Regulations that apply
SaaS / B2B Software sits at the intersection of general digital-accessibility law and sector-specific obligations. The most relevant items to track:
- Section 508US federal
Procurement gate; ACR/VPAT required.
- EN 301 549EU public sector
Required for tenders and many private buyers.
- EAA (consumer-facing portions)EU
If your product has any consumer-facing surface (e.g. customer support portal), it counts.
The accessibility risks specific to SaaS / B2B Software
Every industry has its own failure pattern. The combination below is what audits, complaints, and lawsuits in this sector keep returning to. Fixing them clears the most-cited issues without touching every page.
- Custom data tables and dashboards without semantics1.3.1, 4.1.2
Drag-and-drop builders, virtualised tables, and chart libraries frequently fail 1.3.1 and 4.1.2.
- Modals nested in modals (focus chaos)2.4.3
Wizard flows that stack dialogs lose focus restoration on close.
- No VPAT or out-of-date VPATall
Procurement teams reject vendors without a current ACR.
A short remediation checklist
Most SaaS / B2B Software teams do not need a 200-item audit before they fix anything. They need an ordered list of the highest-impact moves. Start with these and re-audit after each pass.
- Generate or update an ACR/VPAT — Certvo includes a free generator
- Audit the most-used 5 user journeys
- Verify every modal flow restores focus correctly
- Test charts and data tables with NVDA/JAWS
Run a free Certvo scan against your homepage and one task-flow URL (login, checkout, booking). It pinpoints which of the issues above apply to you, and how often.
Scoping an audit for SaaS / B2B Software
SaaS / B2B Software carries 3 distinct obligations to satisfy — Section 508, EN 301 549, EAA (consumer-facing portions) — spanning US federal and EU public sector and EU. An auditor prices the work by how many of those regimes are in scope and how many distinct task flows carry them, not by page count.
The 3 failure patterns above map to 1.3.1, 4.1.2, 2.4.3, all. Every one of those is machine-detectable, which means a scan can clear them before an auditor starts charging by the hour. What remains for manual review is the judgement work: whether custom data tables and dashboards without semantics actually functions end to end for a screen-reader user.
- Scan first, audit second
Clearing the 3 automated patterns above shortens the manual pass to the flows that need a person.
- Scope by template, not by page
A site with thousands of pages usually has fewer than twenty distinct templates. Price the templates.
- Re-test after remediation
The conformance claim rests on the re-test, not the first report.
- Evidence for US federal
Keep dated scan history — it is what turns a conformance claim into something a regulator accepts.
Frequently asked questions
Do I really need a VPAT to win enterprise deals?
For US federal and many state/local agencies, yes. For Fortune 500 procurement, increasingly yes. It is the single highest-leverage accessibility asset for B2B.