How to Conduct an ACR / VPAT Audit: Step-by-Step SaaS Conformance Reporting

Master Accessibility Conformance Reporting (ACR) and VPAT 2.5 authoring. Learn how SaaS companies conduct formal audits to win enterprise and government contracts.

When enterprise organizations, healthcare networks, universities, or government agencies evaluate SaaS software platforms, their procurement departments require an **Accessibility Conformance Report (ACR)** generated from the **Voluntary Product Accessibility Template (VPAT®)**. Having an accurate, professional ACR is often a mandatory prerequisite to pass security reviews and close six-figure enterprise contracts.

VPAT vs ACR Terminology

The VPAT is the blank template document published by ITI (Information Technology Industry Council). Once an auditor completes the evaluation and documents your product's compliance, the resulting document is formally called an Accessibility Conformance Report (ACR).

Understanding VPAT vs ACR (Voluntary Product Accessibility Template)

Enterprise procurement officers scrutinize ACRs to assess third-party vendor risk under Section 508 and ADA Title III. An ACR with vague or dishonest claims can disqualify a vendor during RFP reviews.

The 4 VPAT 2.5 Editions (508, WCAG, EN 301 549, INT)

VPAT Edition Target Standard Primary Buyer Audience
VPAT 2.5 508 Revised Section 508 US Federal Government & Defense Agencies
VPAT 2.5 WCAG W3C WCAG 2.1 & 2.2 (Level A, AA, AAA) US Commercial Enterprise & Higher Education
VPAT 2.5 EU EN 301 549 (European Accessibility Act) European Union Public Sector & Enterprise
VPAT 2.5 INT International (508 + WCAG + EN 301 549) Global SaaS Platforms & Multinational Enterprises

Conformance Levels (Supports, Partially Supports, Does Not Support)

For each WCAG criterion in the table, the report must state:

  • Supports: The functionality of the product has no accessibility barriers conforming to the criterion.
  • Partially Supports: Some functionality does not meet the criterion, with detailed notes explaining exceptions and workarounds.
  • Does Not Support: The majority of the product fails the criterion.
  • Not Applicable: The criterion does not apply (e.g., audio descriptions for a text-only dashboard).

The 5-Step ACR Authoring & Audit Process

  1. Define Product Scope: Specify core user workflows, modules, and role permissions.
  2. Run Automated Scans: Establish baseline code compliance using axe-core and Lighthouse.
  3. Conduct Manual Assistive Tech Audits: Test complete user journeys with NVDA and Apple VoiceOver.
  4. Document Findings & Remarks: Complete the VPAT table with detailed, transparent remarks.
  5. Publish and Maintain: Update the ACR annually or following major product redesigns.

Leveraging Your ACR to Accelerate Enterprise Sales

Providing an honest, detailed ACR alongside a clear remediation roadmap builds procurement trust, shortening enterprise sales cycles from months to weeks.

Audit Your Website for WCAG 2.2 Compliance Today

Scan your domain in 60 seconds with Rogabot and get instant PR-ready code diffs to prevent ADA lawsuit exposure.

View Pricing Plans