Public entities now face a difficult compliance deadline for something most of them have never systematically managed. The DOJ's April 2026 Interim Final Rule extended the Title II deadlines to April 26, 2027, for public entities with a total population of 50,000 or more, and April 26, 2028, for smaller entities and special district governments. The extension bought time, but it didn't make the document problem go away. Siteimprove's work with public entities shows the same pattern: websites got the 2024 and 2025 attention, and the document library is what's still sitting there.

PDF accessibility is now a web content obligation. The 2024 DOJ rule treats four document formats published through government websites as web content: PDF, word processor files such as Word, spreadsheets such as Excel, and presentations such as PowerPoint. Same WCAG 2.1 Level AA standard. Same legal obligation. A PDF backlog that felt manageable before the rule had teeth now has a deadline attached, and the volume of digital documents in most public-sector libraries is bigger than compliance teams tend to estimate before they inventory it.

This guide covers the legal requirements the DOJ rule imposes at the document layer, the enforcement and risk landscape, and what a governed compliance program looks like compared to a remediation sprint:

  • A clear picture of which documents are in scope and where the rule's five exceptions are narrower than assumed.
  • An understanding of why enforcement exposure is live before the formal deadline.
  • The Siteimprove Document Compliance Framework: four phases that sequence work by risk.
  • Criteria for choosing tools at the right scale for your library.

The DOJ rule resolves the ambiguity that lets public entities argue about which documents were covered: Any PDF, word processor file, spreadsheet, or presentation published through a government website or app must conform to WCAG 2.1 Level AA, and the rule's five exceptions are narrower than most compliance teams assume. If it lives on your website and the public can access it, assume it's in scope until you've checked it against those five exceptions.

For PDFs specifically, conformance to WCAG 2.1 Level AA means satisfying all 50 Level A and Level AA success criteria. Criteria that don't apply to a given document, such as captions in a document with no audio, are satisfied by default rather than excused. In practice, the ones that determine most PDFs are:

  • Text alternatives for meaningful images, with decorative ones marked so assistive technology skips them (1.1.1)
  • A tag structure that conveys real relationships, including tables and lists (1.3.1)
  • The correct reading order (1.3.2)
  • Text contrast of at least 4.5:1, or 3:1 for large text at 18pt or 14pt bold, excluding logotypes and incidental text (1.4.3)
  • Programmatically associated labels on form fields (1.3.1, 4.1.2), plus visible labels or instructions where input is required (3.3.2)
  • Keyboard operability with no traps in fillable forms (2.1.1, 2.1.2)
  • Descriptive link text (2.4.4)
  • A declared document language, and declared language changes in multilingual documents (3.1.1, 3.1.2)

Those eight are high-frequency failures, not the whole standard. WCAG conformance is all-or-nothing at each level, so a document that clears eight of them and fails the ninth criterion you didn't check doesn't conform. WCAG was written for web content, and W3C's WCAG2ICT guidance covers how the success criteria apply to non-web documents. The DOJ rule sidesteps that question for public entities by treating these four formats as web content directly.

PDF/UA and WCAG are related standards, not interchangeable ones. PDF/UA (ISO 14289) is the document-specific standard that many remediation tools validate against, and it overlaps heavily with WCAG without being identical. The DOJ rule requires WCAG 2.1 Level AA, so Siteimprove treats a PDF/UA-passing report as evidence, not proof of conformance.

Title II, Section 508, and Section 504

Section 508 governs federal agencies. Title II governs state and local governments: public universities, transit authorities, public hospitals, special districts, the whole roster. Both are anchored to WCAG, but to different versions. The Revised 508 Standards incorporate WCAG 2.0 Level AA by reference, while the Title II rule adopts WCAG 2.1 Level AA. Enforcement mechanisms and compliance timelines also differ. If your organization falls under both, you cannot treat the requirements as interchangeable, and conformance to the 2.1 Level AA satisfies the 508 web content baseline, not the reverse.

