Every property in a portfolio is its own evaluation, and a result found on one never transfers to another. What does travel between them is the template, and that is the whole reason a portfolio can be audited for less than the sum of its parts. Get those two sentences the right way round and the budget conversation becomes straightforward.
The rule underneath is the same one that governs a single site. Conformance is defined for a web page, and a claim covering many pages holds only where each of those pages was itself evaluated or produced by a process guaranteeing it passes. Two franchise sites built from one theme are still two sets of pages, and nobody evaluated the second set.
The short version
Audit depth on one representative property, breadth across the rest, and never let the two be described in the same sentence. A conformance claim has to say which addresses it covers, including whether subdomains are in, which is the standard's own mechanism for stopping a result spreading. A portfolio scorecard is a management instrument. It is not a conformance level for anything on it.
The Required Field That Stops a Result Spreading
There is a line in the conformance claim requirements that reads like paperwork and is doing something important. Among the five things a claim must contain is a concise description of the pages covered, and the standard adds a specific instruction to that item. The description has to state whether subdomains are included in the claim.
That is the standard anticipating exactly this situation. Portfolios live on subdomains, on separate domains, on regional variants, and a claim written without deciding which of them it covers will be read as covering all of them. Making the boundary a required field means the decision has to happen while somebody is thinking about it, rather than in a sales meeting eighteen months later.
So the first artefact in a portfolio engagement is not a test plan. It is a list of properties with a line through the ones that are outside the scope of any sentence you intend to publish. Our guide to what a sampled audit proves covers how to word that sentence once the list exists.
Where One Product Ends and the Next Begins
Before the properties can be listed, somebody has to decide what counts as one product, and W3C's methodology has a principle for this that is more useful than it first sounds. It is designed to evaluate full, self-enclosed digital products, and it asks for full product enclosure, meaning the scope covers all views, states and functionality of the product without carving specific parts out. Carving parts out would conflict with the full-page and complete-process requirements, or would distort the result.
Its worked example is a bank with distinct areas for personal banking, commercial banking, internet banking, and service and contact, plus common views like the legal notice and sitemap linked from everywhere. Scope the whole bank and every area is in, including third-party content used inside it. Scope only commercial banking and you get that area's parts, plus the common views, the legal notice and the sitemap.
That second half is the part portfolios keep tripping over. The shared furniture comes with whatever you scope. You cannot evaluate one brand's site while treating the group-wide header, the shared consent banner and the corporate footer as somebody else's problem, because a visitor on that site meets all of them. If those shared parts are broken, they are broken on every property that carries them, which is also the best news in the whole engagement.
Consistency Is What Makes a Portfolio Cheaper Per Property
The methodology's guidance on sample size explains why a portfolio is not simply the price of one audit multiplied by the property count. Sample sets grow with variety and shrink with consistency, and it names the specific factors. Variety of sample types, of functionality, of technologies and of coding styles all push the sample up. Formalised development processes, trained authors, consistent tooling such as a shared content management system, and a smaller set of authors all push it down.
A well-run portfolio scores well on every one of those. One theme, one component library, one publishing tool, a handful of people with permission to change any of it. That is a legitimately smaller sample per property, and it is the mechanism behind sensible portfolio pricing rather than a discount somebody invented.
It also tells you when the mechanism does not apply. An acquired brand still on its old platform, a campaign microsite built by an agency two years ago, a regional site that forked the theme and never merged back. Each of those is a variety factor, and each needs treating as its own product rather than as another instance of the template.
The Portfolio Scope Worksheet
Sorting properties into tiers is our proposal rather than anything W3C prescribes, and no quota below comes from a standard. What the tiers do is force the honest question, which is what each property's entry on your final scorecard will actually be based on. The example numbers are illustrative.
| Tier | Which properties | What it gets | What its scorecard entry can say |
|---|---|---|---|
| Reference | One property that best represents the shared template | Full audit, all three passes, complete processes included | A real evaluation result for those pages, plus template findings that apply widely |
| Divergent | Anything on a different platform, theme or agency build | Its own audit, scoped separately | A real evaluation result for that property, and nothing inherited from the reference |
| Transactional | Any property carrying payment, application or account journeys | At minimum, the complete processes tested end to end | A claim about those processes, which is a legitimate claim unit on its own |
| Breadth | The remaining near-identical properties | Automated coverage against the failures a machine can settle | Confirmed failures, ranked. Never a pass, and never a conformance statement |
The last row carries the whole integrity of the exercise, so it is worth being blunt about. A scan can confirm a failure and cannot confirm a pass. We graded 356 of W3C's 432 techniques and documented failures, and a machine fully settles 10 of them. So a breadth-tier property with a clean automated result has been shown to lack a specific short list of problems, which is genuinely useful for ranking and completely useless as a conformance statement.
Reading the Scorecard Without Overreading It
W3C's methodology has a note about large-scale evaluation that reads like it was written for this exact deliverable. Mass evaluation of many products, for example for national surveying, is typically carried out primarily with automated tools, with relatively few views getting full manual inspection. Such evaluations, it says, do not usually reach the qualitative depth of conformance review the methodology is designed for.
That is a standards body describing a portfolio report accurately and without judgement. It is a different instrument, aimed at a different question. Where is the risk concentrated, which shared fix pays off across the most properties, and which sites need a proper look first. Those are excellent questions and a portfolio report answers them well.
What it does not answer is whether any given property conforms, and our own portfolio report says so on the page. The scale is ours rather than a conformance level, the report marks which properties were audited and which were only scanned, and no property on the list ends up entitled to say it conforms. Where every property needs a human on it, enterprise accessibility is the version that does that in scheduled waves.
Two Practical Things to Settle Early
First, check which properties are reachable at all. Our scanner only accepts public addresses on standard web ports, so an intranet property, a staging site on an odd port or anything on an internal hostname has to be audited by hand or left off the list. Finding that out from the property spreadsheet is cheaper than finding it out mid-engagement.
Second, decide who owns the fix before the report arrives. A portfolio's most valuable finding is usually a shared template failure, and a shared template usually has an owner who is not the person who commissioned the audit. If that owner is not in the room when the report lands, the finding that would have cleared forty sites at once sits still. Portfolios are scoped per portfolio rather than from a price list, so send the property list and the answer comes back as a written number and a split.
Where This Page Stops
Portfolios raise legal questions this page deliberately does not touch, and they are usually the interesting ones. Whether each entity in a group carries its own duty, whether a franchisor is answerable for a franchisee's site, whether a subsidiary in another country is inside a different regime entirely. Those turn on corporate structure and on the law of each place, not on how the audit was scoped.
They need a lawyer who can see the group structure, and the answer often changes how you would tier the portfolio in the first place. So it is worth asking early. What this page settles is the technical half, which is that evidence does not travel between properties and the scorecard has to show which entries were measured and which were estimated. A page on which laws apply is a reasonable place to start the other conversation.