The three words describe three depths of the same work, and what separates them is what you hold at the end rather than how hard anybody tried. A gap analysis answers how far you are and what to fix first. An audit answers what is wrong on the pages you named, with evidence a developer can act on and a regulator can check. A conformance evaluation answers a reviewer who named a method and expects that method's shape back. Same testing underneath. Three different documents on the other side.
Now the part most comparison pages skip. None of those is an industry definition, because there is no industry definition. Search WCAG 2.2 for the word audit and it is not there. Search W3C's evaluation methodology for it and it is not there either, and neither document contains the phrase gap analysis anywhere. The words those documents use are evaluation, conformance claim and evaluation statement, and no standards body has ruled on what a supplier may call anything else. So every one of these three labels is a name somebody chose, ours included.
That has a practical consequence worth carrying into any conversation with a supplier. Somebody else's gap analysis may be a scanner export with a cover page on it, and somebody else's audit may go further than the evaluation described below. Ask what lands in your hands, never what the engagement is called. Everything that follows is what those three words mean on this site, said plainly so you can hold another quote against it.
The Three Depths, Side by Side
One table, and it is the whole argument. Read the first three rows to choose, and the rest to check a proposal from anybody.
| Gap analysis | Audit | Conformance evaluation | |
|---|---|---|---|
| The question it answers | How far are we, and what do we fix first? | What is wrong on these pages, and how do we prove it? | Can we answer a reviewer who named the method? |
| How the pages get chosen | For coverage. The pages that between them use the most of your templates | For evidence. The pages you name, usually the journeys that carry the revenue | By the method. A structured set, a random tenth on top, and every complete process the sample touches |
| Who usually buys it | A team sizing the work before it commits a budget | A team that has been handed a standard and needs a rule-by-rule answer | An organization whose contract, regulator or procurement checklist names a formal evaluation |
| Findings | Marked systemic or local, ranked by user impact | Coded, mapped to the criterion and a severity, ordered worst blockers first | The same, plus outcomes reported per conformance requirement |
| Evidence per finding | The same evidence, because the three passes underneath are identical | Screenshot, failing element, page state and markup excerpt | The same, plus at least one example for every requirement and criterion not met |
| Pass or fail against each rule | Not the point of this engagement | Recorded, and what each tier records is on the pricing page | Recorded against the target level for every sample |
| Accessibility support baseline | Not required | The report names the browser and screen reader the evaluation ran on | Required. Agreed with you before testing starts and printed in the report |
| Technologies relied upon | Not required | The report names them | Required, and identified during a separate exploration step |
| Random sample, and how it was drawn | No | No | Required, at ten percent of the structured set, with the selection method written down |
| Complete processes named | Named as the journeys a later audit should point at | Tested where they are in the pages you chose | Required. Every step of every process the sample touches, plus the common branches |
| What you can say afterwards | How big the job is and where to start | What was true of these pages, on this date, with this evidence | The same, in the shape a reviewer recognizes, and an evaluation statement where the conditions are met |
What We Mean by a Gap Analysis
A gap analysis is our standard audit with the page choice made for coverage instead of for proof. Rather than picking the ten pages you most need defensible evidence on, you pick the ten that between them use the most of your templates. Home, a listing page, a detail page, a form, the checkout, an account screen. The testing underneath is identical.
That works because most of what an audit finds is template-level. One header, one form pattern, one card component, repeated everywhere. A finding on the listing template is a finding on 4,000 listing pages, so counting the templates is how you reach an estimate a roadmap can hold rather than a number somebody guessed at in a meeting.
What lands in your hands is a set of findings that describe your system rather than six specific addresses. Each one marked systemic or local, so you can see which fixes buy you thousands of pages and which buy you one. Ranked by user impact, so the worst blockers sit above the quick clears. And a note of which journeys a follow-up audit should point at, if you take that step.
What it is not is a number for your site. It samples, so it can size the work and it cannot settle every page. If somebody upstairs needs a figure by Friday, this is the engagement that produces an honest one. How far from Level AA are you has the full offer.
What We Mean by a WCAG Audit
An audit answers the standard rule by rule on the pages you named, and it exists to be checked by somebody who was not there. That is the difference in one sentence. A gap analysis is written for your planning meeting. An audit is written for your developer, your client and anybody who later asks you to prove it.
Every finding arrives in the same shape, and the shape is the deliverable.
- A coded finding, mapped to the WCAG 2.2 criterion it breaks and given a severity.
- A screenshot, captured at the moment the problem was found rather than reconstructed afterwards.
- The exact element, the page state and the markup excerpt behind it, which is what lets somebody who disagrees go and check.
- The date of the evaluation, and the browser and screen reader it was carried out with.
- A link to the fix, from the free library of 432 technique guides.
What gets recorded against each of the rules differs by tier, and rather than paraphrase that here, the pricing page sets out what each one covers and what it costs. If you would rather see the thing than read about it, the sample report is the whole format with three worked findings in it, and our method walks through the three passes that produce them. The audit itself is the WCAG 2.2 audit.
