CIOPages
All RFP question modules

Delivery & Operations

Accessibility questions to ask a software vendor

Questions on conformance with WCAG, EN 301 549 and Section 508, current VPAT or ACR documents, real keyboard and screen-reader support, and the plan for fixing known gaps.

94
questions
28
RFI
32
RFP
34
deep-dive

8 questions from the RFI stage, free

These come from the module as sold. The workbook adds follow-ups, a response format, a weight and a score column to each.

1. Which version and conformance level of WCAG does the product currently conform to (e.g., WCAG 2.1 AA, WCAG 2.2 AA), and what is the scope of that conformance claim (which interfaces, user roles, and product modules are included)?

Why it matters. A 'WCAG compliant' claim that omits the version, level, or covered parts of the product cannot be checked. Buyers need an explicit version/level/scope statement to map vendor conformance to their own legal obligations under ADA, EAA, and Section 508.

Good answer
  • Names a specific WCAG version (2.1 or 2.2) and level (A or AA)
  • Identifies which user interfaces are in-scope (admin console, end-user UI, mobile, embedded widgets)
  • Distinguishes conformance status across modules rather than making a blanket claim
Red flags
  • Generic 'WCAG compliant' with no version or level
  • Scope is silent on admin interfaces, mobile, or AI chat surfaces
  • Conformance claim attributed only to internal self-assessment with no date

2. Provide your current VPAT / Accessibility Conformance Report (ACR) and state the VPAT template version used (e.g., 2.5Rev INT), the exact product name and version covered, and the report's date of issue.

Why it matters. A VPAT/ACR is the standard procurement artifact for accessibility conformance. Buyers must verify that the VPAT covers the product version they will deploy and is recent enough to reflect current capabilities.

Good answer
  • VPAT issued after the most recent major release, within the vendor's own stated refresh cycle
  • VPAT 2.5 or later format (the first editions with WCAG 2.2; current release 2.5Rev, April 2025)
  • Names the exact product version covered
Red flags
  • VPAT predates major releases or new interfaces that have shipped since
  • Product version on VPAT does not match shipping version
  • VPAT covers only a subset of the product without disclosure

3. Can all primary user workflows in the product be completed using a keyboard alone, without requiring a mouse or pointer device?

Why it matters. Keyboard-only operation is foundational to accessibility and is required by WCAG success criterion 2.1.1 (Keyboard, Level A). Keyboard navigation can break in modal dialogs, custom widgets, and drag-and-drop interactions.

Good answer
  • Explicit yes with named exceptions, if any
  • Documents keyboard shortcuts and tab order conventions
  • Identifies any workflows that currently require a pointer
Red flags
  • Vague affirmation without exceptions list
  • Known keyboard traps not disclosed
  • Drag-and-drop or canvas interactions with no keyboard alternative

4. List the known accessibility defects or non-conformances currently tracked in your backlog, and provide target remediation dates for each.

Why it matters. A dated list of known defects shows the buyer which gaps exist today and when the vendor expects to close them.

Good answer
  • Itemized list of known defects with WCAG criterion references
  • Target dates by quarter or release
  • Severity classification (blocker, major, minor)
Red flags
  • Claim of zero known defects
  • No target dates provided
  • Roadmap exists internally but cannot be shared with customers

5. Does the product conform to EN 301 549 (the European accessibility standard for ICT), and which clauses are in scope of that conformance claim?

Why it matters. EN 301 549 V3.2.1 (2021) was cited in the Official Journal as the harmonized standard under the EU Web Accessibility Directive. V4.1.1, published by ETSI in September 2026, maps the standard to the European Accessibility Act and gives presumption of conformity with it once cited in the Official Journal. A WCAG-only conformance claim is insufficient because EN 301 549 covers additional ICT requirements (hardware, two-way voice, real-time text) beyond web content.

Good answer
  • Names the EN 301 549 version (V3.2.1, or V4.1.1 published September 2026)
  • Identifies in-scope clauses beyond Chapter 9 (web)
  • Distinguishes web vs. non-web content vs. software in conformance
Red flags
  • Unaware of EN 301 549
  • Claims EN 301 549 conformance based solely on a WCAG audit
  • No statement about EAA readiness for EU customers

6. Does your VPAT cover all interfaces a buyer's users would interact with, including end-user UI, administrative consoles, mobile applications, and any embedded or chat-style AI surfaces?

Why it matters. Vendors sometimes scope a VPAT to a single end-user web UI and omit admin consoles or mobile clients. AI products can introduce new chat surfaces that may not be covered by an older VPAT.

