TL;DR: In April 2024 the U.S. Department of Justice published a final rule under ADA Title II that adopts WCAG 2.1 Level AA as the technical standard for the websites and mobile apps of all state and local governments. Large entities (populations of 50,000 or more) must comply by April 24, 2026; smaller entities and special district governments by April 26, 2027. The rule covers nearly all public-facing web content and apps, with narrow exceptions for archived content, certain pre-existing documents, third-party content, and some individualized password-protected documents. There is no exemption for “we’re a small town” — only a later deadline.
For years, government web teams operated in a gray zone. The Americans with Disabilities Act clearly applied to public services, courts agreed websites were covered, and the DOJ pursued ADA website complaints against cities and counties — but there was no regulation that named a specific technical standard or a hard deadline. That changed with the DOJ 2024 final rule on web accessibility, published in April 2024 and codified at 28 CFR Part 35. For the first time, state and local governments have a black-and-white answer to the question “what exactly do we have to do, and by when?”
This is a plain-language summary of the rule: what it covers, the standard it adopts, the compliance deadlines by population size, the exceptions, and what it means practically for a public-sector web team. It is not legal advice, but it should give a city clerk, an IT director, or a university web manager an accurate working understanding of their obligations.
What the Rule Actually Is
The rule is a regulation issued under Title II of the ADA, which prohibits discrimination by public entities — that is, state and local governments. Title II has applied to government websites for decades through DOJ enforcement and court rulings, but it never specified how to make a website accessible. The 2024 rule fills that gap by adopting a concrete technical standard and a compliance timeline.
It is important to understand what the rule does and does not change:
- It does not create a new law. The obligation to provide accessible services already existed under Title II. The rule clarifies the technical requirements.
- It does adopt a specific, measurable standard. Web content and mobile apps must now conform to a named version of WCAG.
- It sets enforceable deadlines. After the compliance date, non-conformance is a regulatory violation, not just a litigation risk.
If you want the broader background on how Title II applies to government, see our overviews of ADA Title II state government obligations and the 2026 deadline for local government.
The Technical Standard: WCAG 2.1 Level AA
The rule adopts Web Content Accessibility Guidelines (WCAG) version 2.1, Level AA as the technical standard. This is the single most important practical fact in the regulation.
A few clarifications that trip people up:
- It’s WCAG 2.1, not 2.0 or 2.2. The DOJ chose 2.1 AA as the legal floor. WCAG 2.1 added several criteria over 2.0 that matter for mobile and low-vision users — reflow, orientation, non-text contrast, and others. We break down what changed between versions in WCAG 2.2 vs 2.1: what changed.
- Level AA, not just A. Level AA includes the criteria most users rely on in practice — color contrast (SC 1.4.3), text resize, captions for video, consistent navigation, and more.
- WCAG 2.2 is a safe target. Because WCAG 2.2 is backward-compatible and adds criteria on top of 2.1, a site built to WCAG 2.2 AA comfortably satisfies the 2.1 AA legal requirement. Most teams should simply aim at 2.2 AA and stop worrying about the version gap. See our WCAG 2.2 AA checklist for government.
If WCAG is new to you, start with what WCAG means for government websites and our primer on web accessibility for government.
Who Has to Comply, and When
The rule applies to all state and local government entities — cities, counties, towns, states, public school districts, public colleges and universities, public libraries, transit authorities, courts, and special district governments (water districts, fire districts, and the like).
The compliance deadline depends on the population the entity serves:
| Entity type | Population served | Compliance deadline |
|---|---|---|
| State and local governments | 50,000 or more | April 24, 2026 |
| State and local governments | Fewer than 50,000 | April 26, 2027 |
| Special district governments | Any size | April 26, 2027 |
A few practical notes on how population is counted:
- It’s the population the entity serves, not its staff or budget. A county of 600,000 is a “large” entity even if its web team is one person.
- Special district governments get the later 2027 date regardless of size. A large regional transit authority still falls under the 2027 deadline because it’s a special district.
- There is no permanent small-entity exemption. Serving fewer than 50,000 people doesn’t excuse you — it gives you roughly one additional year.
For small towns and rural governments worried about capacity, our guide to web accessibility for small local governments covers a realistic path.
What’s Covered
The rule covers web content and mobile apps that the public entity provides or makes available, directly or through contractual, licensing, or other arrangements. In plain terms, that means:
- Your main website and all its pages
- Online services and portals (permits, payments, registrations, records requests)
- Documents posted on your site (PDFs, Word, PowerPoint, spreadsheets) — these are web content
- Native mobile apps you offer to the public
- Web content hosted on third-party platforms but that you use to provide a public program (for example, a benefits portal you direct residents to)
The breadth is the point. The rule deliberately covers nearly everything a member of the public would encounter when interacting with the government online.
The Exceptions (Read These Carefully)
The rule includes a defined set of exceptions. These are narrow, and misunderstanding them is the most common way teams get into trouble. An exception does not mean “this content can be inaccessible forever” — most have conditions attached.
