An ACR tells you what a vendor says about their own product, against a standard they picked, on a date they chose. That is a useful document and it is worth asking for. It is also a self-declaration with no auditor behind it, and there are four questions it cannot answer no matter how carefully it was filled in.
This page is for the person on the buying side. If you are the one writing the report, the VPAT and ACR guide covers the template, the editions and how to fill it in honestly, and what to do first when a customer asks for a VPAT covers the triage that comes before any of it.
The four blanks
No edition reports against EN 301 549 version 4. Below Level AAA there is no way to write we did not test this. Nothing names which pages were tested. And nothing names who tested them, or requires that person to be independent.
No Edition Reports Against EN 301 549 Version 4
This is the live one, and it is being sold past right now. Vendors are marketing reports as ready for the European Accessibility Act, which has applied since June 28, 2025. Ask which version of EN 301 549 the report covers and the answer is V3.2.1, from March 2021, whatever the cover letter said.
Two separate things cause that, and both are worth knowing before you push back on a supplier who is not actually lying to you.
The first is the template. The current one is VPAT 2.5Rev, published April 2025, and it ships in four editions. Not one of them names a version of EN 301 549 above V3.2.1, and the international edition that claims to hold every standard at once stops there too.
| Edition | WCAG versions | Other standards named |
|---|---|---|
| WCAG | 2.0, 2.1 and 2.2 | None |
| 508 | 2.0 only | The Revised Section 508 standards |
| EU | 2.0 and 2.1 | EN 301 549 V3.1.1 and V3.2.1 |
| INT | 2.0, 2.1 and 2.2 | The Revised Section 508 standards, plus EN 301 549 V3.1.1 and V3.2.1 |
Read the middle column, because the edition decides your WCAG version as well as your rule set. A federal buyer asking for a 508 report and WCAG 2.2 in the same breath is asking for two documents, since the Revised Section 508 standards incorporate WCAG 2.0 at Level A and AA and have not been updated since. And a European report bought today reports against WCAG 2.1, not 2.2.
The second cause is that there is nothing for the template to point at. The latest published version of EN 301 549 is still V3.2.1. A version 4 exists as a final draft, submitted for its approval vote in June 2026, and a draft is not a standard. So the template is not lagging behind the standard. Both are in the same place.
There is a third layer under that, and it is the one procurement teams should know. The presumption of conformity that a harmonized standard gives you only works once that standard is cited in the Official Journal of the European Union for the law in question. No standard is cited there under the Accessibility Act. V3.2.1 is cited, and it is cited for the Web Accessibility Directive, which is a different instrument covering public sector bodies.
What that means at the negotiating table
Nobody can hand you a document that proves conformance with the Accessibility Act, because the route that would produce one does not exist yet. A vendor offering you that is offering something the European standards system has not built. What they can give you is a current report against EN 301 549 V3.2.1 and a written commitment to reissue when version 4 publishes. Ask for the second part in the contract.
Below Level AAA, Untested and Passing Look Identical
The report has five conformance terms and one of them is fenced off. Not Evaluated means nobody checked, and the template says in as many words that it can only be used in Level AAA criteria.
Follow that through, because the consequence is bigger than it sounds. At Level A and Level AA, which are the levels every law and every contract names, there is no permitted way to say we did not get to this one. The template also requires an answer in every row. So the vendor has four options and all four of them assert a finding.
- Supports. At least one method meets the criterion with no known defects, or meets it by an equivalent route.
- Partially Supports. Some of the product does not meet it.
- Does Not Support. The majority of the product's functionality does not meet it. That is stricter than the everyday reading, and it is not the term for one broken control.
- Not Applicable. The criterion is not relevant to the product.
A row that was never opened has to be filled in as one of those four. So on any report you receive, a criterion nobody looked at is visually identical to a criterion somebody tested carefully and passed. There is no field that separates them, and no rule that says there has to be.
