๐ŸŽ‰ Beta is now open

Book a free demo
Skip to main content

How to Generate a VPAT with HelloCivic Scanner

Samir Alley

VPATs are essential for procurement and compliance documentation. This step-by-step guide shows how HelloCivic Scanner generates them from real scan data in minutes.

A Voluntary Product Accessibility Template (VPAT) is the standard document format for declaring how well your digital product conforms to accessibility standards. If you've ever responded to a procurement RFP that asks about Section 508 compliance, you've encountered the VPAT.

For government agencies, VPATs serve double duty: they're required when procuring technology products, and they're increasingly expected as part of an agency's own compliance documentation under Title II.

Traditionally, creating a VPAT takes weeks of manual testing and documentation. HelloCivic Scanner generates one from your actual scan data in minutes.

What a VPAT Contains

A VPAT documents conformance against one or more standards โ€” typically:

  • WCAG 2.1 Level A and AA (the baseline for Title II)
  • Section 508 (federal procurement requirement)
  • EN 301 549 (European standard, relevant for international agencies)

For each criterion, the VPAT declares a conformance level:

  • Supports: The product fully meets the criterion
  • Partially Supports: Some aspects meet the criterion, others don't
  • Does Not Support: The criterion is not met
  • Not Applicable: The criterion doesn't apply to this product

Each entry includes remarks explaining the assessment โ€” what works, what doesn't, and what the remediation plan looks like.

Prerequisites

Before generating a VPAT, you need:

  1. A completed scan of the site or application you're documenting
  2. Manual check results for criteria that can't be automated (recommended but not required)
  3. A clear scope โ€” which URLs, features, or sections the VPAT covers

Step-by-Step: Generating Your VPAT

Step 1: Run a Comprehensive Scan

Navigate to Apps > ADA Scanner > Scans and run a full-site scan. The VPAT generator uses scan results as the foundation for automated conformance assessments. A more complete scan produces a more accurate VPAT.

For best results:

  • Include all public-facing pages in the crawl scope
  • Enable JavaScript rendering (to catch dynamic content issues)
  • Run the scan against your production environment (not staging)

Some WCAG criteria can't be fully assessed by automated tools. Navigate to Apps > ADA Scanner > Manual Checks to review these criteria:

  • 1.2.1 Audio-only and Video-only: Do your media alternatives meet requirements?
  • 1.2.5 Audio Description: Is audio description provided for video content?
  • 1.3.2 Meaningful Sequence: Is the reading order logical?
  • 2.4.6 Headings and Labels: Are headings and labels descriptive?
  • 3.1.1 Language of Page: Is the page language correctly declared?

For each manual check, record whether it Supports, Partially Supports, or Does Not Support. Add notes explaining your assessment.

Step 3: Navigate to Reports

Go to Apps > ADA Scanner > Reports and click New Report. Select "VPAT / Accessibility Conformance Report" as the report type.

Step 4: Configure VPAT Scope

The wizard asks you to define:

  • Product name: Your website or application name
  • Product version/date: The version being assessed (or today's date)
  • Standards to include: Select WCAG 2.1 AA, Section 508, or both
  • Scan data source: Choose which scan results to use
  • Manual check data: Include any manual assessments you've completed

Step 5: Review Generated Assessments

The system generates a draft VPAT by mapping scan findings to WCAG criteria:

  • No violations found for a criterion โ†’ marked as "Supports"
  • Violations found โ†’ marked as "Partially Supports" or "Does Not Support" depending on severity and scope
  • Can't assess automatically โ†’ marked as "Not Evaluated" unless you completed manual checks

Review each entry. You can override any automated assessment โ€” for example, if you know a "Partially Supports" should actually be "Supports" because the violations were in content you've since fixed.

Step 6: Add Remarks

Good VPAT remarks are specific and honest. The generator pre-fills remarks based on scan findings:

"Partially Supports. Color contrast violations were identified on 12 of 847 pages, primarily in footer link text. Remediation scheduled for Q2 2026."

Edit these to add context, timelines, or clarifications specific to your situation.

Step 7: Export

Export your completed VPAT in multiple formats:

  • PDF: For formal submissions and procurement responses
  • HTML: For publishing on your accessibility page
  • Markdown: For version control and internal documentation
  • ITIC Template Format: The standard Word format used by the Information Technology Industry Council

Keeping Your VPAT Current

A VPAT isn't a one-time document. It should be updated when:

  • You complete remediation work (moving criteria from "Partially Supports" to "Supports")
  • You run new scans that reveal regressions
  • New content or features are added to your site
  • Standards are updated (WCAG 2.1 to 2.2)

HelloCivic makes updates easy: run a new scan, regenerate the VPAT, and review only the changes. The system highlights what's different since your last version.

Tips for Better VPATs

  1. Be specific in remarks. "Partially supports due to 3 missing alt text attributes on the homepage carousel" is better than "Some images lack alt text."

  2. Include timelines. If something doesn't conform, state when you plan to fix it. This shows good faith.

  3. Scope appropriately. A VPAT for your entire web presence is different from one for a specific application. Be clear about what's covered.

  4. Version and date everything. Include the evaluation date, the product version, and the scan data range.

  5. Don't claim "Supports" unless you're sure. Overclaiming conformance creates legal risk. "Partially Supports" with a clear explanation is always better than a false "Supports."

From Documentation to Action

The real value of a VPAT isn't the document itself โ€” it's the process of creating it. Generating a VPAT forces you to systematically assess every WCAG criterion, identify gaps, and create remediation plans.

Use your VPAT findings to prioritize your accessibility roadmap. The criteria marked "Does Not Support" are your highest priority. "Partially Supports" items need targeted fixes. And "Supports" items need monitoring to prevent regressions.

HelloCivic Scanner makes this entire cycle โ€” scan, assess, document, fix, re-scan โ€” repeatable and efficient. What used to take a consulting firm weeks now takes your team hours.