Back to Frameworks

Section 508 - ICT Accessibility (Revised)

United States
v2017 (Revised, WCAG 2.0 AA)
10 domains
30 controls

Section 508 of the Rehabilitation Act (as revised in 2017 incorporating WCAG 2.0 Level AA) requires federal agencies to make their information and communications technology (ICT) accessible to people with disabilities. The revised standards (36 CFR Part 1194) incorporate WCAG 2.0 Level AA success criteria for web, software, and electronic documents, and provide functional performance criteria for hardware. Applies to all federal ICT including websites, software, hardware, and electronic documents.

Verified

Section 508 - ICT Accessibility (Revised) is a compliance framework from United States with 10 domains and 30 controls that map to 68 other frameworks. The largest domains are Chapter 2: Scoping Requirements (6 controls), Chapter 5: Software (6 controls), Chapter 3: Functional Performance Criteria (5 controls). Every control below carries what it requires and what an assessor expects to see.

Maintained by Gerard Blokdyk

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (10)

Chapter 2: Scoping Requirements

6 controls

Chapter 2: Scoping Requirements

Controls in the Chapter 2: Scoping Requirements domain of Section 508 - ICT Accessibility (Revised)6 controls
CodeTitle
E101Application Scope
E205Electronic Content Scoping
E205.4Electronic Content Accessibility
E207Software Scoping
E207.2WCAG Conformance
E208Agency Official Communications

Chapter 3: Functional Performance Criteria

5 controls

Chapter 3: Functional Performance Criteria

Controls in the Chapter 3: Functional Performance Criteria domain of Section 508 - ICT Accessibility (Revised)5 controls
CodeTitle
302.1Functional Performance Without Vision
302.2Functional Performance with Limited Vision
302.3Functional Performance Without Perception of Color
302.4Functional Performance Without Hearing
302.8Functional Performance with Limited Reach and Strength

Chapter 4: Hardware

5 controls

Chapter 4: Hardware

Controls in the Chapter 4: Hardware domain of Section 508 - ICT Accessibility (Revised)5 controls
CodeTitle
402Closed Functionality
403.1Biometrics
407Operable Parts
407.2Contrast Operable Parts
412ICT with Two-Way Voice Communication

Chapter 5: Software

6 controls

Chapter 5: Software

Controls in the Chapter 5: Software domain of Section 508 - ICT Accessibility (Revised)6 controls
CodeTitle
501.0Scope of Software
501.1Scope of Hardware
502Interoperability with Assistive Technology
502.2.1User Control of Accessibility Features
503Applications
504Authoring Tools

Chapter 6: Support Documentation and Services

3 controls

Chapter 6: Support Documentation and Services

Controls in the Chapter 6: Support Documentation and Services domain of Section 508 - ICT Accessibility (Revised)3 controls
CodeTitle
602Support Documentation
603Support Services
603.2Support Services Information About Accommodations

Chapter 7: Referenced Standards

1 controls

Chapter 7: Referenced Standards

Controls in the Chapter 7: Referenced Standards domain of Section 508 - ICT Accessibility (Revised)1 controls
CodeTitle
707Real-Time Text Functionality

Documentation

1 controls
Controls in the Documentation domain of Section 508 - ICT Accessibility (Revised)1 controls
CodeTitle
FIVEOEIGHT-4Support Documentation and Services

Functional Performance

1 controls
Controls in the Functional Performance domain of Section 508 - ICT Accessibility (Revised)1 controls
CodeTitle
FIVEOEIGHT-1Functional Performance Criteria (Chapter 3)

Hardware

1 controls
Controls in the Hardware domain of Section 508 - ICT Accessibility (Revised)1 controls
CodeTitle
FIVEOEIGHT-2Hardware (Chapter 4) - Closed Functionality, Speech, Operability

