Skip to main content
← Back to blog

When Is Section 508 Testing Required: A Complete Compliance Guide

The Scenario That Triggers Section 508 Testing

A federal agency's IT procurement team is finalizing a contract for a new document management platform. Three weeks before deployment, a compliance officer flags that no accessibility testing has been conducted on the web interface or the PDF templates the system generates. The project stalls while the vendor scrambles to produce a Voluntary Product Accessibility Template (VPAT). The remediation cost exceeds the original accessibility line item by a factor of four—a predictable outcome when testing is deferred rather than integrated from the start.

Section 508 testing is not a one-time checkbox at project close. It is a continuous obligation triggered by specific procurement, development, and publishing actions involving federal Information and Communications Technology (ICT). Understanding precisely when testing is required prevents the kind of costly retroactive remediation described above.

When is Section 508 testing required? Section 508 testing is required whenever a federal agency develops, procures, maintains, or uses ICT—including websites, software, electronic documents, kiosks, and telecommunications equipment. The obligation is triggered at procurement (before contract award), at development milestones (before code release), when content is published to agency websites, and when existing ICT is substantially modified. The governing technical standard is WCAG 2.0 Level AA, as incorporated by the Section 508 ICT Refresh effective January 18, 2018. Testing must verify conformance against these criteria before ICT is made available to federal employees or members of the public interacting with agency systems. Delaying testing until post-deployment routinely multiplies remediation costs and creates legal exposure under the Rehabilitation Act.

What Section 508 Is and Why It Applies

Section 508 of the Rehabilitation Act of 1973, as amended by the Workforce Investment Act of 1998, requires that federal agencies ensure their ICT is accessible to people with disabilities—both employees and members of the public. The Access Board's ICT Refresh, effective January 18, 2018, updated the technical requirements to align with WCAG 2.0 Level AA as the binding baseline. The Access Board recommends WCAG 2.1 as best practice, but WCAG 2.0 remains the enforceable standard under Section 508.

Section 508 applies to all federal departments and agencies. It does not apply directly to private-sector companies unless those companies are developing or supplying ICT under a federal contract—at which point the contractor's deliverables must meet Section 508 standards. State and local governments are not covered by Section 508; their obligations flow from the ADA and, where applicable, state statutes.

Scope of ICT Subject to Section 508

The ICT Refresh defines ICT broadly. The following categories are within scope:

  • Web content and web applications — agency websites, intranet portals, web-based forms, and web applications used by employees or the public
  • Software — desktop applications, mobile apps, operating system components, and productivity software procured or developed for agency use
  • Electronic documents — PDFs, Word documents, spreadsheets, and presentations published to agency websites or distributed to the public
  • Telecommunications products — VoIP systems, video conferencing platforms, and TTY-compatible hardware
  • Kiosks and transaction machines — self-service terminals in federal buildings, airports, and public-facing agency locations
  • Multimedia content — audio and video files requiring captions, audio descriptions, and accessible media players

Each category has category-specific technical criteria derived from the WCAG 2.0 Level AA success criteria and the Access Board's functional performance criteria. Testing protocols must address the specific criteria applicable to each ICT type rather than applying a single generic checklist across all formats.

Who Section 508 Applies To

Section 508 applies to federal agencies as the primary obligated entities. The statute covers all executive branch departments, independent agencies, and—by extension through procurement requirements—any vendor or contractor whose product or service constitutes ICT delivered under a federal contract.

Federal Agencies

Every federal agency is required to ensure that ICT it develops, procures, maintains, or uses conforms to Section 508 standards. This includes the General Services Administration (GSA), which maintains section508.gov as the central resource for agency compliance programs, as well as the Access Board, which issues and updates the technical standards.

Federal Contractors and Vendors

Private companies do not face Section 508 obligations for their commercial products in the open market. However, when a company bids on or executes a federal contract that involves ICT, the deliverables must meet Section 508 requirements. Federal Acquisition Regulation (FAR) clauses incorporate Section 508 into solicitations for ICT products and services. Vendors are typically required to submit a VPAT—formally known as an Accessibility Conformance Report (ACR)—documenting how their product meets each applicable standard.

