Skip to main content
WCAGrules
Quick navigation

Guides · Documents and PDFs

Two Audits Hide Inside One Signing Link

The platform sends the email, draws the fields and captures the signature. The contract inside it is the one you wrote, and nobody else is going to tag it.

Last reviewed August 31, 2026

Split it in two before you test anything. The signing interface belongs to your vendor, and you can ask them for evidence about it. The document travelling through that interface belongs to you, and no amount of vendor conformance makes an untagged contract readable. Teams that skip this split end up auditing one half twice and the other half never, usually the half they own.

The second thing to settle early is that signing a contract is a legal commitment, and that single fact pulls a specific rule into the middle of the review. It also means the whole route counts as one process rather than as a set of pages, so a barrier at the confirmation step is not a small finding at the end. It is a barrier in the middle of something somebody is legally committing to.

The Vendor Splits the Product Before You Do

Look at how the best-known platform publishes its own evidence and the shape of the problem appears immediately. Docusign's accessibility hub does not carry one report. It carries separate conformance reports for the signing experience and the sending experience, and then separate ones again for its contract lifecycle product, its web forms, its workspaces, its notary product, its workflow builder and its iOS app.

So "our e-signature platform is accessible" is not a sentence the vendor's own hub supports, and that is not a criticism of the vendor. It is what honest reporting looks like when the product is really a family of them. What it means for you is that the report you were handed covers one of those surfaces, and the first question in any review is which one. A sending report says nothing about what your customer meets.

The same hub also names recommended browser and screen reader combinations, which is another scoping fact rather than a limitation on anybody's rights. It tells you which environments the vendor's evidence is most likely to describe, and it tells you where a test of your own is most likely to disagree with the paperwork. Read a conformance report the way what a VPAT cannot tell you suggests, and treat the environment line as part of the finding rather than as boilerplate.

Signing Is a Legal Commitment, and a Rule Turns On That

3.3.4 Error Prevention (Legal, Financial, Data) applies at Level AA to pages that cause legal commitments or financial transactions, and a signature page is the clearest example there is. The rule is satisfied by any one of three things, which is the part that saves arguments. Submissions are reversible. The data is checked and the user can correct it. Or a mechanism exists for reviewing, confirming and correcting before the thing is final.

Any one. Not all three. A signing flow that lets somebody read the whole document, see every field they filled, and go back and change one before pressing the last button has met the criterion through the third route, and it does not also owe you a cancellation window. Knowing that stops a review turning into an argument about whether contracts should be undoable, which is a business question and not this one.

The rule underneath it is the process rule. When a page is one of a series presenting a process, every page in the series conforms at the level claimed or none of them does. A signing journey is a series by any reading, so the audit runs the route rather than sampling it. That is also why the confirmation screen is not an afterthought. It is inside the same conformance boundary as the signature itself.

The Six Surfaces, and Who Owns Each One

Run the matrix below on a test envelope rather than a live one, using an agreed sandbox and synthetic parties. Each row is a place the journey can stop, and the owner column is the one that decides where a finding goes.

SurfaceWho owns itWhat the evidence has to show
The invitationYou, mostlyAn email whose subject and body say what is being signed and by when. Link text that names the action rather than reading Review Document
Arrival and identity checkSharedWhatever stands between the link and the document. An access code, a one-time passcode, a login. Test it with the keyboard and with a screen reader, and record what a failed attempt sounds like
The document viewYouThe file you uploaded, tagged, in a sensible reading order, with real headings. A viewer cannot invent structure the file never had
Fields and errorsSharedEvery field reachable and named, with the platform's tooltip carrying the label. Required fields announced as required, and a validation failure that says which field and why
Signature captureVendorA route to a signature that does not require drawing with a pointer. Typed and adopted signatures reached by keyboard, and the choice announced
Confirmation and the final fileSharedA confirmation that reaches a screen reader, and a completed document that is still tagged after the platform has written the signature into it
The six surfaces in a signing journey, with the evidence each one needs

The last row is the one that surprises people. A platform flattens, stamps and reassembles the file on the way out, so the document you get back is not byte for byte the document you put in. Test the completed copy as its own artifact, because a tagged contract that comes back untagged is a finding nobody would have looked for.

