Standards

How to Fill Out a VPAT (Step by Step)

Standards · 2026-06-21 · 8

The blank VPAT template is just a table. This guide walks through every step — edition choice, header info, criterion-by-criterion evaluation, conformance levels, and the automation limit you need to document honestly.

How to Fill Out a VPAT (Step by Step)

Pick the right VPAT 2.5Rev edition (WCAG, 508, EU, or INT), fill in the header, evaluate each success criterion, record one of four conformance levels with a remarks note, be candid about gaps, flag what needs manual review, and re-issue after you fix things. That is the whole process. The sections below go through it in order.

What you are actually filling in

A VPAT — Voluntary Product Accessibility Template — is a blank table published by the Information Technology Industry Council (ITI). "VPAT" is an ITI trademark. Once you fill it in with real test results, the completed document is called an Accessibility Conformance Report (ACR). Most people call both the blank and the filled version a "VPAT," but the document a buyer wants is the ACR: the template plus your actual findings, criterion by criterion.

VPAT 2.5Rev is the current revision, aligned with WCAG 2.2. It is the version enterprise procurement teams request by name because it maps to the same technical baseline most accessibility programs run against.

Step 1: Choose the right edition

ITI publishes VPAT 2.5Rev in four editions. Each one reports against a different set of standards, so the edition you choose depends on what the buyer needs to satisfy, not what you prefer to fill out.

  • WCAG edition — covers WCAG 2.2 success criteria only. Use this when the buyer cares about web accessibility conformance and has no specific regulatory requirement beyond that.
  • Section 508 edition — maps to the U.S. federal ICT accessibility standard, which itself incorporates WCAG 2.0 AA as its technical baseline. Use this when you are selling to federal agencies or buyers whose contracts flow downstream from a federal program.
  • EU edition — keyed to EN 301 549, the harmonized European standard referenced by the European Accessibility Act (enforceable since June 28, 2025). Use this when you are selling into EU markets or when a buyer needs EAA conformance evidence.
  • INT (international) edition — combines all three of the above into one document. Use this when you need a single report to satisfy multiple regulatory environments at once, or when the buyer has not specified which standard applies.

When in doubt, ask the buyer which edition they need before you start. The wrong edition does not satisfy their requirement, even if it is thorough.

Step 2: Fill in the header (the "essential information" block)

Every VPAT 2.5Rev starts with a header block before the criteria table. Procurement reviewers read this first, and an incomplete header signals a rushed document. Fill in every field.

  • Product name and version — be specific. "My Shopify store" is not enough; include your store URL and, where relevant, the theme version or app version being evaluated.
  • Report date — the date the evaluation was completed, not the date you are sending it. Buyers track how current the document is.
  • Contact information — name and email of the person or team responsible for accessibility questions. This is a real contact, not a generic inbox.
  • Evaluation methods used — describe what you actually did: automated scan with axe-core, manual keyboard testing, screen-reader testing, expert review. Be accurate. Do not claim manual testing you did not perform.
  • Notes / additional information — a brief scope statement works well here: which pages were tested, which user flows were included, and any known scope exclusions.

Step 3: Evaluate each applicable success criterion

The body of the VPAT is a table of success criteria drawn from the edition you chose. For the WCAG 2.2 edition, that means working through Level A and Level AA criteria. For Section 508 or EU editions, there are additional functional performance criteria and hardware-level criteria that may or may not apply to a web product.

Mark criteria as "Not Applicable" only when they genuinely do not apply to your product. A storefront with no video content can legitimately mark time-based media criteria as not applicable. A storefront that uses images cannot mark image text alternatives as not applicable.

For everything that does apply, you need actual test evidence before you can record a conformance level. This is where the evaluation work happens: running an automated scan, reviewing the output, and doing manual checks for what automation cannot catch.

Step 4: Record a conformance level for each criterion

The VPAT uses exactly four conformance levels. These are the official ITI terms — do not substitute your own language.

  • Supports — the product fully meets the criterion.
  • Partially Supports — the product meets the criterion for some functionality or some instances, but not all.
  • Does Not Support — the product does not meet the criterion.
  • Not Applicable — the criterion is not relevant to this product or component.

Every row that is not "Not Applicable" or "Supports" needs a Remarks and Explanations note. This is not optional. "Partially Supports" with no explanation tells the reviewer nothing useful. Write a plain-language description of what works, what does not, and where the gap is. "Navigation landmark roles are present on the home page but missing from product collection pages" is a useful remark. "Some issues exist" is not.

Step 5: Be candid about partial conformance and gaps

This is where many VPATs fail. There is a temptation to mark everything "Supports" and move on, especially when a deadline is looming or the document is going to a buyer you want to impress. That instinct produces a less credible document, not a more credible one.

