Digital Accessibility Audits
Overview
The Department of Justice has set new ADA Title II compliance deadlines for state and local government web content and documents: April 26, 2027 for entities with a population of 50,000 or more, and April 26, 2028 for smaller entities and special district governments. See Extension of Compliance Dates for Nondiscrimination on the Basis of Disability in the Federal Register.
As a cybersecurity firm, we approach digital accessibility the same way we approach any other organizational risk: not as a one-time content fix, but as a gap in your risk management program that carries real legal liability if it goes unaddressed. The same independent, evidence-based methodology we use to assess application security, verify a claim, document the gap, and provide attestation your stakeholders can rely on, applies directly to document accessibility compliance.
Rietta reviews government document corpora, PDFs, Word files, and Excel spreadsheets, for the metadata-based accessibility deficiencies that remediation vendors most often miss. This is not a remediation service; we are not in the business of rewriting your documents. What we provide is independent, documented evidence of whether an active compliance program is actually working, which should self-evidently carry more weight than a vendor’s own self-attestation of that same work.
What We Look For
Most accessibility discussion focuses on image alt text, which matters, but our reviews are built around the metadata-based deficiencies we see most often in government document corpora:
- Blank or empty document titles. WCAG 2.4.2 Page Titled requires a descriptive title, and for PDFs specifically the PDF18 technique defines setting that title in the document properties as sufficient. Screen reader users rely on it to know what they’ve opened.
- Missing or untrustworthy date information, which matters directly for whether a document can legitimately claim the law’s archival exemption (see below).
- Undefined document language, which breaks screen reader pronunciation and navigation.
We also look at findings the rest of the industry tends to under-discuss, like a vendor stamping every document with the same generic title, which is corpus-wide non-compliance even when it passes a document-by-document check.
The Archival Exemption, Done Correctly
The law exempts documents created before a certain date from remediation, but the exemption has specific requirements defined in § 35.104 Definitions, and the document’s own metadata date is often unreliable, for example, a court order issued decades ago but only digitized recently. Getting this right can mean not having to remediate documents that already qualify for the exemption, rather than paying for changes that were never legally required.
Continuous, Not One-Time
A single point-in-time scan only solves half the problem. Agencies keep publishing new documents after the compliance deadline passes, and each one is a fresh opportunity to fall out of compliance. Metadata Minder can continuously validate newly published documents as they appear, the same way continuous integration validates new code before it reaches production, so compliance is a standing practice rather than a project you finish once.
Independent Attestation
Frank Rietta, a life member of OWASP, can provide signed attestation or bridge letters documenting your organization’s compliance posture, the same independent-evidence approach we use for our OWASP ASVS, MASVS, and SAMM assessments.
Learn More
We’ve written more about this work on our blog:
- 297 Days: The Real ADA Title II Deadline for Government Documents
- Real ADA Title II Findings for Government Documents
You can also learn more directly on our dedicated Metadata Minder website, and schedule a consultation there.
Next Steps
If you'd like to discuss your specific requirements, feel free to schedule a free consultation. We'll provide detailed information about our services and tailor a plan to meet your unique needs. You can reach us at our Atlanta office: +1 (770) 623-2059.