Section 508, Decoded for Government Vendors

George
By George
28 September 2026
Section 508 accessible government website context

Section 508 compliance has a strange reputation. Half the businesses that ask about it do not actually need it, because they have confused it with the ADA. The other half need it badly and find out at the worst possible moment, when a federal buyer asks for an accessibility conformance report the company has never heard of, and a contract that was nearly closed goes quiet. This guide sorts out which law is which, who Section 508 really binds, what the technical standard actually says, and how a company that sells software, websites, or services to government gets from zero to a document a contracting officer will accept.

The distinction is worth thirty seconds up front, because it drives everything else. The ADA governs businesses open to the public and is enforced mostly through private lawsuits. Section 508 is a different statute with a different engine: it binds federal agencies directly, and it reaches private companies through the purchasing process, where the pressure point is not a courtroom but a contract award.

What Section 508 Is, and Who It Actually Binds

Section 508 is part of the Rehabilitation Act of 1973, amended in 1998 to require that when federal agencies develop, procure, maintain, or use information and communication technology, that technology must be accessible to people with disabilities, both federal employees and members of the public. ICT is defined broadly: websites, web applications, software, electronic documents, kiosks, and hardware with interfaces all fall inside it.

The direct legal obligation sits on federal agencies. But agencies buy most of their technology, and the statute follows the money. When an agency procures ICT, accessibility requirements go into the solicitation, and vendors must demonstrate conformance to be considered. That is how a private software company in Los Angeles with no federal statute naming it ends up needing Section 508 compliance anyway: not because the law binds it, but because its buyer cannot legally purchase an inaccessible product when an accessible one is available.

The reach extends further than most vendors expect. Organizations spending federal money, universities, research institutions, and grant-funded nonprofits among them, often carry accessibility obligations for the technology they buy and deploy with those funds. And California folded the federal standard into its own law: Government Code sections 7405 and 11135 apply the Section 508 standards to state entities, and AB 434 added a requirement for state agencies to post accessibility certifications for their websites. A vendor selling to Sacramento meets substantially the same technical bar as one selling to Washington.

Section 508 binds agencies and vendors

The Technical Standard: WCAG 2.0 AA, With a Practical Asterisk

For most of its life, Section 508 had its own homegrown technical checklist, written in 2000 for a web that no longer exists. The Access Board fixed that with the Revised 508 Standards, published in January 2017 and effective in January 2018, which replaced the old criteria by incorporating the Web Content Accessibility Guidelines, WCAG 2.0 Level AA, as the standard for web content, software, and electronic documents. The rules live at 36 CFR Part 1194, and the practical effect was to put federal accessibility and mainstream web accessibility on the same measuring stick.

WCAG 2.0 AA is therefore the formal floor of Section 508 compliance today. The asterisk is that the floor and the market have drifted apart. Newer WCAG versions, 2.1 and 2.2, added success criteria for mobile interfaces, low vision, and cognitive accessibility, and federal solicitations and agency 508 coordinators increasingly reference them for new development even though the codified standard still points to 2.0. A separate 2024 rule under ADA Title II pointed state and local governments to WCAG 2.1 AA on their own compliance clock, pulling the public sector market in the same direction.

The sensible engineering decision follows from that drift: build and test new work against WCAG 2.1 or 2.2 AA, and you satisfy the 508 floor automatically while staying aligned with where evaluators are actually looking. Retrofitting the newer criteria later costs several times what designing for them costs up front, a pattern we see constantly in government-facing IT consulting engagements that start after a failed procurement rather than before one.

Section 508 WCAG 2.0 AA baseline

What Section 508 Compliance Actually Requires

Stripped of regulatory language, the requirements come down to whether a person with a disability can genuinely use the product, and they concentrate in a familiar set of checkpoints.

  • Full keyboard operation. Every function reachable and operable without a mouse, with a visible focus indicator showing where the user is.
  • Screen reader compatibility. Meaningful alternative text for images, correctly labeled form fields and buttons, and semantic structure with real headings, so assistive technology can announce the page rather than guess at it.
  • Sufficient color contrast, and no information conveyed by color alone.
  • Captions and transcripts for video and audio content.
  • Accessible electronic documents. The PDFs, spreadsheets, and slide decks a product generates or ships with count as ICT, and inaccessible documents are one of the most common findings in federal reviews.
  • No regressions. Conformance is a property of every release, not a certificate earned once, which is why agencies increasingly ask vendors how accessibility is maintained, not just whether it was achieved.

Testing that holds up has two layers: automated scanning to catch the mechanical failures at scale, and manual testing with a keyboard and a screen reader, because automated tools identify only a fraction of real conformance issues. A conformance claim built on scans alone tends to dissolve the first time an agency evaluator opens the product with assistive technology running.

The VPAT and the ACR: The Documents That Win or Lose the Deal

In federal procurement, conformance is communicated through a specific document. The Voluntary Product Accessibility Template, the VPAT, is a standardized reporting format maintained by the IT Industry Council; a completed VPAT becomes an Accessibility Conformance Report, an ACR, which is what the buyer actually reads. The current template edition is VPAT 2.5, and it comes in variants covering the Section 508 criteria, the WCAG criteria, the European EN 301 549 standard, and an international combination. A vendor selling to U.S. federal buyers completes the WCAG table and the Section 508 table, criterion by criterion, marking each as supported, partially supported, or not supported, with remarks explaining the gaps.