What Does Not Trigger Section 508

Several categories are explicitly excluded from Section 508 scope:

  • ICT used by contractors in their own operations, not delivered to the government
  • Back-office equipment used solely for manufacturing or similar industrial processes
  • National security systems as defined in 40 U.S.C. § 11103(a)
  • ICT procured prior to the ICT Refresh effective date that has not been substantially modified

The substantial modification exception requires careful interpretation. Adding new functionality, migrating to a new platform, or redesigning the user interface generally constitutes a substantial modification that reactivates the Section 508 testing obligation for the affected components.

The Five Trigger Points That Require Section 508 Testing

Section 508 testing is not triggered by a calendar date alone. It is triggered by specific agency actions involving ICT. Five distinct trigger points govern when testing must occur.

1. Procurement and Pre-Award Evaluation

Before a federal agency awards a contract for ICT, the solicitation must include Section 508 requirements, and the agency must evaluate vendor conformance claims. Testing at this stage means reviewing the vendor's ACR (VPAT), conducting independent validation testing where feasible, and confirming that the product meets WCAG 2.0 Level AA criteria for the applicable ICT categories. Accepting an ACR at face value without verification is a compliance risk—ACR accuracy varies significantly across vendors, and unverified claims have been the basis of post-award disputes and complaints.

2. Development Milestones and Pre-Deployment Testing

When a federal agency or its contractor develops custom ICT, Section 508 testing must be integrated into the development lifecycle—not reserved for a final pre-launch review. Best practice, reflected in GSA's guidance, is to test at each sprint or release candidate. Specific pre-deployment gates that trigger mandatory testing include:

  • Completion of front-end UI components before integration
  • Release of any public-facing web page or web application module
  • Finalization of document templates that will be used to generate agency publications
  • Any code release that modifies navigation, form structure, or reading order

3. Publication of Electronic Documents

Every PDF, Word document, spreadsheet, or presentation posted to an agency website or distributed to the public must meet Section 508 standards before publication. This is the trigger point most frequently missed by agencies focused on web and software compliance. An inaccessible PDF published to a federal website is a Section 508 violation regardless of whether the underlying web page passes automated testing.

PDF accessibility conformance requires verifying the tag tree structure, logical reading order, alt text for images, document language declaration, form field labels, and heading hierarchy—none of which automated web scanners evaluate. RemeDocs' PDF remediation process addresses each of these structural requirements and produces documents that conform to the PDF/UA-1 standard (ISO 14289-1:2014), which aligns with Section 508 functional performance criteria for screen reader accessibility.

4. Substantial Modification of Existing ICT

When an agency substantially modifies ICT that was previously compliant—or was acquired before the ICT Refresh—the modification triggers a fresh Section 508 testing obligation for the modified components. Adding a new data visualization feature, redesigning a form workflow, or migrating content to a new CMS all constitute substantial modifications. Agencies should maintain a modification log that documents what changed and confirms which Section 508 criteria were re-tested following each modification.

5. Complaint, Audit, or Legal Proceeding

A formal Section 508 complaint filed with an agency or with the Equal Employment Opportunity Commission (EEOC), a GSA audit, or litigation under the Rehabilitation Act creates an immediate obligation to conduct comprehensive accessibility testing and produce documented conformance evidence. Agencies without a pre-existing testing program and testing records are at a significant disadvantage at this stage. Contemporaneous test results, remediation logs, and ACRs constitute the primary evidence in Section 508 enforcement proceedings.

Section 508 and WCAG: Understanding the Technical Standard

The technical foundation of Section 508 compliance is WCAG 2.0 Level AA, as incorporated by the ICT Refresh effective January 18, 2018. Understanding the relationship between Section 508 and WCAG is essential for structuring a valid testing program.

