How to Conduct an ACR / VPAT Audit: Step-by-Step SaaS Conformance Reporting
Master Accessibility Conformance Reporting (ACR) and VPAT 2.5 authoring. Learn how SaaS companies conduct formal audits to win enterprise and government contracts.
When enterprise organizations, healthcare networks, universities, or government agencies evaluate SaaS software platforms, their procurement departments require an **Accessibility Conformance Report (ACR)** generated from the **Voluntary Product Accessibility Template (VPAT®)**. Having an accurate, professional ACR is often a mandatory prerequisite to pass security reviews and close six-figure enterprise contracts.
The VPAT is the blank template document published by ITI (Information Technology Industry Council). Once an auditor completes the evaluation and documents your product's compliance, the resulting document is formally called an Accessibility Conformance Report (ACR).
Understanding VPAT vs ACR (Voluntary Product Accessibility Template)
Enterprise procurement officers scrutinize ACRs to assess third-party vendor risk under Section 508 and ADA Title III. An ACR with vague or dishonest claims can disqualify a vendor during RFP reviews.
The 4 VPAT 2.5 Editions (508, WCAG, EN 301 549, INT)
| VPAT Edition | Target Standard | Primary Buyer Audience |
|---|---|---|
| VPAT 2.5 508 | Revised Section 508 | US Federal Government & Defense Agencies |
| VPAT 2.5 WCAG | W3C WCAG 2.1 & 2.2 (Level A, AA, AAA) | US Commercial Enterprise & Higher Education |
| VPAT 2.5 EU | EN 301 549 (European Accessibility Act) | European Union Public Sector & Enterprise |
| VPAT 2.5 INT | International (508 + WCAG + EN 301 549) | Global SaaS Platforms & Multinational Enterprises |
Conformance Levels (Supports, Partially Supports, Does Not Support)
For each WCAG criterion in the table, the report must state:
- Supports: The functionality of the product has no accessibility barriers conforming to the criterion.
- Partially Supports: Some functionality does not meet the criterion, with detailed notes explaining exceptions and workarounds.
- Does Not Support: The majority of the product fails the criterion.
- Not Applicable: The criterion does not apply (e.g., audio descriptions for a text-only dashboard).
The 5-Step ACR Authoring & Audit Process
- Define Product Scope: Specify core user workflows, modules, and role permissions.
- Run Automated Scans: Establish baseline code compliance using axe-core and Lighthouse.
- Conduct Manual Assistive Tech Audits: Test complete user journeys with NVDA and Apple VoiceOver.
- Document Findings & Remarks: Complete the VPAT table with detailed, transparent remarks.
- Publish and Maintain: Update the ACR annually or following major product redesigns.
Leveraging Your ACR to Accelerate Enterprise Sales
Providing an honest, detailed ACR alongside a clear remediation roadmap builds procurement trust, shortening enterprise sales cycles from months to weeks.
Audit Your Website for WCAG 2.2 Compliance Today
Scan your domain in 60 seconds with Rogabot and get instant PR-ready code diffs to prevent ADA lawsuit exposure.