Skip to main content
WCAGrules
Quick navigation

Guides · Documents and PDFs

The Documents Are Already in Scope. The Audit Might Not Be.

Your price list, your application form, your annual report. The standard reached all three the day you uploaded them, and the quote you were sent may not have.

Last reviewed August 31, 2026

Yes, your documents are covered, and the reason is smaller than it sounds. A PDF you link to sits at its own address, and an address is what the standard means by a web page. So the file was in scope from the moment you uploaded it, whatever anybody's audit covered. The second half is the part that is not automatic. Scope of the standard and scope of the engagement are two different lists, and only one of them gets agreed in an email.

That gap is where most of the arguments start. An auditor who tested your page templates and none of your files has not made a mistake, because nobody asked them to. An owner who assumed the files were included has not been unreasonable either, because the law does not distinguish by format and it is fair to expect the report not to. Both of them are right, which means the disagreement can only be settled earlier, in writing, before the work is priced.

Why the File Was Never Outside the Rules

The standard defines a web page as a non-embedded resource you get from a single address, plus whatever is rendered along with it. A PDF you link to is exactly that description, so a law naming WCAG 2.2 at Level AA reaches your statements the same way it reaches your storefront. Nothing has to be translated, and no special provision has to be found. The PDF accessibility guide covers what that means inside the file, and the eight failures that account for most of it.

The consequence people miss runs the other way from what they expect. Documents do not get a gentler standard because they are documents. They get the same one, which is why a document finding and a page finding use identical vocabulary. "The file is untagged" and "the file fails 1.3.1 Info and Relationships" are one sentence in two languages, and the second version is the one that belongs in a report somebody has to act on.

Scope of the Standard Is Not Scope of the Audit

Conformance is defined for a web page, and a conformance claim can cover one page, a series of pages, or a group of related pages. What the standard asks of any claim is that it names what it covers. So the question a buyer should be asking is not whether documents are in principle included, because they are. It is which files were opened, and what the report says about the ones that were not.

The UK government's audit guidance puts documents in its list of what a website sample should hold, in the same breath as the home page, the forms and the logged-in pages. It also says in as many words that auditing an entire website is not feasible. Both halves are worth carrying into your own brief, because together they describe what a document scope actually is. Not everything you have. A named set, chosen on purpose, with the rest of the library described rather than tested.

The Six Lines That Settle a Document Scope

This is the part to write down. Each line changes what the work is, and a vague answer to any one of them costs somebody a re-run. Read it as a worksheet rather than a checklist, because most of the value is in noticing which line you cannot answer yet.

What to settleWhy it changes the workWhat a vague answer costs
Which files, by name or by folderA document set is an inventory rather than a page count, and nobody can sample a list that does not exist yetThe report covers files nobody opens and misses the application form
How each file is deliveredA file linked from your site is web content. The same file emailed as an attachment is a non-web document, and the rules read slightly differently thereOne statement gets one verdict when it needed two, and the wrong one travels
Which standard, version and levelA law names WCAG at a level. A buyer may ask for PDF/UA instead, and that one comes in two parts written against two versions of PDFYou commission a report your customer will not accept
Which files are formsA fillable PDF is an interface, so labels, error messages and keyboard operation all come into play alongside reading orderForm fields get counted as images, and the hardest half goes untested
Who repairs what, and whereAlmost every document fix belongs in the source file rather than in the PDF, and the source usually lives with a different teamThe findings land on people with no access to the original
What the report says about the restA sample describes the sample. Everything else is described rather than tested, and the report should say which is whichSomebody reads a sample as clearance for the whole library
The scope questions to answer before anybody quotes for documents

The Same File Is Judged Twice, Slightly Differently

This is the detail that catches out anybody selling into the US public sector, and it is genuinely useful rather than trivia. Section 508 requires electronic content to meet WCAG 2.0 at Levels A and AA, and then excepts non-web documents from four success criteria, which are 2.4.1 Bypass Blocks, 2.4.5 Multiple Ways, 3.2.3 Consistent Navigation and 3.2.4 Consistent Identification. It also swaps the word document in wherever the criteria say web page.

Look at what those four have in common and the exception stops feeling arbitrary. Every one of them is about moving around a set of pages, and a document is not a set of pages. There is nothing to bypass, no second route to provide, and no navigation bar that has to stay in the same place. So the exception is a scoping decision rather than a discount, and it changes nothing about tagging, alt text, reading order or form labels.