WCAG 2.2 is now the current version. It added nine success criteria and removed one, and it is backwards compatible, so content conforming to 2.2 also conforms to 2.1. Building to 2.2 hedges against a future standard revision, but 2.1 Level AA is the bar you're measured against today.

A third rule, Section 504, catches many of these entities. Public hospitals, public universities, and health departments that receive federal financial assistance from HHS are also covered recipients under the Section 504 web accessibility rule, which HHS extended to May 11, 2027, for recipients with 15 or more employees, and to May 10, 2028, for smaller ones. Same standard, different statutory footing. Neither rule sets a precedence order, so a dual-covered entity should plan to the earlier of the two dates.

The five exceptions

The rule includes five exceptions. They cover genuinely narrow situations, not a general exit from remediation work.

The Five Title II Exceptions
Exception What it covers Where it stops

Archived content

Created before the compliance date, retained solely for reference, research, or recordkeeping, kept in a clearly identified archive area, and unchanged since archiving.

All four conditions must apply. Moving a document into an archive after your compliance date doesn't qualify it.

Preexisting conventional electronic documents

Posted before the compliance date. A closed list: PDF, word processor, presentation, or spreadsheet.

Lost the moment a document is used to apply for, gain access to, or participate in a service.

Individualized password-protected documents

About a specific individual, their property, or their account, and secured rather than public facing.

Doesn't reach documents that are public facing or unsecured.

Third-party content

Posted by an unaffiliated third party.

Not content posted under a contractual, licensing, or other arrangement with the entity. Vendor and contractor content is yours.

Pre-deadline social media

Social posts published before the compliance date.

Posts published on or after the compliance date are in scope.

One condition the exceptions table can't convey. An exception removes the WCAG obligation, not the ADA obligation: If someone with a disability needs an exempt document, you still have to provide it in a usable format under effective communication and reasonable modification requirements that predate this rule. The exceptions are a sequencing tool for remediation priority, not permission to leave content alone.

Of the five exceptions, Siteimprove finds archived content stretched the most, and regulators notice. A document still appearing in search results or linked from an active service page is doing work, and the exception has a hard structural requirement that most teams miss: The content has to live in a clearly identified archive area and stay unmodified. Moving a document into an archive folder after your compliance date doesn't retroactively qualify it. The content itself has to predate the deadline.

The DOJ rule contains relief beyond the five exceptions. Section 35.204 preserves the fundamental alteration and undue burden limitations, but the process is formal: The entity carries the burden of proof, the head of the entity or a designee determines after weighing all available resources, and it must be documented in writing. Even then, you comply to the extent you can. An undocumented determination doesn't meet the rule's own requirements.

The rule as codified at 28 CFR Part 35 is the authoritative text for parsing these requirements. The DOJ's Title II web accessibility rule fact sheet is the plain-language summary.

Understand the implications of non-compliance

DOJ enforcement under Title II is largely complaint-driven, though the Department can also initiate compliance reviews on its own. Your exposure is live right now, but not because of WCAG 2.1 Level AA. The technical standard isn't enforceable as a regulatory requirement until your entity's compliance date. What is enforceable today are Title II's longstanding obligations: effective communication, program access, and reasonable modification. These have applied since 1992 and have supported web accessibility claims for years without a specific technical standard. The extension delayed the WCAG deadline. It did not pause anything else. That's the part most organizations miss when they treat the extended deadline as breathing room.

The risks run deeper than legal exposure. Inaccessible documents create real barriers for people with disabilities trying to access government services: a permit application that breaks a screen reader, a benefits form a low-vision user can't read at 200 percent zoom, a public notice published as an untagged image scan. That's a service failure, and the kind that generates complaints in the first place.

What enforcement looks like

DOJ isn't the only enforcement route, and for most entities, it isn't the likeliest one. Title II gives private individuals a right of action, so a resident, student, or advocacy organization can sue directly in federal court without first filing an administrative complaint, and private plaintiffs can seek injunctive relief and attorneys' fees. Entities that also receive federal financial assistance face a parallel Section 504 complaint path through the funding agency.

