Section 508 and WCAG 2.1 AA checklist

The Revised 508 Standards point to WCAG 2.0 AA, while the ADA Title II rule for state and local governments uses WCAG 2.1 AA. Here is a working checklist for agency web applications.

What the law requires, and what is best practice

Before any Section 508 checklist, get the versions right, because they are often confused. The Revised 508 Standards, published by the U.S. Access Board in January 2017 with compliance required from January 18, 2018, incorporate WCAG 2.0 Level A and Level AA success criteria by reference. That is the legal requirement for federal agencies.

WCAG 2.1 became a W3C Recommendation on June 5, 2018, and added 17 success criteria, 12 of them at Level A or AA. WCAG 2.2 followed on October 5, 2023, adding 9 more and removing 4.1.1 Parsing as obsolete. The W3C encourages using the most current version when developing or updating accessibility policies.

State and local governments face a different rule. The U.S. Department of Justice ADA Title II rule adopted WCAG 2.1 Level AA for web content and mobile apps. An interim final rule in April 2026 moved the compliance dates to April 26, 2027 for public entities with 50,000 or more people, and April 26, 2028 for smaller entities and special districts.

Our practical advice: test to WCAG 2.1 AA. It contains every WCAG 2.0 criterion, so meeting it satisfies the Revised 508 Standards and the ADA Title II rule at the same time.

Section 508 checklist: structure and content

Start with the page itself. These checks catch problems that affect every screen reader user.

  • Every image that conveys meaning has a text alternative, and decorative images are hidden from assistive technology (1.1.1 Non-text Content, A).
  • Headings, lists, tables and form groups are marked up so their structure is available programmatically (1.3.1 Info and Relationships, A).
  • Each page has a title that describes its purpose (2.4.2 Page Titled, A), and the page language is set (3.1.1 Language of Page, A).
  • A skip link or landmark regions let users bypass repeated navigation (2.4.1 Bypass Blocks, A).
  • Prerecorded video has captions (1.2.2 Captions, A).

Keyboard and focus checks

Put the mouse away and try to complete every task with the keyboard alone. This one test finds a large share of real defects.

  • All functionality works from a keyboard (2.1.1 Keyboard, A), and focus never gets trapped in a widget.
  • Focus moves in a logical order (2.4.3 Focus Order, A) and is always visible (2.4.7 Focus Visible, AA).
  • Single-key shortcuts can be turned off or remapped (2.1.4 Character Key Shortcuts, A, new in 2.1).
  • Time limits can be turned off, adjusted or extended (2.2.1 Timing Adjustable, A). Session timeouts in agency apps are a frequent miss.

Visual design checks

Several of the WCAG 2.1 additions are about visual presentation, and they are cheap to get right during design.

  • Text contrast is at least 4.5:1, or 3:1 for large text (1.4.3 Contrast Minimum, AA).
  • Borders of inputs, buttons, focus indicators and meaningful icons reach 3:1 against adjacent colors (1.4.11 Non-text Contrast, AA, new in 2.1).
  • Text can be resized to 200 percent without loss of content (1.4.4 Resize Text, AA).
  • Content reflows at a width equal to 320 CSS pixels without horizontal scrolling, apart from content like data tables that needs two dimensions (1.4.10 Reflow, AA, new in 2.1).
  • The page works in portrait and landscape (1.3.4 Orientation, AA, new in 2.1).

Forms, errors and dynamic content

Agency applications are mostly forms, so this is where the checklist earns its keep.

  • Every input has a visible label or instructions (3.3.2 Labels or Instructions, A).
  • Common personal fields such as name, email and address declare their purpose so browsers can autofill them (1.3.5 Identify Input Purpose, AA, new in 2.1).
  • Errors are identified and described in text, not by color alone (3.3.1 Error Identification, A).
  • Custom controls expose their name, role and state to assistive technology (4.1.2 Name, Role, Value, A).
  • Status messages such as "saved" or "3 results" are announced without moving focus (4.1.3 Status Messages, AA, new in 2.1).

