Yes, your documents are covered, and the reason is smaller than it sounds. A PDF you link to sits at its own address, and an address is what the standard means by a web page. So the file was in scope from the moment you uploaded it, whatever anybody's audit covered. The second half is the part that is not automatic. Scope of the standard and scope of the engagement are two different lists, and only one of them gets agreed in an email.
That gap is where most of the arguments start. An auditor who tested your page templates and none of your files has not made a mistake, because nobody asked them to. An owner who assumed the files were included has not been unreasonable either, because the law does not distinguish by format and it is fair to expect the report not to. Both of them are right, which means the disagreement can only be settled earlier, in writing, before the work is priced.
Why the File Was Never Outside the Rules
The standard defines a web page as a non-embedded resource you get from a single address, plus whatever is rendered along with it. A PDF you link to is exactly that description, so a law naming WCAG 2.2 at Level AA reaches your statements the same way it reaches your storefront. Nothing has to be translated, and no special provision has to be found. The PDF accessibility guide covers what that means inside the file, and the eight failures that account for most of it.
The consequence people miss runs the other way from what they expect. Documents do not get a gentler standard because they are documents. They get the same one, which is why a document finding and a page finding use identical vocabulary. "The file is untagged" and "the file fails 1.3.1 Info and Relationships" are one sentence in two languages, and the second version is the one that belongs in a report somebody has to act on.
Scope of the Standard Is Not Scope of the Audit
Conformance is defined for a web page, and a conformance claim can cover one page, a series of pages, or a group of related pages. What the standard asks of any claim is that it names what it covers. So the question a buyer should be asking is not whether documents are in principle included, because they are. It is which files were opened, and what the report says about the ones that were not.
The UK government's audit guidance puts documents in its list of what a website sample should hold, in the same breath as the home page, the forms and the logged-in pages. It also says in as many words that auditing an entire website is not feasible. Both halves are worth carrying into your own brief, because together they describe what a document scope actually is. Not everything you have. A named set, chosen on purpose, with the rest of the library described rather than tested.
The Six Lines That Settle a Document Scope
This is the part to write down. Each line changes what the work is, and a vague answer to any one of them costs somebody a re-run. Read it as a worksheet rather than a checklist, because most of the value is in noticing which line you cannot answer yet.
| What to settle | Why it changes the work | What a vague answer costs |
|---|---|---|
| Which files, by name or by folder | A document set is an inventory rather than a page count, and nobody can sample a list that does not exist yet | The report covers files nobody opens and misses the application form |
| How each file is delivered | A file linked from your site is web content. The same file emailed as an attachment is a non-web document, and the rules read slightly differently there | One statement gets one verdict when it needed two, and the wrong one travels |
| Which standard, version and level | A law names WCAG at a level. A buyer may ask for PDF/UA instead, and that one comes in two parts written against two versions of PDF | You commission a report your customer will not accept |
| Which files are forms | A fillable PDF is an interface, so labels, error messages and keyboard operation all come into play alongside reading order | Form fields get counted as images, and the hardest half goes untested |
| Who repairs what, and where | Almost every document fix belongs in the source file rather than in the PDF, and the source usually lives with a different team | The findings land on people with no access to the original |
| What the report says about the rest | A sample describes the sample. Everything else is described rather than tested, and the report should say which is which | Somebody reads a sample as clearance for the whole library |
The Same File Is Judged Twice, Slightly Differently
This is the detail that catches out anybody selling into the US public sector, and it is genuinely useful rather than trivia. Section 508 requires electronic content to meet WCAG 2.0 at Levels A and AA, and then excepts non-web documents from four success criteria, which are 2.4.1 Bypass Blocks, 2.4.5 Multiple Ways, 3.2.3 Consistent Navigation and 3.2.4 Consistent Identification. It also swaps the word document in wherever the criteria say web page.
Look at what those four have in common and the exception stops feeling arbitrary. Every one of them is about moving around a set of pages, and a document is not a set of pages. There is nothing to bypass, no second route to provide, and no navigation bar that has to stay in the same place. So the exception is a scoping decision rather than a discount, and it changes nothing about tagging, alt text, reading order or form labels.
Then the catch, which is the part worth writing into a brief. The exception is for non-web documents, and a PDF served from your website is web content. So the same statement is judged one way when a customer downloads it from their account and another way when you email it as an attachment. If both deliveries exist, and for statements they nearly always do, the scope needs to say so rather than leaving an auditor to guess which one you meant.
One more thing about that standard, because buyers quote it as though it were finished. It reaches well beyond web content, into hardware, software and support documentation, and it is patchier out there than its reputation suggests. Its own provision for real-time text inside a two-way voice call reads [Reserved], which is a standard's way of saying the requirement was left blank. Name the standard by all means. Do not assume naming it answers every question about every format you own.
Count the Files Before You Price Anything
An inventory takes an afternoon and it changes the quote more than any other single thing you could do. Work through it in this order, because each step narrows the next one.
- Find them all, including the orphans. Crawl your own site for document extensions, then look in the uploads folder as well. Plenty of files are indexed by search engines and linked from nowhere a person would find on purpose, and those are still published.
- Rank by how often each one is opened. Your analytics already knows. The top of that list is where a sample should start, and the bottom of it is where the honest answer is often deletion.
- Mark the forms separately. A file somebody has to fill in is an interface rather than a document, and it takes longer to test than a file somebody reads.
- Mark anything scanned. Try selecting a word with your cursor. If you cannot, there is no text in the file, and the work starts a step earlier than tagging.
- Ask which files still have a living source. A Word or InDesign original that somebody can open decides where the repair goes, and it is usually far cheaper than editing the PDF.
- Decide what should stop being a PDF. Turning the most-read documents into web pages is the cheapest finding in any document report, and you can reach it before you commission one.
Steps one and two are yours alone. Nobody can inventory your library from outside it, and an auditor who offers to is guessing at what your uploads folder holds. Step six is the one to reach for first, and the conditions a replacement has to meet are in does the HTML version really replace the PDF, because a web page beside a PDF only counts when four things are true at once.
What a Document Audit Does Not Include
Three boundaries, and all three are easier to hear now than after an invoice. We audit files and we never tag them, so what you get is a report your own team or your document vendor works from. E-books are a separate discipline with separate tooling and we do not sell conformance testing for them, which is why the EPUB guide exists as an explanation rather than an offer. And an automated document check is a first sweep rather than a verdict, for the reasons set out on scanners versus humans.
One honest limit, and one piece of counting
A sample describes what it sampled. A clean result on 10 files says those 10 files were clean, and a report that implies more than that is doing you no favors. On counting, documents are quoted by file rather than by pages inside them, and we agree the set with you before anything starts, which is why the PDF accessibility audit asks for your list first. What the tiers include is on pricing.