Skip to main content
Simkins and Elgazar

How to Read an Accessibility Conformance Report (ACR)

Ahmed Elgazar, Simkins & Elgazar
ACRVPATSection 508Federal Procurement

When a federal agency or prime contractor requests an Accessibility Conformance Report, they are asking for structured evidence that a digital product meets Section 508 requirements. But an ACR is only as useful as your ability to read it critically.

Many procurement decisions are made by contracting officers, program managers, or technical leads who receive a VPAT document and have limited guidance on how to interpret what it says, or what it is carefully avoiding saying. This guide explains what an ACR contains, how to interpret each section, and what distinguishes a credible report from one that should prompt further scrutiny.

What an ACR Contains

An Accessibility Conformance Report (ACR) is a completed VPAT template that documents how a specific digital product conforms to accessibility standards. A complete ACR includes the following sections:

Product information, the product name, version, and release date being evaluated. This is a critical detail: an ACR for version 2.3 of a product does not cover version 3.0. Always verify that the ACR version matches the product version in the contract.

Evaluation methodology, a description of how the evaluation was conducted. This section should name the testing tools used, the assistive technologies included (screen readers, keyboard-only navigation), the testing scope (which pages or workflows were included), and the professional credentials of the evaluator.

Applicable standards, the VPAT edition used (WCAG, Section 508, EU, or INT) and the specific version of those standards. For federal procurement, the correct edition is the Section 508 Edition, which covers WCAG 2.0 AA and the additional ICT standards for hardware, software, support documentation, and closed functionality.

Conformance tables, the core of the document. These tables list each applicable success criterion and assign a conformance level: Supports, Partially Supports, Does Not Support, or Not Applicable. Each non-"Supports" designation must include a remark explaining the specific gap or the basis for the Not Applicable determination.

Legal disclaimer, a standard statement clarifying that the document represents the vendor's assessment at the time of testing and that conformance may vary with product updates.

How to Interpret Conformance Levels

The four conformance levels have precise meanings that are worth understanding in detail before drawing conclusions from an ACR.

Supports means the product fully meets the criterion as written. There are no known failures for this criterion, and users who rely on assistive technology can access the relevant functionality without a workaround.

Partially Supports is the most common, and most frequently misread, designation. It means the product meets the criterion for some content, some features, or some user workflows, but not all. A well-authored ACR will include a remark that specifies which areas fail and which succeed. A remark that says only "some functionality may not be fully accessible" is not informative. The question to ask is: does the failure affect the functionality your users actually need?

Does Not Support is an explicit acknowledgment that the product fails the criterion. This designation should not automatically disqualify a product, the relevant question is whether the failing criterion is material to the intended use case. A product used exclusively by keyboard users, for example, carries more risk from a keyboard navigation failure than from a deficiency in audio description.

Not Applicable means the criterion is irrelevant to this product. A server-side API, for example, would mark all visual presentation criteria as Not Applicable. This designation is legitimate when justified, but it is also the easiest designation to misuse. Every "Not Applicable" row should have a remark explaining why the criterion does not apply.

What "Partially Supports" Really Means in Practice

Federal Section 508 program managers are trained to pay particular attention to "Partially Supports" designations, because this level is where the most ambiguity, and the most evasion, occurs.

A "Partially Supports" entry can represent a minor deficiency on a rarely used feature, or it can represent a fundamental accessibility barrier on a core workflow. The conformance level alone does not tell you which. The remark is what matters.

Consider the difference between these two remarks for the same criterion (1.4.3 Contrast Minimum):

Informative remark: "Most interface text meets the 4.5:1 contrast ratio requirement. Exception: placeholder text in form input fields renders at approximately 3.2:1. This affects all form fields site-wide."

Non-informative remark: "Contrast ratios are generally supported. Some areas may not meet minimum requirements."

The first remark identifies the specific failure, its scope, and the affected user population. The second remark is a hedge that tells the reader almost nothing. When reviewing an ACR with "Partially Supports" entries and vague remarks, you are looking at a document that has prioritized liability management over honest disclosure.

Red Flags in an ACR

Several patterns in an ACR should prompt a closer look before relying on it for procurement decisions.

No testing methodology cited. An ACR that does not name the tools, assistive technologies, and test process used to arrive at its conformance determinations is not a tested ACR. It may reflect the development team's belief about the product's accessibility, which is not the same as a structured evaluation.

Rows marked "Not Evaluated." This designation means the criterion was not tested. A VPAT with "Not Evaluated" rows is, by definition, incomplete. No row should carry this designation in a document submitted for federal procurement.

"Supports" across every criterion with no remarks anywhere. A product that perfectly supports every applicable criterion with no partial failures or exceptions is either an extraordinary engineering achievement or a document that was not tested. Products of any meaningful complexity routinely have partial failures; a clean sweep without explanation warrants scrutiny.

Outdated template. The current VPAT version is 2.5 (2023). An ACR produced on a pre-2017 template does not reflect the current Section 508 standards, which were refreshed in 2017 to incorporate WCAG 2.0.

Scope limited to the homepage. An evaluation that tested only the product's landing page or a single workflow does not represent the full product. The evaluation scope should be documented, and it should cover the functionality that federal users will actually use.

Self-reported without named evaluator credentials. An ACR prepared by the vendor's own team without independent testing, and without identifying the professional credentials of the evaluator, carries less evidentiary weight than one produced by a certified third party.

How Contracting Officers Evaluate ACRs

Section 508 program managers and contracting officers reviewing ACRs in procurement typically follow a structured evaluation process:

  1. Verify the product version matches the version in the solicitation or contract.
  2. Confirm the VPAT edition is the Section 508 Edition (not WCAG-only or EU).
  3. Review the evaluation methodology section for evidence of real testing: named tools, assistive technology versions, test scope, and evaluator credentials.
  4. Identify all non-"Supports" designations and read the corresponding remarks to assess materiality.
  5. Flag missing or vague remarks on "Partially Supports" or "Does Not Support" entries for follow-up.
  6. Assess the scope coverage, does the evaluation cover the specific features and content that the agency will use?
  7. Consider the source, was the report produced by an independent third party or self-reported by the vendor?

A product with documented partial failures in non-critical areas, supported by clear remarks and a credible evaluation methodology, is often more trustworthy than a product claiming perfect conformance across all criteria without explanation.

What Makes an ACR Credible

The factors that distinguish a credible ACR from a compliance-on-paper document are consistent:

Independent evaluation. An ACR produced by a firm with no development relationship to the product being evaluated eliminates the conflict of interest inherent in self-certification. The evaluator's only interest is in accurate reporting.

Documented test methodology. The evaluation approach should be described in enough detail to allow a reviewer to assess its rigor. DHS Trusted Tester certification is the federal standard for this methodology.

Specific, actionable remarks. Every non-"Supports" designation should identify what fails, where it fails, and for which user populations. Remarks should be written for the reader who needs to make a procurement or remediation decision, not for the reader who needs reassurance.

Current template and standards version. The report should reflect current standards, VPAT 2.5, Section 508 Edition, and the WCAG 2.0 AA criteria incorporated into the 2017 Section 508 refresh.

Versioned and dated. The ACR should clearly identify the product version and the date of testing. A report more than 12-18 months old, or one that does not reference a specific product version, may not reflect the current state of the product.


Simkins & Elgazar produces independently evaluated ACRs using DHS Trusted Tester methodology. Our reports are designed to meet the scrutiny of federal Section 508 program offices and prime contractor compliance reviews. Review our VPAT and ACR preparation service or contact us to discuss your evaluation timeline.