Section 508 testing is how you prove that the software, website, documents or hardware you sell to a US federal agency meet the Revised 508 Standards, which for web content, software and electronic documents means WCAG 2.0 Level A and AA plus the 508-specific software, documentation and support requirements. In 2026 that proof matters more than the claim: GSA’s FY 2025 Governmentwide Section 508 Assessment tells agencies to use acquisition as “a primary lever” for compliance by validating vendors’ accessibility claims, enforcing contract requirements and holding vendors accountable. If your Accessibility Conformance Report (ACR) is not backed by real manual testing, a contracting officer now has a reason to look harder at it.
This guide is written by IAAP-certified accessibility testers who audit and remediate products for government suppliers. It is not legal advice. It explains what the federal data shows, what Section 508 actually requires you to test, which testing methods agencies trust, and how to turn results into an ACR and a fix plan that survive procurement review.
Why Section 508 Testing Is a Sales Issue Now
Agencies admit they are not testing enough
GSA published the FY 2025 assessment on 5 March 2026, based on responses from 212 agencies, parent agencies and components (U.S. Access Board announcement). Its highlighted findings are blunt:
- The governmentwide average for Section 508 conformance of ICT was 1.96 on a 5-point scale.
- Fewer than half of agencies’ most viewed or used ICT assets were fully conformant, and about half of agencies said they do not routinely test ICT for accessibility as standard business practice.
- Testing and remediation is the weakest area of Section 508 implementation across the federal enterprise.
- Including accessibility in acquisition is common, but enforcement is low: less than 30% of agencies almost always verify ICT deliverables for Section 508 conformance.
- Agencies focus testing on web content and largely neglect hardware and software.
The fix GSA recommends runs through vendors
The assessment’s third recommendation to agencies is to “use acquisition as a primary lever for Section 508 compliance by prioritizing accessible commercial solutions, validating accessibility claims, enforcing contract requirements, and holding vendors accountable” (Section508.gov). As Federal News Network reported, the report also suggests evaluating ICT through ACRs to validate the accuracy of vendor conformance claims and folding accessibility performance into contract renewals, past performance evaluations and future award decisions. GSA also asked Congress to direct agencies to independently validate Section 508 conformance for high-use, public-facing digital products.
For a vendor, that changes the question from “do you have a VPAT?” to “can you show how you tested?”
The FAR rewrite kept Section 508
The 2025 Revolutionary FAR Overhaul rewrote FAR Part 39, but accessibility stayed. GSA’s class deviation RFO-2025-39 states that accessibility standards, including Section 508 compliance, are still required, with limited exceptions and exemptions. Under the RFO Part 39 model deviation text:
- ICT acquisitions must meet the ICT accessibility standards at 36 CFR 1194.1 unless an exception or exemption applies (39.104-3).
- Indefinite-quantity contracts must identify which supplies and services the contractor indicates as compliant and show where to find full details, for example a link to the vendor’s website (39.201).
- When a task or delivery order is issued, the requiring and ordering activities must ensure compliance, and any noncompliant ICT item needs a documented exception or exemption (39.301).
In plain terms, every order on a contract vehicle is another point where someone can check your accessibility evidence. And because the US federal fiscal year starts on 1 October (31 U.S.C. 1102), new-year buying is getting under way right now.
If you need the wider picture of how Section 508 relates to ADA, WCAG, EN 301 549 and VPATs, see our accessibility framework comparison.
