
Two documents, two readers, one set of tests
VPAT or accessibility statement: which document does your buyer actually want?
A procurement team asks for a VPAT. A regulator asks for a statement. A customer with a screen reader wants neither: they want the checkout to work. The three requests are related but not interchangeable, and confusing them wastes weeks in a sales cycle. This page explains what each document is, who reads it, what it must contain, and how one round of testing can produce both without contradicting itself.
We test and sign. Buyers get facts, users get a document that is true.
The short version
| VPAT / ACR | Accessibility statement | |
|---|---|---|
| Audience | Buyers, procurement, legal review | Users of the service, and regulators |
| Status | Voluntary, contractual in practice | Legally required in the EU, Ontario and by convention in the UK |
| Format | Fixed template, criterion by criterion | Free prose, six required elements |
| Length | Many pages | One page |
| Published | Sent on request, sometimes on a trust page | Public, linked from every page |
| Written by | The supplier, ideally with external testing | The operator, ideally with external testing |
| Typical trigger | A tender or a security and accessibility review | A legal obligation or a complaint |
Both rest on the same foundation: someone opened the product and tested it. Without that, one is a form filled from optimism and the other is a paragraph of goodwill.


What a VPAT contains, section by section
- Product identification. Name, version, date of the report and the contact for questions. A report without a version number is unusable by a buyer.
- Evaluation methods. How the product was tested: which assistive technology, which browsers, automated and manual, and by whom. This is the section experienced buyers read first.
- Applicable standards. WCAG at the chosen level, and depending on the edition, Section 508 chapters or EN 301 549 clauses.
- The criterion tables. Each criterion with a conformance level and a remark. The remark is the report: a bare word without explanation tells the buyer nothing.
- Legal disclaimer. Standard, and it is the reason a VPAT alone rarely satisfies a regulator.
The most common weakness is not dishonesty but vagueness: pages of criteria marked as supported with no remark and no evidence of testing. A buyer who has read a hundred of these can spot the pattern in a minute.
Where each document is asked for
Public procurement in Europe
Contracting authorities reference EN 301 549. They want the European edition of the report, dated, with the evaluation method stated.
Enterprise software sales
Large customers pass their own obligations down the chain. The accessibility question arrives with the security questionnaire and blocks the deal until answered.
Consumer services in the EU
The European Accessibility Act asks for a public statement, not a supplier form. The detail is on the EAA checklist.
Ontario
The compliance record and the report filed under O. Reg. 191/11, described on the AODA page.
United Kingdom
Tenders ask for a WCAG 2.2 AA report signed by a named company; the route is on the UK page.


How the two documents can contradict each other
This is the risk nobody plans for. The sales team sends a report marked as supporting every criterion, because it was written eighteen months ago for a different release. Meanwhile the public statement, written after real testing, honestly lists three open barriers. Both are on the internet. A buyer who reads both now has a question about your internal controls rather than about your accessibility.
The rule is simple: one round of testing, one set of findings, two formats. When the findings change, both documents change together, with the same date. Our plan keeps the testing monthly precisely so the underlying facts have a single current version.
What we do and what we do not
We run the audit described on the audit page: automated pass, then manual testing with keyboard and screen reader across your real flows. From that testing we write the findings report and the public statement, signed by the company established in your jurisdiction and carrying a verification code anyone can check.
What we do not do is fill in a supplier form and sign it as if we were the vendor: the report is your representation about your product, and it has to come from you. What we provide is the evidence underneath it, including the evaluation method section, which is the part buyers actually scrutinise, and the criterion-level findings you transfer into the template.
We also do not write code. The findings list what to change and in which order; your team or your agency implements it, and the monthly re-test confirms the result.


A practical sequence for a software company
If accessibility questions are blocking deals, the order that works is this. Book the audit and get the findings, because every document downstream depends on them. Publish the statement immediately, listing what is open; it costs nothing to be honest and it removes the legal gap while engineering works. Transfer the criterion-level findings into the supplier report for the buyers who ask, keeping the evaluation method section intact so the report carries weight. Fix the blocking items, which are usually few. Re-test monthly, and reissue both documents together when something material changes.
Six weeks in, the sales team has an answer that survives scrutiny, the legal obligation is covered, and the product is measurably better for the people who were struggling with it. That sequence costs 690 € a year for the European Union, 890 CAD for Canada, 1,290 € for three domains and six languages, or 1,990 € for all three regions with a single renewal date.
How buyers read these documents
Procurement teams that handle accessibility regularly develop a fast triage, and knowing it changes how you write. The first thing checked is the date and the version: a report about release 3.2 when the buyer is purchasing 5.1 goes to the bottom of the pile immediately, because it says the supplier does not maintain the document. The second is the evaluation method section, which separates reports written after testing from reports written after a meeting. If it names the assistive technology, the browsers and the flows covered, the rest of the document is read with attention. If it says an internal review was performed, the rest is skimmed.
The third check is the remarks column. A page of criteria marked as supported, each with an empty remark, reads as unverified. A report marked as partially supporting eleven criteria, each with one honest sentence about the limitation and the workaround, reads as competent. Buyers are not looking for perfection: they are looking for a supplier who knows their own product and will not surprise them after signature.
The fourth is consistency with everything else you publish. If the report claims full support and the public statement names three open barriers, or if the marketing site advertises a badge from an overlay vendor, the contradiction becomes the topic of the next call.