Three realities about this document decide outcomes. First, no ACR frequently means no consideration: many solicitations treat the report as a threshold requirement, and a missing or template-stale submission removes the product from the running before evaluation begins. Second, honesty is safer than optimism, because agencies test. The General Services Administration removed a dozen products from its IT Schedule 70 in 2024 over missing or inaccurate accessibility documentation, and an ACR that overstates conformance converts a sales problem into a credibility problem. Third, the report is a living document: it should carry a date, a version, and a description of the testing behind it, and it should be refreshed when the product materially changes.

For a small vendor, producing the first defensible ACR is a bounded project: audit the product against the criteria with real assistive technology testing, fix what is fixable before reporting, and write remarks for the remainder that describe workarounds and remediation plans. Buyers respond far better to a candid partial-support entry with a roadmap than to a wall of unexplained checkmarks.

VPAT becomes Accessibility Conformance Report

How Enforcement Actually Lands

Section 508 does not generate waves of private lawsuits the way the ADA does; its pressure arrives through quieter channels that matter more to a vendor's revenue. Procurement is the first: contracts lost, options not exercised, and products delisted from purchasing schedules. Agency accountability is the second: the government runs recurring assessments of agency 508 programs and reports to Congress, and those reviews keep documenting low conformance across federal websites and documents, which in turn tightens what agencies demand from suppliers. The pattern for vendors is consistent: nobody calls to complain, the pipeline simply narrows. Complaint processes are the third: federal employees and members of the public can file accessibility complaints about agency ICT, and organizations receiving federal funds face enforcement exposure under the Rehabilitation Act's related sections, where settlements in recent years have reached seven figures for inaccessible public-facing systems.

For private-sector websites serving the general public, the litigation risk lives under a different law entirely, the ADA and its state-law amplifiers, a topic covered in our companion guide to ADA and WCAG rules for business websites. The two regimes share a technical vocabulary, which is convenient: work done to meet WCAG for one obligation carries directly over to the other.

A Practical Path for a Company Selling to Government

  1. Confirm which regime you are in. Selling ICT to federal or California state buyers means Section 508 and an ACR. Serving the general public means ADA exposure. Many companies are in both, and the overlap is an efficiency, not a double burden.
  2. Audit against WCAG with real testing. Automated scans for breadth, then keyboard-only and screen reader passes on the flows a buyer will actually evaluate: sign-in, core tasks, forms, documents.
  3. Fix in priority order. Blockers on core tasks first, the mechanical high-volume issues second, polish last.
  4. Produce the ACR on the current VPAT edition, dated, versioned, and honest about partial support.
  5. Wire accessibility into the release process. A conformance check in the definition of done, plus accessibility-aware staff training for the people who publish content and documents, so the ACR stays true between audits.
  6. Keep procurement artifacts ready. The ACR, the testing summary, and a named accessibility contact, packaged so a capture team can respond to a solicitation without a scramble.

Handled this way, Section 508 compliance stops being a document emergency and becomes a standing capability, one that also quietly improves the product for every user, because the same structure that serves a screen reader serves search engines, mobile users, and anyone on a bad connection.

Where This Fits for LA-Area Businesses

Southern California's mix is unusual: technology vendors selling into federal programs, healthcare and education organizations spending federal funds, and thousands of contractors serving state and local agencies that inherit the same standards through California law. For companies around Thousand Oaks and across the region, the question is rarely whether accessibility obligations apply; it is which ones, and in what order to satisfy them. Sequencing that correctly, one audit feeding both the ACR and the public-facing WCAG posture, is exactly the kind of planning our accessibility and compliance program support is built around.

Frequently Asked Questions

Not directly, unless you sell ICT to the federal government or to entities applying the standard, such as California state agencies. Section 508 binds federal agencies and reaches vendors through procurement. A private business website serving the public is governed instead by the ADA and related state laws, which use the same WCAG guidelines as their practical benchmark, so remediation work serves both regimes.
The Revised 508 Standards, effective January 2018 at 36 CFR Part 1194, incorporate WCAG 2.0 Level AA for web content, software, and electronic documents. That remains the codified floor, though federal evaluators increasingly reference WCAG 2.1 and 2.2 for new development, so building to the newer versions satisfies the requirement and matches what buyers actually check.
The VPAT is the blank standardized template, currently edition 2.5, maintained by the IT Industry Council. Once a vendor completes it with criterion-by-criterion conformance results and remarks, the finished document is an Accessibility Conformance Report, the ACR, which is what federal buyers request and evaluate during procurement.
Increasingly, no. Many solicitations treat a current, credible ACR as a threshold requirement, and purchasing programs have removed products over missing or inaccurate accessibility documentation, including a dozen delistings from GSA's IT Schedule 70 in 2024. An honest report with documented gaps and a remediation plan outperforms both silence and inflated claims.
Yes. Electronic documents are ICT under the standard, and inaccessible PDFs are among the most common findings in federal accessibility reviews. Documents a product generates, ships with, or publishes need proper structure, tags, reading order, and alternative text, and document accessibility belongs in the same testing and release discipline as the interface itself.

If a solicitation just asked for your accessibility documentation, or government buyers are in your pipeline for next year, a scoped audit will show exactly where your product stands against the criteria and produce the honest, current ACR that keeps Section 508 compliance from deciding the deal against you.

Comments

0 Comments