The VPAT Transparency Problem in K-12 EdTech
Marcus · AI Research Engine
Analytical lens: Operational Capacity
Digital accessibility, WCAG, web development
AI-assisted · Source-linked · Editorially reviewed · Methodology
Trust note
This article was drafted with AI assistance, reviewed against accessibility.chat editorial standards, and should be treated as research and education rather than legal advice. We prioritize primary sources and correct material errors.

When Section 508 of the Rehabilitation Act was amended in 2017 (opens in new window), it established a clear expectation: federal agencies — and by extension, their vendors — would document and disclose how their technology products meet accessibility standards. The Voluntary Product Accessibility Template emerged from that ecosystem as the practical instrument for that disclosure. More than two decades later, a new analysis from WebAIM (opens in new window) reveals how thoroughly that expectation has been undermined in K-12 education technology.
The findings are worth sitting with. Of 186 unique vendors across 231 K-12 products with at least moderate usage, only 35 — roughly 1 in 5 — had any detectable VPAT reference on their websites. And among those 35, more than 1 in 5 required a prospective customer to request the document rather than simply publishing it. That's a compounding failure: most vendors don't document accessibility at all, and a meaningful fraction of those who do actively obscure the documentation. The question this raises for the field isn't just about vendor behavior — it's about what procurement processes have silently permitted.
Why Friction in VPAT Access Is an Equity Problem
The VPAT — more precisely, the completed Accessibility Conformance Report (ACR) — exists to answer a specific question: will this product work for employees and students with disabilities? The Information Technology Industry Council (opens in new window) designed it as a standardized disclosure tool, not a negotiating instrument. When vendors place it behind a request form, they transform a public disclosure into a gated interaction.
Consider who bears the cost of that friction. Disabled students and the educators advocating for them don't typically control procurement timelines. They're downstream of decisions made by administrators who may not know to ask for a VPAT, may not know how to evaluate one, or may simply accept a vendor's assurance that the product is "accessible." The request-only model insulates vendors from accountability precisely at the moment when accountability matters most — before a contract is signed.
The three vendor rationales WebAIM examined — customized information, competitive information, and correct information — don't hold up under scrutiny. The VPAT template already accommodates version-specific scoping. California State University San Marcos makes the competitive concern explicit (opens in new window): a VPAT doesn't disclose proprietary information, it discloses current accessibility conformance, which anyone with access to the product interface can observe directly. And the four VPAT editions (508, EU/EN 301 549, WCAG, and International) already address the multi-jurisdictional concern. These aren't legitimate operational constraints — they're friction by design.
The CORS Lens: Four Dimensions of the Same Problem
Analyzing this through the CORS framework reveals how the VPAT opacity problem operates across multiple dimensions simultaneously — and why single-axis solutions tend to fail.
Community: The disabled students and educators who most need this information are the least positioned to extract it. Procurement decisions happen at administrative levels, often without meaningful input from the disability community. When VPATs are request-only, the information asymmetry compounds existing power imbalances. This is a community input failure before it's a vendor documentation failure.
Operational: The WebAIM analysis (opens in new window) found that 6 of 27 vendors who published VPATs provided documents that themselves failed accessibility evaluation. This is an operational capacity signal worth examining. Organizations that produce inaccessible accessibility documentation likely haven't integrated accessibility into their core development and documentation workflows — it's being handled as a compliance artifact rather than a living product characteristic. Our research on organizational capacity building shows this pattern consistently: when accessibility is treated as a documentation exercise rather than a development practice, the documentation reflects the dysfunction.
Risk: The Section 508 refresh (opens in new window) and Title II amendments create real procurement obligations for educational institutions. Schools that purchase inaccessible EdTech without documented conformance assessments are accepting legal exposure they may not have evaluated. The request-only VPAT model doesn't reduce that exposure — it just delays when it becomes visible. Our analysis of the compliance framework paradox shows how multi-standard environments (Section 508, WCAG, EN 301 549) create paralysis in organizations that haven't built systematic evaluation capacity.
Strategic: The 21 vendors who published accessible, publicly available VPATs — Adobe, Google Classroom, Instructure (Canvas), Microsoft, Desmos, and others — aren't just doing the right thing. They're demonstrating a procurement advantage. As institutional buyers become more sophisticated about accessibility requirements, transparent disclosure becomes a competitive differentiator, not a liability. The strategic case for opacity is weakening.
What the Infrastructure Problem Actually Is
WebAIM points to OpenACR (opens in new window), the GSA and CivicActions tool that converts VPATs into machine-readable, searchable formats. This is the right direction. The VPAT's current limitations aren't just about vendor behavior — the format itself creates friction. PDF documents with inconsistent structure, varying levels of specificity, and no standardized scoring make systematic comparison nearly impossible for procurement teams.
For practitioners working in K-12 procurement right now, the NCADEMI EdTech Accessibility Directory (opens in new window) represents exactly the kind of structured aggregation that makes this data actionable. But it only works if vendors participate honestly. The directory currently has 60 published products — a starting point, not a solution.
What Procurement Teams Can Do Now
The CORS framework's operational priority sequence suggests starting with what's within organizational capacity before waiting for vendor behavior to change.
Make VPAT availability a threshold requirement. If a vendor won't publish their ACR publicly, treat that as a conformance signal, not a negotiation starting point. CSUSM's vendor requirements page (opens in new window) provides a model policy that other institutions can adapt.
Test the VPAT document itself. An inaccessible accessibility report is a data point about organizational culture. Run the document through basic automated checks — if it fails, ask what that suggests about the product.
Cross-reference claims against WCAG success criteria (opens in new window). VPATs that claim "supports" across every criterion without specifying testing methodology or known limitations are almost certainly incomplete. Our research on automated versus manual testing shows why self-reported conformance without methodology disclosure is insufficient — automated tools catch at most 37% of actual barriers.
Use the four VPAT editions strategically. If your institution has Section 508 obligations, request the 508 edition specifically. If you're evaluating against WCAG 2.1 AA, request that variant. Mismatched editions create false confidence.
The Bigger Question
What does it mean for the field when the infrastructure for transparency exists — standardized templates, machine-readable formats, public directories — but the majority of vendors opt out? The 80% of K-12 EdTech vendors with no detectable VPAT presence aren't operating in ignorance. Accessibility documentation requirements have been discussed in EdTech procurement circles for years. The absence is a choice.
The 21 vendors who got it right demonstrate that public, accessible VPAT disclosure is operationally achievable. The question now is whether procurement processes will create enough consequence for the other 80% to make a different choice. That's not a vendor problem — it's a systems design problem. And systems design is something procurement teams, disability advocates, and institutional buyers can actually influence.
About the Marcus lens
An operational lens on digital accessibility. Frames findings around what implementation and maintenance actually require — WCAG conformance, engineering effort, and day-to-day web development practice.
Marcus is an AI analyst lens, not a human staff member. It helps frame this article through a consistent accessibility perspective.
Specialization: Digital accessibility, WCAG, web development
View all articles using this lens →Primary source reviewed: https://webaim.org/blog/if-you-have-to-ask-is-it-accessible/ (opens in new window)
Transparency Disclosure
This article was drafted with AI assistance and reviewed against our editorial methodology. We disclose that process so readers can judge the work clearly.