What Section 508 Actually Requires You to Test
The Revised 508 Standards (36 CFR 1194, final rule issued 18 January 2017) cover ICT that federal agencies develop, procure, maintain or use. What you test depends on what you sell:
| What you sell | Requirement in the Revised 508 Standards | What testing has to cover |
|---|---|---|
| Website or web app | E205.4: WCAG 2.0 Level A and AA | Every page template and key user flow, with keyboard and screen readers, not just the home page |
| Installed, desktop or mobile software | E207.2 (WCAG 2.0 A and AA, with four exceptions for non-web software) plus Chapter 5 | Interoperability with assistive technology (502: names, roles, states, focus, events), user preferences (503.2), caption and audio description controls (503.4) |
| Electronic documents (PDF, Word, slides) | E205.4: WCAG 2.0 A and AA, except 2.4.1, 2.4.5, 3.2.3 and 3.2.4 for non-web documents | Tags, reading order, headings, table structure, alt text, form fields, language |
| Authoring tools and platforms that generate content | 504: accessible output, prompts, templates, and PDF/UA-1 export where PDF export exists (504.2.2) | Whether the content your customers create with the tool can be accessible |
| Help pages, manuals, help desk | Chapter 6: support documentation in WCAG 2.0 A and AA, and support services that accommodate users’ communication needs | Your knowledge base, PDFs and support channels |
| Hardware, kiosks, devices | Chapter 4 (for example 402 closed functionality, 407 operable parts) | Speech output, tactile controls, reach ranges, captions |
| Anything the technical rules miss | Chapter 3 functional performance criteria (302.1 to 302.9) | Use without vision, with limited vision, without hearing, with limited manipulation, and so on |
Two scoping details trip vendors up:
- Legacy safe harbor is narrow. ICT procured, maintained or used on or before 18 January 2018 that met the original 508 standards does not have to be updated, but only until it is altered. Any changed component must meet the current standards (Access Board E202.2; RFO 39.104-3). A SaaS product that ships every two weeks will not stay “legacy” for long.
- Web apps get one shortcut, not a free pass. Under 501.1, a web application without access to platform accessibility services does not have to meet 502 and 503, provided it conforms to WCAG 2.0 Level A and AA (Access Board). So for most browser-based SaaS, rigorous WCAG testing is the job.
WCAG 2.0 in the rule, WCAG 2.1 and 2.2 in the market
Section 508 still incorporates WCAG 2.0, but many buyers also ask for WCAG 2.1 or 2.2 AA, and state and local governments buying the same product face the DOJ’s WCAG 2.1 AA rule (see our DOJ Title II web accessibility deadline guide). Testing once against WCAG 2.2 AA and reporting the 2.0 rows in your 508 ACR saves a second audit. One wrinkle: success criterion 4.1.1 Parsing still appears in a 508 report, and W3C now notes it “should be considered as always satisfied for any content using HTML or XML”, with real nesting or duplicate-ID problems reported under other criteria (W3C Understanding 4.1.1).
If a federal or state RFP has already landed on your desk, request an ADA & Section 508 accessibility audit or book a consultation so the test scope matches what the solicitation asks for.

Automated, Manual or Hybrid: What Counts as Section 508 Testing
Section508.gov recognises three ways to validate conformance: automated, manual (a documented, consistent, repeatable process), and hybrid. Its guidance is clear about the limits of scanners: automated tools “cannot apply human subjectivity”, so they either produce excessive false positives or, when tuned to avoid them, test only a small portion of the requirements. For a large volume of content it says a hybrid approach is usually best.
What that means when an agency reviews your evidence:
- A scanner report alone is not Section 508 testing. It cannot tell whether alt text is equivalent, whether focus order makes sense, or whether a screen reader user can finish a task. Our automated accessibility testing guide covers where tools help and where they stop.
- Manual testing needs a method you can name. Federal teams align with the ICT Testing Baseline and the DHS Trusted Tester process, a manual test approach that “provides repeatable and reliable conformance test results”. Agencies that adopt Trusted Tester only accept results from certified Trusted Testers (Section508.gov), so check the solicitation for that requirement before you choose a tester.
- Assistive technology passes are what buyers ask about. Keyboard-only, NVDA, JAWS and VoiceOver passes on real workflows are the evidence that holds up. See our manual keyboard testing, screen reader testing and mobile accessibility testing guides.
- Documents need their own pass. GSA flags that tools which convert documents to HTML before testing lose accuracy, so PDFs and Office files should be tested in their native format (Section508.gov; our document accessibility testing guide).
A Section 508 Testing Checklist for Vendors
Use this before you send an ACR or answer an accessibility section in a proposal:
- Name the product and version you are testing, and the environment (production, staging or a documented build).
- List every in-scope ICT type: web app, mobile app, desktop client, PDFs and exports, help centre, support channels, any hardware.
- Map the user journeys a federal user must complete: sign in (including SSO, MFA and session timeouts), the core task, search, forms, data tables, dashboards, file upload and export, and admin settings.
- Run automated checks first, but treat them as triage only.
- Test manually against every WCAG 2.0 A and AA criterion, with keyboard and at least two screen reader and browser combinations, and record the method and tools used.
