Openly Published
The report is linked from a public page and opens on click, so a procurement reviewer can read it the same afternoon they think to look for it.
We went looking for a published accessibility conformance report at 107 recognizable SaaS vendors on one day. Thirty had one a buyer could open on the spot. This counts documents, and renders no verdict on any product.
A VPAT (Voluntary Product Accessibility Template) is the standard form a software vendor fills out to describe how its product conforms to WCAG. The completed document is an ACR (Accessibility Conformance Report). Procurement teams in government, education, and the enterprise ask for one before they buy. On August 5, 2026 we checked how many vendors have one sitting where a buyer can find it.
The sample was 107 recognizable SaaS vendors, drawn across six verticals. It includes publicly traded companies and Forbes Cloud 100 members, and no vendor in it is named anywhere on this page.
Thirty vendors clear that bar. The remaining 77 split three ways: 23 hold a report and put a gate in front of it, 50 had nothing we could reach from their public pages, and 4 came back ambiguous enough that we declined to call them either way.
Each vendor landed in exactly one bucket. The four sum to 107, so the arithmetic reconciles without anything quietly dropped along the way.
The report is linked from a public page and opens on click, so a procurement reviewer can read it the same afternoon they think to look for it.
The vendor plainly has a report and asks for something first: a request form, a named sales contact, or an account login. Recorded as existing, behind a gate.
We found no conformance document on the vendor’s public pages. Some of these vendors may hold one internally, or publish one somewhere we did not reach.
The evidence pointed both ways: a broken link to a document, a statement referencing a report it never linked, or a page that would not load. Calling these would have been a guess.
The middle two buckets are the ones worth keeping apart. A vendor holding a finished report behind a request form has done the work and made a distribution choice. A vendor with nothing reachable may be in a different position entirely, or may simply have filed the document somewhere a search of their public pages does not go.
Open publication is not spread evenly across the sample. It clusters, and it clusters where buyers have been asking for the document the longest.
| Vertical | Publish Openly | Rate |
|---|---|---|
| Healthcare IT and Education | 7 of 12 | 58% |
| Developer Tools, Infrastructure, Security | 8 of 14 | 57% |
| Collaboration, Productivity, ITSM | 4 of 8 | 50% |
| CRM, Sales, Marketing | 4 of 14 | 29% |
| Finance, Accounting, Fintech | 5 of 21 | 24% |
| HR, Payroll, People Operations | 2 of 38 | 5% |
Healthcare IT and education sits at 58%. HR, payroll, and people operations sits at 5%. That is an 11x spread across one sample, on one day, under one test.
The obvious reading is procurement pressure. Hospital systems, universities, and school districts have been buying under Section 508 and its state analogues for years, and their solicitations ask for a conformance report by name. Developer tools and infrastructure sell into the same federal and enterprise pipelines. Software bought by a people team has historically faced a checklist that asked about other things. We offer that as a reading, not as a measured cause: this count looked at documents, and it cannot see why a vendor did or did not post one.
Two cautions belong with the table. The verticals are different sizes, so the collaboration row rests on 8 vendors while the HR row rests on 38, and one vendor moves the smallest row by more than 12 points where it moves the largest by under 3. The vertical labels are also ours: a vendor selling into both hospitals and banks had to land in one row, and a different sorting would shift these numbers.
This finding measures one thing: whether a document was reachable from a vendor’s public pages on one date. That is an observation about a web server and a publishing decision, and it stops there.
It is not a judgement about whether any product is accessible, and it cannot be read as one. A vendor that publishes nothing may run a mature accessibility program with a dedicated team and a well-tested product. A vendor that publishes a spotless report may have a product that fails on the first tab press. The document and the product are separate things, and this page looked only at the document.
That distinction is why the sample stays anonymous. Publication status changes the day a vendor posts a PDF, and a page that named companies for what was missing on one Wednesday would be describing a world that no longer exists while still turning up in search results. The aggregate is the durable part, so the aggregate is what gets published.
The method is deliberately shallow, and stating its limits is the point of this section.
When procurement asks a vendor for an accessibility conformance report, a little over one in four can hand one over immediately. The rest route the request through a sales team, or need to write the document before they can answer.
The cost of that shows up late in an evaluation, which is the expensive place for it to show up. A report requested midway through a procurement cycle typically arrives after the window in which it could have changed the decision, and a report drafted under deadline pressure is the kind that ends up marked “Supports” on criteria nobody sat down and tested.
Two things follow. Ask for the document at the start of an evaluation rather than at contract stage, and read the date on it when it arrives. And treat a gated report as neutral: 23 vendors in this sample hold one and route it through a person, which is a distribution policy rather than a signal about the product behind it.
Harbor authors ACRs for a living, and publishes them in the form a buyer can read. See the sample ACR and remediation plan, or read how Harbor authors VPATs.
This is a finding about availability. It counts documents and stops at the point where a document either opens or does not.
The VPAT Accuracy Report is a separate, pre-registered study that asks the harder question: when a vendor’s conformance report marks a criterion “Supports”, does the product hold up against that claim? Its methodology was published before the first scan ran, so the rules cannot drift to fit the results. That study has not reported, and nothing on this page previews what it will find or names a vendor inside it.
The two connect at one point. A conformance document that a buyer cannot read is a document nobody outside the vendor can check, and the accuracy study only has anything to test because some vendors publish openly.
Read the pre-registered methodology for the VPAT Accuracy Report.
The bucket definitions are on this page and the method is stated with its limits attached. If you publish a conformance report we did not reach, or you believe a count here is wrong, tell us and we will re-check it and date the correction.
Corrections and questions go to [email protected].
Contact Harbor