WCAG 2.0 Level AA as the Binding Baseline

Section 508 references WCAG 2.0 Level AA success criteria for web content and software. This means testing must verify conformance against all Level A and Level AA success criteria in the WCAG 2.0 specification. WCAG 2.1, published as a W3C Recommendation on June 5, 2018, added 17 new success criteria—including mobile accessibility and cognitive accessibility improvements—and the Access Board recommends it as best practice. However, WCAG 2.1 Level AA is not the enforceable Section 508 standard. Agencies testing to WCAG 2.1 are exceeding the minimum requirement, which is defensible and advisable, but agencies must not substitute WCAG 2.1-only testing for WCAG 2.0 coverage.

WCAG 2.2, published as a W3C Recommendation on October 5, 2023, is not incorporated into Section 508 or the current version of EN 301 549 (V3.2.1, March 2021).

How Section 508 Criteria Map to ICT Categories

Section 508 does not apply WCAG 2.0 uniformly to all ICT. The ICT Refresh maps specific technical criteria to specific ICT categories:

  • Web content — WCAG 2.0 Level AA success criteria (1.1.1 through 4.1.3) apply directly
  • Software — Software-specific criteria in Chapter 5 of the Access Board's standards, which reference WCAG 2.0 where applicable
  • Electronic documents — Document-specific criteria in Chapter 10; PDF documents must also conform to PDF/UA-1 (ISO 14289-1:2014) to satisfy the functional performance criteria for screen reader compatibility
  • Hardware — Hardware-specific criteria in Chapter 4, including physical reach and operable parts requirements

ADA Title II and Its Distinct Standard

Federal agencies often ask how Section 508 relates to ADA Title II. They are distinct obligations with overlapping technical requirements. Section 508 applies to federal agencies under the Rehabilitation Act. ADA Title II applies to state and local government entities. Both reference WCAG 2.1 Level AA as the relevant standard for web and mobile content under the DOJ's current regulatory framework—but Section 508's binding baseline remains WCAG 2.0 Level AA under the ICT Refresh. Public entities serving populations of 50,000 or more must comply with ADA Title II web accessibility requirements by April 26, 2027 (extended from the original April 24, 2026 deadline), and entities under 50,000—along with special district governments—have until April 26, 2028 under the DOJ interim final rule effective April 20, 2026.

Section 508 testing is not limited to automated scanning. Automated tools identify approximately 30–40% of WCAG success criteria violations. A complete Section 508 testing program requires three components working in combination:

  • Automated testing — Tools such as axe, WAVE, or PAC 3 (for PDFs) identify detectable issues like missing alt attributes, insufficient color contrast ratios, and absent form labels. These tools produce repeatable, documented results but cannot evaluate reading order, logical heading structure, or the semantic accuracy of tag trees.
  • Manual testing — A trained accessibility specialist evaluates focus order, keyboard navigation paths, meaningful sequence, error identification, and context-dependent alt text accuracy. Manual testing is required to assess WCAG criteria that automated tools cannot evaluate.
  • Assistive technology testing — Testing with screen readers (NVDA, JAWS, VoiceOver), voice control software, and magnification tools confirms that the ICT functions correctly in the environments used by people with disabilities. Screen reader testing of PDFs, in particular, requires evaluating the tag tree traversal order and the accuracy of role assignments in the document's logical structure tree.

Warning: Relying exclusively on automated scan results to certify Section 508 conformance creates legal and operational risk. Enforcement actions and litigation have repeatedly cited the gap between automated pass results and real-world assistive technology failures.

Section 508 Compliance Testing: A Practical Checklist

The following checklist is organized by ICT category. Each item corresponds to a specific Section 508 testing obligation. Use this checklist to structure testing programs, vendor evaluations, and pre-publication reviews.

Web Content and Web Applications

  • Run automated testing on all public-facing pages using a validated tool (axe-core, WAVE, or equivalent) and document results per page
  • Manually test keyboard navigation for all interactive elements: menus, modals, carousels, and data tables
  • Verify that all images have accurate, context-appropriate alt text (not filename strings or generic labels)
  • Confirm color contrast ratios meet WCAG 2.0 Level AA minimums: 4.5:1 for normal text, 3:1 for large text
  • Test all forms for label association, error identification (1.3.1, 3.3.1, 3.3.2), and submission confirmation
  • Verify that video content includes synchronized captions and, where required, audio descriptions
  • Test with JAWS or NVDA to confirm page structure, landmarks, and heading hierarchy are announced correctly
  • Document all findings in a structured test report with pass/fail per success criterion

