VPAT generator (2.4 INT)

A Voluntary Product Accessibility Template (VPAT) is the document procurement teams ask you for when they evaluate your product for accessibility. It is a self-disclosure: you state, criterion by criterion, whether you Support, Partially Support, Do Not Support, or Not Applicable. This generator builds a VPAT 2.4 INT-style HTML report covering WCAG 2.1 Level A and AA — the version most US federal and EU buyers expect.

Everything is local in your browser. The export is HTML — Microsoft Word will open it directly.

Per-criterion conformance (WCAG 2.1 A & AA)

#CriterionLevelConformanceRemarks
1.1.1Non-text ContentA
1.2.1Audio-only and Video-only (Prerecorded)A
1.2.2Captions (Prerecorded)A
1.2.3Audio Description or Media AlternativeA
1.2.4Captions (Live)AA
1.2.5Audio Description (Prerecorded)AA
1.3.1Info and RelationshipsA
1.3.2Meaningful SequenceA
1.3.3Sensory CharacteristicsA
1.3.4OrientationAA
1.3.5Identify Input PurposeAA
1.4.1Use of ColorA
1.4.2Audio ControlA
1.4.3Contrast (Minimum)AA
1.4.4Resize TextAA
1.4.5Images of TextAA
1.4.10ReflowAA
1.4.11Non-text ContrastAA
1.4.12Text SpacingAA
1.4.13Content on Hover or FocusAA
2.1.1KeyboardA
2.1.2No Keyboard TrapA
2.1.4Character Key ShortcutsA
2.2.1Timing AdjustableA
2.2.2Pause, Stop, HideA
2.3.1Three Flashes or Below ThresholdA
2.4.1Bypass BlocksA
2.4.2Page TitledA
2.4.3Focus OrderA
2.4.4Link Purpose (In Context)A
2.4.5Multiple WaysAA
2.4.6Headings and LabelsAA
2.4.7Focus VisibleAA
2.5.1Pointer GesturesA
2.5.2Pointer CancellationA
2.5.3Label in NameA
2.5.4Motion ActuationA
3.1.1Language of PageA
3.1.2Language of PartsAA
3.2.1On FocusA
3.2.2On InputA
3.2.3Consistent NavigationAA
3.2.4Consistent IdentificationAA
3.3.1Error IdentificationA
3.3.2Labels or InstructionsA
3.3.3Error SuggestionAA
3.3.4Error Prevention (Legal, Financial, Data)AA
4.1.1ParsingA
4.1.2Name, Role, ValueA
4.1.3Status MessagesAA

When you actually need a VPAT

If you sell to US federal agencies, public universities, or large enterprise buyers, you will be asked for a VPAT during procurement. EU public-sector buyers ask for an equivalent EN 301 549 conformance report, which a VPAT 2.4 INT also covers (the INT variant maps to both Section 508 and EN 301 549). For consumer SaaS, a VPAT is rarely required — but having one accelerates enterprise deals and removes a back-and-forth round during security reviews.

Honest disclosure beats inflated claims

A VPAT that claims full support for criteria you actually fail is worse than no VPAT at all — procurement and legal teams notice, and a misrepresentation can void the contract. Mark partial support honestly, list known exceptions, and commit to a remediation timeline. Buyers reward transparency; they reject lies.

VPAT vs ACR: the terms buyers mix up

A VPAT is the blank template published by the Information Technology Industry Council (ITI). An ACR — Accessibility Conformance Report — is what you have once that template is filled in with findings about your product. Vendors say “send us your VPAT” and mean the completed ACR; the distinction only matters when a procurement officer insists on the formal wording. This generator produces the completed report, so what you download is technically an ACR based on the VPAT 2.4 INT template.

Which VPAT edition and version to use

  • VPAT 2.4 / 2.5 INT — covers WCAG, Section 508 and EN 301 549 together. Use this unless a buyer names something else; 2.5 differs mainly in editorial clarifications, and a buyer asking for 2.5 will accept a well-completed 2.4 INT in practice.
  • VPAT WCAG edition — WCAG criteria only. Enough for a private-sector buyer who just wants the conformance picture.
  • VPAT 508 edition — US federal procurement only.
  • VPAT EU edition — EN 301 549 only, for European public-sector tenders.

On the standard itself: report against WCAG 2.1 AA as the baseline, because that is what Section 508, EN 301 549 and the European Accessibility Act all reference. Adding WCAG 2.2 criteria on top is a differentiator, not yet a requirement — no major procurement regime mandates 2.2 as of 2026.

VPAT vs HECVAT and other procurement documents

Higher-education buyers frequently request a HECVAT alongside a VPAT, and the two are not substitutes. HECVAT is a security and privacy questionnaire; the VPAT/ACR is the accessibility conformance report. A full HECVAT does contain accessibility questions, but they ask whether a VPAT exists rather than replacing it. Similarly, a VPAT is not a VAPT — vulnerability assessment and penetration testing is a security exercise with an unfortunately similar acronym.

How to fill each conformance level

Every criterion takes one of four values, and using them precisely is what makes a report credible:

  • Supports — the product meets the criterion with no known exceptions.
  • Partially supports — some functionality does not meet it. Name what, specifically.
  • Does not support — the majority of functionality fails it.
  • Not applicable — the criterion has no bearing on the product (no video, so no captions).

The remarks column carries the weight. “Partially supports” with an empty remark reads as evasion; the same value with “date picker in the booking flow is not keyboard operable, fix scheduled Q4” reads as a vendor who tested their product. Run a scan first so the remarks describe measured findings rather than guesses, and pair the report with a public accessibility statement.

Frequently asked questions

What is a VPAT?

A VPAT (Voluntary Product Accessibility Template) is the standard form, published by the Information Technology Industry Council, on which a vendor reports how its product measures against accessibility standards — WCAG, Section 508 and EN 301 549. It is filled in per success criterion, not as a pass/fail badge.

What is the difference between a VPAT and an ACR?

The VPAT is the empty template; the ACR (Accessibility Conformance Report) is the completed document produced from it. Buyers usually say "VPAT" when they mean the ACR. What this generator gives you is a completed ACR based on the VPAT 2.4 INT template.

Is a VPAT the same as WCAG conformance?

No. WCAG is the standard being measured; the VPAT is the reporting format that records your results against it. You can publish a VPAT that honestly reports failures — that is a valid, and often smart, use of the document. Claiming WCAG conformance is a statement about the product; a VPAT is the evidence for that statement.

Should I report against WCAG 2.1 or 2.2?

WCAG 2.1 Level AA is the baseline every current regime references — Section 508, EN 301 549 and the European Accessibility Act all point at it. Reporting WCAG 2.2 criteria as well is a differentiator in competitive procurement, but no major buyer mandates it as of 2026.

Do I need a VPAT and a HECVAT?

If you sell to higher education, usually both. HECVAT is a security and privacy questionnaire; the VPAT/ACR covers accessibility. The full HECVAT asks whether a VPAT exists rather than replacing it, so having one ready shortens the review.

Who is allowed to write a VPAT?

Anyone — it is a self-report, and vendors complete their own. That is exactly why buyers read the remarks column rather than the conformance values: a report backed by scan output, dated testing and named exceptions carries weight, while blanket "Supports" rows invite scrutiny. Some buyers ask for third-party attestation on high-value contracts.

How often should a VPAT be updated?

At every significant product release, and at minimum annually. An ACR carries its evaluation date, and a buyer looking at a two-year-old report will assume it no longer describes the product.