What Is 508 Compliance?


Overview

Section 508 of the Rehabilitation Act requires federal agencies and their technology vendors to make websites, software, documents, and other digital tools accessible to people with disabilities. The technical standard is WCAG 2.0 Level AA. If your organization builds or sells digital products to the federal government, 508 compliance isn't optional. It's a procurement requirement.

Most Government Websites Are Failing. Here's What the Law Actually Requires.

If you work in government IT, procurement, or web development, you've probably heard the term Section 508 compliance more times than you can count. But there's a big difference between knowing it's required and understanding what it actually means in practice.

The FY25 Governmentwide Section 508 Assessment found that the average federal conformance score is just 1.96 out of 5. Fewer than half of the most-viewed federal digital assets are fully accessible. That means most federal agencies are falling short of a law that's been on the books since 1998.

Whether you're a government IT director trying to understand your obligations, a vendor selling technology to a federal agency, or a web developer building a government site, this guide explains what section 508 compliance actually requires. No legalese. Just plain language.

What Is Section 508 Compliance?

Section 508 of the Rehabilitation Act of 1973 is a federal law that requires federal agencies to make their digital technology accessible to people with disabilities. It's been around since 1973, but got significantly stronger in 1998 and again in 2018 when it was updated to reflect how much of government work now happens online.

The law covers what's called ICT, which stands for information and communication technology. That's basically everything digital. Websites, software, PDFs, emails, videos, mobile apps, kiosks, even phone systems. If a federal agency uses it, creates it, or buys it, Section 508 applies to it.

The U.S. Access Board sets the technical standards. The General Services Administration and the Department of Justice share responsibility for oversight and reporting. Every year, the GSA publishes a report to Congress on how well federal agencies are actually doing. That's where that 1.96 out of 5 score came from, and it's not a good number.

Who Does Section 508 Apply To?

This is where a lot of people get tripped up. Section 508 applies to federal agencies, all of them, but it doesn't stop at the agency door.

If your company sells software to a federal agency, builds a website for one, or provides any kind of digital service under a federal contract, you're expected to meet 508 standards too. The agency can't just hand the project to a vendor and wash their hands of the accessibility requirement. The vendor has to meet it. That's why understanding section 508 compliance website requirements matters whether you're the agency or the company doing work for one.

What about state and local governments?

State and local governments aren't covered by Section 508. They fall under a different law called ADA Title II. The practical requirements are similar, but the technical standard is slightly different and the deadlines are their own.

In April 2024, the DOJ issued a final rule requiring state and local government websites and mobile apps to meet WCAG 2.1 Level AA. Then on April 20, 2026, four days before the original deadline, the DOJ pushed the dates back by a year. Larger governments serving populations of 50,000 or more now have until April 26, 2027. Smaller governments and special districts have until April 26, 2028.

The deadline moved. The obligation didn't. The DOJ made that very clear. Private lawsuits can still be filed during the extension period, and they have been.

The Technical Standard: WCAG 2.0 Level AA

When people ask what Section 508 actually requires technically, the answer is WCAG 2.0 Level AA. WCAG stands for Web Content Accessibility Guidelines, and it's the internationally recognized set of rules that defines what accessible web content actually looks like. The 2018 update to Section 508 formally adopted it as the standard.

Here's where it gets confusing. WCAG has multiple versions, and different laws reference different ones:

  • WCAG 2.0 Level AA: The standard required for Section 508 compliance (federal agencies and their vendors)
  • WCAG 2.1 Level AA: The standard required under ADA Title II for state and local governments
  • WCAG 2.2 Level AA: The newest version, published in 2023, not yet required by law but increasingly what agencies and procurement officers expect

The good news is that WCAG 2.1 covers everything in 2.0 and then some. So if you build to 2.1, you've automatically satisfied 2.0 as well. For anyone doing work across both federal and state or local government clients, building to 2.1 or 2.2 is the smarter move. It covers both requirements at once and some federal agencies are already expecting it in procurement evaluations even though 2.0 is still the legal floor.

What does WCAG 2.0 AA actually require?

WCAG is built around four core ideas. Content needs to be perceivable, operable, understandable, and robust. In plain terms, that means someone with a disability can actually see, hear, navigate, and use your site. For a section 508 compliance website, here's what that looks like in practice:

  • Every image has a text description that explains what it is, so someone using a screen reader doesn't miss anything
  • Videos have captions and audio descriptions for people who can't see or hear them
  • Everything on the site can be accessed using just a keyboard, no mouse required
  • Text is dark enough against its background that people with low vision can actually read it
  • Forms tell users what they need to fill in and what went wrong if they make a mistake
  • Headings are organized in a logical order so a screen reader can make sense of the page
  • The site works reliably with the assistive technology people depend on

What ICT Actually Covers

ICT is the official term the law uses, and it basically means anything digital a federal agency touches. That includes the public-facing website, the internal tools employees use every day, PDFs and other documents, emails, videos, podcasts, mobile apps, kiosks, and even phone and conferencing systems.

