Legal & Compliance

What Is a VPAT? Voluntary Product Accessibility Templates Explained

A VPAT (Voluntary Product Accessibility Template) is a standardized document format in which a vendor reports how their product or service conforms to recognized accessibility standards — WCAG, Section 508, and EN 301 549 — one success criterion at a time. It originated as a Section 508 procurement tool for federal government purchasing, and has since become a common due-diligence document requested well beyond federal contexts, including by enterprise customers doing their own vendor accessibility review.

The current version and its scope

VPAT 2.5 is the current template, published by the IT Industry Council (ITI). It comes in edition variants depending on which standards the reporting organization wants to cover — a "VPAT 2.5 INT" (International) edition covers WCAG, Section 508, and EN 301 549 together in one document, which is why it's the most commonly requested edition for vendors selling across US and EU markets simultaneously.

What's actually inside one

A VPAT is structured as a large table, one row per applicable success criterion, with columns for:

  • The criterion itself (e.g., "1.4.3 Contrast (Minimum) — Level AA")
  • Conformance level, one of five defined values (see below)
  • Remarks and explanations — specific notes on what was tested, what wasn't, and any known limitations

The five conformance-level values

LevelMeaning
SupportsNo violations found for this criterion
Partially SupportsSome violations found, but not universally across all pages/instances
Does Not SupportSignificant violations found for this criterion
Not ApplicableThe criterion doesn't apply to this product (e.g., video-related criteria for a product with no video content)
Not EvaluatedThe criterion requires manual testing that hasn't been performed

Why an automatically-generated VPAT should always say "DRAFT"

This is a genuinely important point: a VPAT generated from automated scanning alone can only speak reliably to the criteria that are actually automatable — roughly a third of the full WCAG spec (see the testability breakdown in Automated vs Manual Testing). The remainder genuinely requires human expert review to assess accurately. The FTC's 2023 enforcement action against accessiBe (over misleading claims that an automated overlay tool could deliver full compliance) is widely cited industry precedent for why any VPAT generated primarily from automated scanning should be explicitly labeled DRAFT, with a clear methodology disclosure — never presented as a final, audited compliance certification.

What a VPAT is not

A VPAT is not itself a legal certification of compliance, and it's not legally binding proof that a product satisfies any particular law — it's a standardized disclosure document, meant to give a purchaser or auditor a structured, comparable way to understand a vendor's accessibility posture, gaps included. A VPAT that reports several "Does Not Support" entries honestly is more useful (and more defensible) to everyone involved than one that inflates its own conformance claims.

Common questions

What is a VPAT?
A Voluntary Product Accessibility Template — a standardized document in which a vendor reports how their product conforms to accessibility standards like WCAG, Section 508, and EN 301 549, one success criterion at a time.
What are the VPAT conformance levels?
Five values are used per criterion: Supports, Partially Supports, Does Not Support, Not Applicable, and Not Evaluated.
Why should an automatically generated VPAT say DRAFT?
Automated scanning reliably covers only about a third of WCAG; the rest needs human expert review. Following the FTC's accessiBe precedent, an automated VPAT should be labeled DRAFT and never presented as a final audited certification.

Want to see how your own site scores?

Run a free accessibility scan