
Provides accessibility audits and VPAT documentation services.
levelaccess.com
A Practical Guide for Buyers and Risk Teams
If you are buying or selling software, you may be asked for a VPAT. This is common in sectors such as government, higher education, and regulated organizations, for example, but the requirement is not limited to these areas.
Most people encountering the term for the first time are unsure what it means, what it proves, or how seriously to treat it.
A VPAT is a structured document used by software vendors to describe how their product aligns with recognised accessibility standards. It supports procurement and risk review. It is not a certificate. It is not proof of legal compliance. It is a disclosure statement.
Understanding how to read one properly can reduce procurement risk and prevent false assurance.
A VPAT tells you what the vendor says about their product. An independent audit tells you what is actually there.
VPAT stands for Voluntary Product Accessibility Template.
It is a reporting template created by the Information Technology Industry Council to standardise how vendors describe accessibility conformance.
A completed VPAT:
Most VPATs are structured against recognised accessibility standards such as:
Web Content Accessibility Guidelines. The international standard for making web content accessible to people with disabilities.
US federal accessibility standard requiring electronic and information technology to be accessible to people with disabilities.
European standard for accessibility requirements for ICT products and services used in public procurement.
The selected edition depends on the regulatory environment of the buyer. The VPAT allows procurement teams to compare vendors using a consistent framework.
A VPAT is often misunderstood. It is not any of the following.
A certification
A legal compliance guarantee
An independent audit, unless explicitly stated
A permanent assurance
Most VPATs are self-declared by vendors. That means the claims are made by the supplier, not independently verified. If a VPAT is inaccurate or outdated, the purchasing organization may inherit risk. It reflects the product at a specific point in time.
VPATs are commonly requested in:
Government agencies must demonstrate due diligence when procuring accessible ICT.
Universities frequently require VPATs before adopting learning platforms or digital services.
Large enterprises use VPATs to support governance, supplier risk assessment, and audit trails.
A VPAT helps answer a core procurement question: Is this vendor aware of accessibility obligations, and have they documented their position clearly?
Publicly available examples from well-known software providers. When reviewing examples, note how detailed remarks are provided under each criterion. Strong VPATs are specific, structured, and current.
Provided for illustration only.

Accessibility Conformance Reports
Detailed per-product VPATs covering Office 365, Azure, Windows, and other Microsoft services.

Accessibility Conformance Reports
Platform-level conformance documentation for Salesforce CRM and related cloud products.

Accessibility Conformance Reports
Product-specific VPATs for Creative Cloud, Acrobat, Experience Cloud, and Document Cloud.
Manual review of a VPAT can be time-consuming and inconsistent. AI tools such as ChatGPT can help identify potential red flags quickly.
AI cannot replace an accessibility audit. It can:
This approach supports structured internal review before escalation to technical teams.
You are acting as a procurement risk reviewer. Review the following VPAT text and provide a structured risk analysis. Tasks: Identify any instances of vague language such as "partially supported," "supports with exceptions," or generic statements without detailed remarks. Flag criteria marked as "Supports with Exceptions" and summarise the nature of the exception. Identify any missing remarks or incomplete sections. Confirm which WCAG version is referenced and flag if outdated. Identify any contradictory claims within the document. Note whether testing methodology or assistive technology testing is described. Highlight areas that may create procurement or legal risk. Provide a plain-language executive summary of overall accessibility risk exposure. Output structure: • Section 1: Key Red Flags • Section 2: Documentation Gaps • Section 3: Standards Currency • Section 4: Risk Implications • Section 5: Executive Summary (under 150 words) Here is the VPAT text: [PASTE VPAT CONTENT HERE] - or upload readable PDF
AI review is a screening tool. It does not replace formal accessibility validation.
When reviewing a VPAT, pay attention to these indicators.
Frequent "Supports with Exceptions" without detailed explanation
Generic remarks such as "Partially supported" without specifics
Missing dates or version numbers
Reference to outdated WCAG versions
No description of testing methodology
No mention of assistive technology testing
Weak documentation increases procurement uncertainty.
Practical answers on what VPATs are, how they work, and what to watch for.
Voluntary Product Accessibility Template. It is a standardized document format created by the Information Technology Industry Council (ITI) for vendors to report how their products conform to accessibility standards.
The vendor or manufacturer of the product. A VPAT is a self-reported document. The vendor assesses their own product against the relevant accessibility standards and records the results. This is why independent auditing of VPATs matters.
For federal procurement, yes. Section 508 of the Rehabilitation Act requires federal agencies to evaluate VPATs when purchasing technology. For private sector and state/local government, VPATs are not legally mandated but are increasingly requested as part of procurement due diligence.
An Accessibility Conformance Report (ACR) is the completed version of a VPAT. The VPAT is the blank template; the ACR is the filled-in document. In practice, people often use 'VPAT' to refer to both the template and the completed report.
A VPAT should be updated with each major product release or at least annually. An outdated VPAT does not reflect the current state of the product and should not be relied upon for procurement decisions.
Not without verification. VPATs are self-reported by vendors. There is no certification body that validates them. The quality and accuracy vary widely. Some vendors overstate conformance, omit known issues, or use vague language. Independent auditing of vendor VPATs is a recommended practice.
A VPAT is a disclosure tool, not a guarantee. It is useful when:
Procurement confidence depends not just on receiving a VPAT, but on reviewing it critically.
Many organisations engage specialist firms to produce or independently audit VPATs.
These firms may provide testing, documentation support, or independent verification.

Provides accessibility audits and VPAT documentation services.

Offers WCAG testing and VPAT preparation support.

Delivers accessibility assessments and conformance reporting.

Provides VPAT assessments and accessibility consulting services.

Offers accessibility audits and VPAT preparation services.
All trademarks, service marks, and logos displayed on this page are the property of their respective owners. Their use does not imply any affiliation with, endorsement by, sponsorship by, or contractual relationship with AAAtraq. All rights remain with the respective owners.
References to third-party products, services, organizations, or published documents are provided for informational purposes only and do not constitute endorsement or recommendation. AAAtraq has no commercial or contractual relationship with any of the firms, vendors, or organizations named on this page unless explicitly stated.
Example VPATs and conformance reports linked from this page are publicly available documents maintained by their respective publishers. AAAtraq is not responsible for the accuracy, currency, or completeness of third-party content.
The information on this page does not constitute legal advice. Organizations should consult qualified professionals regarding their specific accessibility and procurement obligations.