Skip to main content
WCAGrules
Quick navigation

Guides · Comparisons

Three Words for Three Depths, and Nobody Agrees Which Is Which

Gap analysis, audit, conformance evaluation. There is no industry definition of any of the three, so this page says what we mean by each and what each one hands you.

Last reviewed August 31, 2026

The three words describe three depths of the same work, and what separates them is what you hold at the end rather than how hard anybody tried. A gap analysis answers how far you are and what to fix first. An audit answers what is wrong on the pages you named, with evidence a developer can act on and a regulator can check. A conformance evaluation answers a reviewer who named a method and expects that method's shape back. Same testing underneath. Three different documents on the other side.

Now the part most comparison pages skip. None of those is an industry definition, because there is no industry definition. Search WCAG 2.2 for the word audit and it is not there. Search W3C's evaluation methodology for it and it is not there either, and neither document contains the phrase gap analysis anywhere. The words those documents use are evaluation, conformance claim and evaluation statement, and no standards body has ruled on what a supplier may call anything else. So every one of these three labels is a name somebody chose, ours included.

That has a practical consequence worth carrying into any conversation with a supplier. Somebody else's gap analysis may be a scanner export with a cover page on it, and somebody else's audit may go further than the evaluation described below. Ask what lands in your hands, never what the engagement is called. Everything that follows is what those three words mean on this site, said plainly so you can hold another quote against it.

The Three Depths, Side by Side

One table, and it is the whole argument. Read the first three rows to choose, and the rest to check a proposal from anybody.

Gap analysisAuditConformance evaluation
The question it answersHow far are we, and what do we fix first?What is wrong on these pages, and how do we prove it?Can we answer a reviewer who named the method?
How the pages get chosenFor coverage. The pages that between them use the most of your templatesFor evidence. The pages you name, usually the journeys that carry the revenueBy the method. A structured set, a random tenth on top, and every complete process the sample touches
Who usually buys itA team sizing the work before it commits a budgetA team that has been handed a standard and needs a rule-by-rule answerAn organization whose contract, regulator or procurement checklist names a formal evaluation
FindingsMarked systemic or local, ranked by user impactCoded, mapped to the criterion and a severity, ordered worst blockers firstThe same, plus outcomes reported per conformance requirement
Evidence per findingThe same evidence, because the three passes underneath are identicalScreenshot, failing element, page state and markup excerptThe same, plus at least one example for every requirement and criterion not met
Pass or fail against each ruleNot the point of this engagementRecorded, and what each tier records is on the pricing pageRecorded against the target level for every sample
Accessibility support baselineNot requiredThe report names the browser and screen reader the evaluation ran onRequired. Agreed with you before testing starts and printed in the report
Technologies relied uponNot requiredThe report names themRequired, and identified during a separate exploration step
Random sample, and how it was drawnNoNoRequired, at ten percent of the structured set, with the selection method written down
Complete processes namedNamed as the journeys a later audit should point atTested where they are in the pages you choseRequired. Every step of every process the sample touches, plus the common branches
What you can say afterwardsHow big the job is and where to startWhat was true of these pages, on this date, with this evidenceThe same, in the shape a reviewer recognizes, and an evaluation statement where the conditions are met
What we mean by each of the three engagements, and what each one delivers. These are our labels rather than industry definitions

What We Mean by a Gap Analysis

A gap analysis is our standard audit with the page choice made for coverage instead of for proof. Rather than picking the ten pages you most need defensible evidence on, you pick the ten that between them use the most of your templates. Home, a listing page, a detail page, a form, the checkout, an account screen. The testing underneath is identical.

That works because most of what an audit finds is template-level. One header, one form pattern, one card component, repeated everywhere. A finding on the listing template is a finding on 4,000 listing pages, so counting the templates is how you reach an estimate a roadmap can hold rather than a number somebody guessed at in a meeting.

What lands in your hands is a set of findings that describe your system rather than six specific addresses. Each one marked systemic or local, so you can see which fixes buy you thousands of pages and which buy you one. Ranked by user impact, so the worst blockers sit above the quick clears. And a note of which journeys a follow-up audit should point at, if you take that step.

What it is not is a number for your site. It samples, so it can size the work and it cannot settle every page. If somebody upstairs needs a figure by Friday, this is the engagement that produces an honest one. How far from Level AA are you has the full offer.

What We Mean by a WCAG Audit

An audit answers the standard rule by rule on the pages you named, and it exists to be checked by somebody who was not there. That is the difference in one sentence. A gap analysis is written for your planning meeting. An audit is written for your developer, your client and anybody who later asks you to prove it.

