Skip to main content
← Back to Blog
Compliance7 min readJuly 29, 2026

ADA Compliance and Software Procurement: What Your Organization Needs to Know

Buying software without an ADA compliance review is a liability. Here is what the law requires, what due diligence looks like, and how to build a process that scales.


What the ADA Requires from Software Purchasers

Title II of the Americans with Disabilities Act applies to state and local government entities, including public universities, school districts, municipal agencies, and other public bodies. Title III applies to places of public accommodation, which courts have increasingly interpreted to include websites and digital services offered by private businesses.

Under both titles, organizations are required to ensure that the programs and services they offer — including through third-party software — are accessible to people with disabilities. That means you cannot purchase an inaccessible tool and disclaim responsibility because the vendor built it. The obligation runs to your organization, and the fact that the accessibility failure was the vendor's is a factor in remediation, not a defense against the original complaint.

The practical implication is straightforward: software procurement decisions are ADA compliance decisions. Every contract you sign for a tool that your employees, students, customers, or constituents will use is an implicit representation that you have evaluated whether that tool is accessible.

Section 508 and Its Relationship to the ADA

For federal agencies and organizations that receive federal funding, Section 508 of the Rehabilitation Act adds a separate, explicit requirement. Section 508 requires that electronic and information technology procured, developed, or used by federal agencies be accessible to people with disabilities. Many state-level equivalents extend similar requirements to state agencies and their vendors.

Section 508 is implemented through the ICT Accessibility Standards, which reference WCAG 2.1 Level AA as the technical standard for web and software accessibility. This means that for most covered organizations, WCAG 2.1 AA conformance is the benchmark against which vendor software must be evaluated.

What Due Diligence Looks Like in Practice

The primary mechanism for vendor accessibility due diligence is VPAT review. A Voluntary Product Accessibility Template is a document in which vendors self-report their product's conformance to WCAG 2.1 and Section 508 criteria. Requesting and reviewing a VPAT before contract execution is the baseline expectation for any organization with ADA or Section 508 obligations.

But requesting a VPAT is not the same as reviewing it. Due diligence requires evaluating the VPAT for completeness, specificity, and recency — not simply confirming that one was submitted. An incomplete VPAT, a VPAT with vague or non-committal language, or a VPAT that was written three years ago for a product that has changed significantly since then does not constitute evidence of due diligence.

Organizations that are serious about ADA compliance in procurement also document their reviews. If a complaint arises after procurement, the ability to produce a written record of what you evaluated, what gaps you identified, and what remediation the vendor committed to is what demonstrates that your organization acted in good faith.

Common Legal Risks in Software Procurement

The most common legal risk pattern in software procurement is straightforward: an organization purchases a tool, a user with a disability encounters an accessibility barrier, they file an ADA complaint or OCR complaint, and the organization cannot demonstrate that it performed any accessibility review before signing the contract.

A secondary risk pattern is procurement without ongoing review. Organizations that review accessibility at initial procurement but do not revisit vendor VPATs at renewal may be relying on documentation that no longer reflects the current state of the product — particularly for SaaS tools that release updates frequently.

A third risk pattern is inconsistency: some vendors in a portfolio get rigorous VPAT review and others get none, depending on who handled the procurement and when. This inconsistency is itself a liability, because it suggests that accessibility review is ad hoc rather than systematic.

Building a Scalable Compliance Process

The organizations that manage ADA compliance in procurement most effectively treat it as a system rather than a series of individual judgments. They require VPATs at the RFP stage, use a scoring rubric to evaluate them consistently, document their findings, include accessibility commitments in contract language, and re-evaluate vendor VPATs at each renewal.

The challenge is that this process is time-intensive at scale. A single VPAT review can take an experienced accessibility coordinator one to several hours. For organizations managing dozens of vendor relationships, that time burden is significant.

Inclusive Digital VPAT Evaluator was built to solve this problem. It automates the scoring of vendor VPATs against WCAG 2.1 criteria, identifies incomplete or vague responses, and produces an audit-ready report in seconds. It was designed specifically for ADA coordinators, procurement officers, and compliance teams that need to evaluate vendor accessibility at scale — without sacrificing the rigor that due diligence requires.

If your organization is responsible for ADA compliance in software procurement, this is the process upgrade that makes the difference between a defensible program and one that creates exposure.

Make ADA-compliant procurement the default.

Inclusive Digital automates vendor accessibility scoring so your team can move faster without cutting corners on compliance.

Try VPAT Evaluator