When a DOJ complaint does land, the Department decides whether to investigate. Complaints cost nothing to file, and the DOJ has broad discretion over which ones it pursues. Once an investigation starts, you have to work with the documentation you have. Title II settlement agreements routinely impose remediation timelines, training, policy adoption, monitoring, and multiyear reporting, and an entity arriving with active workflows, defined ownership, and progress tracking negotiates from a different position than one arriving with a backlog and good intentions. Terms turn on the facts of each case, so treat this as a reason to keep records, not a predicted outcome.

Starting your ADA Title II compliance checklist now isn't just about meeting a deadline. It's about controlling the terms of any enforcement conversation you might find yourself in.

Steps to help documents meet ADA Title II accessibility standards

The Siteimprove Document Compliance Framework sequences four phases: inventory, failure identification, prioritized remediation, and ongoing monitoring. Organizations that skip the first two phases routinely waste remediation budget fixing low-risk documents while high-exposure content stays untouched.

Across public-sector document libraries, Siteimprove sees the same misordering: A team spends three months remediating archived annual reports while the public-facing benefits application on the homepage hasn't been opened in Acrobat.

Phase one: Inventory before remediation

Phase one inventories the document library, and organizations underestimate its size because no one owns it: A single agency website can hold thousands of PDFs accumulated across years of staff turnover, platform migrations, and departmental publishing. Before any remediation work begins, you need a complete picture of what's published, where it lives, and who owns it.

Inventory is the phase that most often gets skipped (usually because it's unglamorous), and it's the one regulators look for when a complaint arrives.

Phase two: Identify failures and score severity

Phase two identifies failures and scores their severity, which sets the remediation sequence. A missing tag on a public-facing permit form carries more legal and user impact than a contrast issue on an archived board meeting agenda. Remediating by severity is defensible, and it shows a good-faith compliance program rather than a reactive cleanup.

Two things to keep straight about severity scoring under ADA Title II. Severity is an operational prioritization concept, not a WCAG one: The standard has conformance levels, not severity tiers. And conformance is all-or-nothing per document, so a partially remediated PDF doesn't conform at Level AA. Sequencing by severity is how you spend a finite budget well. It isn't a partial credit mechanism.

Phase three: Remediate by priority

Phase three is where ADA Title II document remediation follows a prioritized queue: highest-risk public-facing documents first, then legacy reference content. Highest-risk means public-facing service documents first, not whichever files are easiest to fix.

Phase four: Monitor continuously

Phase four closes the loop with ongoing monitoring. New documents enter your library constantly, and a remediation sprint without monitoring infrastructure restarts the backlog cycle.

Accessible authoring standards and prepublish review workflows are what convert phase four from a one-time project into a sustained program.

Tools and resources for auditing PDF and document accessibility

Platform-level governance tools are what separate organizations that maintain compliance from those that perpetually chase it, and for any entity with a substantial document library, file-level remediation utilities won't get you there. The tool that fixes one file at a time has a role, but it's a finishing tool. To prioritize PDF remediation at scale, you need infrastructure that can categorize and sequence work across an entire library.

What governance tools do that remediation utilities don't

File-level tools check and fix individual documents. Governance platforms surface compliance issues across your full library, categorize failures by type and severity, and feed a prioritized remediation queue. For a public entity with thousands of public-facing documents, that difference in capability determines whether digital accessibility is manageable or perpetually behind. Automation changes the volume a team can process. It doesn't change what needs human judgment.

Ask any platform what it detects automatically versus what it flags for human review, and how it supports assistive technology testing on your highest-risk documents. That distinction belongs in every procurement conversation. A platform reporting a conformance percentage without separating machine-checkable criteria from the rest is reporting on a subset and calling it the whole.

