What Section 508 Is and Why It Carries Real Consequences
A federal procurement officer submits a solicitation package as a 300-page PDF scanned from paper originals—no tags, no reading order, no alt text. A contracting specialist who uses a screen reader cannot access a single line. The agency fails its own accessibility audit, delays the procurement cycle, and faces a Section 508 complaint filed with the agency's Section 508 Coordinator. That scenario is not hypothetical; it is the operational reality for hundreds of federal entities each year.
Section 508 of the Rehabilitation Act of 1973, as amended in 1998 and refreshed in 2018, requires federal agencies to develop, procure, maintain, and use information and communications technology (ICT) in a way that gives people with disabilities access comparable to that available to people without disabilities. The binding technical standard, established by the Access Board's ICT Refresh effective January 18, 2018, is WCAG 2.0 Level AA—with WCAG 2.1 recommended as best practice.
What does Section 508 require? Section 508 of the Rehabilitation Act mandates that federal agencies ensure their ICT—websites, software, electronic documents, kiosks, and telecommunications equipment—is accessible to employees and members of the public with disabilities. The binding technical baseline is WCAG 2.0 Level AA, established by the Access Board's January 18, 2018 ICT Refresh. This applies to agencies developing ICT internally and to vendors supplying ICT under federal contracts. Non-compliant ICT can trigger Section 508 complaints, Office of Civil Rights referrals, and procurement disqualification. Agencies must also provide equivalent access when full compliance is not technically feasible—documented exceptions are required, not assumed. For document remediation workflows, tools like RemeDocs enforce these structural requirements systematically across large document sets.
The Legislative History: From 1973 to the 2018 ICT Refresh
Understanding Section 508's authority requires tracing its legislative arc. The Rehabilitation Act of 1973 established the foundational civil rights framework for people with disabilities in federal programs—predating the Americans with Disabilities Act by 17 years. Section 508 was added as a largely aspirational provision. The 1998 amendment, passed as part of the Workforce Investment Act, gave Section 508 enforcement teeth: agencies became legally obligated to make electronic and information technology accessible, and individuals gained the right to file administrative complaints or civil lawsuits.
The statute remained static while technology evolved dramatically. By the mid-2010s, the original 1998 technical standards no longer mapped to modern web applications, PDFs, mobile interfaces, or cloud-based software. The Access Board initiated a formal rulemaking, and the resulting ICT Refresh was published and became effective January 18, 2018. Key structural changes from the Refresh include:
- Functional performance criteria — replaced device-specific checklists with outcome-based criteria covering vision, hearing, cognition, and physical operation
- WCAG 2.0 Level AA incorporation — web content and electronic documents are now evaluated against the same international standard, unifying federal and global accessibility benchmarks
- Scope expansion — explicitly covers software, hardware, support documentation, and services, not just websites
- Safe harbor for existing content — ICT that complied with pre-2018 standards is grandfathered until it is altered
The Access Board's formal position is that agencies should implement WCAG 2.1—published as a W3C Recommendation on June 5, 2018—as best practice, though WCAG 2.0 Level AA remains the binding regulatory floor under Section 508.
Who Section 508 Applies To: Agencies, Contractors, and the Supply Chain
Section 508 applies directly to federal executive agencies. By statutory extension and contract clause, it reaches every vendor, systems integrator, content producer, and subcontractor whose ICT deliverables will be used by a federal agency or its employees. Applicability is determined not by organizational type but by the nature of the ICT and its federal nexus.
Federal Agencies
All federal executive branch agencies are covered. Legislative and judicial branch entities are not bound by Section 508 but are subject to separate accessibility requirements under their own governing authorities. Covered agencies include Cabinet departments, independent regulatory commissions, and grant-making bodies. Each agency must designate a Section 508 Coordinator responsible for policy, training, acquisition reviews, and complaint handling.
