Back to Frameworks

US Section 508 - ICT Accessibility Standards (Revised 2017)

United States (Federal)
vRevised 2017
24 domains
40 controls

Section 508 of the Rehabilitation Act (29 U.S.C. § 794d), as revised in January 2017 by the US Access Board, requires that all federal government ICT (information and communications technology) be accessible to people with disabilities. The revised standards incorporate WCAG 2.0 Level AA for web and electronic content. Applies to federal agencies developing, procuring, maintaining, or using ICT. The Revised 508 Standards align with EN 301 549 for international harmonisation. Enforced through complaint mechanisms, Section 508 coordinators, and OMB reporting.

Unverified

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (24)

Accessibility Requirements

1 controls
Controls in the Accessibility Requirements domain of US Section 508 - ICT Accessibility Standards (Revised 2017)1 controls
CodeTitle
508-A3Functional Performance Criteria

Chapter 1-2: Application and Scoping

4 controls
Controls in the Chapter 1-2: Application and Scoping domain of US Section 508 - ICT Accessibility Standards (Revised 2017)4 controls
CodeTitle
E101Application Scope
E205Electronic Content Scoping
E207Software Scoping
E208Agency Official Communications

Chapter 3: Functional Performance Criteria

5 controls
Controls in the Chapter 3: Functional Performance Criteria domain of US Section 508 - ICT Accessibility Standards (Revised 2017)5 controls
CodeTitle
302.1Functional Performance Without Vision
302.2Functional Performance with Limited Vision
302.3Functional Performance Without Perception of Color
302.4Functional Performance Without Hearing
302.8Functional Performance with Limited Reach and Strength

Chapter 4: Hardware Accessibility

3 controls
Controls in the Chapter 4: Hardware Accessibility domain of US Section 508 - ICT Accessibility Standards (Revised 2017)3 controls
CodeTitle
402Closed Functionality
407Operable Parts
412ICT with Two-Way Voice Communication

Chapter 5: Software Accessibility

4 controls
Controls in the Chapter 5: Software Accessibility domain of US Section 508 - ICT Accessibility Standards (Revised 2017)4 controls
CodeTitle
501.1Scope of Hardware
502Interoperability with Assistive Technology
503Applications
504Authoring Tools

Chapters 6-7: Support and Communication

4 controls
Controls in the Chapters 6-7: Support and Communication domain of US Section 508 - ICT Accessibility Standards (Revised 2017)4 controls
CodeTitle
602Support Documentation
603Support Services
707Real-Time Text Functionality
WCAG 2.0WCAG 2.0 Level AA Incorporation

Documentation

1 controls
Controls in the Documentation domain of US Section 508 - ICT Accessibility Standards (Revised 2017)1 controls
CodeTitle
508-A8Support Documentation and Services

Governance

1 controls
Controls in the Governance domain of US Section 508 - ICT Accessibility Standards (Revised 2017)1 controls
CodeTitle
508-A1ICT Accessibility Policy and Governance

Hardware

1 controls
Controls in the Hardware domain of US Section 508 - ICT Accessibility Standards (Revised 2017)1 controls
CodeTitle
508-A7Hardware Accessibility

Mobile

1 controls
Controls in the Mobile domain of US Section 508 - ICT Accessibility Standards (Revised 2017)1 controls
CodeTitle
508-A14Mobile Application Accessibility

Multimedia

1 controls
Controls in the Multimedia domain of US Section 508 - ICT Accessibility Standards (Revised 2017)1 controls
CodeTitle
508-A10Video and Multimedia Accessibility

Operations

1 controls
Controls in the Operations domain of US Section 508 - ICT Accessibility Standards (Revised 2017)1 controls
CodeTitle
508-A18Complaint Handling and Reasonable Accommodation

Procurement

1 controls
Controls in the Procurement domain of US Section 508 - ICT Accessibility Standards (Revised 2017)1 controls
CodeTitle
508-A2Procurement Requirements for ICT

Quality Assurance

1 controls
Controls in the Quality Assurance domain of US Section 508 - ICT Accessibility Standards (Revised 2017)1 controls
CodeTitle
508-A15Accessibility Testing Lifecycle

Recordkeeping

1 controls
Controls in the Recordkeeping domain of US Section 508 - ICT Accessibility Standards (Revised 2017)1 controls
CodeTitle
508-A20Records Retention for Accessibility Artifacts

