TL;DR: A state IT department doesn’t have one website to keep compliant — it has dozens or hundreds across agencies, boards, and subdomains, all subject to the same ADA Title II WCAG 2.1 AA deadlines (April 2026 for the state, since it serves more than 50,000 people). Managing this at scale means treating compliance as a portfolio: publish a single standard, deploy central monitoring tooling, run agency scorecards, bake accessibility into procurement (VPATs), and prioritize remediation by traffic and risk. Continuous monitoring becomes your control plane — the shared dashboard that tells you which of 200 sites are drifting out of compliance this week. Start by building an authoritative inventory of every domain and subdomain the state operates.
A city web manager wrestles with one website. A state IT department — the office of the state CIO, the central technology agency, or a shared-services bureau — wrestles with the entire executive branch’s web presence: the department of motor vehicles, health and human services, revenue, labor, parks, the secretary of state, dozens of boards and commissions, and a long tail of micro-sites and legacy subdomains nobody fully remembers launching. Each one is a public-facing service of the same legal entity, and each one is subject to the same ADA Title II accessibility obligations.
Because a state government serves a population far above 50,000, the state and its agencies fall into the earliest DOJ compliance cohort: April 24, 2026 for conformance to WCAG 2.1 Level AA. The CIO or CISO who owns the cross-agency view can’t remediate every page personally — and shouldn’t try. The job is to govern compliance as a portfolio: set the standard, give agencies the tools, measure conformance, and hold owners accountable. This guide lays out how to do that.
Why Portfolio Thinking Beats Site-by-Site Firefighting
The instinct in a decentralized state government is to let each agency handle its own compliance. That fails for three reasons.
First, the legal exposure is shared. A DOJ investigation or a private complaint targets “the State,” not just one agency’s webmaster. One badly inaccessible agency site creates risk for the whole enterprise. See what actually happens when a complaint is filed.
Second, agencies have wildly uneven capacity. A large department may have a UX team and a dedicated accessibility lead; a three-person licensing board has nobody. Site-by-site self-management guarantees that the weakest agencies — often the ones touching the most vulnerable residents — fall furthest behind.
Third, duplication is wasteful. Twenty agencies independently buying scanning tools, writing accessibility statements, and learning WCAG from scratch costs far more than doing it once, centrally, and distributing the result.
Portfolio management replaces this with a model where the central office owns standards, tooling, measurement, and procurement leverage, while agencies own remediation of their own content. The center provides the rails; the agencies run the trains.
Build the Inventory First
You cannot manage what you cannot see, and most states cannot see their full web footprint. The single most valuable thing a state IT office can do is build an authoritative inventory of every domain and subdomain the executive branch operates. This is harder than it sounds — states accumulate sites through legacy projects, grant-funded micro-sites, agency shadow IT, and vendor-hosted applications that never went through central review.
Build the inventory from multiple sources and reconcile them:
- DNS and domain registrar records for every
.govand vanity domain the state owns. - TLS certificate transparency logs, which reveal subdomains that issued certificates.
- Web analytics and CDN accounts that list active properties.
- Agency self-reporting — ask every agency to declare the sites and applications they operate.
For each property, record the owning agency, a business owner and technical contact, the CMS or platform, the hosting arrangement (state data center, cloud, or vendor SaaS), and the estimated traffic. This inventory becomes the spine of the entire program. A site that isn’t in the inventory isn’t being monitored — and is exactly where a complaint will originate.
Publish One Standard, Not Twenty
With the inventory in hand, the central office publishes a single, authoritative web compliance standard that applies to every executive-branch property. This removes the question “what does compliance mean here?” from every agency and replaces it with a checklist they can follow and you can audit against. The standard should specify:
- Accessibility: Conformance to WCAG 2.1 AA as the legal floor (many states adopt 2.2 AA to stay ahead, since 2.2 is backward-compatible). Reference the WCAG 2.2 AA checklist and clarify how it relates to Section 508 for any federally funded systems.
- Privacy: Required privacy policy, cookie/tracker rules, and compliance with applicable state privacy laws.
- Security: Baseline security headers, HTTPS everywhere, and alignment with CISA guidance.
- Performance: Targets for Core Web Vitals, which matter doubly for residents on slow connections and older devices.
- Required artifacts: Every site must publish an accessibility statement with a feedback channel.
Make the standard normative — a policy agencies are required to meet — not a suggestion. Tie it to the enterprise architecture review or whatever governance gate new and redesigned sites already pass through.
Deploy Central Tooling as a Shared Service
The most powerful lever a state IT office has is central tooling delivered as a shared service. Instead of each agency fending for itself, the central office licenses a continuous monitoring platform, configures it against the full inventory, and gives every agency access to its own results — at no cost to the agency.
This shared-services model has compounding advantages:
- One configuration, total coverage. Point the platform at every domain in the inventory and you get enterprise-wide visibility from day one, including the long tail of small sites that would otherwise never be scanned.
- Consistent methodology. Every agency is measured the same way, so scores are comparable and the central office can rank and prioritize honestly.
- Lower total cost. Enterprise licensing is far cheaper than twenty agencies buying overlapping tools — and it eliminates the agencies that buy nothing.
- No barrier to entry for small agencies. The three-person board that could never staff or fund accessibility work gets the same monitoring as the flagship department.
