How to answer
Do you have a current VPAT, and does the product conform to WCAG 2.1 AA?
The most-asked question in our corpus that no security document can answer, and one many vendors do not realise is coming until a university asks it.
Our most recent Accessibility Conformance Report, prepared against WCAG 2.1 Level AA using the VPAT 2.4 template, is dated [date] and is available at [URL]. It records [n] partial-support items with remediation targets.
Square brackets are yours to fill in. FillTrust grades an answer like this not in your documents when your documents support it.
- Answered from
- Nothing in your security documentation. This is the clearest example of a question a security policy set cannot answer, and the right output is a gap rather than a guess.
- Evidence to attach
- The VPAT or Accessibility Conformance Report itself, with the date of the audit it came from.
- Where it is asked
- Bespoke vendor questionnaires
This is the surprise in the data. Across the real questionnaires we parse, accessibility comes up more often than DDoS protection, data subject requests or FedRAMP. It is not a security question at all, and it arrives inside the security questionnaire because in higher education and government the same procurement office sends one file.
Why you are being asked. A US public university buying software has obligations under Section 508 and the ADA. It discharges part of them by requiring documentation from its vendors, and the standard artefact is a VPAT: an accessibility conformance report, filled in against WCAG success criteria, saying for each one whether the product supports it, supports it partially, or does not. The buyer is not asking you to be perfect. They are asking you to have looked, and to be able to prove you looked.
Partial support is a normal answer. The three values are supports, partially supports and does not support, and a report claiming full support across every criterion is the one that gets read sceptically. What a reviewer wants beside a partial is a remark explaining the limitation and, ideally, when it will be addressed. An honest report with fifteen partials and clear remarks is worth more than a clean one nobody believes.
It has to be current, and about this version. Questionnaires now ask specifically whether the report covers the version under consideration and whether it was produced within the last twelve months. That is because stale VPATs were being recycled across years of releases. If yours is old, say so and give the date rather than sending it silently.
If you do not have one, say that plainly, and say what you do have: an audit booked, an internal review against WCAG 2.1 AA, keyboard and screen-reader testing as part of your release process. That is a workable answer for a small vendor. What does not work is answering a question about accessibility with a sentence about your security programme, which is what happens when this row gets filled in by pattern-matching.
This is also where FillTrust deliberately writes nothing. Feed it a policy library full of security documentation and ask it about WCAG conformance, and there is no supporting evidence anywhere in the corpus. It returns the gap and names the document it would need. Guessing here would produce a confident, plausible, entirely invented accessibility claim, submitted to a public university.
How this one goes wrong
Specific to this question, not general advice.
- Answering yes because someone once ran an automated checker. Automated tools find a minority of WCAG failures, and a VPAT built only from one will not survive a reviewer who tests with a screen reader.
- Sending a VPAT for a version of the product that no longer exists. Higher-education questionnaires increasingly ask whether it was produced in the last twelve months and for the version being purchased, which is a very deliberate question.
- Confusing the template with the report. A VPAT is the blank form; the completed document is an Accessibility Conformance Report. Reviewers use both names, sometimes in the same row.