Skip to main content
All articles
3 min read

Section 508, WCAG, or EN 301 549: which edition to require

VPAT 2.5 comes in four editions. Requiring the wrong one means the report you get back does not answer the question you asked.

VPAT 2.5 is published in four editions. They cover overlapping but different standards, and a report written to one does not necessarily answer a requirement written to another. Naming the wrong edition in a solicitation is one of the easiest mistakes to make and one of the most annoying to discover after award.

The four editions

VPAT 2.5 WCAG — conformance with the Web Content Accessibility Guidelines (also published as ISO/IEC 40500). The baseline most other standards build on. Comes in 2.1 and 2.2 flavours; the difference matters, see below.

VPAT 2.5 508 — conformance with the Revised Section 508 standards. Required for US federal procurement and by many recipients of federal funding. Section 508 incorporates WCAG 2.0 Level AA by reference and adds requirements covering hardware, software, documentation and support.

VPAT 2.5 EU — conformance with EN 301 549, the harmonised European standard, used in EU public-sector procurement and under the European Accessibility Act.

VPAT 2.5 INT — all three in one document. What vendors selling across jurisdictions typically produce.

Which to require

US state and local government. Name WCAG 2.1 Level AA. That is what the ADA Title II rule references for web content and mobile applications. Requiring Section 508 instead is not wrong — it is a superset in some respects — but it answers a federal question when yours is a Title II question.

US federal, or federally funded. Name Section 508. It is the applicable standard and it covers more ground than WCAG alone, including documentation and support services.

Buying across jurisdictions, or unsure. The INT edition covers all three. Accepting an INT report where you asked for WCAG is fine; the reverse is not.

The 2.1 versus 2.2 trap

This is the mismatch we see most often.

WCAG 2.2 added nine success criteria beyond 2.1. If your solicitation names WCAG 2.2 Level AA and the vendor submits a report written to 2.1, the report is silent on those nine — not compliant with them, not non-compliant, simply unaddressed.

Because the document still looks complete, this is easy to miss. Every row is filled in. It is the rows that are not there that are the problem.

Two practical defences:

  • State the version explicitly in the solicitation. "WCAG 2.1 Level AA", not "WCAG Level AA".
  • When a report arrives, count the criteria. Conformance at Level AA includes the Level A criteria: 50 of them in WCAG 2.1, 55 in WCAG 2.2. A count of 50 against a 2.2 requirement tells you immediately.

What a mismatch actually costs

Discovering the wrong edition after award leaves poor options: accept a report that does not address your standard, ask for a new one mid-contract when your leverage has gone, or re-run an evaluation you already paid for.

Discovering it during evaluation costs one email.

Language you can reuse

Vendors shall submit a completed Accessibility Conformance Report using the current ITI VPAT template, in the [WCAG 2.1 / Section 508 / INT] edition, evaluated against the product version proposed. Where any criterion is reported as other than "Supports", the Remarks and Explanations field shall describe the specific limitation and, where applicable, the remediation plan and target date.

That last sentence does more work than the rest of it. Requiring the explanations is what turns a conformance report from a checklist into evidence.


GOVvpat checks reports against the edition your solicitation names, and flags it when a vendor answered a different question. Request a quote.

VPATSection 508EN 301 549procurement