Federal Contractors and Vendors
Any company supplying ICT under a federal contract must meet Section 508 standards for the deliverables covered by that contract. This is enforced through the Federal Acquisition Regulation (FAR) clause 52.239-2 and agency-specific supplements. Vendors who submit Voluntary Product Accessibility Templates (VPATs)—formally called Accessibility Conformance Reports (ACRs)—are asserting conformance claims that procurement officers are required to evaluate. A VPAT that overstates conformance exposes the vendor to contract disputes and potential False Claims Act liability.
Grant Recipients and State Agencies Using Federal Funds
Section 504 of the Rehabilitation Act (not Section 508) governs grant recipients, but many state and local entities adopt Section 508 standards contractually as a condition of federal funding. This creates a de facto Section 508 obligation even for non-federal entities operating federally funded programs.
Section 508 Requirements: What Must Be Accessible
The ICT Refresh organizes Section 508 requirements across seven functional categories. Each maps to specific technical standards drawn from WCAG 2.0, ANSI/ATSC standards for telecommunications, and the Access Board's own functional performance criteria.
Web Content and Applications
Federal websites and web-based applications must conform to WCAG 2.0 Level AA in full. This includes all 38 success criteria at levels A and AA, covering perceivability (text alternatives, captions, adaptable content), operability (keyboard access, sufficient time, seizure safety, navigability), understandability (readable, predictable, input assistance), and robustness (compatibility with assistive technology). WCAG 2.1 adds 17 additional success criteria—the Access Board recommends these but cannot mandate them until a future rulemaking adopts 2.1 as the binding standard.
Electronic Documents
PDFs, Word documents, spreadsheets, and presentations distributed by or to federal agencies must be accessible. For PDFs, this means a conformant tag tree—the semantic structure that assistive technology uses to interpret document content—correct reading order, meaningful alt text for all informational images, accessible form fields with labels, and appropriate color contrast. The PDF/UA-1 standard (ISO 14289-1:2014) provides the most rigorous technical specification for PDF accessibility and aligns with WCAG 2.0 requirements.
Software
Desktop applications, mobile apps, and authoring tools are covered. Software must support platform accessibility APIs so that screen readers, magnification software, and switch access devices can interact with all functional elements.
Hardware and Telecommunications
Physical ICT—kiosks, copiers, phones, video conferencing systems—must meet functional performance criteria for operation without vision, hearing, fine motor control, or speech. Telecommunications products must support TTY-compatible connections and captioning where applicable.
Support Documentation and Services
User manuals, help content, training materials, and technical support must themselves be accessible. An agency cannot provide an accessible web application while distributing its user guide as an untagged PDF.
Section 508 and WCAG: Understanding the Technical Standard
The relationship between Section 508 and WCAG is foundational: Section 508 is the law; WCAG 2.0 Level AA is the technical specification that defines what conformance means in practice. The Access Board incorporated WCAG 2.0 by reference into the 2018 ICT Refresh, meaning WCAG success criteria carry the same legal force as the regulation itself for covered web content and electronic documents.
WCAG 2.0 vs. WCAG 2.1 Under Section 508
WCAG 2.1, published as a W3C Recommendation on June 5, 2018, added 17 success criteria addressing mobile accessibility, low vision, and cognitive accessibility. These include criteria such as 1.3.4 (Orientation), 1.4.10 (Reflow), 1.4.11 (Non-text Contrast), and 4.1.3 (Status Messages). Despite their practical value, these criteria are not binding under Section 508—WCAG 2.0 Level AA remains the regulatory floor. Agencies implementing WCAG 2.1 are adopting a more defensible posture and aligning with international standards like EN 301 549 V3.2.1, but they are exceeding the Section 508 minimum, not meeting a different requirement.
WCAG 2.2 and Section 508
WCAG 2.2 became a W3C Recommendation on October 5, 2023, adding nine new success criteria and deprecating one (4.1.1 Parsing). WCAG 2.2 is not incorporated into Section 508 and is not yet part of EN 301 549. Agencies referencing WCAG 2.2 in procurement specifications are imposing contract requirements beyond the statutory floor—a legitimate procurement decision, but one that should be documented as an agency-specific standard rather than a Section 508 mandate.