Combine automated monitoring with shared specialist capacity — a small central accessibility team (or an on-call vendor) that handles the things automation can’t: manual screen-reader testing, complex remediation, VPAT review, and training. Automated scanning finds roughly a third to half of WCAG issues; the central specialists handle the judgment-dependent remainder for agencies that lack their own.
Scorecards and Dashboards: Make Compliance Visible
Measurement is what turns a standard from a document into a behavior. The central office should publish a compliance dashboard and per-agency scorecards that make each agency’s status visible — ideally visible to peers and leadership, because nothing motivates a cabinet secretary like ranking below another department.
An effective scorecard reports, per agency and per site:
- Accessibility conformance — count of WCAG failures by severity, and trend over time.
- Privacy and security posture — missing policies, risky trackers, absent security headers.
- Performance — Core Web Vitals pass/fail.
- Required artifacts — accessibility statement present, contact channel working.
- Direction of travel — improving, flat, or regressing since last period.
Two design principles make scorecards work. Roll up and drill down: leadership sees one enterprise number and an agency ranking; an agency webmaster drills into the specific failing pages. And measure trend, not just absolute state: a small agency that started badly but is improving fast deserves different treatment from a large agency that’s quietly regressing. Continuous monitoring is what makes trend visible — a point-in-time audit gives you a single dot, not a line.
Bake Compliance Into Procurement
A large share of a state’s web compliance problems are bought, not built. Agencies license SaaS applications, hire web vendors, and adopt platforms that arrive non-compliant — and then the state inherits the accessibility debt. The central office can stop the bleeding by putting compliance requirements into procurement, where the state’s purchasing power is greatest.
Concretely:
- Require a current VPAT/ACR (Accessibility Conformance Report against WCAG 2.1 AA or 2.2 AA) from every web or application vendor as a condition of bidding. Our VPAT procurement guide covers how to evaluate them.
- Write WCAG conformance and remediation timelines into contracts, with the vendor obligated to fix defects and to maintain conformance through updates.
- Add accessibility, privacy, and security to evaluation criteria so they actually affect award decisions, not just appear as boilerplate.
- Standardize the language. Publish model RFP and contract clauses the whole enterprise reuses, so every agency buys to the same bar. If your office is building or refreshing those requirements, the government compliance tool procurement guide is a useful companion for evaluating the monitoring tooling itself.
Procurement is also where you control the central monitoring tool’s own data handling — ask vendors about hosting location, data residency, and security posture, since you’ll be pointing the tool at every state property.
Prioritize Remediation Like a Portfolio Manager
With 200 sites and finite resources, you can’t fix everything April 1. Prioritize the way a portfolio manager allocates capital — by impact and risk:
- Highest-traffic, highest-stakes services first. The DMV, benefits and Medicaid enrollment, tax filing, unemployment, and licensing portals touch millions of residents and the most safety-net-dependent ones. Failures here are both the biggest legal exposure and the biggest human harm.
- Resident-facing transactional flows over informational pages. A broken keyboard path in an online application blocks a service entirely; a contrast issue on a press release is lower-stakes.
- Severity-weighted failures. Level A blockers (missing form labels, keyboard traps, missing alt text on functional images) outrank minor AA issues. The top accessibility failures list is a good triage guide.
- Sites about to be redesigned — fold compliance into the redesign rather than remediating twice. See the redesign accessibility checklist.
Publish the priority order so agencies understand why the center is pushing them on certain pages and not others.
Accountability Without a Single Throat to Choke
The structural challenge of state IT is that the CIO sets policy but doesn’t directly control agency staff. Accountability has to come through governance, not org-chart authority. The levers that work:
- Executive sponsorship — a governor’s directive or enterprise policy that names web accessibility as a requirement gives the CIO standing.
- Transparent scorecards seen by agency leadership and, where appropriate, the public.
- Gated approvals — new sites and redesigns can’t go live without passing the standard.
- Named owners — every site in the inventory has an accountable business owner, not just a technical contact.
- Regular reporting cadence — a monthly or quarterly compliance report to leadership keeps the topic alive.
Continuous Monitoring as the Control Plane
Tie it together and the architecture becomes clear. The inventory defines the portfolio. The standard defines the bar. Procurement controls what enters the portfolio. Scorecards measure conformance. And continuous monitoring is the control plane that powers all of it — the always-on system that scans every property on the inventory, scores it against the standard, populates the dashboards, and flags drift the moment an agency publishes a regression or a vendor pushes a breaking update.
A point-in-time audit can’t do this job at portfolio scale. You can’t manually audit 200 sites every quarter, and even if you could, the results would be stale before the report was printed. The only sustainable model for an enterprise this large is automated, continuous, centrally configured monitoring with per-agency visibility. The full scope to monitor across accessibility, privacy, security, and performance is laid out in the government website compliance checklist.
State IT departments don’t get to choose between governing one website well and governing two hundred poorly — the legal deadlines apply to the whole portfolio at once. The way through is to stop treating each agency site as a separate fire and start managing the estate: one standard, shared tooling, transparent scorecards, procurement leverage, and risk-based prioritization, all riding on continuous monitoring. Govzu is built for exactly this scale — one platform that monitors every agency domain and subdomain against accessibility, privacy, security, and performance standards, with rollup dashboards for the CIO and drill-down detail for each agency team. Start by building your inventory, then point monitoring at every property you own.