Touch, pointer and text spacing checks

Several WCAG 2.1 criteria were written with phones and tablets in mind. Agency staff and the public increasingly use both, so include them.

  • Anything that uses a multipoint or path-based gesture, such as a pinch or a swipe, also works with a single tap or click (2.5.1 Pointer Gestures, A).
  • Actions fire on release, not on press, or can be aborted or undone (2.5.2 Pointer Cancellation, A).
  • The accessible name of a control contains its visible label text, so voice control users can say what they see (2.5.3 Label in Name, A).
  • Features triggered by shaking or tilting the device can also be done through the interface, and the motion trigger can be turned off (2.5.4 Motion Actuation, A).
  • Nothing breaks when users increase line height, paragraph spacing, letter spacing and word spacing (1.4.12 Text Spacing, AA).
  • Tooltips and pop-ups that appear on hover or focus can be dismissed, can be hovered over without disappearing, and stay visible while the user needs them (1.4.13 Content on Hover or Focus, AA).

WCAG 2.2 items worth adopting now

Neither the Revised 508 Standards nor the ADA Title II rule requires WCAG 2.2 today. Still, several of its additions fix problems agency users hit often, and they cost little when built in from the start.

  • A focused element is never entirely hidden behind sticky headers, footers or banners (2.4.11 Focus Not Obscured Minimum, AA).
  • Drag-and-drop actions have a single-pointer alternative (2.5.7 Dragging Movements, AA).
  • Click and tap targets meet a minimum size or spacing (2.5.8 Target Size Minimum, AA).
  • Help options appear in the same place across pages (3.2.6 Consistent Help, A).
  • Users are not asked to re-enter information they already gave in the same process (3.3.7 Redundant Entry, A).
  • Sign-in does not require a cognitive function test, such as remembering a password or transcribing a code, unless an alternative or help is available, such as allowing paste and password managers (3.3.8 Accessible Authentication Minimum, AA).

Test with tools and with people

Section508.gov describes automated, manual and hybrid testing, and publishes the ICT Testing Baseline so agencies test consistently. Automated scanners are fast and catch missing labels and contrast failures, but they cannot judge whether alt text is meaningful or whether focus order makes sense. Plan for both.

Remember documents. The Revised 508 Standards apply to non-web electronic documents too, including PDFs and office files. If your application generates letters, notices or reports, those outputs need the same care as the screens.

Vendors selling ICT to agencies are often asked for an Accessibility Conformance Report, which explains how a product conforms to the Revised 508 Standards. Many vendors produce one using the Voluntary Product Accessibility Template (VPAT). Write it from real test results, and be specific about partial support.

Build accessibility into every sprint

Accessibility retrofits are expensive because they touch every screen at once. It is cheaper to add these checks to the definition of done, so each feature is tested before it ships. Foundry Peak builds agency web applications to WCAG 2.1 AA as a standard part of delivery, and we test by hand as well as with tools.

Sources

Common questions

Does Section 508 require WCAG 2.1 or WCAG 2.0?

Section 508 requires WCAG 2.0. The Revised 508 Standards, with compliance required since January 18, 2018, incorporate WCAG 2.0 Level A and Level AA success criteria by reference. WCAG 2.1 AA is a common best practice because it includes every WCAG 2.0 criterion plus 12 more at Levels A and AA.

What WCAG level do state and local government websites need?

The U.S. Department of Justice ADA Title II rule requires WCAG 2.1 Level AA for state and local government web content and mobile apps. After an April 2026 extension, entities with 50,000 or more people must comply by April 26, 2027, and smaller entities and special districts by April 26, 2028.

Can automated tools prove Section 508 conformance?

No. Automated scanners find problems such as missing labels and low contrast quickly, but they cannot judge whether alternative text is meaningful, whether focus order is logical, or whether a task is usable with a screen reader. Section508.gov describes automated, manual and hybrid testing. Reliable conformance claims need manual testing.

Tell us what you're building.

We reply within one business day. If we're not the right fit, we'll say so and point you somewhere better.