Applying WCAG to PDFs Under Section 508
WCAG success criteria were written for HTML web content, but the Access Board's guidance and PDF/UA-1 (ISO 14289-1:2014) map those criteria to the PDF format. For a PDF to be Section 508 conformant, it must have: a valid tag tree with semantically correct element types; a logical reading order that matches visual presentation; programmatic document language; alt text for all informational non-text content; accessible form fields with tooltip labels; and sufficient color contrast for text and UI components. RemeDocs' PDF remediation process systematically addresses each of these requirements, applying tag-level corrections at scale that manual authoring workflows routinely miss.
When Section 508 Testing Is Required
Section 508 testing is required at four distinct points in the ICT lifecycle, and conflating them is a common source of compliance gaps.
At Procurement
Before acquiring ICT, contracting officers must perform a market research accessibility review. This includes evaluating vendor ACRs, requesting product demonstrations with assistive technology, and documenting the basis for a conformance determination. The General Services Administration's (GSA) Accessibility Requirements Tool (ART) provides structured language for including accessibility requirements in solicitations.
During Development
Agencies developing ICT internally—custom web applications, agency-specific software, or document templates—must integrate accessibility testing throughout the software development lifecycle, not just at release. This means automated scanning in CI/CD pipelines, manual keyboard and screen reader testing at each sprint, and accessibility review as a definition-of-done criterion.
At Acceptance
When accepting ICT deliverables from contractors, agencies must verify conformance claims. An ACR is not acceptance—it is a self-attestation. Agencies should conduct independent verification using tools such as the Trusted Tester conformance methodology, which the Department of Homeland Security (DHS) developed as a standardized, reproducible Section 508 testing approach.
On a Recurring Basis
ICT that passes an initial conformance assessment can regress. Websites change content; software receives updates; document templates get modified. Agencies must establish recurring testing schedules—GSA guidance recommends annual assessments at minimum, with higher-risk systems tested more frequently. OMB's annual Section 508 assessment process, mandated by the 2023 amendment to the Consolidated Appropriations Act, now requires agencies to report conformance metrics publicly, creating an accountability mechanism that did not exist before 2023.
Section 508 Compliance Checklist for Electronic Documents and PDFs
Document accessibility is the most frequently cited Section 508 deficiency in agency audits, primarily because document production is decentralized and often performed by staff without accessibility training. The following checklist applies to PDFs and other electronic documents submitted to or distributed by federal agencies.
Structural Requirements
- Tag tree present and valid — an untagged PDF fails Section 508 categorically; every document must contain a complete, well-formed tag structure that assistive technology can traverse
- Semantic element types — headings must use
<H1>through<H6>PDF tags in a logical hierarchy; paragraphs use<P>; lists use<L>,<LI>, and<LBody> - Reading order — the tag tree sequence must match the intended visual reading order; multi-column layouts, sidebars, and footnotes are common failure points
- Document language — the
Langentry in the document catalog must specify the correct BCP 47 language tag (e.g.,en-US) - Document title metadata — the
Titlefield in document properties must be populated andDisplayDocTitleenabled in viewer preferences
Content Requirements
- Alt text for informational images — every
<Figure>tag enclosing a meaningful image requires a concise, accurateAltattribute; decorative images must be tagged as artifacts, not figures with empty alt text - Table structure — data tables require
<TH>elements with correct scope attributes; layout tables must be restructured or fully artifacted - Color contrast — normal-size text requires a minimum contrast ratio of 4.5:1 against its background; large text (18pt or 14pt bold) requires 3:1
- Color independence — charts, diagrams, and status indicators must convey information through shape, pattern, or text labels, not color alone
- Meaningful link text — hyperlink display text must describe the destination or action; generic text such as
click hereorread morefails WCAG 2.0 SC 2.4.4
Form Requirements
- Field labels — every form field must have a programmatic label via tooltip or associated tag; placeholder text does not satisfy this requirement
- Tab order — the tab sequence through form fields must follow logical document flow
- Error identification — validation errors must be identified in text, not only by color or icon
Process Requirements
- ACR on file — for third-party documents and tools, an Accessibility Conformance Report must be obtained and evaluated before acceptance
- Remediation workflow — agencies should maintain a documented process for converting non-conformant legacy documents; RemeDocs provides structured remediation pipelines that address tag tree deficiencies, reading order errors, and alt text gaps systematically
- Testing verification — remediated documents should be verified with both automated tools and screen reader testing (NVDA, JAWS, or VoiceOver) before distribution
Binding technical standard: WCAG 2.0 Level AA, as incorporated by the Access Board's ICT Refresh effective January 18, 2018. The Access Board recommends WCAG 2.1 as best practice, but it is not the regulatory floor under Section 508.