Software

1 controls
Controls in the Software domain of Section 508 - ICT Accessibility (Revised)1 controls
CodeTitle
FIVEOEIGHT-3Software (Chapter 5) - WCAG 2.0 AA + Authoring Tools

Your Compliance Coverage

If you comply with Section 508 - ICT Accessibility (Revised), you already cover:

Maps to 68 other frameworks

30 total controls
Virginia CDPA
2 source controls mapped|1 target controls covered
7%
Vietnam PDPD
2 source controls mapped|1 target controls covered
7%
Vermont Artificial Intelligence and Consumer Data Act (AICDA)
2 source controls mapped|1 target controls covered
7%
Uruguay DPL
2 source controls mapped|1 target controls covered
7%
UK GDPR (UK General Data Protection Regulation)
2 source controls mapped|1 target controls covered
7%
Turkey KVKK
2 source controls mapped|1 target controls covered
7%
Texas Data Privacy Act
2 source controls mapped|1 target controls covered
7%
Taiwan PDPA
2 source controls mapped|1 target controls covered
7%
Rhode Island Data Transparency and Privacy Protection Act (RIDTPPA)
2 source controls mapped|1 target controls covered
7%
Qatar DPL
2 source controls mapped|1 target controls covered
7%
Privacy Act 2020
2 source controls mapped|1 target controls covered
7%
Privacy Act 1988 (Australia)
2 source controls mapped|1 target controls covered
7%
POPIA
2 source controls mapped|1 target controls covered
7%
Peru DPL
2 source controls mapped|1 target controls covered
7%
Personal Data Act (personopplysningsloven)
2 source controls mapped|1 target controls covered
7%
PDPA Thailand
2 source controls mapped|1 target controls covered
7%
PDPA Singapore
2 source controls mapped|1 target controls covered
7%
Pakistan Personal Data Protection Bill 2023
2 source controls mapped|1 target controls covered
7%
Oregon Consumer Privacy Act
2 source controls mapped|1 target controls covered
7%
NRF Cybersecurity and Data Privacy Framework (National Retail Federation)
2 source controls mapped|1 target controls covered
7%
NIST SP 800-122
2 source controls mapped|1 target controls covered
7%
NIST Privacy Framework
2 source controls mapped|1 target controls covered
7%
Nigeria Data Protection Regulation (NDPR)
2 source controls mapped|1 target controls covered
7%
Nigeria Data Protection Act 2023 (NDPA)
2 source controls mapped|2 target controls covered
7%
Nebraska Data Privacy Act
2 source controls mapped|2 target controls covered
7%
New Jersey Data Privacy Act
2 source controls mapped|1 target controls covered
7%
New Hampshire Data Privacy Act
2 source controls mapped|1 target controls covered
7%
Montana Consumer Data Privacy Act
2 source controls mapped|1 target controls covered
7%
Minnesota Consumer Data Privacy Act
2 source controls mapped|1 target controls covered
7%
Mexico LFPDPPP
2 source controls mapped|1 target controls covered
7%
Mauritius DPA
2 source controls mapped|1 target controls covered
7%
Maryland Online Data Privacy Act of 2024
2 source controls mapped|1 target controls covered
7%
Malaysia PDPA 2010
2 source controls mapped|1 target controls covered
7%
Liechtenstein DPA
2 source controls mapped|1 target controls covered
7%
LGPD
2 source controls mapped|1 target controls covered
7%
Ley Orgánica de Protección de Datos Personales (LOPDP)
2 source controls mapped|1 target controls covered
7%
Law No. 172-13 on the Protection of Personal Data
2 source controls mapped|1 target controls covered
7%
South Korea PIPA
2 source controls mapped|1 target controls covered
7%
Kenya Data Protection Act
2 source controls mapped|1 target controls covered
7%
Kentucky Consumer Data Protection Act
2 source controls mapped|1 target controls covered
7%
Jamaica Data Protection Act 2020
2 source controls mapped|1 target controls covered
7%
Iowa Consumer Data Protection Act
2 source controls mapped|1 target controls covered
7%
Indonesia PDP Law
2 source controls mapped|1 target controls covered
7%
Indiana Consumer Data Protection Act
2 source controls mapped|1 target controls covered
7%
India DPDP Act
2 source controls mapped|1 target controls covered
7%
India Account Aggregator Framework (RBI)
2 source controls mapped|1 target controls covered
7%
7%
HITECH Act
2 source controls mapped|2 target controls covered
7%
Family Educational Rights and Privacy Act (FERPA)
2 source controls mapped|1 target controls covered
7%
Switzerland New Federal Act on Data Protection (nFADP/nDSG, 2023)
2 source controls mapped|2 target controls covered
7%
Singapore Government Instruction Manual on ICT&SS Management (IM8)
2 source controls mapped|1 target controls covered
7%
DAMA-DMBOK2 - Data Management Body of Knowledge (2nd Edition)
2 source controls mapped|1 target controls covered
7%
ISO 22739:2024 - Blockchain and Distributed Ledger Technologies Vocabulary
2 source controls mapped|1 target controls covered
7%
WHO Global Strategy on Digital Health 2020-2025
2 source controls mapped|2 target controls covered
7%
Bahrain PDPL
2 source controls mapped|1 target controls covered
7%
UK Age Appropriate Design Code (Children's Code)
2 source controls mapped|1 target controls covered
7%
ISO 8000 - Data Quality
2 source controls mapped|1 target controls covered
7%
COSO Internal Control - Integrated Framework (2013)
2 source controls mapped|2 target controls covered
7%
APPI
2 source controls mapped|1 target controls covered
7%
US Consumer Product Safety Commission (CPSC) - Connected Product Safety
2 source controls mapped|1 target controls covered
7%
Azure Security Benchmark
2 source controls mapped|1 target controls covered
7%
Saudi Arabia PDPL
2 source controls mapped|1 target controls covered
7%
UK Open Banking Standard
2 source controls mapped|1 target controls covered
7%
GDPR
2 source controls mapped|1 target controls covered
7%
Authorised Economic Operator (AEO) Programmes - Global Standards
2 source controls mapped|1 target controls covered
7%
Barbados Data Protection Act 2019
2 source controls mapped|1 target controls covered
7%