Good answer
  • Explicit enumeration of which interfaces are in/out of scope
  • Separate VPATs or sections for distinct surfaces where applicable
  • Covers conversational/chat interfaces explicitly
Red flags
  • VPAT silent on admin or mobile surfaces
  • AI chat interfaces excluded with no plan to assess them
  • Scope statement absent

7. Which screen readers and browser combinations are tested against the product (e.g., NVDA + Firefox, JAWS + Chrome, VoiceOver + Safari, TalkBack + Chrome on Android)?

Why it matters. Screen reader behavior varies significantly across combinations. Behavior in an untested combination is unknown. Buyers must know which combinations the vendor has actually validated.

Good answer
  • Names specific screen reader + browser + OS combinations
  • Includes both desktop and mobile screen readers
  • States testing frequency
Red flags
  • Generic 'screen reader compatible' with no combinations listed
  • Only one combination tested
  • Mobile screen readers not mentioned

8. Who is the named accessibility owner within your organization, what is their role, and how can buyers escalate accessibility concerns to them?

Why it matters. A named owner gives the buyer a person accountable for the VPAT, the roadmap and escalations.

Good answer
  • Names a specific role (e.g., Head of Accessibility, Accessibility Program Manager)
  • Owner sits in product/engineering, not just legal or marketing
  • Documented escalation channel for customers
Red flags
  • No named owner
  • Accountability spread across legal/marketing only
  • No customer escalation path

The full set: 94 questions in a scored Excel workbook

  • RFI, RFP and deep-dive sheets, with an evaluator guide on every question
  • A 0–5 score column, suggested weights and a scorecard that totals by depth and section
  • An RFP cover template in Word
  • An audit log of all 147 changes made to the draft

Consultancy License $399, for use with any number of clients.

What the module covers

  • WCAG / EN 301 549 / Section 508 conformance (26)
  • VPAT / Accessibility Conformance Report (13)
  • Keyboard navigation & screen-reader behavior (26)
  • Known gaps & accessibility roadmap (29)

What the audit changed

A language model drafted these questions and a second model critiqued them. Three audit passes followed and made 147 changes. Three examples:

Wrong or outdated citation

Draft: (the European harmonized accessibility standard referenced by the European Accessibility Act)

Now: (the European accessibility standard for ICT)

The EAA (Directive (EU) 2019/882) does not name EN 301 549. AccessibleEU (European Commission), 7 September 2026: ETSI published EN 301 549 V4.1.1 in September 2026, based on WCAG 2.2; until it is cited in the Official Journal the reference remains V3.2.1 (2021, WCAG 2.1 AA). V3.2.1 is cited under the Web Accessibility Directive by Commission Implementing Decision (EU) 2021/1339. Directive (EU) 2019/882 (EAA) names no standard; Article 15 gives presumption of conformity to harmonized standards cited in the Official Journal.

Wrong or outdated citation

Draft: Names the EN 301 549 version (e.g., V3.2.1)

Now: Names the EN 301 549 version (V3.2.1, or V4.1.1 published September 2026)

AccessibleEU (European Commission), 7 September 2026: ETSI published EN 301 549 V4.1.1 in September 2026, based on WCAG 2.2; until it is cited in the Official Journal the reference remains V3.2.1 (2021, WCAG 2.1 AA). V3.2.1 is cited under the Web Accessibility Directive by Commission Implementing Decision (EU) 2021/1339. Directive (EU) 2019/882 (EAA) names no standard; Article 15 gives presumption of conformity to harmonized standards cited in the Official Journal.

Wrong or outdated citation

Draft: EN 301 549 V3.2.1 is the harmonized standard under the EU Web Accessibility Directive.

Now: EN 301 549 V3.2.1 (2021) was cited in the Official Journal as the harmonized standard under the EU Web Accessibility Directive.

Past tense keeps the sentence true after V4.1.1 is cited. As of 2026-10-05 V4.1.1 (published September 2026) is not yet cited in the Official Journal; until it is, the reference remains V3.2.1. Commission Implementing Decision (EU) 2018/2048, as amended by (EU) 2021/1339. https://accessible-eu-centre.ec.europa.eu/content-corner/news/european-accessibility-standard-en-301-549-has-been-updated-2026-09-07_en

Questions about this module

How many accessibility questions are there?

94: 28 for the RFI stage, 32 for the RFP and 34 deep-dive questions for the finalists.

What comes with each question?

Why it matters, what a good answer looks like, the red flags, follow-up questions, the response format, whether most buyers treat it as mandatory, and a suggested weight for scoring.

Were the questions checked?

A language model drafted them and a second model critiqued them. Three audit passes followed (2026-10-05) and made 147 changes, each listed in the workbook with the old and new text. No named subject-matter expert wrote them.

Related