Then the catch, which is the part worth writing into a brief. The exception is for non-web documents, and a PDF served from your website is web content. So the same statement is judged one way when a customer downloads it from their account and another way when you email it as an attachment. If both deliveries exist, and for statements they nearly always do, the scope needs to say so rather than leaving an auditor to guess which one you meant.

One more thing about that standard, because buyers quote it as though it were finished. It reaches well beyond web content, into hardware, software and support documentation, and it is patchier out there than its reputation suggests. Its own provision for real-time text inside a two-way voice call reads [Reserved], which is a standard's way of saying the requirement was left blank. Name the standard by all means. Do not assume naming it answers every question about every format you own.

Count the Files Before You Price Anything

An inventory takes an afternoon and it changes the quote more than any other single thing you could do. Work through it in this order, because each step narrows the next one.

  1. Find them all, including the orphans. Crawl your own site for document extensions, then look in the uploads folder as well. Plenty of files are indexed by search engines and linked from nowhere a person would find on purpose, and those are still published.
  2. Rank by how often each one is opened. Your analytics already knows. The top of that list is where a sample should start, and the bottom of it is where the honest answer is often deletion.
  3. Mark the forms separately. A file somebody has to fill in is an interface rather than a document, and it takes longer to test than a file somebody reads.
  4. Mark anything scanned. Try selecting a word with your cursor. If you cannot, there is no text in the file, and the work starts a step earlier than tagging.
  5. Ask which files still have a living source. A Word or InDesign original that somebody can open decides where the repair goes, and it is usually far cheaper than editing the PDF.
  6. Decide what should stop being a PDF. Turning the most-read documents into web pages is the cheapest finding in any document report, and you can reach it before you commission one.

Steps one and two are yours alone. Nobody can inventory your library from outside it, and an auditor who offers to is guessing at what your uploads folder holds. Step six is the one to reach for first, and the conditions a replacement has to meet are in does the HTML version really replace the PDF, because a web page beside a PDF only counts when four things are true at once.

What a Document Audit Does Not Include

Three boundaries, and all three are easier to hear now than after an invoice. We audit files and we never tag them, so what you get is a report your own team or your document vendor works from. E-books are a separate discipline with separate tooling and we do not sell conformance testing for them, which is why the EPUB guide exists as an explanation rather than an offer. And an automated document check is a first sweep rather than a verdict, for the reasons set out on scanners versus humans.

One honest limit, and one piece of counting

A sample describes what it sampled. A clean result on 10 files says those 10 files were clean, and a report that implies more than that is doing you no favors. On counting, documents are quoted by file rather than by pages inside them, and we agree the set with you before anything starts, which is why the PDF accessibility audit asks for your list first. What the tiers include is on pricing.

Common questions

Are PDFs really covered by the same law as our website?
Yes, where they are published on your site. A PDF you link to sits at its own address, and the standard defines a web page by address rather than by format. So a law naming WCAG 2.2 at Level AA reaches the file directly, with nothing to translate and no separate provision to find.
Our auditor did not test any documents. Did they do something wrong?
Probably not. An audit covers what the scope named, and most page-based scopes name pages. That is why the document inventory belongs in the brief rather than in the report. Ask what the scope said, and if documents were not in it, agree them as a separate set rather than assuming they were folded in.
How many documents should be in the sample?
There is no published number, and anybody quoting one is quoting themselves. Choose by use rather than by count. The files people actually open, the forms somebody has to complete, one of each template you produce at volume, and one of anything scanned. Then let the report say plainly which files were tested and which were only described.
Does a PDF/UA report answer a Section 508 request?
Not on its own. The US Access Board considered naming PDF/UA in the 508 rule and removed it before the final version, on the reasoning that PDF/UA does not address scripting or PDF used as a container for video, so a reader would still need WCAG for some requirements. WCAG can stand alone for a PDF and PDF/UA cannot. Ask your buyer which one they want, and expect the answer to be WCAG.
Should we just delete the old documents instead?
For a good number of them, yes, and it is the cheapest thing in this whole subject. Nobody needs a tagged copy of a memo from 2015 that gets opened twice a year. Rank by use, retire what nothing links to, and spend the budget on the files people actually open.

Sources

Keep reading

More on documents and pdfs

Reading about it is the cheap part.

Find out where your site actually stands. The free scan checks 10 pages in a real browser against all 90 supported automated rules, keeps its 27 best-practice checks separate from WCAG findings, and names the rule behind every finding. The full audit adds an expert review and a real blind screen-reader user. From $499, with the report in 5 business days on Rapid and 10 on Standard, and the clock starting at cleared payment.

Go somewhere useful

Find tools, resources and your workspace.

29 destinations