Scope: All federal executive branch agencies and any contractor or vendor supplying ICT under a federal contract. Support documentation and services are explicitly covered—an accessible application with an inaccessible user guide does not achieve full conformance.
PDF standard: PDF/UA-1 (ISO 14289-1:2014) is the most complete technical specification for accessible PDFs and maps directly to WCAG 2.0 requirements. A PDF conforming to PDF/UA-1 satisfies the structural and semantic requirements of Section 508 for electronic documents.
Enforcement mechanisms: Section 508 complaints may be filed with the agency's Section 508 Coordinator, referred to the agency's civil rights office, or escalated to the Department of Justice. Individuals may also file civil suits under Section 504 of the Rehabilitation Act when ICT inaccessibility constitutes a denial of program access. Contractors face procurement consequences including contract non-award, cure notices, and potential False Claims Act exposure for materially false conformance claims.
Annual reporting: Since fiscal year 2023, agencies must submit annual Section 508 conformance assessments to OMB and GSA under the mandate in the Consolidated Appropriations Act, 2023. These reports are publicly available and create a measurable accountability record.
How Section 508 Relates to ADA Title II and the Broader Regulatory Landscape
Section 508 and the Americans with Disabilities Act address different institutional populations but share the same technical standard for web and document accessibility. Understanding the boundary matters for compliance officers managing obligations across federal, state, and private contexts.
Section 508 vs. ADA Title II
Section 508 applies to federal agencies and their contractors. ADA Title II applies to state and local government entities—public universities, transit authorities, municipal websites, court systems. The DOJ's final rule for ADA Title II web and mobile accessibility was published April 24, 2024 and mandates WCAG 2.1 Level AA—one version above the Section 508 floor. Public entities serving populations of 50,000 or more must comply by April 26, 2027 (extended from the original April 24, 2026 deadline), and entities under 50,000—along with special district governments—have until April 26, 2028 under the DOJ interim final rule effective April 20, 2026.
Section 508 vs. Section 504
Section 504 of the Rehabilitation Act is the parent provision that prohibits discrimination against people with disabilities in any program or activity receiving federal financial assistance. Section 508 is a specific, operationalized subset of Section 504 obligations focused on ICT. When an individual cannot access a federal website or document, they may claim a Section 504 violation even when no Section 508 complaint has been filed.
Section 508 and the European Accessibility Act
Federal contractors operating in European markets face a parallel obligation under the European Accessibility Act (Directive (EU) 2019/882), which has been in force since June 28, 2025. The EAA's technical conformance pathway runs through EN 301 549 V3.2.1, which incorporates WCAG 2.1 Level AA in full. A contractor building ICT deliverables to WCAG 2.1 standards—rather than the Section 508 minimum of WCAG 2.0—satisfies both regulatory regimes with a single technical implementation.
Frequently Asked Questions About Section 508
When was Section 508 of the Rehabilitation Act passed?
Section 508 was added to the Rehabilitation Act of 1973 as a substantive enforcement provision through the 1998 amendment included in the Workforce Investment Act of 1998. The most recent technical update—the ICT Refresh—became effective January 18, 2018, replacing the original 1998 technical standards with WCAG 2.0 Level AA and expanded functional performance criteria.
What is the difference between Section 508 compliance and Section 508 conformance?