One thing the FY25 assessment flagged is that most agencies focus their testing on public web pages and largely ignore their internal software and hardware. That leaves real gaps, because Section 508 covers what employees use too, not just what the public sees.

What Is a VPAT and Why Do Vendors Need One?

If you're a vendor selling digital products or services to a federal agency, there's a good chance you'll be asked for a VPAT. It stands for Voluntary Product Accessibility Template, and it's essentially a document where you explain how your product meets accessibility standards. Once you've filled it out, it becomes an Accessibility Conformance Report, or ACR.

Federal agencies are required to consider accessibility when they're buying technology, and a VPAT is how they evaluate it. If you're bidding on a contract and you don't have one, you're likely to lose to a vendor who does. It's that straightforward.

A few things worth knowing about VPATs:

  • A VPAT isn't a certification. It's self-reported. You're documenting how your product meets the standards and being transparent about any known gaps.
  • The template itself is maintained by the Information Technology Industry Council and comes in several editions, including one specifically for Section 508.
  • Agencies do scrutinize these during procurement. A vague or incomplete VPAT raises red flags and can sink a bid.
  • Some agencies, like the Centers for Medicare and Medicaid Services, already require VPATs to meet WCAG 2.1 or higher even though 2.0 is the legal baseline.

Is Section 508 Actually Enforced?

For a long time, Section 508 had a reputation for being a law without much teeth. That's changing. A 2023 spending law now requires OMB and GSA to submit annual compliance reports to Congress, and the DOJ submits its own report every two years. There's more oversight now than there's ever been.

The FY25 assessment paints a pretty honest picture of where things stand. About half of all federal agencies said they don't routinely test their technology for accessibility as part of normal business practices. Only 27% require any kind of mandatory Section 508 training. The assessment's conclusion was that the problem isn't technical complexity. It's governance. Agencies that have made accessibility part of how they operate score significantly better.

For state and local governments, the risk comes from a different direction. Private individuals and advocacy organizations can file ADA lawsuits, and they don't need the DOJ to act first to do it. The deadline extension bought agencies more time to get compliant, but it didn't eliminate the legal exposure that comes from running an inaccessible website.

What a Section 508 Compliant Website Actually Requires

A lot of 508 compliance articles stop at listing the technical requirements. That's not very useful if you're the one who has to actually make it happen. Here's what building a section 508 website compliance actually involves when it's done right.

Automated testing is only the starting point

Automated accessibility scanners are useful and worth using. But they can miss up to half of real accessibility issues. The rest require a person who actually understands how someone with a disability navigates the web. That means testing with screen readers, keyboard navigation, and real assistive technology. Running a scan and calling it done isn't enough.

Accessibility has to be built in, not bolted on

The agencies that score well on the governmentwide assessment are the ones that treat accessibility as part of how they build things, not something they check at the end. That means thinking about it at the design stage, writing code that's structured for screen readers from the start, and making sure anyone who publishes content to the site understands the basics.

Overlays and plugins don't cut it

There are tools that claim to make any website compliant by adding a layer on top of it. They don't work. They hide surface problems without fixing what's actually broken underneath, and they've been widely criticized by accessibility experts. An overlay won't hold up in a procurement audit or a legal challenge.

Compliance requires ongoing attention

A site that passes a 508 audit today can fail tomorrow when someone adds a new page, uploads a PDF, or embeds a video without captions. Compliance isn't something you achieve once and move on from. It requires consistent attention every time the site changes.

How to Get Your Government Website Into Compliance

Getting to compliance isn't a single project with a finish line. It's more like ongoing maintenance. But there's a practical order that makes it manageable.

Start with an audit

You can't fix what you don't know is broken. Free tools like PublicWebCompliance, Google Lighthouse, or WAVE give you a quick surface-level read and are worth running first. But a proper audit goes further, combining automated scanning with manual testing using real screen readers and keyboard navigation. That's what gives you the full picture.

Fix the big things first

Not every accessibility issue is equally serious. Start with the ones that prevent people from getting anything done at all. Broken keyboard navigation, forms with no labels, PDFs that can't be read by a screen reader. Get those fixed first, then work down the priority list.

