Title II of the Americans with Disabilities Act prohibits disability discrimination by state and local government entities. It has applied to public entities since the ADA was enacted in 1990, and courts and the U.S. Department of Justice have long treated websites and other digital services as part of the programs, services, and activities Title II covers. What was missing for most of that period was a specific technical standard. Public entities knew they had an obligation but had no regulation telling them what an accessible website actually had to meet.
In April 2024, the Department of Justice issued a rule that supplied that standard. The rule is codified at 28 CFR part 35, subpart H, titled Web and Mobile Accessibility, and it requires state and local government entities to make their web content and mobile applications conform to a named technical standard by a named date. In April 2026, the Department issued an interim final rule that extended both compliance dates by one year. The extended dates are the ones now written into the Code of Federal Regulations.
The practical effect is that public entities are no longer working from general principles. There is a rule, a standard, a deadline, and a defined set of exceptions. This page explains what the rule requires, who it covers, what content falls inside it, and what a public entity can reasonably do to prepare. It is written for people who have to act on the rule rather than litigate it.
The rule applies to public entities as Title II defines them. That includes state governments and their agencies, departments, boards, and commissions; counties, cities, towns, townships, and villages; public school districts; public colleges, universities, and community colleges; special district governments such as transit, water, utility, library, fire, and similar single-purpose districts; and instrumentalities of any of these.
Coverage does not depend on whether an entity receives federal funding, how large it is, or whether it has a dedicated technology staff. A small rural water district and a state department of motor vehicles are both public entities under Title II. Size affects only which compliance date applies, not whether the rule applies at all.
Title II does not, on its own, extend these specific requirements to private businesses or to private nonprofits. Private entities may have obligations under other parts of the ADA or under other laws, and organizations that receive federal financial assistance may have parallel obligations under Section 504 of the Rehabilitation Act. Those are separate frameworks with their own standards and their own timelines.
Two compliance dates apply, and which one applies to a given entity depends on its total population as the rule defines that term. Both dates below reflect the one-year extension the Department of Justice adopted in April 2026 and are the dates currently codified in 28 CFR 35.200.
Public entity, other than a special district government, with a total population of 50,000 or more: April 26, 2027
Public entity with a total population of less than 50,000: April 26, 2028
Any public entity that is a special district government: April 26, 2028
These dates replaced the original deadlines of April 24, 2026 and April 26, 2027. The extension was issued as an interim final rule effective on publication, with a post-promulgation comment period that closed in June 2026. Because the extension is already reflected in the regulatory text, an entity planning against the original 2026 date is planning against a date that no longer appears in the rule.
The rule defines total population rather than leaving it to judgment, and the definition has three branches that matter in practice.
A public entity that has its own population figure in the most recent decennial Census uses that figure. This covers cities, counties, towns, and similar general-purpose governments.
An independent school district, or an instrumentality of one, uses the population estimate for the district calculated by the Census Bureau in the most recent Small Area Income and Poverty Estimates. This is a district-level figure, not a student count and not the population of a surrounding city or county.
A public entity other than a special district government or an independent school district that has no decennial Census population of its own, but is an instrumentality or commuter authority of one or more state or local governments that do, uses the combined population of those governments. A city police department or a city library, for example, uses the city's population. A state agency or a state university, as an instrumentality of the state, effectively takes the state's population, which in every state places it above the 50,000 threshold and on the earlier date.
Special district governments are treated separately. The Census Bureau does not calculate populations for them, and the rule assigns them the later date regardless of the size of the area they serve. Importantly, the rule's definition of special district government expressly excludes counties, municipalities, townships, and independent school districts, so a school district does not fall into the later category simply by virtue of being a district.
The rule requires conformance with the Level A and Level AA success criteria and conformance requirements of WCAG 2.1. The version incorporated by reference is the W3C Recommendation of 5 June 2018, a fixed document rather than a moving target. Level AAA criteria are not required.
WCAG 2.1 is not the newest version of the guidelines. WCAG 2.2 became a W3C Recommendation in October 2023 and was updated in December 2024, and it is the version the W3C encourages organizations to use. The two facts sit together without conflict. WCAG 2.2 did not deprecate or supersede WCAG 2.1; it added success criteria on top of it, and it is backward compatible, so content that meets WCAG 2.2 Level AA also meets WCAG 2.1 Level AA.