The Document You Uploaded Is Still Your Document

This is the half that gets orphaned. Signing platforms overlay their own fields on top of your file, and the platform's tooltip on each field becomes what a screen reader announces. So a tagged contract with well-drawn fields reads properly, and an untagged one reads as a wall of unlabelled boxes on top of a document nobody can navigate. Neither outcome has anything to do with the vendor's conformance report.

Which means the preparation work is a document job, and it belongs with whoever produces the contract. Tag the source, set the language and the title, mark the tables properly, and give every field a tooltip that says what it is rather than repeating its position. All of that is in what makes a PDF readable and how to tag a PDF, and none of it can be done after the envelope has gone out.

Sessions Expire, and That Is a Rule Too

Signing sessions time out, which makes them a time limit set by the content, which puts them under 2.2.1 Timing Adjustable at Level A. Three routes satisfy it. Let the user turn the limit off before they meet it. Let them adjust it before they meet it, over a range at least ten times the default. Or warn them before it expires, give them at least 20 seconds to extend with a simple action, and let them do that at least ten times.

Test it by leaving the session open and going to make a coffee, which is the same thing your customer does when a contract asks them to read something long. What you want to know is whether a warning arrives, whether it reaches a screen reader, and whether anything they typed survives the timeout. And while you are in there, look at whether the flow asks for the same information twice, because 3.3.7 Redundant Entry landed at Level A in WCAG 2.2 and a signing flow that re-asks for an address is exactly what it is about.

What This Review Cannot Tell You

Say this part out loud at the start of the engagement rather than at the end. An accessibility review of a signing journey establishes whether disabled people can complete it. It establishes nothing about whether the resulting signature is legally binding, whether the identity check is strong enough for your regulator, or whether the platform's security holds up. Those are three separate specialisms and none of them is ours.

It also cannot be run on live contracts. Real envelopes go to real people and create real obligations, so the review needs an agreed sandbox, synthetic signers and test documents that nobody will mistake for the genuine article. That is a scoping question rather than a purchase, and it is why this work starts with a conversation.

One honest limit

There is no e-signature package on our price list, because a journey that crosses a vendor's product and your own document is scoped rather than counted. The closest matched doors are the forms and errors audit for the field-level half and the PDF accessibility audit for the document. For the whole route, tell us what the journey looks like through contact and we will tell you what can be tested and what cannot.

Common questions

Our e-signature vendor sent us their VPAT. Are we covered?
Only for what it covers. Vendors publish separate reports for separate products and separate experiences, so a sending report says nothing about what your customer meets on the signing side. Check which surface the report names, which version it was written against, and which browser and screen reader combinations the vendor recommends, because that last line tells you which environments the evidence describes.
Whose job is the contract itself?
Yours. The platform overlays its fields on the file you uploaded and cannot invent structure the file never had. A tagged document with well-labelled fields reads properly. An untagged one reads as a wall of unlabelled boxes, whatever the vendor's report says about their own interface.
Does WCAG require an e-signature to be reversible?
No. The rule about legal commitments offers three routes and any one of them satisfies it. Reversible submissions, checked data with a chance to correct it, or a mechanism to review and confirm before finalizing. A flow with a proper review step has met it, and whether contracts should also be cancellable is a business decision rather than a WCAG one.
Can you test our real signing flow?
Not with real contracts. Live envelopes create real obligations for real people, so this work runs in an agreed sandbox with synthetic signers and test documents. Setting that up is part of the scoping conversation rather than something to arrange after the fact.
What about the completed document that comes back?
Test it as its own artifact, because platforms flatten and reassemble a file on the way out and the copy you get back is not the copy you sent. A contract that went in tagged and comes back untagged is a real finding, and it is one nobody looks for unless they know to.

Sources

Keep reading

More on documents and pdfs

Reading about it is the cheap part.

Find out where your site actually stands. The free scan checks 10 pages in a real browser against all 90 supported automated rules, keeps its 27 best-practice checks separate from WCAG findings, and names the rule behind every finding. The full audit adds an expert review and a real blind screen-reader user. From $499, with the report in 5 business days on Rapid and 10 on Standard, and the clock starting at cleared payment.

Go somewhere useful

Find tools, resources and your workspace.

29 destinations