Procurement guide

VPAT and ACR explained: versions, editions, conformance levels, and how to read one before you buy

What a VPAT is, what an Accessibility Conformance Report is, the current VPAT 2.5 template and its four editions, the conformance levels, why an ACR is not a certification, and the questions to ask when a vendor sends one.

Updated September 2, 2026. Reviewed by the DocAccessible team under our editorial policy.

Any organisation that buys software for a public body, a university, or a health system will be asked for a VPAT, and any vendor selling to them will be asked to produce one. The document is widely required and widely misunderstood: it is not a certificate, it comes in several editions, and its most useful content is in the column people skip. This guide explains the template, the report, and how to read one, and it says where DocAccessible's own evaluation stands.

VPAT versus ACR

The Voluntary Product Accessibility Template is a free template published by the Information Technology Industry Council. ITI's own description is that it is a blank form: a structured list of accessibility criteria with empty columns. A version of the VPAT that has been completed for a specific product is an Accessibility Conformance Report, or ACR. "VPAT" and "report form" are ITI registered service marks, and ITI asks that the name and form not be altered and that the registered mark be shown. In everyday procurement, "send us your VPAT" means "send us your ACR", and a vendor who sends the blank template has misunderstood the request.

The current template and its editions

As of the review date, the current template is VPAT 2.5Rev, dated April 2025. It comes in four editions, chosen according to the standards the buyer's market requires:

VPAT 2.5 editions and the standards each reports against, per ITI.
EditionStandards coveredTypical buyer
VPAT 2.5 508Revised Section 508 Standards, the U.S. federal accessibility standardU.S. federal agencies and organisations that follow federal procurement rules
VPAT 2.5 EUEN 301 549, the EU's accessibility requirements suitable for public procurement of ICT products and services (which incorporates WCAG 2.1)European public sector and EU-regulated buyers
VPAT 2.5 WCAGWCAG 2.0 (ISO/IEC 40500), WCAG 2.1, and WCAG 2.2Buyers whose policy names WCAG directly, including many universities and U.S. state and local governments
VPAT 2.5 INTAll three of the aboveVendors selling into several markets

Conformance levels

For each criterion the vendor declares one of four conformance levels: Supports, Partially Supports, Does Not Support, or Not Applicable. Version 2.5 also includes a remarks and explanations column for each criterion, and it is there that the report earns its keep: "Partially Supports" with a remark that names the affected feature and the workaround tells a buyer something; "Partially Supports" with an empty remark tells them nothing. ITI's rules for completing the template require the vendor to explain each rating, to test rather than assume, and to report the product version and evaluation methods used.

How to read one

  1. Check the template version and edition. A report on VPAT 1.x or 2.0 is old; a WCAG edition that stops at WCAG 2.0 may predate criteria the buyer's policy requires.
  2. Check the product name, version, and date. An ACR describes one version of one product on one date. Software changes; a two-year-old report may describe a product that no longer exists.
  3. Read the evaluation methods. Automated testing alone, manual testing with named assistive technology, or a third-party audit produce very different reports. Section508.gov's guidance on creating an ACR expects the methods to be stated.
  4. Read every remark, especially on Level A and AA criteria. Look for the criteria that matter to your users: keyboard access, name-role-value, focus order, contrast, error identification, and status messages.
  5. Treat "Supports" as a claim, not a finding. ITI publishes the template; it does not review or certify the conclusions. A completed ACR is the vendor's report of the vendor's testing.
  6. Ask for the evidence. Test records, the audit report behind a third-party ACR, and a roadmap with dates for "Partially Supports" items.

What a VPAT is not for

A VPAT describes a product or service: software, a platform, a website, hardware. It does not describe an individual document, and a vendor asked for "a VPAT for this PDF" cannot sensibly provide one. The evidence for a document is a test record against a defined set of checks, such as the U.S. federal ICT Testing Baseline for Electronic Documents, a PDF/UA validator report, and the manual checks in the 15-point checklist. For document remediation services, ask instead for the vendor's method, a sample of the evidence they deliver with each file, and the ACR for any software portal you will use.

DocAccessible's own evaluation

DocAccessible publishes its product accessibility evaluation on the accessibility conformance report page and its accessibility statement. The evaluation describes scope, method, and documented support statements against WCAG 2.2 AA as a target, states what has and has not been manually verified with assistive technology, and does not claim full conformance or present a signed third-party ACR, because neither has been completed. That is the level of candour a buyer should expect from any vendor, and it is the standard the editorial policy holds the rest of this site to.

Frequently asked questions

What is the difference between a VPAT and an ACR?

A VPAT (Voluntary Product Accessibility Template) is the blank template published by the Information Technology Industry Council, with a structured list of accessibility criteria and empty columns. An ACR (Accessibility Conformance Report) is a VPAT completed for a specific product version, recording a conformance level and remarks for each criterion. When a buyer asks for a VPAT they almost always mean the completed ACR.

What are the VPAT 2.5 editions?

VPAT 2.5, currently at revision 2.5Rev dated April 2025, comes in four editions: 508 for the Revised Section 508 Standards, EU for EN 301 549, WCAG for WCAG 2.0, 2.1, and 2.2, and INT, which incorporates all three. Vendors choose the edition matching the standards their buyers require; the INT edition covers several markets at once.

Is a VPAT a certification?

No. A completed ACR is the vendor's report of its own testing, using one of four conformance levels (Supports, Partially Supports, Does Not Support, Not Applicable) with remarks. ITI publishes the template but does not review or certify the conclusions. Buyers should check the template version, product version, date, and evaluation methods, read the remarks, and ask for the underlying test evidence.

Sources

The statements above rest on the primary sources below. Where a source is a law or standard, the version and date named in the text are the ones checked on the review date. This guide is general information, not legal advice.

  1. ITI: VPAT (Voluntary Product Accessibility Template) . The current version 2.5Rev (April 2025), the four editions and their standards, the conformance levels, the definition of an ACR, and the trademark requirements.
  2. Section508.gov: How to Create an Accessibility Conformance Report Using a VPAT
  3. U.S. Access Board: ICT Testing Baseline for Electronic Documents . The document-level evidence that stands in for a VPAT where documents rather than products are being procured.

Keep reading