Electronic Documents (PDFs and Office Formats)

  • Verify the document tag tree is present and complete—untagged PDFs fail Section 508 on first inspection
  • Confirm heading tags (H1 through H6) reflect the actual document structure and reading order
  • Validate alt text for all figures, charts, and images; decorative images must be marked as artifact
  • Check that the document language is set correctly in document properties
  • Verify form fields have programmatic labels and that tab order matches visual order
  • Confirm tables have header cells tagged with TH and scope attributes
  • Run PAC 3 or equivalent PDF/UA validation to produce a machine-readable conformance report
  • Test the final PDF with NVDA + Adobe Acrobat or JAWS + Adobe Acrobat to confirm screen reader traversal

Software and Web Applications (Additional Checks)

  • Verify that all UI components expose correct ARIA roles, states, and properties to assistive technology APIs
  • Test focus management in dynamic content: modals must trap focus; closed modals must return focus to the trigger element
  • Confirm that status messages (errors, confirmations, progress indicators) are announced without requiring focus movement
  • Validate that custom controls (sliders, date pickers, drag-and-drop interfaces) have keyboard-operable equivalents

Vendor and Procurement Evaluation

  • Require an ACR (VPAT 2.4 or later) from all ICT vendors before award
  • Cross-reference ACR claims against independent testing results for high-risk ICT categories
  • Include Section 508 conformance as an evaluation factor in source selection documentation
  • Specify remediation timelines and re-testing obligations in contract language

When remediating PDFs at scale, RemeDocs provides structured remediation workflows that address each checklist item for electronic documents, producing ACR-ready documentation alongside the remediated files.

Common Misconceptions That Create Compliance Gaps

Several persistent misconceptions cause federal agencies and contractors to test inadequately or at the wrong point in the ICT lifecycle.

Misconception 1: Passing an Automated Scan Means Section 508 Compliance

Automated scans detect a subset of WCAG 2.0 Level AA violations—those that are programmatically determinable. Success criteria related to reading order, meaningful sequence (1.3.2), keyboard traps (2.1.2), focus visibility (2.4.7), and consistent navigation (3.2.3) require human judgment and assistive technology testing. An automated pass with underlying manual failures is not a defensible conformance claim.

Misconception 2: PDFs Are Exempt if the Web Page Is Accessible

A PDF published on an accessible web page is independently subject to Section 508. The web page's conformance does not extend to the document. Each PDF must be evaluated on its own tag structure, reading order, and semantic markup. This is the most common gap in agency document publication workflows.

Misconception 3: Section 508 Only Applies to New ICT

The ICT Refresh's substantial modification trigger means that updates to legacy systems reopen Section 508 obligations. Agencies maintaining ICT acquired before 2018 that has since been modified cannot assume grandfathered status for the modified components. The modification date, not the acquisition date, determines testing obligations for updated elements.

Misconception 4: A VPAT From the Vendor Is Sufficient

A VPAT (ACR) is a vendor's self-assessment. It documents claims, not verified conformance. Agencies that rely solely on vendor VPATs without independent testing or validation face compliance risk when those claims prove inaccurate. GSA guidance explicitly recommends that agencies conduct independent testing for high-use or high-risk ICT, particularly software and web applications deployed agency-wide.

What triggers a Section 508 testing obligation? A Section 508 testing obligation is triggered by any of five agency actions: (1) procuring ICT under a federal contract, requiring vendor ACR review and independent validation before award; (2) developing or deploying custom ICT, requiring testing at each development milestone and before any public release; (3) publishing electronic documents—PDFs, spreadsheets, presentations—to agency websites or distributing them to the public, requiring document-level tag tree and reading order validation; (4) substantially modifying existing ICT, which reactivates testing requirements for the modified components regardless of the original acquisition date; and (5) responding to a Section 508 complaint, audit, or litigation, which requires immediate comprehensive testing and documentation of conformance evidence. The governing technical standard is WCAG 2.0 Level AA under the Section 508 ICT Refresh effective January 18, 2018. All five triggers apply regardless of whether the ICT is used by federal employees, contractors, or members of the public.