Siteimprove.ai surfaces and categorizes accessibility failures across document libraries at scale, connecting document accessibility to procurement decisions to a governed remediation workflow, rather than leaving teams to triage failures manually. The platform integrates with the ADA Title II web accessibility compliance program already in place so document compliance sits within the same governance structure as web accessibility, with shared visibility and reporting.

Design and technology implementation for accessibility

The most durable compliance strategy is upstream prevention: building accessible templates, authoring standards, and prepublish review checkpoints into document creation workflows before inaccessible digital content enters the library.

Upstream prevention is where Siteimprove sees the widest gap between what organizations plan and what they do. Remediation gets resourced. Prevention gets scheduled for "after we clear the backlog" (which never comes). The result is a pipeline that produces new inaccessible documents faster than the remediation queue can process them.

Accessible design defaults aren't advanced practices. Producing an accessible PDF starts at the authoring stage: structured heading hierarchies, proper tagging, and meaningful alt text added when you insert images. These decisions happen at creation time, in tools your team already uses. Microsoft Word and Google Docs both support heading structure and alt text natively. For most routine documents, the barrier is workflow, not technology. The exception to plan for is export: Tagged-PDF output handles headings and alt text reasonably well, but degrades on complex tables, multicolumn layouts, and fillable forms, which need a pass through a PDF editor regardless of how well the source was authored.

Where technology fits in

For PDF accessibility, technology handles automated prepublish scanning, tag-structure validation, and remediation queue management well. Screen reader compatibility isn't one of them. Verifying that a document works with JAWS, NVDA, or VoiceOver requires someone to open it in a screen reader: An automated scan can confirm that a form's fields are tagged and labeled, but not that a blind user can complete it end to end.

AI-assisted tagging accelerates remediation for straightforward documents: clean layouts, standard formatting, and text-based content. Complex layouts, fillable forms, and scanned files still require guided human review (which is worth saying plainly because vendors sometimes oversell automation here). The honest framing is that technology handles volume and humans handle judgment, and judgment is a larger share of the work than edge cases suggest. Automated checks can confirm that a required element is present, not that it is correct: A tool can tell you an image lacks alt text, but not whether the alt text describes the image.

What technology doesn't replace is the upstream authoring decision: A prepublish scanner can flag a missing tag, but it can't retroactively fix a document built on an inaccessible template.

The most legally defensible compliance posture combines both: Documented prepublish checks create an evidence trail of good-faith effort that regulators evaluate when complaints arrive. An organization that can demonstrate consistent prepublish review, even with residual failures, is in a materially stronger position than one that relied on reactive remediation.

Building these checkpoints into existing workflows is also where document accessibility in procurement decisions become relevant: Vendors and contractors producing documents on your behalf are part of your compliance surface, and authoring standards should extend to them.

What comes next?

ADA Title II's document accessibility requirements have deadlines and a technical standard, with two caveats worth tracking. The April 2026 extension arrived as an Interim Final Rule rather than a final one, and the DOJ has signaled it may pursue further rulemaking on the technical standards themselves. The extension is also being litigated: In May 2026 the National Federation of the Blind filed an Administrative Procedure Act challenge asking a federal court to vacate both the DOJ and HHS extensions and restore the original 2024 deadlines. That case was pending as of publication. None of that is reason to slow down, and the DOJ said it fully expects to implement the regulation by the new deadline. But build a program that survives a standard change, not one calibrated to a single date. The gap between web compliance and document compliance is the primary remaining exposure for most public entities.

Organizations that meet these deadlines will be the ones that build governance infrastructure, such as defined ownership, accessible authoring standards, and ongoing monitoring, rather than those that clear a backlog once and hope nothing new breaks.

Start with your document library scope. Inventory what's published before deciding how to fix it because scope determines whether you need a file-level tool or a platform that governs compliance across thousands of documents. That single step changes every resource and prioritization decision that follows.

This content is for informational purposes only and does not constitute legal advice. WCAG is a technical standard; legal obligations vary by jurisdiction and context. Consult qualified counsel for legal guidance.