Conformance is a technical determination—ICT either meets all applicable WCAG 2.0 Level AA success criteria or it does not. Compliance is a legal and programmatic determination—an agency has implemented policies, procurement practices, testing processes, and remediation workflows that produce conformant ICT across its operations. An individual document can conform; an agency achieves compliance through systemic practices.
Does Section 508 apply to contractors?
Yes. Any contractor supplying ICT to a federal agency under a federal contract must ensure that ICT meets Section 508 standards. This obligation flows through FAR clause 52.239-2 and is enforced at the contract level. Vendors submit Accessibility Conformance Reports to document conformance; agencies are required to evaluate those reports as part of the acquisition process.
Is an untagged PDF a Section 508 violation?
An untagged PDF distributed by or to a federal agency for operational purposes is non-conformant with Section 508. Without a tag tree, screen readers cannot determine reading order, heading structure, or the meaning of images. The document fails WCAG 2.0 Success Criterion 1.3.1 (Info and Relationships) and 1.3.2 (Meaningful Sequence) at minimum. Scanned PDFs without OCR and tagging are categorically inaccessible and require full remediation before distribution.
How does Section 508 testing work in practice?
Testing combines automated scanning and manual verification. Automated tools—such as PAC (PDF Accessibility Checker) for PDFs or axe for web content—identify structural errors at scale but cannot evaluate semantic accuracy, meaningful alt text, or reading order logic. Manual testing with screen readers such as JAWS, NVDA, or VoiceOver is required to verify functional accessibility. DHS's Trusted Tester methodology provides a standardized, reproducible protocol for web content. For PDFs, the PDF/UA-1 standard's machine-readable conformance requirements enable automated rule-based checking for structural compliance, with manual review required for content quality.
What is a VPAT and when is it required?
A VPAT (Voluntary Product Accessibility Template) is the template used to produce an Accessibility Conformance Report—the vendor's documented self-assessment of how their ICT conforms to Section 508. Federal acquisition rules require agencies to request and evaluate ACRs for ICT acquisitions above the micro-purchase threshold. The VPAT is voluntary in the sense that the format is industry-maintained (by the Information Technology Industry Council), but providing an ACR during federal procurement is effectively mandatory. The current template version is VPAT 2.5, which covers Section 508, WCAG 2.1, EN 301 549, and ADA in separate reporting columns.
The Path Forward: Section 508 in a WCAG 2.2 and AI-Augmented Environment
Section 508's regulatory floor—WCAG 2.0 Level AA—has not changed since the 2018 ICT Refresh, and the Access Board has not published a proposed rule updating it to WCAG 2.1 or 2.2 as of September 2026. However, three convergent pressures are reshaping the practical meaning of Section 508 compliance.
First, OMB's annual reporting mandate is generating agency-level conformance data at a granularity that did not previously exist. Agencies with persistent conformance gaps—particularly in electronic document accessibility—face increasing scrutiny from oversight bodies and advocacy organizations that now have comparable data across agencies.
Second, AI-generated content and AI-assisted document production introduce new accessibility risks. Automated layout tools, AI-generated PDFs, and large language model-produced documents frequently lack valid tag structures, generate decorative-image alt text that is semantically meaningless, and produce reading orders that diverge from visual presentation. Agencies adopting AI-assisted workflows must build Section 508 verification into the output pipeline, not treat it as an authoring-phase concern. RemeDocs' remediation workflows are designed to operate on document outputs regardless of how they were generated, applying structural and semantic corrections to the tag tree after production.
Third, the ADA Title II WCAG 2.1 mandate is normalizing WCAG 2.1 as the de facto federal standard across government contexts. As state and local governments build procurement, design, and content workflows around WCAG 2.1, federal agencies that remain at the WCAG 2.0 floor will face increasing interoperability friction—and internal pressure to adopt the higher standard voluntarily. Agencies that embed WCAG 2.1 into their accessibility program now will not face a compliance gap when a regulatory update eventually arrives.
The structural investment required is not a future project—it is an operational baseline that Section 508 has required since January 2018. Organizations that treat document remediation as a remedial activity rather than a production standard will continue to generate non-conformant ICT faster than they can fix it.