Study: AudioEye detects up to 2.5x more issues than other tools
Get ReportGuide
Section 508 Compliance, Explained
Section 508 of the Rehabilitation Act of 1973 requires federal agencies, federal contractors, and organizations receiving federal funding to make their information and communication technology (ICT) accessible, using WCAG 2.0 Level AA as the technical baseline. The guide covers who must comply, the specific requirements, how Section 508 differs from the ADA, what a VPAT is, and how to maintain compliance over time.
)
On this page
In the 1970s, U.S. lawmakers recognized the need to create laws that protected the rights of individuals with disabilities. This ultimately laid the groundwork for key accessibility laws, including the Americans with Disabilities Act (ADA) and the Rehabilitation Act of 1973(opens in a new tab).
As time went on, lawmakers saw the need to update the Rehabilitation Act to address the rapid changes happening in technological development and ensure equal access to online spaces for individuals with disabilities. This led to the introduction of Section 508 in 1998.
Below, we’ll provide an overview of what Section 508 is, who must comply, what the requirements include, and how your business can maintain 508 compliance.
What is Section 508 compliance?
Section 508 requires federal agencies and their contractors to make information and communication technology (ICT) accessible to people with disabilities. It covers websites, software, operating systems, emails, and digital documents.
Congress added Section 508 of the Rehabilitation Act of 1973 in 1998, and the U.S. Access Board issued the Revised 508 Standards in 2017. The Revised 508 Standards incorporate the Web Content Accessibility Guidelines (WCAG) 2.0 Level AA as the technical baseline for web content and electronic documents.
Section 508 applies to all electronic communication, including:
Every page on every public-facing website.
All online forms.
All telecommunications.
All internal and external emails.
All software and applications, including mobile apps.
All online training resources.
All job application pages.
All digital documents, such as PDFs.
Who must comply with Section 508?
Any federal agency must ensure its ICT is accessible to individuals with disabilities. This includes:
Enforcement is handled by each federal agency for its own contracts and grantees, not by a central authority such as the DOJ for ADA matters.
Exemptions for Section 508 Compliance
There are some listed exceptions for Section 508 compliance(opens in a new tab). For example, technology operated by agencies as part of a national security system is not covered.
The law also makes an exception if conformance would impose an “undue burden” or require a “fundamental alteration” of functionality.
For example, suppose an agency uses legacy billing software that fails to meet Section 508 standards. In that case, the agency may be able to prove that upgrading to compliant software would be too expensive and time-consuming. However, they would need to show that they’d purchased the software before 2017, when the Section 508 standards were updated.
What are the Section 508 compliance requirements?
Section 508 requires ICT to meet WCAG 2.0 Level AA success criteria, including keyboard operability, alt text for images, captions for multimedia, sufficient color contrast, and screen reader compatibility, as well as additional physical accessibility requirements for hardware. These categories cover the high-impact issues that prevent people who use screen readers, keyboard-only navigation, and magnification from completing tasks on federal ICT.
For the full criterion-by-criterion breakdown, see the Section 508 compliance checklist.
What WCAG version does Section 508 require?
Section 508 requires conformance to WCAG 2.0 Level AA, the baseline set by the Revised 508 Standards in 2017; WCAG 2.2 Level AA is not required but is the forward-looking best practice. The U.S. Access Board set that baseline when it issued the Revised 508 Standards, and it has not changed since. Building to WCAG 2.2 Level AA means meeting today’s legal requirements while preparing for the update to the standards that are widely expected to be adopted.
Section 508 vs. ADA: which applies to you?
The three laws differ in who they cover, what technology they apply to, which standard they cite, and who enforces them.
For a full breakdown on how these laws differ, see our Section 508 vs. ADA comparison post.
Ultimately, which law applies to you comes down to your relationship to government:
You deliver ICT to a federal agency, or your technology is federally funded. Section 508 applies.
You are a state or local government entity. ADA Title II applies, and its compliance deadlines are already set.
You are a private business open to the public with no federal contracts or funding. ADA Title III applies, and Section 508 does not.
A federally funded public entity often owes both. A public university running a federally funded research portal meets Section 508 for that portal and ADA Title II for the rest of its digital presence.
What is a VPAT, and how does it differ from an ACR?
A Voluntary Product Accessibility Template (VPAT) is a document that demonstrates how a product conforms to Section 508 accessibility standards. VPATs are typically required during federal procurement to help agencies assess whether ICT meets compliance requirements before purchase. The General Services Administration(opens in a new tab) (GSA)(opens in a new tab) recommends that vendors produce a VPAT for any technology marketed to the federal government, federal employees, and related organizations.
What is an Accessibility Conformance Report (ACR)?
A VPAT is the blank template; an Accessibility Conformance Report (ACR) is the completed, evidence-backed document a federal agency actually requests during procurement. Agencies use the ACR to compare vendors before purchase and to document why a selection met their accessibility obligations.