For a public entity, the practical consequence is straightforward. WCAG 2.1 Level AA is the regulatory floor under the Title II rule. Designing and procuring to WCAG 2.2 Level AA exceeds that floor, satisfies it, and positions an organization better for future standards work. What an entity should not do is assume that the newer version is what the rule requires, or treat a WCAG 2.2 gap as a Title II violation in itself.
WCAG 3 is sometimes mentioned in vendor materials and conference talks. It is an early working draft, it is expected to remain in development for years, and it is not a standard. It should not be used as a conformance target or written into a contract.
The rule reaches the web content and mobile applications that a public entity provides or makes available, directly or through contractual, licensing, or other arrangements. That framing is broader than a public-facing website.
In practice it includes agency and department websites; web applications and online services such as permit systems, payment portals, and registration forms; resident, student, patient, and parent portals; online forms of every kind; conventional electronic documents posted or distributed through those systems, including PDFs, word processing files, presentations, and spreadsheets; audio and video content delivered through the entity's web properties; and mobile apps the entity offers, whether built in-house or licensed.
Content that an entity makes available through a platform it licenses is not outside the rule because the platform belongs to someone else. If residents use it to reach a service the entity provides, the entity remains responsible for the accessibility of that content.
The rule treats third-party content differently depending on the relationship behind it.
Content posted by members of the public with no contractual relationship to the entity, such as comments on a public page, falls within an exception. Content posted under a contractual, licensing, or other arrangement with the entity does not. If a vendor operates a payment portal, hosts a job application system, or supplies a platform the entity has bought, that content is treated as the entity's own for purposes of the rule.
The Department's guidance to public entities on this point is direct: using an outside service does not remove the obligation, and entities should review vendor contracts, request detailed accessibility information, and consider warranty language addressing conformance with the technical standard.
It is worth being precise about what this does and does not mean. The rule places the compliance obligation on the public entity. It does not, by itself, resolve how responsibility or cost is allocated between an entity and its vendor; that is a matter of contract. An entity that cannot get a vendor to remediate is still the entity with the obligation, which is why procurement is one of the few points where a public entity has real leverage.
The rule contains five exceptions, set out in 28 CFR 35.201. Each is narrower than it first appears, and several have conditions that are easy to fail.
Archived web content is excepted only when four conditions all hold: it was created before the entity's compliance date, or reproduces paper or physical media created before that date; it is retained exclusively for reference, research, or recordkeeping; it is not altered or updated after being archived; and it is organized and stored in a dedicated area clearly identified as archived. Content that is merely old, or that sits in a folder nobody maintains, does not qualify.
Preexisting conventional electronic documents, meaning PDFs, word processing files, presentations, and spreadsheets posted before the compliance date, are excepted unless they are currently used to apply for, access, or participate in a service, program, or activity. A form residents still use, or a document a program still depends on, falls outside the exception no matter how old the file is.
Content posted by third parties is excepted where the third party is not posting under a contractual, licensing, or other arrangement with the entity.
Individualized documents about a specific person that are password protected, such as an individual's bill or account record in a conventional document format, are excepted.
Social media posts created before the compliance date are excepted. Posts created after it are not.
Three further provisions sit alongside the exceptions. A conforming alternate version may be used where a technical or legal limitation prevents the primary content from being made accessible. Equivalent facilitation permits alternative designs that provide substantially equivalent or greater accessibility. And an entity may show that a particular nonconformance is so minor that it would not affect a person with a disability's ability to use the content with substantially equivalent ease, though the burden of demonstrating that rests on the entity. The general Title II defenses of fundamental alteration and undue financial and administrative burden also remain available, and they are demanding standards rather than routine escape hatches.
Mobile applications are covered on the same terms and the same dates as web content, whether an entity develops an app itself or licenses one. The applicable standard is the same: WCAG 2.1 Level A and AA.