Work with someone who actually knows Section 508

There's a real difference between a developer who has run accessibility scanners and a developer who has actually remediated a government website for 508 compliance. The latter knows where the problems tend to hide and how to fix them in ways that hold up. That expertise matters, especially if you're working toward a VPAT or preparing for a procurement audit.

Publish an accessibility statement

Many agencies are now expected to have an accessibility statement on their website. It doesn't need to be complicated. It should explain what standard you're working toward, note any known gaps, and tell users how to report issues they encounter. It's a straightforward way to show good faith.

Section 508 vs ADA: What's the Difference?

These two laws get mixed up constantly, and it causes real confusion for government web teams. Here's a straightforward way to think about it.

  • Section 508 covers federal agencies and the vendors that build or sell technology to them. The technical standard is WCAG 2.0 Level AA.
  • ADA Title II covers state and local governments, including cities, counties, public universities, and special districts. The technical standard is WCAG 2.1 Level AA, with compliance deadlines of April 26, 2027 for larger governments and April 26, 2028 for smaller ones and special districts.
  • ADA Title III covers private businesses. There's no specific technical standard written into the law, but courts and the DOJ consistently reference WCAG 2.1 AA as the benchmark.

If your organization works with both federal agencies and state or local governments, the practical answer is simple. Build to WCAG 2.1 or 2.2. It satisfies the Section 508 requirement and meets or exceeds what ADA Title II requires, all in one build.

Building a Website That Actually Meets Section 508 Standards

The data from the FY2025 assessment makes something clear. Most federal agencies aren't where they need to be, and that's after decades of this law being on the books. But that gap also tells you something useful. Organizations that take accessibility seriously right now have a real opportunity to stand out.

Section 508 compliance isn't just about checking a legal box. It's about building digital tools that work for everyone who needs them, including people who rely on assistive technology to do their jobs or access services every day.

At White Whale Web, we build government websites with accessibility built into every decision, from the structure of the code to how we write the content to how we test before anything goes live. If your agency needs help getting to Section 508 compliance, we'd love to talk. Reach out to our team anytime.

Common Questions About Section 508 Compliance

Section 508 comes up for a lot of different people, federal IT teams, procurement officers, web vendors, and state agencies all trying to figure out what applies to them. Here are straightforward answers to the questions that come up most.

What is Section 508 compliance and who does it apply to?

Section 508 is a federal law that requires federal agencies to make their digital technology accessible to people with disabilities. It applies to every federal agency and to any contractor or vendor that builds, buys, maintains, or uses digital tools on behalf of one. If you do work for the federal government, 508 compliance applies to you.

What is the difference between Section 508 and ADA compliance?

Section 508 applies to federal agencies and their technology vendors. ADA Title II applies to state and local governments and requires WCAG 2.1 Level AA, with compliance deadlines of April 26, 2027 for larger governments and April 26, 2028 for smaller ones. Both laws are working toward the same goal of accessible digital services. They just apply to different kinds of organizations and reference slightly different technical standards.

What is a VPAT and does my organization need one?

A VPAT is a Voluntary Product Accessibility Template, a standardized document where you explain how your product or service meets accessibility standards. Once it's completed, it becomes an Accessibility Conformance Report. If you sell technology or digital services to federal agencies, you'll almost certainly need one. Agencies review them during procurement, and not having one puts you at a real disadvantage.

What WCAG level is required for Section 508 compliance?

The legal requirement under Section 508 is WCAG 2.0 Level AA. But WCAG 2.1 covers everything in 2.0 and adds more, so meeting 2.1 automatically satisfies 2.0. If you're working with both federal and state or local government clients, building to 2.1 or 2.2 is the practical choice and increasingly what procurement evaluators expect.

How do I know if my government website is Section 508 compliant?

Start with a free tool like PublicWebCompliance, Google Lighthouse, or WAVE for a quick look at obvious issues. Just keep in mind those tools catch maybe half of real problems at most. A proper assessment combines automated scanning with manual testing using screen readers and keyboard navigation. If your site hasn't been audited properly, there's a good chance issues are hiding that you don't know about yet.

What are the consequences of not being Section 508 compliant?

For federal agencies, non-compliance can lead to formal complaints, DOJ investigations, and mandated remediation. For vendors, not having documented compliance can mean losing a federal contract. For state and local governments, individuals can file ADA lawsuits without waiting for the DOJ to step in. And fixing accessibility problems after the fact almost always costs significantly more than building it right from the start.

Can a private company build a Section 508 compliant website?

Yes, and it happens all the time. Private web development companies build Section 508 compliant websites for federal agencies and government contractors regularly. What matters is working with a developer who actually understands the requirements, tests with real assistive technology, and builds accessibility into the process from the beginning rather than checking a box at the end.