1. Archived web content
Content qualifies as “archived” only if it meets all of these conditions: it was created before the compliance date (or reproduces paper documents created before that date), it’s kept only for reference/research/recordkeeping, it’s kept in a special area for archived content, and it has not been changed since being archived. Edit it, and it loses the exception.
2. Pre-existing conventional electronic documents
Documents such as PDFs, word-processing files, presentations, and spreadsheets that were posted before the compliance date are excepted — unless they are currently used to apply for, access, or participate in a service. So an old meeting agenda from 2019 may qualify, but a tax form still in active use does not, even if it was posted years ago. Practically, this is why PDF accessibility remains a major remediation effort for most governments.
3. Content posted by a third party where the third party is not under contract
User-generated content posted by members of the public — comments on a public forum, for example — is excepted, provided the third party isn’t acting on the entity’s behalf or under contract. This does not cover vendors and contractors you’ve hired; content from a CMS vendor, a payment processor, or an agency you contracted is still your responsibility.
4. Individualized, password-protected documents
Documents about a specific person, that are password-protected and conveyed to that individual (for example, a single resident’s water bill or a student’s tax document in a portal), are excepted from the general requirement — though related general content and the portal itself still must be accessible.
5. Linked third-party content for which you aren’t responsible
A simple link to an external site you don’t control isn’t your obligation. But if you’re using third-party content to deliver your own program or service, you are responsible for it.
The recurring theme: if the content is part of an active government service, assume it’s covered. The exceptions protect stale, archival, or genuinely external material — not the working core of your site.
“Substantial Compliance” and the Practical Standard
The rule allows for the reality that perfection on a large website is nearly impossible. The operative concept is conformance with limited exceptions — minor, isolated defects that don’t meaningfully impair access for people with disabilities don’t necessarily put an entity out of compliance. This is not a loophole. It does not cover known, systemic, or service-blocking failures. It acknowledges that on a 50,000-page site, a single overlooked alt attribute on a decorative image isn’t the same as an inaccessible payment portal.
The safe interpretation: aim for full WCAG 2.1 AA (or 2.2 AA) conformance, fix issues continuously, and document your remediation. The “limited exceptions” language is a defense for good-faith operators, not a target.
What This Means Practically for Your Team
Here is how to translate the rule into action.
1. Determine your deadline. Identify the population your entity serves and whether you’re a special district. That tells you whether you’re working toward April 2026 or April 2027.
2. Run a baseline audit against WCAG 2.2 AA. You can’t plan remediation without knowing your starting point. See how to run a government website accessibility audit and the most common accessibility failures on government websites.
3. Inventory and triage your documents. PDFs are usually the largest single source of non-conformance. Identify which documents support active services (covered) versus which are archival (potentially excepted), and remediate the active ones first.
4. Fix the high-impact, high-frequency issues first. Missing alt text, poor color contrast, and broken keyboard navigation affect users across your entire site and are weighted heavily in automated and manual testing.
5. Address your vendors and contracts. Your CMS, payment portal, and any contracted content are your responsibility. Require accessibility commitments and a VPAT in procurement going forward.
6. Publish an accessibility statement. It signals good faith and gives users a way to report barriers. See how to write an accessibility statement.
7. Set up continuous monitoring. A one-time audit goes stale the moment your staff publishes new content. Government sites change daily, and every new page is a chance to reintroduce a violation.
How This Relates to Section 508 and Federal Rules
State and local governments sometimes confuse the DOJ Title II rule with Section 508, which is the federal procurement-and-IT accessibility standard for federal agencies. They are related but distinct. Section 508 also references WCAG, but it applies to the federal government’s own technology, not to your city or county. We compare them directly in Section 508 vs. ADA Title II. Federal digital-experience expectations are also shaped by the 21st Century IDEA Act, which influences state standards even though it doesn’t bind them.
Where to Find the Official Rule
The rule was published by the U.S. Department of Justice, Civil Rights Division, and amends the Title II regulations at 28 CFR Part 35. You can find the official text and the DOJ’s plain-language fact sheet on ADA.gov, and the rule as published in the Federal Register. When in doubt about a specific obligation — particularly around exceptions or your compliance date — consult the official text and your legal counsel rather than secondary summaries.
The DOJ 2024 final rule turned a decade of ambiguity into a clear, dated obligation: conform to WCAG 2.1 AA by April 2026 or April 2027, depending on your size. The entities that struggle won’t be the ones that started too late on a single audit — they’ll be the ones who fixed everything once and assumed they were done, only to drift out of conformance as staff published new pages, documents, and forms. Continuous monitoring is what keeps a site conformant between audits. Govzu crawls your government website on an ongoing basis, checks every page against WCAG 2.2 AA, and alerts your team the moment new content introduces a violation — so you reach your deadline and stay there.