Skip to main content
WCAGrules
Quick navigation

Free tools · Checker

VPAT and ACR review checklist

A supplier sent you a conformance report and almost every row says Supports. This is the buyer's read: nine questions about the document's own rules, answered with the report open beside you, and a list of what to send back. Nothing is uploaded and nothing leaves your browser.

1 of 9Which edition of the template does the report name?

The edition decides which version of WCAG the report answers to. WCAG 2.0 sits in the Section 508 edition, WCAG 2.1 in the EU edition, and only the WCAG and INT editions reach WCAG 2.2.

2 of 9Does it state the template version and date?

The template is required to carry its own version. The current one is VPAT 2.5Rev, published April 2025.

3 of 9Does it name the version of the product it is about?

The template asks for a version identifier where one is available, so a report can legitimately arrive without one. You still need to know which build you are being told about.

4 of 9Has the product had a release that touched the interface since the report date?

There is no expiry anywhere in the template and nothing sets a refresh interval, so age alone answers nothing. What ages is the product, not the document.

5 of 9Does the evaluation methods section say what was actually done?

It is a required field, but its content is a menu. The template offers a list to choose from and marks naming the assistive technologies and the tools as optional in each case, so a single sentence naming a proprietary process satisfies the field.

6 of 9Does the phrase Not Evaluated appear outside the Level AAA section?

The template restricts that term to Level AAA criteria, in a sentence printed next to its own definition. At Levels A and AA every available answer asserts a finding.

7 of 9Do the rows that are not a clean pass say which features have the issue and how?

The template's guidance for those rows asks the remarks to identify the functions or features with issues and how they do not fully support the criterion. The verb is should rather than must, so a thin remark is a question to ask rather than a rule broken.

8 of 9Does the report say which parts of the product were covered?

The template has no field for it. Not a thin field, no field: no pages, no screens, no flows anywhere in the required content. So the answer is usually no, and that is a property of the form rather than a failing of the vendor.

9 of 9Did anything arrive alongside the report explaining how it was produced and which core functions cannot be used?

US federal buyers require a second document for every off-the-shelf item, carrying the evaluation methods, the features that help, and the core functions that disabled people cannot use at all.

Questions to send back

Nothing answered yet. Work down the questions on the left with the report open beside you, and the ones worth asking the vendor appear here.

Three things that are true of every report

  • Nobody certifies these. ITI publishes the template, does not review or approve completed reports, and says outright that there is no VPAT certification.
  • Nothing expires. No edition contains an expiry and no guidance sets a refresh interval. Ask what shipped since the report date instead.
  • The words may not mean what you think. A vendor may change the ITI definitions of Supports and the rest, and the only obligation is to say so in the notes section. Which is why counting rows is not a comparison.

This is the buyer's route. If you are the one writing a report rather than reading one, what a VPAT is and who needs one is the page you want.

What it checks

  • Which edition, and so which WCAG version

    WCAG 2.0 sits in the Section 508 edition, WCAG 2.1 in the EU edition, and only the WCAG and INT editions reach WCAG 2.2. A report cannot answer a question about a version its edition does not contain.

  • Whether Not Evaluated appears where it should not

    The template restricts that term to Level AAA. At A and AA every available answer asserts a finding, so an untested criterion and a tested, passing one look identical on the page.

  • Whether the methods section says anything

    It is a required field whose content is a menu, and naming the tools and assistive technologies is optional in each case. A single sentence naming a proprietary process satisfies it.

  • Whether the failing rows explain themselves

    The template asks those remarks to identify the features with issues and how they fall short. The verb is should, so a thin remark is a question to ask rather than a rule broken, and the checklist says which it is.

  • What is missing by design

    No scope of pages or flows, no evaluator named, no independence requirement, no expiry. Those absences are properties of the form, not failings of the vendor, and the questions follow from them.

What it cannot tell you

  • Whether the report is accurate. It never sees the document, only your answers about it. Its all-clear line says no question was raised by the answers you gave, and that is all it means.
  • Whether one vendor is better than another. There is no score here and there will not be, because a vendor may change the ITI definitions and disclose the change in a notes field, which makes counting rows a comparison of two different vocabularies.
  • Whether a report has expired. Nothing in any edition sets an expiry and no guidance sets a refresh interval, so the checklist asks what shipped since instead, which is a question about the product.
  • Whether the product suits you. That is answered by somebody exercising the journeys your people use, which is what the report is a preliminary substitute for. Preliminary is the template's own word.

Where to go next

Go somewhere useful

Find tools, resources and your workspace.

29 destinations