What happens after the contract is signed
The document does not stop mattering at signature. Framework contracts in the public sector increasingly carry an accessibility clause that survives into delivery: the supplier undertakes to maintain the level described and to notify material regressions. That turns an annual marketing exercise into an operational duty, and it is the reason monthly testing is worth more than a yearly report. A regression found by your own monitoring is a maintenance ticket. The same regression found by the customer, eight months after you promised a level you no longer meet, is a contractual conversation.
It also changes who needs to see the findings internally. Sales owns the document, engineering owns the defects, and somebody has to own the loop between them. In the companies where this works, the monthly result goes to a single named person who decides what is a ticket and what is a note, and the supplier report is updated at each release rather than rewritten in a panic before a tender closes.
One further detail worth settling early: decide which edition of the template you publish. Suppliers selling on both sides of the Atlantic often keep two, one keyed to the American rules and one to the European standard, and then let them drift apart. If your buyers are mainly European, publish the European edition and keep a single source of findings behind it; if you genuinely need both, generate them from the same audit on the same day and say so in each.
Three mistakes that cost deals
Sending a template with the placeholders still in it. It happens more often than anyone admits, and it ends the conversation.
Marking everything as supported. One buyer with a screen reader tries the trial account and finds the unlabelled control in four minutes. Everything else in the document is now suspect.
Refusing to send anything. Some suppliers stall, hoping the question goes away. In public procurement it does not: a missing answer is scored as zero, and the contract goes to the competitor who sent an honest, imperfect report.
VPAT and statement, common questions
What is a VPAT?
A Voluntary Product Accessibility Template: a structured form, published by the Information Technology Industry Council, in which a supplier reports how a product meets a list of accessibility criteria.
What is an ACR?
The completed document. VPAT is the blank template; the Accessibility Conformance Report is what you fill in and send.
Which editions exist?
Editions keyed to WCAG, to the United States Section 508 rules, to EN 301 549 for Europe, and an international edition combining them.
Which edition do European buyers want?
The EN 301 549 edition, because that is the standard referenced by European procurement.
Is a VPAT the same as an accessibility statement?
No. A VPAT is a supplier document for buyers. A statement is a public document for users, required by law in several jurisdictions.
Can one replace the other?
No. They answer different questions for different readers, and an authority asking for a statement will not accept a procurement form.
Who writes a VPAT?
The supplier, sometimes with an external tester. Self-completed reports are common and treated with corresponding scepticism.
How long is a VPAT?
Long. Every applicable criterion gets a conformance level and a remark, so a full report typically runs to many pages.
What are the conformance levels?
Supports, partially supports, does not support, and not applicable, each with an explanation.
Do I need a VPAT to sell in Europe?
Not by law. You need one when a buyer asks, which in public procurement and enterprise sales is often.
Do I need a statement even if I have a VPAT?
Yes, if the European Accessibility Act, Ontario law or UK practice applies to you.
Can you produce a VPAT for us?
We produce the testing and the findings that any honest report rests on. Whether the output is formatted as a report for a buyer or a statement for users is a formatting decision.
Does an automated scan produce a VPAT?
It cannot. Most criteria need a judgement about intent and context that only manual testing provides.
How often should a VPAT be refreshed?
With every major release, and at least annually. A report describing a two-year-old version misleads the buyer.
What if we do not support a criterion?
Say so, explain the impact and describe the alternative. Buyers award points for honesty and deduct them for discovered overstatement.
Is a VPAT legally binding?
It is a representation about your product. Overstating it in a tender is a contractual and reputational risk.
What do you deliver?
An audit, a findings report, a signed public statement and a verifiable code, from 690 € a year.
Where do we start?
The free scan, then the audit. Both documents are written from the same testing.