Every finding arrives in the same shape, and the shape is the deliverable.

  • A coded finding, mapped to the WCAG 2.2 criterion it breaks and given a severity.
  • A screenshot, captured at the moment the problem was found rather than reconstructed afterwards.
  • The exact element, the page state and the markup excerpt behind it, which is what lets somebody who disagrees go and check.
  • The date of the evaluation, and the browser and screen reader it was carried out with.
  • A link to the fix, from the free library of 432 technique guides.

What gets recorded against each of the rules differs by tier, and rather than paraphrase that here, the pricing page sets out what each one covers and what it costs. If you would rather see the thing than read about it, the sample report is the whole format with three worked findings in it, and our method walks through the three passes that produce them. The audit itself is the WCAG 2.2 audit.

What We Mean by a Conformance Evaluation

A conformance evaluation is an audit run to W3C's published method, WCAG-EM, and reported in that method's shape. You buy it when something outside your company has named the method, which is usually a contract, a regulator or a procurement reviewer, and expects to see the structure back in what you hand over.

The testing underneath is the same testing. What changes is that the choosing gets taken out of your hands on purpose, and that four things a normal audit report leaves out become required.

  • The accessibility support baseline. Which browsers and assistive technologies the site is expected to work with, agreed with you before any testing starts rather than chosen quietly by whoever runs it. Two evaluations holding different baselines can reach different verdicts on the same site while both are right.
  • The technologies relied upon. Which web technologies the pages depend on to conform, identified during a separate exploration step.
  • The random sample and the method used to draw it. Ten percent of the structured set, added on top, with the selection written down so somebody else can judge whether the sample flattered you.
  • The complete processes. Every step of every process the sample touches, including the branches people commonly take, because a process conforms only when every page in it does.

Then the structured results get compared against the random ones, which is the step that makes the whole thing checkable. A random slice that turns up findings the chosen pages missed proves the chosen pages were not representative, and the honest response is to go back and pick more.

One naming point saves a lot of confusion later. The method's own public output is an evaluation statement, and it is deliberately not a conformance claim. It requires six items, it can only be published when every non-optional requirement of the method was met and every sample reached the target level, and it says what was evaluated rather than what the site is. The audit method W3C publishes explains the five steps and the report minimum in full, and a WCAG-EM evaluation is the engagement.

Where a Free Scan Sits Underneath All Three

A scan is a real thing that finds real failures, and it is not one of the three. It is a preliminary check, and W3C keeps that in a separate category from an evaluation for a reason it states plainly. A quick first review is designed to be quick rather than definitive, a page can seem to pass one and still carry serious barriers, and a fuller assessment by a person is needed afterwards. W3C puts the same point about tools even more bluntly, saying an evaluation tool cannot determine accessibility and can only assist in doing so.

The method itself recommends starting there, which is worth knowing if a supplier treats a free scan as beneath them. Before evaluating a whole product, it says, it is usually good to do a preliminary evaluation of a few samples to spot the obvious barriers and get a sense of where the product stands. That is the free-scan-then-audit order, described by W3C rather than by a firm that sells the second half.

The arithmetic is worth having, because it is the honest shape of the gap. Our own scan runs all 90 supported automated rules: 63 WCAG-mapped checks and 27 separate best-practice checks. The WCAG-mapped checks touch 20 of the 55 criteria at Level A and AA. Touching is not clearing. We graded 356 of the 432 techniques and documented failures W3C publishes, and 10 of those can be settled by a machine outright. That figure is ours rather than W3C's, which publishes none. From the other direction, 24 of the 55 criteria at A and AA have no automated rule written against them at all, so for those there is nothing for a tool to run.

So run one, and read the result as a floor rather than a verdict. Our free scan covers up to 10 pages, what a free scan cannot see is the honest account of the gap, and free scan versus audit is the longer comparison of those two specifically.

Which One Answers the Question You Actually Have

Four questions, and the answer to whichever one you recognize is the engagement to buy.

  1. Somebody has asked how big this is, and there is no budget yet. A gap analysis. It sizes the work and hands the roadmap a place to start, which is what a budget conversation actually needs.
  2. A client, a contract or a regulator has handed you a standard. An audit. You need the rules answered on real pages with evidence attached, and you need it in a form the person who asked can check.
  3. A procurement reviewer or a contract has named WCAG-EM or asked for a formal conformance evaluation. The evaluation. The shape of the report is part of the requirement, and an audit with a new label on it will come back.
  4. You have fixed things and want to know whether they landed. None of the three, at first. That is a retest of an existing scope, and it is a different piece of work with its own before and after.