What is Section 508 - ICT Accessibility (Revised) and who does it apply to?

Section 508 - ICT Accessibility (Revised) is a compliance framework from United States with 10 domains and 30 controls. Section 508 of the Rehabilitation Act (as revised in 2017 incorporating WCAG 2.0 Level AA) requires federal agencies to make their information and communications technology (ICT) accessible to people with disabilities. The revised standards (36 CFR Part 1194) incorporate WCAG 2.0 Level AA success criteria for web, software, and electronic documents, and provide functional performance criteria for hardware. Applies to all federal ICT including websites, software, hardware, and electronic documents. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

What does Section 508 - ICT Accessibility (Revised) actually require?

Section 508 - ICT Accessibility (Revised) has 30 controls organised across 10 domains. The largest domains are Chapter 2: Scoping Requirements (6 controls), Chapter 5: Software (6 controls), Chapter 3: Functional Performance Criteria (5 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

If I already comply with another framework, how much of Section 508 - ICT Accessibility (Revised) do I already cover?

Section 508 - ICT Accessibility (Revised) maps to 68 other compliance frameworks. The top mapping partners are Virginia CDPA (7% coverage), Vietnam PDPD (7% coverage), Vermont Artificial Intelligence and Consumer Data Act (AICDA) (7% coverage). Use our comparison tool to explore control-level mappings between frameworks.

How do I implement Section 508 - ICT Accessibility (Revised)?

Start your Section 508 - ICT Accessibility (Revised) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about Section 508 - ICT Accessibility (Revised) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 30 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 686 frameworks.

Get Started Free →

Free forever — no credit card required