- Add the 508-specific rows: Chapter 5 interoperability for non-web software, 503.4 caption controls for video, Chapter 6 support documentation and services, and Chapter 4 if you ship hardware.
- Test the documents you ship, including generated PDFs, in their native format.
- Log every defect with location, criterion, user impact and severity, so it can feed both remediation and the ACR remarks.
- Re-test after fixes with the same method, and date the results.
- Keep the evidence file: test plan, raw results, re-test results and the final ACR, ready for a contracting officer or a customer’s accessibility team.

From Test Results to an ACR Agencies Can Trust
Your test results become credible to buyers through the ACR. Section508.gov’s ACR guide (updated June 2026) sets the rules:
- If you sell to the US federal government, use the Revised Section 508 or INT edition of the ITI VPAT. ITI’s current templates are VPAT 2.5Rev (April 2025); the 508 edition incorporates WCAG 2.0 and the INT edition adds the EN 301 549 and WCAG 2.2 tables (ITI).
- Complete the title page, including evaluation methods: whether testing was manual, automated or both, and which tools were used.
- Use only the four conformance terms: Supports, Partially Supports, Does Not Support, Not Applicable. Remarks are required for Partially Supports and Does Not Support.
- Only Level A and AA tables are required for federal procurement.
- Make sure the ACR document itself is accessible.
GSA also offers an ACR Editor for machine-readable OpenACR reports and recommends linking your ACR from the product page. Under RFO 39.201, that public link is exactly where an indefinite-quantity contract can point buyers for compliance details.
Two things to avoid. ITI states there is no VPAT certification and that it does not review or approve VPATs, so never describe an ACR as “certified”. And never mark “Supports” for a criterion you did not test: with agencies now told to validate vendor claims, an overstated ACR is a risk to the contract, not just a weak document. For the full ACR walkthrough, read our VPAT for SaaS guide, or request a VPAT quote.
Section 508 Remediation: Fix in the Order That Protects the Deal
Testing usually produces a long list. Fix it in this order so the next ACR shows real progress:
- Blockers in the journeys the solicitation names: sign-in, the core task, forms and submission.
- Shared components: your design system’s buttons, menus, modals, tables and form fields. One fix there clears dozens of rows. Our accessible React development team works at this level.
- Documents and exports that agencies will republish, through PDF document remediation.
- Support content: help articles, onboarding emails and video captions.
- Re-test and update the ACR, then keep it current with accessibility monitoring and governance so new releases do not undo the work.
Where a fix cannot ship before the bid, say so in the ACR remarks and give a roadmap item. Agencies can still buy the product that best meets the standards, but they need honest information to make that call. Our accessibility remediation developers can take the fix list straight from the audit report.

What Section 508 Testing Costs with HalfAccessible
| Your situation | Best starting point | Price |
|---|---|---|
| You have an RFP and need to know what it really requires | 1-hour expert consultation | $100 |
| Small product or site, need a fast read on the worst barriers | Quick Audit: up to 5 templates, top-10 issues report | $500 |
| Federal bid, ACR due, or a customer asking for evidence | Complete Audit: full manual WCAG 2.2 testing of up to 25 templates or key user flows, with re-test | $2,000 |
| Larger platforms, apps, hardware or document libraries | ADA & Section 508 audit with a custom scope, plus VPAT / ACR documentation | Quoted |
See the full pricing page or our breakdown of accessibility audit cost. Public bodies can use the government accessibility audit request form, and SaaS teams can read how we support SaaS and B2B software and the government and public sector.
Get Section 508 Testing You Can Put in Front of a Contracting Officer
Federal buyers have been told to stop taking accessibility claims on trust. Section 508 testing that names its method, covers real journeys with assistive technology, and ends in a dated re-test and an honest ACR is what keeps your product in the running.
HalfAccessible’s IAAP-certified testers audit web apps, SaaS platforms, documents and mobile apps against the Revised 508 Standards and WCAG 2.2 AA, write ACRs on the current VPAT 2.5Rev editions, and hand the fix list to developers who build accessible software themselves. Prices are fixed and public: $100 consultation, $500 Quick Audit and $2,000 Complete Audit.
Request an ADA & Section 508 accessibility audit, start a $500 Quick Audit, book a consultation, or see our pricing and sample audit report.