Quick answer
Section 508 requires federal agencies to make electronic and information technology accessible to people with disabilities, imposing compliance obligations on IT contractors and vendors.
Section 508 of the Rehabilitation Act of 1973 (as amended in 1998 and 2018) requires federal agencies to ensure that electronic and information technology (EIT) they develop, procure, maintain, or use is accessible to federal employees and members of the public with disabilities.
What is Section 508?
Section 508 is administered by the Access Board and enforced through GSA and agency procurement processes. The law requires that when federal agencies develop or procure information and communication technology (ICT) - including software, websites, hardware, video, and multimedia - those products and services must be accessible to people with disabilities to the same degree they are accessible to people without disabilities, unless an undue burden would result.
The technical standards for Section 508 compliance were updated in 2017 (effective January 2018) to align with the Web Content Accessibility Guidelines (WCAG) 2.0 Level AA for web content and electronic documents, and the Revised 508 Standards published by the Access Board. The standards cover a broad range of ICT: software applications, operating systems, web-based intranet and internet information and applications, telecommunications products, video and multimedia, and hardware.
For federal IT contractors, Section 508 compliance is a procurement requirement. Agencies must obtain Accessibility Conformance Reports (ACRs) - typically in the Voluntary Product Accessibility Template (VPAT) format - from vendors documenting how their products conform to Section 508 standards. Contracts for IT systems, software development, websites, and digital content creation typically include Section 508 compliance requirements with acceptance contingent on demonstrated conformance. Failure to deliver Section 508-compliant products can result in rejection of deliverables.
Why Section 508 matters for government contractors
Section 508 compliance is a technical requirement on virtually every federal IT contract. Developers building systems for federal agencies must build accessibility in from the start, not retrofit it at the end. Testing for Section 508 conformance using both automated tools and manual testing with assistive technologies is a standard part of federal IT delivery. Contractors that do not have internal Section 508 testing capability or familiarity with WCAG 2.0 AA requirements will face repeated deliverable rejections and rework costs on federal IT projects.
Example
An IT development firm wins a contract to build a new benefits portal for a federal agency serving millions of citizens, including many with visual impairments and motor disabilities. The firm's development team integrates Section 508 compliance requirements from the project outset: using semantic HTML, providing alternative text for all images, ensuring keyboard navigability for all functions, maintaining minimum color contrast ratios, and providing captions for all audio and video content. The team conducts automated accessibility testing with axe-core and manual testing with screen readers (NVDA and JAWS) before each sprint release. At project acceptance, the firm submits a VPAT documenting full WCAG 2.0 AA conformance, and the agency's Section 508 coordinator validates conformance before approving final acceptance.
Frequently Asked Questions
What is a VPAT and when is it required?
A VPAT (Voluntary Product Accessibility Template) is a standardized document where a vendor documents how its product conforms to Section 508 standards. Agencies typically require VPATs from vendors when purchasing ICT products. The VPAT lists each applicable Section 508 standard or WCAG 2.0 criterion and indicates whether the product supports, partially supports, or does not support the requirement, with explanatory remarks. A VPAT is self-reported and is not an independent certification, but agencies review VPATs as part of their accessibility evaluation in procurement.
Does Section 508 apply to commercial-off-the-shelf products purchased by agencies?
Yes. Section 508 applies to ICT that federal agencies develop, procure, maintain, or use. When agencies purchase COTS software or hardware, they must consider Section 508 conformance as part of the procurement evaluation. If a product does not conform, the agency must document the accessibility gap and either seek a conforming alternative or document an undue burden exception. Vendors selling COTS products to federal agencies should maintain current VPATs and address accessibility gaps in product roadmaps.
What is the difference between Section 508 and ADA accessibility requirements?
The Americans with Disabilities Act (ADA) applies to private sector businesses, state and local governments, and public accommodations - requiring physical and digital accessibility for customers and employees. Section 508 applies specifically to federal agencies' development and procurement of ICT. Both draw on similar accessibility principles (both reference WCAG standards for web content), but they are separate legal requirements with different coverage scopes and enforcement mechanisms. Federal contractors primarily deal with Section 508 in government contracts and ADA in their own commercial products and facilities.
Is WCAG 2.1 or 2.2 required under Section 508?
The current Section 508 standards reference WCAG 2.0 Level AA, which remains the required standard as of 2026. While WCAG 2.1 and 2.2 add additional success criteria beyond 2.0, federal agencies and contractors are only formally required to meet WCAG 2.0 AA. However, many agencies encourage or prefer WCAG 2.1 AA compliance, and the Access Board has been working on updates to the Section 508 standards that may reference newer WCAG versions. Building to WCAG 2.1 AA is considered best practice for forward compatibility.
How Bidovate helps
Bidovate puts Section 508 Accessibility to work inside your capture and proposal workflow.
Federal contractingSee Bidovate in action
Book a demo and we will show you the platform using your actual contract data.
Related terms
FedRAMP (Federal Risk and Authorization Management Program)
FedRAMP is the federal government's standardized security authorization program for cloud services, enabling agencies to use cloud products that have been pre-approved for federal use.
ViewFederal Information Security Modernization Act (FISMA)
FISMA is the federal law requiring government agencies to develop, document, and implement information security programs protecting federal information systems and data.
ViewRepresentations and Certifications
Representations and Certifications are legally binding statements contractors make in SAM.gov and proposals attesting to their size, status, and compliance with FAR requirements.
ViewCybersecurity Maturity Model Certification (CMMC)
CMMC is the DoD's mandatory cybersecurity certification framework requiring defense contractors to demonstrate compliance with NIST security controls before receiving contracts.
View