Legal & Compliance

“WCAG 2.2 AA Certified” Is Not a Thing. Here Is What You Actually Bought.

Nobody certifies WCAG conformance — there is no body that issues it. Here is the difference between a conformance claim, an evaluation statement and a VPAT, and what to demand in procurement.

Khushwant Parihar
Khushwant Parihar
7 min read

If a vendor has told you your site is "WCAG 2.2 AA certified," you have been sold something that does not exist. There is no certification body for WCAG. The W3C writes the standard and does not certify anyone against it, no accredited scheme issues WCAG certificates, and no badge carries legal weight. Conformance under WCAG is self-declared.

This matters more than it sounds, because the gap between what an audit tested and what a certificate implies is exactly the gap that surfaces in litigation. Below: what the standard actually offers, what a sampled audit can honestly produce, and the language to put in your next contract.

What WCAG actually offers: an optional claim

WCAG defines a conformance claim, and it is explicitly voluntary. In the standard’s own words, "it is not required to make any conformance claim in order to conform." You can build a fully conformant product and never publish a claim; publishing one changes nothing about the product, only about what you have asserted.

A conformance claim has five required components:

  1. The date of the claim.
  2. The title, version and URI of the guidelines being claimed against — for example WCAG 2.2.
  3. The conformance level satisfied: A, AA or AAA.
  4. A concise description of the pages covered, such as a list of URIs.
  5. A list of the web content technologies relied upon.

Read component four carefully, because it is where most claims quietly fall apart. A claim covers the pages you describe — and every page in that description must fully meet every success criterion at the level claimed. Conformance in WCAG is per-page and all-or-nothing. There is no 94% conformant.

Why a sampled audit cannot produce a claim

Nearly every commercial audit is sample-based, because testing every page of a real product is rarely affordable or useful. The W3C’s evaluation methodology is blunt about the consequence: "WCAG 2 conformance claims cannot be made for entire websites based upon the evaluation of a selected sub-set of web pages and functionality alone, as it is always possible that there will be unidentified conformance errors." It adds that in most situations, using the methodology alone does not put you in a position to make a claim at all.

The logic is simple. A claim asserts something about every page in scope. A sample gives you evidence about the pages you tested. Those are different statements, and no amount of sampling turns the second into the first.

What you actually get: an evaluation statement

The honest deliverable is what WCAG-EM calls an evaluation statement — an optional step in its reporting phase. It says that the samples evaluated met the conformance target defined at the start of the engagement, and it carries the scope, the sample and the baseline alongside it so a reader knows precisely what was examined.

The difference in plain language:

  • Conformance claim: "Every page at these URIs fully meets WCAG 2.2 AA." Self-declared, per-page, all-or-nothing, and undermined by a single failure anywhere in scope.
  • Evaluation statement: "These 31 samples, selected this way, were evaluated against WCAG 2.2 AA on this date using this baseline, and met it." Bounded, evidenced, and reproducible.

The second is weaker on paper and stronger in practice. It is defensible because it describes what somebody actually did, and a second evaluator can repeat it and get the same answer.

Where the VPAT fits

A VPAT — Voluntary Product Accessibility Template — is a template published by the Information Technology Industry Council. Filling it in produces an Accessibility Conformance Report, and buyers commonly ask for "a VPAT" when they mean the completed report.

The word doing the work is Voluntary. A VPAT is a structured self-disclosure: for each criterion the supplier records Supports, Partially Supports, Does Not Support, or Not Applicable, with remarks. Nobody validates it. Its value lies almost entirely in the remarks column — a report where every row says Supports with no explanation is a marketing document, while one that documents partial support and names the affected components is a supplier being straight with you.

A VPAT is not a certificate and does not become one because a third party filled it in. It is worth exactly as much as the evaluation behind it, which is why the sampling and methodology questions matter more than the artifact.

What to require in procurement

If you are buying an audit or evaluating a supplier’s accessibility documentation, these questions separate substance from paperwork:

  1. What exactly was in scope — which product, which views, which account states?
  2. What was the sample, and how was it selected? Ask specifically whether a random sample was included and what it found.
  3. What was the accessibility support baseline — which browsers, screen readers and versions were actually used?
  4. What conformance level was targeted, and at what date?
  5. Is this an evaluation statement or a conformance claim, and if it is a claim, what supports it beyond a sample?
  6. For a VPAT, what evaluation produced the ratings, and who performed it?

A supplier who can answer all six has done real work. One who responds with a badge and a percentage score has not, and the difference will matter to you long before it matters to a court.

The litigation angle

Accessibility claims rarely turn on whether a company tried. They turn on the distance between what was asserted and what a user actually experienced. A certificate implying whole-product conformance, backed by a sampled audit that cannot support it, widens that distance and puts it in writing — and overlay vendors have already demonstrated how badly a confident accessibility promise ages when the underlying product does not deliver.

An evaluation statement narrows it instead. It documents what was tested, what was found and what remains, which is both more honest and considerably easier to defend. Accuracy is the cheaper option here, and it is also the correct one.

Sources

Khushwant Parihar
Written by
Khushwant Parihar

Khushwant Parihar is the founder of Accessibility.build and an accessibility specialist, consultant, and developer with more than four years of professional accessibility and software testing experience. His work covers WCAG auditing, keyboard and screen-reader testing with NVDA, JAWS, and VoiceOver, accessible frontend implementation, remediation workflows, and team enablement.

Found this useful? Share it.

Essential Accessibility Resources

Comprehensive tools, checklists, and guides to help you create inclusive digital experiences

Top Pick

WCAG 2.2 Level AA Requirements

Complete list of every Level A and AA requirement for WCAG 2.2 conformance
wcag 2.2 aa
wcag conformance
View guide

WCAG 2.2 Interactive Checklist

Complete interactive checklist with all 86 WCAG 2.2 success criteria
wcag 2.2
compliance
View checklist

WCAG Success Criteria Guides

In-depth guides to WCAG Level A and AA success criteria with interactive examples, testing methods, and implementation code
wcag
wcag 2.2
View guide

Other posts filed under Legal & Compliance.