What We Mean by a Conformance Evaluation
A conformance evaluation is an audit run to W3C's published method, WCAG-EM, and reported in that method's shape. You buy it when something outside your company has named the method, which is usually a contract, a regulator or a procurement reviewer, and expects to see the structure back in what you hand over.
The testing underneath is the same testing. What changes is that the choosing gets taken out of your hands on purpose, and that four things a normal audit report leaves out become required.
- The accessibility support baseline. Which browsers and assistive technologies the site is expected to work with, agreed with you before any testing starts rather than chosen quietly by whoever runs it. Two evaluations holding different baselines can reach different verdicts on the same site while both are right.
- The technologies relied upon. Which web technologies the pages depend on to conform, identified during a separate exploration step.
- The random sample and the method used to draw it. Ten percent of the structured set, added on top, with the selection written down so somebody else can judge whether the sample flattered you.
- The complete processes. Every step of every process the sample touches, including the branches people commonly take, because a process conforms only when every page in it does.
Then the structured results get compared against the random ones, which is the step that makes the whole thing checkable. A random slice that turns up findings the chosen pages missed proves the chosen pages were not representative, and the honest response is to go back and pick more.
One naming point saves a lot of confusion later. The method's own public output is an evaluation statement, and it is deliberately not a conformance claim. It requires six items, it can only be published when every non-optional requirement of the method was met and every sample reached the target level, and it says what was evaluated rather than what the site is. The audit method W3C publishes explains the five steps and the report minimum in full, and a WCAG-EM evaluation is the engagement.
Where a Free Scan Sits Underneath All Three
A scan is a real thing that finds real failures, and it is not one of the three. It is a preliminary check, and W3C keeps that in a separate category from an evaluation for a reason it states plainly. A quick first review is designed to be quick rather than definitive, a page can seem to pass one and still carry serious barriers, and a fuller assessment by a person is needed afterwards. W3C puts the same point about tools even more bluntly, saying an evaluation tool cannot determine accessibility and can only assist in doing so.
The method itself recommends starting there, which is worth knowing if a supplier treats a free scan as beneath them. Before evaluating a whole product, it says, it is usually good to do a preliminary evaluation of a few samples to spot the obvious barriers and get a sense of where the product stands. That is the free-scan-then-audit order, described by W3C rather than by a firm that sells the second half.
The arithmetic is worth having, because it is the honest shape of the gap. Our own scan runs all 90 supported automated rules: 63 WCAG-mapped checks and 27 separate best-practice checks. The WCAG-mapped checks touch 20 of the 55 criteria at Level A and AA. Touching is not clearing. We graded 356 of the 432 techniques and documented failures W3C publishes, and 10 of those can be settled by a machine outright. That figure is ours rather than W3C's, which publishes none. From the other direction, 24 of the 55 criteria at A and AA have no automated rule written against them at all, so for those there is nothing for a tool to run.
So run one, and read the result as a floor rather than a verdict. Our free scan covers up to 10 pages, what a free scan cannot see is the honest account of the gap, and free scan versus audit is the longer comparison of those two specifically.
Which One Answers the Question You Actually Have
Four questions, and the answer to whichever one you recognize is the engagement to buy.
- Somebody has asked how big this is, and there is no budget yet. A gap analysis. It sizes the work and hands the roadmap a place to start, which is what a budget conversation actually needs.
- A client, a contract or a regulator has handed you a standard. An audit. You need the rules answered on real pages with evidence attached, and you need it in a form the person who asked can check.
- A procurement reviewer or a contract has named WCAG-EM or asked for a formal conformance evaluation. The evaluation. The shape of the report is part of the requirement, and an audit with a new label on it will come back.
- You have fixed things and want to know whether they landed. None of the three, at first. That is a retest of an existing scope, and it is a different piece of work with its own before and after.
What None of the Three Can Claim
All three sample, and so does every honest engagement on the market. Conformance in WCAG is defined for a web page, and only for a web page. A claim is allowed to cover more than one, because it may be made for a single page, for a series of pages, or for multiple related pages. What the standard never does is loosen the requirement underneath, so every page inside a claim has to have conformed.
That is the ceiling, and depth does not raise it. W3C's evaluation methodology states that a conformance claim cannot be made for an entire website on the strength of an evaluation of a selected sub-set of its pages and functionality. The reason given is not that samples are sloppy. It is that an unexamined page may always carry an error, and no sample size closes that gap.
So a deeper engagement buys you a better-documented sample and a better guide to the templates behind it. It never buys a certificate covering pages nobody opened, and there is no accessibility certification any vendor can issue that means anything in law, ours included. Our pricing page states that under the heading about what none of the tiers buys you, and the five conformance requirements sets out what a claim has to carry when you do make one.
Two things to hold on to from this page
The first is that these three labels are ours. We define them here so a quote of ours can be read against a quote of somebody else's, and presenting them as industry-wide would be inventing a standard that does not exist. The second is that we audit and never sell the repair work, so none of the three ends with us quoting you for the fixing. That split is deliberate, because a firm paid by the length of the repair job should not be the firm writing the list. What you do with the findings is yours to hand to your own team or to a supplier you choose.