Reporting

1 controls
Controls in the Reporting domain of US Section 508 - ICT Accessibility Standards (Revised 2017)1 controls
CodeTitle
508-A17Public Reporting and Section 508 Self-Assessment

Software

2 controls
Controls in the Software domain of US Section 508 - ICT Accessibility Standards (Revised 2017)2 controls
CodeTitle
508-A5Software Applications Accessibility
508-A6Authoring Tools

Technical Requirements

0 controls

ICT accessibility technical standards

Telecommunications

1 controls
Controls in the Telecommunications domain of US Section 508 - ICT Accessibility Standards (Revised 2017)1 controls
CodeTitle
508-A9Telecommunications and Real-Time Text

Training

1 controls
Controls in the Training domain of US Section 508 - ICT Accessibility Standards (Revised 2017)1 controls
CodeTitle
508-A16Training for Personnel

User Interaction

2 controls
Controls in the User Interaction domain of US Section 508 - ICT Accessibility Standards (Revised 2017)2 controls
CodeTitle
508-A12Forms and Interactive Components
508-A13Time-Based Limits and Notifications

Vendors

1 controls
Controls in the Vendors domain of US Section 508 - ICT Accessibility Standards (Revised 2017)1 controls
CodeTitle
508-A19Third Party and Cloud Service Accessibility

Visual Design

1 controls
Controls in the Visual Design domain of US Section 508 - ICT Accessibility Standards (Revised 2017)1 controls
CodeTitle
508-A11Color, Contrast, and Visual Presentation

Web Accessibility

1 controls
Controls in the Web Accessibility domain of US Section 508 - ICT Accessibility Standards (Revised 2017)1 controls
CodeTitle
508-A4WCAG 2.0 Level A and AA Conformance for Web Content

Your Compliance Coverage

If you comply with US Section 508 - ICT Accessibility Standards (Revised 2017), you already cover:

Maps to 102 other frameworks

40 total controls
Section 508 - ICT Accessibility (Revised)
2 source controls mapped|1 target controls covered
5%
NRF Cybersecurity and Data Privacy Framework (National Retail Federation)
2 source controls mapped|1 target controls covered
5%
NIST SP 800-122
2 source controls mapped|1 target controls covered
5%
NIST Privacy Framework
2 source controls mapped|1 target controls covered
5%
Nigeria Data Protection Regulation (NDPR)
2 source controls mapped|1 target controls covered
5%
Nigeria Data Protection Act 2023 (NDPA)
2 source controls mapped|2 target controls covered
5%
Nebraska Data Privacy Act
2 source controls mapped|2 target controls covered
5%
New Jersey Data Privacy Act
2 source controls mapped|1 target controls covered
5%
New Hampshire Data Privacy Act
2 source controls mapped|1 target controls covered
5%
Montana Consumer Data Privacy Act
2 source controls mapped|1 target controls covered
5%
Minnesota Consumer Data Privacy Act
2 source controls mapped|1 target controls covered
5%
Mexico LFPDPPP
2 source controls mapped|1 target controls covered
5%
Mauritius DPA
2 source controls mapped|1 target controls covered
5%
Maryland Online Data Privacy Act of 2024
2 source controls mapped|1 target controls covered
5%
Malaysia PDPA 2010
2 source controls mapped|1 target controls covered
5%
Liechtenstein DPA
2 source controls mapped|1 target controls covered
5%
LGPD
2 source controls mapped|1 target controls covered
5%
Ley Orgánica de Protección de Datos Personales (LOPDP)
2 source controls mapped|1 target controls covered
5%
Law No. 172-13 on the Protection of Personal Data
2 source controls mapped|1 target controls covered
5%
South Korea PIPA
2 source controls mapped|1 target controls covered
5%
Kenya Data Protection Act
2 source controls mapped|1 target controls covered
5%
Kentucky Consumer Data Protection Act
2 source controls mapped|1 target controls covered
5%
Jamaica Data Protection Act 2020
2 source controls mapped|1 target controls covered
5%
Iowa Consumer Data Protection Act
2 source controls mapped|1 target controls covered
5%
Indonesia PDP Law
2 source controls mapped|1 target controls covered
5%
Indiana Consumer Data Protection Act
2 source controls mapped|1 target controls covered
5%
India DPDP Act
2 source controls mapped|1 target controls covered
5%
India Account Aggregator Framework (RBI)
2 source controls mapped|1 target controls covered
5%
5%
HITECH Act
2 source controls mapped|2 target controls covered
5%
Family Educational Rights and Privacy Act (FERPA)
2 source controls mapped|1 target controls covered
5%
Regulation (EU) 2019/1239 on the Maritime Single Window (MSW)
2 source controls mapped|3 target controls covered
5%
Union Customs Code (UCC) - Regulation (EU) No 952/2013
2 source controls mapped|1 target controls covered
5%
Spain Organic Law 3/2018 on Data Protection and Digital Rights (LOPDGDD)
2 source controls mapped|3 target controls covered
5%
Peru Personal Data Protection Law (Law No. 29733)
2 source controls mapped|4 target controls covered
5%
Turkey Personal Data Protection Law (KVKK - Law No. 6698)
2 source controls mapped|5 target controls covered
5%
Ukraine Law on Personal Data Protection (Law No. 2297-VI)
2 source controls mapped|4 target controls covered
5%
Senegal Law on Personal Data Protection (Law No. 2008-12)
2 source controls mapped|2 target controls covered
5%
Tunisia Organic Law on Personal Data Protection (Law No. 2004-63)
2 source controls mapped|3 target controls covered
5%
Uzbekistan Law on Personal Data (No. ZRU-547)
2 source controls mapped|4 target controls covered
5%
Panama Law on Personal Data Protection (Law No. 81 of 2019)
2 source controls mapped|4 target controls covered
5%
Romania Law No. 190/2018 on Data Protection Measures (GDPR Implementation)
2 source controls mapped|4 target controls covered
5%
Portugal Law No. 58/2019 - Data Protection Implementation Act
2 source controls mapped|2 target controls covered
5%
Qatar Personal Data Privacy Protection Law (Law No. 13 of 2016)
2 source controls mapped|4 target controls covered
5%
UNCITRAL Model Law on Electronic Commerce (1996, updated 2005)
2 source controls mapped|4 target controls covered
5%
Utah Consumer Privacy Act
2 source controls mapped|1 target controls covered
5%
South Korea Credit Information Act
2 source controls mapped|2 target controls covered
5%
Switzerland New Federal Act on Data Protection (nFADP/nDSG, 2023)
2 source controls mapped|1 target controls covered
5%
Rwanda Law No. 058/2021 Relating to the Protection of Personal Data
2 source controls mapped|4 target controls covered
5%
Pakistan Personal Data Protection Bill 2023
2 source controls mapped|3 target controls covered
5%
Peru DPL
2 source controls mapped|1 target controls covered
5%
Vermont Artificial Intelligence and Consumer Data Act (AICDA)
2 source controls mapped|1 target controls covered
5%
Washington My Health My Data Act (MHMD)
2 source controls mapped|2 target controls covered
5%
Singapore Government Instruction Manual on ICT&SS Management (IM8)
2 source controls mapped|1 target controls covered
5%
DAMA-DMBOK2 - Data Management Body of Knowledge (2nd Edition)
2 source controls mapped|1 target controls covered
5%
POPIA
2 source controls mapped|1 target controls covered
5%
Personal Data Act (personopplysningsloven)
2 source controls mapped|1 target controls covered
5%
ISO 22739:2024 - Blockchain and Distributed Ledger Technologies Vocabulary
2 source controls mapped|1 target controls covered
5%
Virginia CDPA
2 source controls mapped|1 target controls covered
5%
Rwanda DPL
2 source controls mapped|1 target controls covered
5%
WHO Global Strategy on Digital Health 2020-2025
2 source controls mapped|2 target controls covered
5%
Philippines DPA
2 source controls mapped|1 target controls covered
5%
Philippines Data Privacy Act (RA 10173)
2 source controls mapped|2 target controls covered
5%
Bahrain PDPL
2 source controls mapped|1 target controls covered
5%
UK Age Appropriate Design Code (Children's Code)
2 source controls mapped|1 target controls covered
5%
TEFCA - Trusted Exchange Framework and Common Agreement
2 source controls mapped|1 target controls covered
5%
Privacy Act 1988 (Australia)
2 source controls mapped|1 target controls covered
5%
ISO 8000 - Data Quality
2 source controls mapped|1 target controls covered
5%
Rhode Island Data Transparency and Privacy Protection Act (RIDTPPA)
2 source controls mapped|1 target controls covered
5%
Wisconsin Data Privacy Act (SB 670)
2 source controls mapped|1 target controls covered
5%
Tennessee Information Protection Act (TIPA)
2 source controls mapped|1 target controls covered
5%
Qatar DPL
2 source controls mapped|1 target controls covered
5%
Switzerland FADP
2 source controls mapped|1 target controls covered
5%
UK Concordat on Open Research Data (UKRI)
2 source controls mapped|2 target controls covered
5%
COSO Internal Control - Integrated Framework (2013)
2 source controls mapped|2 target controls covered
5%
Oregon Consumer Privacy Act
2 source controls mapped|1 target controls covered
5%
UK GDPR (UK General Data Protection Regulation)
2 source controls mapped|1 target controls covered
5%
Privacy Act 2020
2 source controls mapped|1 target controls covered
5%
APPI
2 source controls mapped|1 target controls covered
5%
Vietnam Law on Cybersecurity (No. 24/2018/QH14)
2 source controls mapped|1 target controls covered
5%
Uruguay Personal Data Protection Act (Law No. 18.331)
2 source controls mapped|1 target controls covered
5%
Serbia Law on Personal Data Protection (2018)
2 source controls mapped|1 target controls covered
5%
Vietnam PDPD
2 source controls mapped|1 target controls covered
5%
UK Data Protection Act 2018
2 source controls mapped|1 target controls covered
5%
US Consumer Product Safety Commission (CPSC) - Connected Product Safety
2 source controls mapped|1 target controls covered
5%
Azure Security Benchmark
2 source controls mapped|1 target controls covered
5%
Tennessee IPA
2 source controls mapped|1 target controls covered
5%
PDPA Thailand
2 source controls mapped|1 target controls covered
5%
Saudi Arabia PDPL
2 source controls mapped|1 target controls covered
5%
Turkey KVKK
2 source controls mapped|1 target controls covered
5%
UK Open Banking Standard
2 source controls mapped|1 target controls covered
5%
GDPR
2 source controls mapped|1 target controls covered
5%
Authorised Economic Operator (AEO) Programmes - Global Standards
2 source controls mapped|1 target controls covered
5%
Taiwan PDPA
2 source controls mapped|1 target controls covered
5%
Texas Data Privacy Act
2 source controls mapped|1 target controls covered
5%
Barbados Data Protection Act 2019
2 source controls mapped|1 target controls covered
5%
Uruguay DPL
2 source controls mapped|1 target controls covered
5%
PDPA Singapore
2 source controls mapped|1 target controls covered
5%