Frequently Asked Questions About Section 508 Testing

Does Section 508 apply to state and local governments?

No. Section 508 applies to federal agencies under the Rehabilitation Act. State and local governments are subject to ADA Title II. However, state and local entities that receive federal funding may face additional accessibility obligations through Section 504 of the Rehabilitation Act, which prohibits discrimination in federally funded programs.

What is the difference between Section 508 and WCAG?

WCAG—the Web Content Accessibility Guidelines published by the W3C—is a technical standard. Section 508 is a federal law that incorporates WCAG 2.0 Level AA as its technical benchmark for web content and software. Section 508 extends beyond WCAG to address hardware, telecommunications, and documentation through additional chapters in the ICT Refresh. WCAG provides the success criteria; Section 508 provides the legal obligation and enforcement mechanism for federal ICT.

Is a VPAT the same as passing Section 508 testing?

No. A VPAT (Voluntary Product Accessibility Template), formally called an Accessibility Conformance Report, is a vendor's self-reported claim of how their product addresses each Section 508 criterion. It is a disclosure document, not a test result. Independent testing is required to validate VPAT claims, particularly for products used at scale across an agency.

Do PDFs on federal websites need to be Section 508 compliant?

Yes. Every PDF published to a federal agency website or distributed to the public must conform to Section 508's document accessibility requirements. This includes proper tag tree structure, logical reading order, alt text for non-text content, language declaration, and accessible form fields where applicable. Conformance to PDF/UA-1 (ISO 14289-1:2014) is the recognized technical path to meeting these requirements.

What happens if a federal agency fails Section 508 testing?

Individuals can file complaints with the relevant agency's Section 508 program office, with the EEOC (for employee-facing ICT), or pursue litigation under the Rehabilitation Act. Agencies found non-compliant may be required to remediate specific ICT within defined timeframes, document corrective action plans, and submit to follow-up audits. Contractors whose ICT fails Section 508 requirements may face contract disputes, rejection of deliverables, or termination for cause depending on contract language.

How often should Section 508 testing be conducted?

Testing frequency should be tied to the ICT lifecycle, not a fixed calendar interval. Web content should be tested at each significant release. Electronic documents should be tested before each publication. Software should be tested at each deployment milestone. Additionally, agencies should conduct periodic audits of high-traffic ICT—such as primary public-facing websites and frequently downloaded document libraries—on at least an annual basis to catch regressions introduced by content updates or platform changes.

The Trajectory of Federal ICT Accessibility: What to Prepare For

Section 508 enforcement is intensifying on two fronts. First, GSA's government-wide accessibility data collection—through the annual Section 508 assessment required by the Consolidated Appropriations Act of 2023—is producing comparative agency performance data that is publicly reported. Agencies at the low end of this assessment face increased oversight and Congressional scrutiny. Second, the convergence of Section 508 and ADA Title II technical standards around WCAG 2.1 Level AA creates pressure on federal agencies to exceed the WCAG 2.0 minimum, particularly for public-facing digital services where ADA Title II-covered entities interact with the same platforms.

The European Accessibility Act (Directive (EU) 2019/882), in force since June 28, 2025, establishes WCAG 2.1 Level AA—through EN 301 549 V3.2.1—as the de facto global benchmark for digital accessibility. Federal contractors operating in EU markets are now subject to both Section 508 and EAA conformance requirements, making WCAG 2.1 Level AA testing the practical minimum for any organization with cross-jurisdictional ICT obligations.

Agencies and contractors that build Section 508 testing into procurement criteria, development pipelines, and document publication workflows—rather than treating it as a post-deployment audit—will be positioned to meet both current requirements and the more stringent technical standards that regulatory alignment is moving toward. Investing in structured PDF remediation workflows, such as those RemeDocs provides, addresses one of the highest-volume and most frequently cited Section 508 gaps before documents reach publication.

Ready to make your PDFs accessible?

Upload any PDF and get a fully compliant, audit-ready document back in seconds.

Try free PDF audit
← Back to all posts