Applying web-oriented success criteria to native mobile applications takes interpretation. WCAG was written primarily for web content, and platform conventions on iOS and Android determine how many criteria are satisfied in practice. An app satisfies the intent of name, role, and value requirements by labeling controls so that VoiceOver and TalkBack announce them correctly. It satisfies text-resizing expectations by honoring the platform's dynamic type settings rather than hard-coding font sizes. Custom controls built outside the platform's standard components do not inherit accessibility information and have to have it added deliberately.
Apple and Google both publish accessibility guidance for developers on their platforms. That guidance is useful for implementation, but it is not a substitute for the standard the rule names, and conformance still has to be assessed against WCAG 2.1 Level AA.
Automated accessibility scanners are genuinely useful. They cover many pages quickly, they catch well-defined problems such as missing alternative text, insufficient contrast, and malformed headings, and they are the only practical way to monitor a large site continuously.
They cannot establish conformance on their own. A substantial share of WCAG requirements depend on context and human judgment that a scanner cannot exercise: whether alternative text is meaningful rather than merely present, whether a focus order follows a logical sequence, whether a page still works when operated by keyboard alone, whether an error message tells a person what to fix. The Department of Justice's own guidance to public entities preparing for this rule says plainly that automated tools alone cannot assess all aspects of accessibility and should be combined with manual evaluation.
Any claim that a site is compliant because a scanner reported no errors should be treated with caution, whether the claim comes from a vendor, an overlay product, or an internal report.
The rule does not prescribe a compliance process. What follows is an implementation sequence that reflects how the work is usually approached, not a requirement of the regulation.
Start with an inventory. Most public entities do not have a reliable list of the websites, subsites, applications, portals, and mobile apps they operate, and the inventory almost always turns up more than expected: department microsites, campaign pages, systems bought by individual offices, and platforms still running under expired contracts.
Inventory the content as well as the systems. Documents are usually the largest and least understood category, and the question that matters is not how many PDFs exist but which ones people currently use to access a service.
Assign ownership. Digital accessibility fails most often where no one owns it. Someone needs to be accountable for the program, and individual systems need named owners.
Prioritize by use and consequence. The highest-traffic pages, the systems people must use to obtain a benefit or complete a transaction, and the content that reaches the whole community come first. Low-traffic reference material can wait.
Fix templates and design systems before individual pages. A defect in a site template repeats on every page it generates, and correcting it once resolves thousands of instances.
Put accessibility into procurement. Contracts and renewals are the moments when an entity can require conformance information, testing, and remediation commitments. Every renewal that passes without those terms is an opportunity lost for the length of the next contract.
Train the people who create content. Most accessibility defects are introduced by well-intentioned staff publishing documents and pages without knowing what makes them usable.
Test with a combination of automated and manual methods, including keyboard-only and screen reader testing, and retest after changes.
Plan remediation as ongoing work rather than a project with an end date. New content is created every day, and a site that conforms in April will not stay that way on its own.
Monitor and document. Keeping a record of what was assessed, what was fixed, what remains, and on what schedule is useful for managing the work and for demonstrating good faith if questions arise.
Enforcement of this rule is worth describing precisely, because it is frequently described inaccurately.
Title II is enforced through the compliance procedures in subpart F of 28 CFR part 35. A person may file a complaint with a designated federal agency or the Department of Justice, generally within 180 days. The agency investigates, attempts informal resolution, issues a letter of findings if it finds a violation, and seeks voluntary compliance. If voluntary compliance cannot be secured, the matter may be referred to the Attorney General. Individuals may also bring private actions; Title II remedies derive from Section 505 of the Rehabilitation Act and include injunctive relief, damages in appropriate cases, and attorney's fees.
Subpart H contains no penalty provision. Subpart F provides no monetary civil penalties and no per-document fines against public entities; its remedies provision addresses reasonable attorney's fees, litigation expenses, and costs for a prevailing party. Neither the Department's fact sheet on the rule nor its small entity compliance guide states any fine amount.
Claims circulating online that each inaccessible file carries a fixed federal fine are not supported by the rule or by the Department's guidance. The civil penalty figures sometimes quoted in that context come from ADA Title III enforcement actions against public accommodations, which is a different title of the statute with different defendants and different procedures.
The realistic exposure for a public entity is different in character but not trivial: a federal investigation, a settlement agreement with a remediation schedule and reporting obligations, private litigation and the costs that come with it, the operational cost of remediating under time pressure rather than on a planned schedule, and the reputational consequence of excluding residents from services they are entitled to use.