What None of the Three Can Claim

All three sample, and so does every honest engagement on the market. Conformance in WCAG is defined for a web page, and only for a web page. A claim is allowed to cover more than one, because it may be made for a single page, for a series of pages, or for multiple related pages. What the standard never does is loosen the requirement underneath, so every page inside a claim has to have conformed.

That is the ceiling, and depth does not raise it. W3C's evaluation methodology states that a conformance claim cannot be made for an entire website on the strength of an evaluation of a selected sub-set of its pages and functionality. The reason given is not that samples are sloppy. It is that an unexamined page may always carry an error, and no sample size closes that gap.

So a deeper engagement buys you a better-documented sample and a better guide to the templates behind it. It never buys a certificate covering pages nobody opened, and there is no accessibility certification any vendor can issue that means anything in law, ours included. Our pricing page states that under the heading about what none of the tiers buys you, and the five conformance requirements sets out what a claim has to carry when you do make one.

Two things to hold on to from this page

The first is that these three labels are ours. We define them here so a quote of ours can be read against a quote of somebody else's, and presenting them as industry-wide would be inventing a standard that does not exist. The second is that we audit and never sell the repair work, so none of the three ends with us quoting you for the fixing. That split is deliberate, because a firm paid by the length of the repair job should not be the firm writing the list. What you do with the findings is yours to hand to your own team or to a supplier you choose.

Common questions

What is the difference between an accessibility gap analysis and an audit?
On this site, the page choice and the purpose. A gap analysis picks the pages that between them cover the most of your templates, so it can size the work and say what to fix first. An audit picks the pages you need defensible evidence on and answers the rules against them with screenshots, elements and markup attached. The testing underneath is the same. No standards body defines either word, so another supplier may use them differently.
Is a conformance evaluation the same as an audit?
Not quite. A conformance evaluation is an audit run to W3C's published method and reported in that method's shape, which adds four required items an ordinary report leaves out. The accessibility support baseline, the technologies relied upon, a random sample at ten percent with the method used to draw it, and the complete processes. You buy it when a contract, a regulator or a procurement reviewer named the method.
Which one should I buy first?
If there is no budget yet and somebody wants to know how big this is, start with a gap analysis. If a client, a contract or a regulator has handed you a standard, buy the audit, because you need the rules answered with evidence. If the requirement in front of you names WCAG-EM or asks for a formal conformance evaluation, buy that, because the shape of the report is part of what is being asked for.
Are these standard industry definitions?
No, and treating them as though they were would be inventing a standard. The word audit appears nowhere in WCAG 2.2 and nowhere in W3C's evaluation methodology, and the phrase gap analysis appears in neither. The vocabulary those documents use is evaluation, conformance claim and evaluation statement. These three labels are ours, published so a quote of ours can be compared against anybody else's. Always ask what lands in your hands rather than what the engagement is called.
Does any of the three prove my whole site conforms?
No. All three sample, and W3C's evaluation methodology says a conformance claim cannot be made for an entire website on the strength of a selected sub-set of its pages, because an unexamined page may always carry an error. Conformance is defined for a web page. A claim may cover a page, a series of pages or multiple related pages, and every page inside it has to have conformed.
Where does a free automated scan fit in?
Underneath all three, as a preliminary check rather than an evaluation. Our scan runs all 90 supported automated rules: 63 WCAG-mapped checks and 27 separate best-practice checks. The WCAG-mapped checks touch 20 of the 55 criteria at Level A and AA, and touching is not clearing. On our own grading, 10 of the 356 techniques and documented failures we graded can be settled by a machine outright. Read a clean scan as a floor and never as a verdict.
Do you fix what you find?
No. We audit and we do not sell remediation, deliberately, because a firm paid by the length of the repair job should not be the firm writing the list. The findings arrive with the failing element, the page state and a link to a fix guide, so your own team or a supplier you choose can act on them. We can retest afterwards to confirm the fixes landed.

Sources

Keep reading

More on comparisons

Reading about it is the cheap part.

Find out where your site actually stands. The free scan checks 10 pages in a real browser against all 90 supported automated rules, keeps its 27 best-practice checks separate from WCAG findings, and names the rule behind every finding. The full audit adds an expert review and a real blind screen-reader user. From $499, with the report in 5 business days on Rapid and 10 on Standard, and the clock starting at cleared payment.

Go somewhere useful

Find tools, resources and your workspace.

29 destinations