Frequently Asked Questions

What is US Section 508 - ICT Accessibility Standards (Revised 2017)?

US Section 508 - ICT Accessibility Standards (Revised 2017) is a compliance framework from United States (Federal) with 24 domains and 40 controls. Section 508 of the Rehabilitation Act (29 U.S.C. § 794d), as revised in January 2017 by the US Access Board, requires that all federal government ICT (information and communications technology) be accessible to people with disabilities. The revised standards incorporate WCAG 2.0 Level AA for web and electronic content. Applies to federal agencies developing, procuring, maintaining, or using ICT. The Revised 508 Standards align with EN 301 549 for international harmonisation. Enforced through complaint mechanisms, Section 508 coordinators, and OMB reporting. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

How many controls does US Section 508 - ICT Accessibility Standards (Revised 2017) have?

US Section 508 - ICT Accessibility Standards (Revised 2017) has 40 controls organised across 24 domains. The largest domains are Chapter 3: Functional Performance Criteria (5 controls), Chapter 1-2: Application and Scoping (4 controls), Chapter 5: Software Accessibility (4 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

What frameworks does US Section 508 - ICT Accessibility Standards (Revised 2017) map to?

US Section 508 - ICT Accessibility Standards (Revised 2017) maps to 102 other compliance frameworks. The top mapping partners are Section 508 - ICT Accessibility (Revised) (5% coverage), NRF Cybersecurity and Data Privacy Framework (National Retail Federation) (5% coverage), NIST SP 800-122 (5% coverage). Use our comparison tool to explore control-level mappings between frameworks.

How do I get started with US Section 508 - ICT Accessibility Standards (Revised 2017) compliance?

Start your US Section 508 - ICT Accessibility Standards (Revised 2017) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about US Section 508 - ICT Accessibility Standards (Revised 2017) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 40 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 700 frameworks.

Get Started Free →

Free forever — no credit card required