor's claim. The remarks are the vendor's evidence for that claim. A claim without evidence is an assertion.
Read the remarks column top to bottom and ask one question of each row: does this explain how they know?
- "Supports." with an empty remarks field tells you nothing. It might be true. You cannot tell from the document.
- "Supports. All images are given text alternatives; decorative images are marked with empty alt attributes." is a claim with a mechanism behind it.
- "Partially Supports." with an empty remarks field is worse than useless, because partially is the vendor telling you something fails and then declining to say what.
VPAT's own instructions require an explanation whenever conformance is anything other than full support. A report that skips those explanations is not merely thin — it is incomplete on the template's own terms.
Understand what the four conformance levels actually mean
VPAT 2.5 permits exactly four values:
| Value | What it means |
|---|---|
| Supports | The product meets the criterion |
| Partially Supports | Some functionality does not meet the criterion |
| Does Not Support | The product does not meet the criterion |
| Not Applicable | The criterion is not relevant to this product |
Two of these deserve suspicion by default.
"Partially Supports" is the most-used and least-informative value in the format. It can mean one obscure edge case fails, or it can mean the feature is unusable with a screen reader in the most common workflow. The words are identical. Only the remarks distinguish them, which is why the remarks matter more than the level.
"Not Applicable" is legitimate — a product with no audio genuinely cannot fail the captions criteria — but it requires a justification. "Not Applicable" with a blank remarks field on a criterion that plainly could apply is a flag, not a pass.
Weigh Level A differently from Level AA
Not all failures are equal, and treating them as equal is the most common analytical mistake.
WCAG success criteria come in levels. Level A is the floor — the non-negotiable baseline. Level AA is the standard almost every public-sector procurement requires, and it is what the ADA Title II rule references for state and local government web content.
A product that fails a single Level A criterion has not met the minimum, regardless of how well it does on AA. "We support 49 of 50 criteria" sounds excellent until you learn the one is 2.1.1 Keyboard, which means the product cannot be operated without a mouse.
So when you tally, do not tally. Ask instead:
- Are there any Level A gaps? If yes, that is the headline finding.
- How many Level AA criteria are not supported?
- How many are "Partially Supports" with no explanation of what fails?
Check for the criteria that are simply missing
A conformance table should account for every applicable success criterion. Conforming at Level AA means meeting the Level A criteria too: 50 of them in WCAG 2.1, 55 in WCAG 2.2.
Count the rows. If a report addresses 38 criteria, twelve are unaccounted for, and unaccounted-for is not the same as supported. This is easy to miss because absence is invisible — you have to go looking for it.
Ask who tested it, and how
Near the top, a complete report names the evaluation methods used: the assistive technologies tested with, the browsers, whether testing was automated, manual, or both.
This section is frequently vague or absent. When it is, you are being asked to take conformance claims on trust without knowing whether anyone opened the product with a screen reader. Automated tooling alone catches a minority of accessibility issues — the DOJ itself has noted the limits of automated and AI tools — so a report resting entirely on a scanner is a weaker document than one describing manual testing with named assistive technology.
What to do with what you find
You will rarely get a clean report, and a report with gaps is not automatically disqualifying. What matters is whether the vendor will commit to fixing them.
For each gap worth raising, ask for one of three things:
- the testing evidence supporting the stated conformance level,
- a remediation plan with target dates, or
- an explanation of why the criterion does not apply to this product.
Put the request in writing and keep the answer. The record of what you asked and what they said is the part of this process that protects you later — more than the report itself does.
A note on what a VPAT is not
A VPAT is a self-disclosure by the company selling the product. That is how the format is designed to work and it is not a criticism of vendors. But it means the document is a starting point for a conversation, not proof of anything, and the burden of assessing it falls on the receiving agency.
There is also no certification behind it. No accreditation body exists for WCAG or Section 508 conformance, and no certificate establishes ADA compliance. Be wary of anything presented as one.
GOVvpat reviews vendor conformance reports against the standard your solicitation names and returns a dated assessment for the procurement file. Request a quote or check a report.