Does this rule apply to public school districts? Yes. Public school districts are public entities under Title II and are covered. Which deadline applies depends on the district's population figure as the rule defines it.
Is WCAG 2.2 required? No. The rule incorporates WCAG 2.1 Level A and AA. WCAG 2.2 is the newer W3C Recommendation and is a reasonable design target, and meeting it also meets WCAG 2.1, but it is not what the rule requires.
Do old PDFs have to be remediated? It depends on use, not age. A conventional electronic document posted before the compliance date is excepted unless it is currently used to apply for, access, or participate in a service, program, or activity. Documents still in active use are not excepted.
Are mobile apps covered? Yes, on the same dates and to the same standard as web content.
Are third-party platforms covered? Content provided through a contractual, licensing, or other arrangement is treated as the entity's own. Content posted by unaffiliated members of the public is not.
Does a vendor's accessibility report prove compliance? No. A conformance report is a vendor's own account of a specific product version at a specific time. It is a useful input to evaluation, not evidence of conformance, and it should be read critically and verified by testing.
Can an automated tool certify accessibility? No. Automated testing is valuable and necessary at scale, but it cannot assess all WCAG requirements and cannot establish conformance by itself.
Which deadline applies to my entity? If it is a general-purpose government with a decennial Census population of 50,000 or more, April 26, 2027. If its population is under 50,000, or it is a special district government, April 26, 2028. Independent school districts use the Census Bureau's Small Area Income and Poverty Estimates figure for the district.
For a general orientation to digital accessibility, including how laws, standards, and practices fit together, see Digital Accessibility. For how the rule applies specifically to K-12 public education, see ADA Title II Digital Accessibility for Public Schools. For how assistive technology intersects with education law, see Education, IDEA & IEPs. For the postsecondary context, see Assistive Technology for College and Postsecondary Education. For what WCAG is and how conformance levels work, see WCAG Overview. For how WCAG relates to United States law, see WCAG vs ADA vs Section 508. For documents in every format, see Accessible Documents. For how accessibility is evaluated in practice, see Accessibility Testing and Evaluation, and for how vendors document conformance, see VPAT and Accessibility Conformance Reports. For an introduction to assistive technology generally, see Assistive Technology 101, and for further reading across topics, see Resources. For how accessibility is built into purchasing, see Accessible Procurement.
Request accessibility services
28 CFR part 35, subpart H, Web and Mobile Accessibility, sections 35.200 through 35.205, including the definitions in section 35.104.
Nondiscrimination on the Basis of Disability; Accessibility of Web Information and Services of State and Local Government Entities, 89 FR 31337, April 24, 2024, as amended by AG Order No. 6742-2026, 91 FR 20902, April 20, 2026.
U.S. Department of Justice, ADA.gov: Fact Sheet on the web and mobile app rule; Small Entity Compliance Guide; and First Steps Toward Complying with the Title II Web and Mobile Application Accessibility Rule.
W3C Web Accessibility Initiative, WCAG 2 Overview, for the status of WCAG 2.0, 2.1, and 2.2 and the development status of WCAG 3.
Last regulatory review: September 20, 2026. On that date the compliance dates, the incorporated technical standard, the population methodology, the exceptions, and the enforcement framework described on this page were verified against the current text of 28 CFR part 35 and current Department of Justice guidance.
September 18, 2026 - Page created. Current Department of Justice compliance dates of April 26, 2027 and April 26, 2028 verified against the current Code of Federal Regulations text. WCAG 2.1 Level A and AA confirmed as the standard incorporated by the rule. The April 2026 interim final rule extending both dates by one year confirmed as in effect.
This page provides general educational information about digital accessibility requirements for state and local government entities in the United States. It is prepared by The Accessibility Clinic Inc. as educational information only. It is not legal advice, and it does not guarantee that any specific website, application, or document meets a particular standard or legal requirement. Organizations should evaluate their own obligations in light of their specific circumstances and consult qualified counsel when needed. Regulations and standards change; the last regulatory review date above indicates when the regulatory statements on this page were most recently verified against primary sources.