Technology

How to Read a VPAT

A VPAT is the document vendors send when you ask whether their product is accessible. Most of the useful information is in the column buyers skip.

You asked a vendor whether their platform is accessible. They sent back a thirty-page document called a VPAT with a lot of rows marked "Supports." Now what?

What the document actually is

A VPAT — Voluntary Product Accessibility Template — is a form. Filled in, it produces an Accessibility Conformance Report: a criterion-by-criterion statement of how a product measures against a standard.

Two things follow from "voluntary." Nobody audits these. The vendor writes it themselves, and the quality ranges from rigorous third-party evaluation to a sales engineer filling in a template in an afternoon.

But it isn't nothing. A VPAT is a representation about the product, and in a contract, representations have weight.

The four conformance levels

Every row gets one of four values:

  • Supports — meets the criterion.
  • Partially Supports — some functionality doesn't.
  • Does Not Support — the majority doesn't.
  • Not Applicable — the criterion doesn't apply to this product.

An honest report has a mix. A report where every row says "Supports" is the single strongest signal that no real testing happened. Complex software conforms to everything only rarely, and vendors who actually test know that.

Read the remarks column

This is the entire game, and it's the column most buyers skip.

"Supports" with a blank remarks column tells you nothing about how it was determined. "Partially Supports" with a remark reading "the date picker in the reporting module is not keyboard operable; fix targeted for the Q3 release" tells you the vendor tested, knows their product, and is being straight with you.

Counterintuitively, a report with more honest "Partially Supports" rows and specific remarks is usually from a more accessible product than one claiming universal support. The vendor who found their own problems is the vendor who looked.

Five things to check before you trust it

  1. Which product version? A VPAT for version 4 says nothing about the version 11 you're buying.
  2. When was it tested? An undated report, or one more than a year or two old, is a historical document.
  3. Which standard and edition? WCAG 2.0 or 2.1? Which level? Does it cover Section 508, EN 301 549, or both? If your obligation is WCAG 2.1 AA, a 2.0 report leaves a gap.
  4. What was the methodology? Real reports name the assistive technologies and platforms used. "Internal review" is not a methodology.
  5. Who wrote it? Third-party evaluation is stronger than self-assessment. Either is stronger than an unsigned document.

What to do with what you find

Gaps aren't automatically disqualifying. What matters is whether the vendor has a credible plan and whether the gaps sit on the paths your users depend on.

A failure in an admin-only reporting screen is a different risk than a failure in the flow where residents submit an application. Map the findings to your actual use, not to the row count.

Then put it in the contract. Accessibility representations, a right to test independently before acceptance, a remediation timeline for known gaps, and a remedy if the claims turn out to be inaccurate. A VPAT referenced in a contract is leverage. A VPAT in a folder is paperwork.

The part buyers forget

Under ADA Title II, the services you deliver through a vendor's platform are still your obligation. The VPAT doesn't transfer responsibility — it informs your decision and gives you something to hold the vendor to.

Which is exactly why the honest report from the vendor who tested is worth more than the clean one from the vendor who didn't.

Want help applying this?

We turn ideas like this into a roadmap for your organization.