A VPAT is the blank template; an ACR is the finished report. The Voluntary Product Accessibility Template is a free form published by the Information Technology Industry Council (ITI), and once you fill it out with test results for your product, it becomes an Accessibility Conformance Report — ITI’s own words: “a version of the VPAT which has been completed for a specific product is an ACR.” So when a procurement team asks for “your VPAT,” they are not asking for the empty form. They want the completed, credible ACR.

If you’re a SaaS founder or vendor who just hit this request in an enterprise or government deal, here’s what to actually deliver — and how reviewers will judge it.

Why did the buyer ask for a “VPAT”?

Because “VPAT” has become shorthand for the report itself. As accessibility firm Level Access notes, “buyers may ask for a ‘VPAT’ as part of an RFP, but what they really need is an ACR — one that clearly reflects how the product measures up to accessibility requirements” (Level Access, Aug 2025). The terms get used interchangeably in RFPs, security questionnaires, and vendor portals. Don’t correct the buyer — just send the finished document.

The request isn’t optional politeness, either. For U.S. federal sales, Section508.gov’s ACR/VPAT FAQ is blunt: while the template is technically voluntary, “it is not voluntary to complete an ACR if you wish the government to consider purchasing your product.” Agencies use ACRs to evaluate a product’s accessibility and to compare competing vendors. State agencies, universities, hospital systems, and Fortune 500 legal teams have copied the same requirement into their own purchasing rules — which is why the ask now reaches SaaS companies that have never sold to a government in their lives.

Underneath the paperwork sits a real legal standard. Federal buyers answer to Section 508; most private-sector requests trace back to WCAG. If you’re fuzzy on how those relate, our plain-English breakdown of ADA vs Section 508 vs WCAG covers who enforces what.

Which VPAT 2.5 edition do you need?

The current template is VPAT 2.5Rev, released in April 2025, and it comes in four editions (ITI). Picking the wrong one is a common first-timer mistake: a WCAG-only ACR sent to a federal buyer is missing required Section 508 chapters, and reviewers will send it back.

EditionStandards coveredWho asks for itPick it when
VPAT 2.5 508Revised Section 508 (U.S. federal standard)U.S. federal agencies and their contractorsYour pipeline is federal-only
VPAT 2.5 WCAGWCAG 2.0, 2.1, 2.2 (ISO/IEC 40500)U.S. enterprises, universities, healthcareBuyers cite WCAG, not a law
VPAT 2.5 EUEN 301 549 (EU public procurement standard)European public-sector buyersYou sell only into the EU
VPAT 2.5 INTAll three of the aboveGlobal enterprises, mixed pipelinesYou want one document for every deal
Honest verdictMost SaaS vendors should do the INT edition once, properly tested, rather than juggle three thinner documents. The extra tables cost little if the testing is already done.

The template is free to download from ITI, no membership required — but the VPAT name is a registered service mark and the form “should not be altered without the express written permission of ITI” (ITI). Don’t delete rows you find inconvenient. Reviewers know the template by heart.

One more note on the EU edition: EN 301 549 is the same standard behind the European Accessibility Act, so U.S. SaaS companies with European customers increasingly get this request from private buyers too. We cover that shift in our guide to the European Accessibility Act for US businesses.

What do “Supports” and “Partially Supports” actually mean?

Every row of an ACR grades one WCAG success criterion or 508 requirement using fixed conformance terms with precise definitions, published in Section508.gov’s authoring guidance:

  • Supports — the functionality “meets the criterion without known defects or meets with equivalent facilitation.”
  • Partially Supports — “some functionality of the product does not meet the criterion.”
  • Does Not Support — “the majority of product functionality does not meet the criterion.”
  • Not Applicable — the criterion isn’t relevant to the product (your web app has no live video, say).
  • Not Evaluated — allowed only for the optional Level AAA tables.

Here’s the part first-timers get backwards: a wall of “Supports” does not win the deal, and a scattering of “Partially Supports” does not automatically lose it. Buyer-side reviewers are trained to read the remarks. McGraw Hill’s guide for higher-ed procurement reviewers says “Partially Supports” entries require examining the detailed explanations to judge how severe the impact really is — while “Does Not Support” ratings signal “significant barriers for users with disabilities” and get the hardest scrutiny (McGraw Hill, Mar 2026).

In scoring terms: “Partially Supports” with a specific, dated remark and a fix timeline reads as a competent vendor managing known issues. “Supports” everywhere with empty remarks reads as a vendor who never tested. Guess which one procurement escalates to legal.

What red flags do procurement reviewers look for?

Reviewers see hundreds of these documents, and they screen for the same tells. Before you submit, check your ACR against this list:

  1. An outdated template. Submitting VPAT 2.2 in 2026 says nobody has looked at accessibility in years. Download the current 2.5Rev edition from ITI every time.
  2. No testing methodology. The title page asks what evaluation methods you used. Reviewers question reports that relied only on automated tools without “manual accessibility testing and native user testing” (McGraw Hill). Automated scanners catch only a fraction of WCAG failures — we’ve documented what automated scans miss.
  3. Vague or empty remarks. Section508.gov’s quality checklist tells authors to “explain further in the respective remarks column” for every “Partially Supports” and “Does Not Support” entry (Section508.gov). “Some issues may exist” is not a remark; “date-picker component is not keyboard operable; fix scheduled for Q3 release” is.
  4. Blank title-page fields. All seven fields — product version, report date, evaluation methods, contact, and so on — must be filled in. A missing report date is the fastest credibility killer, because ACRs go stale.
  5. A report older than your product. Section508.gov notes that “every time your product is changed or updated (e.g. version change, bug fix, etc.), an updated ACR may be required” (FAQ). An ACR describing a version you shipped past two years ago describes a product that no longer exists.
  6. An inaccessible PDF. The final checklist item in the federal guidance: the document itself must be tested for accessibility. An ACR that fails a screen reader is its own counterargument.

Why does a self-graded VPAT without testing backfire?

Because the document is a factual claim, and the person reading it is paid to doubt you. The McGraw Hill reviewers’ guide frames self-assessment with a pointed analogy: “is it as credible if your student grades their own exam as it is if you grade it?” — and states flatly that “testing and reporting by a third-party adds credibility to the report” (McGraw Hill).

The failure mode isn’t just a lost deal. An ACR is often attached to the contract. If you graded twenty criteria “Supports” without testing, and the buyer’s own tester — or a user with a disability — finds keyboard traps and unlabeled forms in week one, you now have a document in the file that misrepresented the product. That conversation moves from the sales team to the lawyers. Honest “Partially Supports” entries never do that.

Real testing means a human working through your product with a keyboard and a screen reader against each criterion — the same manual accessibility testing that underpins any defensible compliance claim. The template is free; the credibility comes entirely from what you put in it.

What should you actually send?

Here’s the short version of a submission that survives review:

  1. Pick the right edition — INT if your pipeline is mixed, 508 for federal-only, WCAG for standards-based enterprise asks.
  2. Test first, grade second. Run a real audit — manual plus automated — so every conformance rating traces to evidence. An accessibility audit produces exactly the criterion-by-criterion findings an ACR needs.
  3. Write remarks a stranger can act on. Name the component, the barrier, and the plan.
  4. Date it, version it, and calendar the refresh for your next major release.

If you want to see the document’s structure before committing to anything, our free VPAT generator walks you through the sections and produces a working draft you can build on.

And if the RFP deadline is real and you need the testing behind the paper, that’s the exact gap our VPAT / ACR service covers: manual WCAG testing of your product, honest conformance ratings, and a finished ACR that reads like it came from a vendor who knows what’s in their own product — because you will.