Section 508 · Procurement · 2026

The 2026 Section 508 Guide for Vendors Selling to US Government

An oxblood and cream editorial illustration of a procurement folder stamped with a checklist, evoking a federal contract review.
  • Section 508
  • Procurement
  • 2026

A software vendor spent eight months chasing a federal contract. They beat three competitors on price. Their product had the features the agency wanted. Then, during final contract review, a contracting officer sent one email: "Please provide your completed VPAT/ACR for this solution."

The vendor's sales team had never heard the term. Nobody on staff knew what it meant, who was supposed to fill it out, or why it was suddenly standing between them and a signed contract. The deal that had felt closed for weeks was now on hold, and the clock was ticking toward a deadline nobody had planned for.

This happens more often than most vendors expect, and it happens late, when there is the least room to fix it.

The Stat: Federal agencies are required under Section 508 to evaluate ICT purchases using a VPAT/ACR before procurement. (Source: Section508.gov)

Government Procurement Lifecycle for Section 508 A four-step horizontal flow: RFP published with 508 clause included, vendor submits VPAT or ACR, agency evaluates against the ICT Testing Baseline, then contract is awarded or the vendor is disqualified. The third step includes a callout noting it is where vendors first face real technical scrutiny. RFP published (508 clause included) Vendor submits VPAT/ACR Agency evaluates against ICT Testing Baseline Real technical scrutiny usually starts here Contract awarded or vendor disqualified

Where the VPAT actually enters the process

Most vendors treat accessibility as a technical afterthought, something the engineering team handles if a customer ever complains. In federal sales, that order is reversed. Accessibility enters the deal on page one of the solicitation, buried in a clause referencing Section 508 of the Rehabilitation Act, long before anyone talks about pricing or delivery timelines.

That clause exists because federal agencies are legally required to evaluate ICT (information and communications technology) purchases against Section 508 standards before they buy. The VPAT, or Voluntary Product Accessibility Template, is the document vendors use to make that evaluation possible. Once a vendor fills it out and signs it, it becomes an ACR, an Accessibility Conformance Report, the agency's actual evidence file.

If your sales team has never flagged this clause during RFP review, you already have a process gap. The fix is not a legal team, it is a habit: someone reads every solicitation for the 508 language on day one, not the week before award.

Think about how most sales cycles actually run. A solicitation lands, the capture team scans it for scope, budget ceiling, and deadline, and the accessibility clause gets skimmed past because it reads like boilerplate. It is not boilerplate. It is the checkpoint that decides whether your technical claims get scrutinized before or after you have already invested months of proposal work. Catching it early costs you almost nothing. Catching it late costs you a contracting officer's trust at the exact moment you need it most.

Filling out the VPAT honestly, not optimistically

Here is where deals actually start to wobble. A VPAT has a column for every accessibility criterion, and the vendor has to mark it "Supports," "Partially Supports," "Does Not Support," or "Not Applicable." The temptation, especially under deadline pressure, is to mark everything "Supports" and hope nobody checks.

Agencies check. That is the entire point of the ICT Testing Baseline, and marking a criterion as fully supported when it is not is the single fastest way to turn a completed VPAT into a liability instead of an asset.

A better approach:

  • Test before you claim. Run your product through actual assistive technology (screen readers, keyboard-only navigation, voice control) before writing a single "Supports" in the document.
  • Use "Partially Supports" honestly, and pair it with a remediation note describing what is missing and when you expect to close the gap. Agencies see partial conformance constantly. What they do not tolerate well is a partial claim dressed up as a full one.
  • Keep your evidence. Screenshots, test scripts, and internal notes from your own testing process matter if an agency's evaluators ask follow-up questions.
  • Assign one owner. Someone on your team, not a rotating cast of whoever is free that week, should own the VPAT end to end. Consistency in how criteria get tested and described matters more than most vendors assume, especially when an agency comes back with clarifying questions months after submission.

None of this needs to be expensive or slow. It needs to be deliberate. A VPAT that took real testing time to produce reads differently to an experienced evaluator than one that was clearly filled out from a template in an afternoon, and evaluators who review these documents regularly can usually tell the difference.

For the specific standards your product needs to meet criterion by criterion, our companion piece on what vendors actually have to meet under Section 508 walks through the technical requirements in detail. This article is about the process around that document, not the standards themselves.

How agencies verify your claims: the ICT Testing Baseline

A VPAT is a claim. The GSA's ICT Testing Baseline is how agencies check the claim against reality. It is a published set of test procedures that federal evaluators use to independently verify accessibility conformance, rather than taking a vendor's self-reported VPAT at face value.

This is the moment in the lifecycle where vendors get the most real technical scrutiny, and it is also where most vendors are least prepared, because they treated the VPAT as a one-time form to submit rather than a claim they need to be able to defend.

Practically, that means:

  1. Assume someone will retest your top claims. Evaluators do not retest every line item, but they commonly spot-check the criteria most relevant to the agency's use case.
  2. Know your own gaps before they do. If your VPAT says "Partially Supports" somewhere, be ready to explain exactly what that means in practice and what your remediation plan looks like.
  3. Treat your VPAT as a living document. A VPAT completed a year before a bid, without re-testing against the current version of your product, is a red flag to an evaluator who compares dates.

The Testing Baseline exists precisely because self-reported claims, on their own, are not enough for agencies to rely on when they are making a purchasing decision that has to hold up to audit later. Vendors who understand this stop treating the VPAT as paperwork and start treating it as the first round of due diligence in a process that will continue, in some form, for as long as the contract runs.

If you have not yet written a formal accessibility statement or VPAT internally, our guide to building an accessibility statement and VPAT is a useful starting point before you get into an active procurement.

What happens after award if remediation is required

Winning the contract is not the finish line. Many federal contracts include ongoing accessibility obligations, and if post-award testing or a user complaint surfaces a real gap, the contract itself often specifies what happens next: a remediation timeline, required status updates, and in some cases, financial or performance consequences if the vendor does not close the gap on schedule.

This is where the honest-VPAT approach pays off twice. A vendor who disclosed a partial support gap up front, with a credible remediation plan, is negotiating from a position of trust. A vendor who claimed full support and got caught later is negotiating from a position of damage control, often with a contracting officer who now questions every other claim in the document.

Two resources worth bookmarking directly from the source: Section508.gov's guidance for vendors walks through the seller-side expectations in plain language, and the U.S. Access Board's ICT standards page is the authoritative reference for the underlying technical requirements referenced throughout this process.

Building the habit before your next RFP

None of this is complicated once it is a process rather than a scramble. The vendors who handle Section 508 well are not necessarily the ones with the most polished product. They are the ones who caught the 508 clause on page one, tested honestly instead of optimistically, and treated the VPAT as a document they could defend rather than a form they needed to survive.

If your team is heading into a federal RFP and has not been through this process before, it is worth getting a second set of eyes on your VPAT before a contracting officer's evaluators do. You can start with a free accessibility audit to see where your current claims might not hold up under the ICT Testing Baseline.

Have a specific RFP deadline or a VPAT you are not confident in? Reach out to our team directly at experts@wcag.world, or get started with a free audit before your next submission is due.