The one signal you do get is the Remarks column. The template asks for remarks that name the features with issues and say how they fall short, and a row that passed after real testing usually leaves a trace there. A page of one-word remarks across fifty-five rows is telling you something.
Nothing in the Report Says Which Pages Were Tested
The template lists what a report must contain at a minimum. The product name and version, a report date, a short product description, contact details, the evaluation methods used, the standards covered, the definitions of the terms, and the criteria tables.
Read that list for what is missing. There is no field for which pages, screens or user journeys were examined. A product description is a sentence about what the software does, not a statement of what was in front of the tester. So a report covering a 4,000-page application and a report covering its logged-out marketing site look the same on the page.
This is also, precisely, why an ACR is not a WCAG conformance claim. A claim under the standard has five required components, and one of them is a description of the web pages the claim is made for, including whether subdomains are in. Another is the list of web technologies relied upon. The template has a field for neither. An ACR does not become a conformance claim by being detailed, because the missing component is a different kind of thing from detail.
Ask for the scope in writing and you will usually get it. It is not a hostile question and most honest vendors have the answer sitting in their test notes.
Nothing Says Who Did the Testing, and Nobody Certifies It
There is no field naming the evaluator. No edition requires the tester to be independent of the vendor, or to hold any qualification, or to be named at all. The Evaluation Methods field is required, and what goes in it is unbounded, so evaluated with automated tooling satisfies the template.
The body that publishes the template is blunt about the rest. There is no VPAT certification. ITI does not review or approve reports, expects the product owner to complete their own, and says there is no conformance logo available. Any supplier offering you a certified VPAT is selling a thing that has never existed.
Which is not a reason to stop asking for one. It is a reason to read it as a supplier's statement about themselves, weigh it the way you would weigh any other supplier statement, and verify the parts you are relying on.
The Definitions Themselves Can Be Changed
This is the one almost nobody checks. The template supplies standard definitions for the five terms, and it also permits a vendor to deviate from them, so long as the change is noted in the report's own Notes section.
So the Terms block near the top of the report is not boilerplate. It is the key to every row underneath it, and it is the second thing to read after the date. A report where Supports has been quietly widened is a report where fifty-five green rows mean something other than what you assumed.
What the Biggest Buyer in the World Asks For Instead
The US federal government co-created this template and does not treat it as sufficient on its own, which is the most useful precedent available to you. Federal buyers are told to require two documents from every supplier, not one.
- The ACR itself, complete, or the offer is not considered for award.
- A Supplemental Accessibility Report, which carries what the ACR structurally cannot. A description of the evaluation methods sufficient to show due diligence, the features that help, how to install and configure the product accessibly, and a list of core functions that people with disabilities cannot use.
That last item is the one to steal. A written list of core functions a disabled user cannot perform is the single most valuable sentence you can extract from a supplier, and it is exactly the thing a page of Partially Supports rows leaves you to reconstruct.
Federal buyers are also advised to reserve, in the solicitation, the right to test the product themselves before making an award. That is not how anybody treats a certificate. It is how you treat a claim.
Six Things to Ask Before You Sign
Six short questions, and none of them is hostile. Send them as a list and a supplier who is doing the work will answer all six in an afternoon.
- Which standard and which version. Get the answer in the contract, not in an email. If the answer is EN 301 549, the version number is the whole answer.
- Which pages, screens and journeys were tested. In writing, as a list.
- Who tested, and were they independent of the product team.
- What are the core functions a disabled user cannot complete today. Ask for it in the supplier's own words.
- Read the Terms block and check the five definitions match the template's.
- When will the report be reissued. Tie it to your renewal date and to any version 4 publication, and write that into the agreement.
A supplier who cannot answer the second one has told you the report was produced without a defined scope, which is the answer you needed anyway.
One honest limit
None of this makes an ACR worthless, and we produce them ourselves. A dated report with real remarks from a supplier who tested properly is far better evidence than nothing, and it is the only accessibility document most procurement processes will ever see. The point is to read it as what it is. A statement made by an interested party, in a format that has no space for the four things you most want to know.