Accurately completing a VPAT is where most organizations need support, because it requires testing a product against every applicable Section 508 and WCAG criterion, not just filling in a form. AudioEye’s VPAT Services handle that work directly: AudioEye audits your site or digital asset, completes the VPAT for you, documenting both accessibility features and current limitations, and updates it as your content changes. That turns a static procurement document into an accurate, current record you can hand to an agency with confidence.
What happens if you are not Section 508 compliant?
A federal contractor that fails to comply with Section 508 can lose an existing contract or be excluded from future procurements, and a federally funded institution can face a complaint, an enforcement agreement, or a discrimination lawsuit. Because each agency enforces Section 508 for its own contracts and grantees, the consequence arrives through the relationship that created the obligation: a contracting officer, a grant administrator, or a program office. There is no central authority that issues fines.
For contractors, the exposure is commercial. An accessibility claim that does not hold up under agency review can cost an award before it is made, and a conformance failure discovered after the fact puts an existing contract at risk. For federally funded institutions, the exposure looks more like the cases below.
NAD v. Harvard University(opens in a new tab): Harvard settled for over $1.5 million after failing to provide accurate captioning for online course materials.
DRA v. University of California, Berkeley(opens in a new tab): UC Berkeley agreed to overhaul its accessibility policies after failing to provide accessible documents for students.
NFB v. Los Angeles Community College District(opens in a new tab): A federal jury found that the LACCD discriminated against two blind students across 14 counts, including inaccessible websites and course materials, and awarded $242,500 in damages.
All three are federally funded institutions, which is what makes them relevant rather than generic accessibility litigation. Web accessibility lawsuits have continued to rise(opens in a new tab) in recent years, with over 3,100 filings in 2025. Prioritizing Section 508 compliance reduces that exposure and makes digital content usable by the widest possible audience.
How do you test for Section 508 compliance?
Testing for Section 508 compliance requires automated scanning to find WCAG 2.0 Level AA failures at scale, plus expert testing by trained testers using assistive technology to verify the criteria automation cannot evaluate.
Start with an automated scan of the entire site to establish your baseline and catch what machines reliably detect: missing alternative text, unlabeled form fields, low color contrast, and broken heading structure. Then bring in trained testers for what a machine cannot judge. They navigate your site looking for more complex issues that automation can’t catch. Document each criterion and the evidence behind it as you go, because that record becomes your Accessibility Conformance Report.
Section 508 testing needs both, which is what a platform is for. Take AudioEye, for example. AudioEye combines automation (which catches 2.5 times more issues than other tools) and expert audits from certified testers, so nothing gets claimed as conformant that was never actually tested.
How to maintain Section 508 compliance
Maintaining Section 508 compliance requires continuous monitoring as content changes, scheduled expert audits, and current conformance documentation, because a one-time audit goes stale as soon as the site does. Organizations that treat compliance as a continuous program are better positioned to meet evolving standards and reduce legal exposure. Regular testing, ongoing monitoring, and timely fixes are what keep a conformance claim accurate between audits.
Part of that is handling two standards at once. Section 508 incorporates WCAG 2.0 Level AA as its legal baseline. Still, the standard is widely expected to modernize toward newer WCAG versions, which is why building to WCAG 2.2 Level AA is a forward-looking best practice. The practical goal is to meet the standard you owe today while staying ahead of the one you will likely owe tomorrow.
Is Section 508 being updated?
Section 508’s technical standards have not changed since the Revised Section 508 Standards took effect in 2017; the Section 504 Refresh Act, introduced in July 2024, would have directed the U.S. Access Board to update them, but did not advance. The bill would also have reformed the complaint process, required agencies to include people with disabilities in technology testing and acquisition, and mandated the appointment of dedicated Section 508 compliance officers at each agency.
The Refresh Act did not clear the 118th Congress before it ended in January 2025. Still, it signals the direction of federal accessibility policy and reflects growing recognition that the current standards need modernization. Organizations subject to Section 508 should watch for reintroduction and treat WCAG 2.2 Level AA conformance as a forward-looking best practice.
Read more on the push to refresh Section 508 here.
Where to start with Section 508 compliance
Section 508 comes down to a single question with a lot of follow-ups: Does your ICT meet WCAG 2.0 Level AA, and can you prove it? Whether you are a federal agency, a contractor supplying a deliverable, or an institution operating federally funded technology, the obligation is the same, and so is the evidence an agency will request. The hard part is not producing that evidence once. It is keeping it accurate as the site changes. With AudioEye, ongoing compliance is easy.
AudioEye combines automation with Expert Audits from certified testers, so conformance is verified rather than assumed, and the documentation you hand to a contracting officer reflects the site you actually have today.
GET STARTED
Accessibility is a journey, and we're here to help guide you down that path.
Ready to get started on the path to Section 508 compliance? Get started by entering the URL of your digital content in our free Web Accessibility Scanner. Want to see AudioEye in action? Schedule a demo today.