A procurement reviewer who has seen dozens of ACRs will notice when every criterion is marked "Supports" on a site with obvious accessibility gaps. An honest document that records three criteria as "Partially Supports" with clear explanations, alongside a note that remediation is planned, is more useful and more trusted than a document that papers over the same three gaps.

The VPAT documents conformance. It is not a certificate of compliance, not a guarantee of ADA compliance, and it does not prevent litigation. What it does is give a buyer accurate information to make a procurement decision. Candor serves that purpose; inflation does not.

Step 6: Flag what automation cannot cover and get manual review

Automated accessibility tools, including axe-core, detect only a portion of WCAG issues. Industry research puts automated coverage at roughly a third to half of total issues. The rest require human judgment: does an image's alt text actually describe what the image shows, does a keyboard user get stuck in a component, is the reading order sensible when a screen reader navigates the page, does a CAPTCHA have an accessible alternative.

Your VPAT should be honest about this boundary. If your evaluation was limited to an automated scan, say so in the evaluation methods section and in the remarks for criteria that require manual verification. Mark criteria that automation cannot fully evaluate as "Partially Supports" rather than "Supports" when you have not completed the manual check. This is accurate, and it is exactly the kind of transparency a serious buyer is looking for.

For a more complete ACR, complement the automated scan with at least a targeted manual review of the highest-risk criteria: keyboard navigation, focus order, color contrast in dynamic states, form error handling, and any media content.

Step 7: Date it and re-issue after fixes

A VPAT is a snapshot. It reflects the state of the product at the time of the evaluation. If you fix the issues documented in a "Partially Supports" row, the document needs to be updated and re-issued with a new date. Sending a buyer a two-year-old ACR for a store that has changed significantly since then is not useful, and a careful reviewer will ask when the evaluation was done.

Re-evaluation does not have to be a full audit every time. For targeted fixes, re-running the automated scan and updating the affected rows, with a new evaluation date and a note about what changed, is often sufficient. For broader changes, a full re-evaluation makes sense.

How Paperfort generates your completed VPAT 2.5Rev

Paperfort runs an automated WCAG 2.2 AA scan of your Shopify storefront using axe-core and produces a completed VPAT 2.5Rev (an ACR) directly from the results. Every applicable criterion gets a conformance level, every non-"Supports" row gets a remark, and the evaluation methods section is accurate about what automated testing covers and where manual review is needed. The $249 bundle also includes a plain-language audit report and a hosted accessibility statement for your own domain.

If a buyer has asked you for conformance documentation, or if you are preparing to sell into markets that expect it, the practical next step is to get your VPAT for Shopify and have it ready when the request comes.

Answers

Common questions.

Paperfort produces documentation and a prioritized remediation plan — not legal advice, and not a promise of compliance.

What are the four VPAT conformance levels?
The four official ITI conformance levels are: Supports (the product fully meets the criterion), Partially Supports (the product meets the criterion for some functionality but not all), Does Not Support (the product does not meet the criterion), and Not Applicable (the criterion is not relevant to the product). These are the exact terms the template uses, and every row that is not Supports or Not Applicable requires a Remarks and Explanations note explaining the gap.
Which VPAT 2.5Rev edition should I use?
It depends on what the buyer needs. Use the WCAG edition for buyers focused on web accessibility without a specific U.S. or EU regulatory requirement. Use the Section 508 edition for U.S. federal agencies and buyers connected to federal programs. Use the EU edition for buyers subject to the European Accessibility Act and EN 301 549. Use the INT (international) edition when you need a single document that covers all three frameworks, or when the buyer has not specified. When in doubt, ask the buyer before you start.
Does a completed VPAT prove my store is ADA compliant?
No. A VPAT is a conformance report, not a certificate of compliance and not a guarantee. It documents how your product measures against accessibility standards, including any criteria it only partially meets or does not meet. It does not guarantee ADA compliance and does not prevent litigation. An honest ACR is more useful to a buyer than an inflated one, and no document substitutes for legal advice on your own exposure.
Can I fill out a VPAT using only an automated scan?
You can start with one, but automated tools like axe-core detect only a portion of WCAG issues. Industry research puts automated coverage at roughly a third to half of total issues. Criteria that require human judgment, such as whether alt text actually describes an image, whether a keyboard user gets stuck, or whether reading order is sensible, cannot be verified by automation alone. Your VPAT should accurately describe what evaluation methods you used. For criteria you did not manually test, Partially Supports with an honest remark is more accurate than Supports.

Paperfort produces defensible documentation and a prioritized remediation plan. It is not a law firm and does not provide legal advice; it does not guarantee lawsuit prevention or automatic ADA/WCAG compliance. Automated scans detect roughly 30–50% of WCAG issues; Paperfort documents what an automated axe-core scan finds and flags where a qualified professional should review further.