1. Our commitment
FrameworkMapper is a browser-based compliance platform used by security practitioners, consulting partners and the organizations they serve. We build it so that it can be operated without a mouse, read by a screen reader, resized, recoloured and reflowed — and we treat an accessibility defect as a defect, not as a feature request.
We also think an accessibility statement is only worth reading if it says what is wrong as well as what is right. This one does. The conformance figures below come from an evaluation of the actual product, and every criterion we have not met is listed by name with the measurement behind it.
2. The standard we follow
We have adopted WCAG 2.2 Level AA as our technical standard, and we report against WCAG 2.0, 2.1 and 2.2 at Levels A and AA using the VPAT 2.5Rev template.
That standard covers the technical requirements referenced by Section 508 of the Rehabilitation Act, which incorporates WCAG 2.0 Level AA, and it meets or exceeds the WCAG 2.1 Level AA baseline commonly required by state procurement rules and by institutional accessibility policies.
Level AAA is explicitly out of scope. We have not evaluated any Level AAA criterion and we make no claim about one.
3. Conformance status
Of the 56 Level A and Level AA success criteria evaluated:
48
criteria Supports
8
criteria Partially Supports
0
criteria Does Not Support
In the language of WCAG, FrameworkMapper partially conforms to WCAG 2.2 Level AA: most of the product meets the standard, and the parts that do not are identified below. No criterion is unmet outright.
The open items are structural or editorial rather than barriers that stop a keyboard user completing a task — with one exception we call out by name in Known issues, on an internal administrator page. Remediation is in progress and this statement is revised as items close.
4. The full report
The complete Accessibility Conformance Report gives a determination and supporting remarks for every individual success criterion, not just the summary above.
FrameworkMapper Accessibility Conformance Report
VPAT® 2.5Rev — WCAG 2.0, 2.1 and 2.2, Levels A and AA
Issued 18 September 2026
Download the report (PDF, 494 KB)
If you need the report in a different format, or a version prepared to a particular procurement template, email support@frameworkmapper.com and we will produce one.
5. What this statement covers
The evaluation covers the public website at frameworkmapper.com, the client, partner, vendor and administrator portals, and the framework assessment tool. FrameworkMapper is delivered entirely as web content rendered in a standard desktop or mobile browser: there is no installed client, and no separate native, kiosk or documentation component.
FrameworkMapper is continuously deployed and carries no discrete release number. The report describes the build evaluated 15–18 September 2026.
Content we do not control
Two components are rendered by third parties, sit outside our evaluation, and should be requested from their publishers if you need conformance information about them:
- The Cloudflare edge bot-mitigation interstitial, which may briefly appear before a page loads. Conformance information is available from Cloudflare, Inc.
- The Square-hosted payment pages used to complete a purchase. Conformance information is available from Block, Inc.
6. Known issues
These are the eight criteria we do not fully meet, with the measurement behind each. They are stated here in the same terms as the full report.
| Criterion | What is wrong |
|---|---|
| 1.3.1 Info and Relationships (A) | 17 help tables in the administrator portal carry no header cells, so their row and column relationships are not conveyed programmatically. |
| 1.3.5 Identify Input Purpose (AA) | Identity inputs on three organization-profile forms and one portal sign-in page lack an autocomplete token, so the browser cannot offer to fill them. |
| 1.4.10 Reflow (AA) | 35 of 279 pages require the page itself to be scrolled horizontally at a 320 pixel viewport width, concentrated in the authenticated portals and the assessment tool. The public marketing site reflows correctly throughout. |
| 2.1.1 Keyboard (A) | Five non-interactive elements carry a click handler with no role and no keyboard equivalent. Two of them — section toggles on an internal administrator test page — cannot be operated by a keyboard user at all. This is the one open item that blocks a task rather than degrading one. |
| 2.4.6 Headings and Labels (AA) | 41 pages skip a heading level and 26 content pages have no first-level heading, which weakens navigation by heading structure. |
| 3.2.6 Consistent Help (A) | The help affordance is available on most pages but is not consistently placed across them. |
| 3.3.1 Error Identification (A) | Where a form falls back to the browser's own constraint validation rather than rendering its own message, the error text and its announcement are the browser's rather than the product's. |
| 3.3.3 Error Suggestion (AA) | Some messages report that an operation failed without suggesting how to correct it. |
If one of these is blocking you today, tell us (below) and we will prioritise it and offer a workaround in the meantime.
7. How we test
Accessibility testing is automated and continuous rather than a one-off audit:
- Every week, an automated scan runs the axe accessibility engine across the full page set in our build pipeline and compares the result against a committed baseline. A regression opens a tracked issue in the repository rather than sending an email that might go unread.
- Manual verification supplements it: keyboard operation, visual measurement, scripted re-checks of static markup, obscured-element checks and status-message checks.
- A signed-in browser round against the client, partner and administrator portals confirmed skip-link behaviour, modal focus containment and restoration, and live-region mirroring of error text.
Accessibility findings are handled as defects with measured counts, alongside every other defect.
8. The limits of this claim
We would rather you learn these from us than discover them yourself.
We have not tested with assistive technology. No screen reader, screen magnifier, speech-input or switch-access testing has been performed for this product. Every determination in our report rests on programmatic inspection, keyboard operation and visual measurement. This is the single largest gap in our evaluation. If you require assistive-technology verification, ask us before relying on the report for a procurement decision — we will tell you plainly what we have and have not done.
The report is a self-assessment. It was produced by us, not by an independent accessibility auditor. No third-party expert audit of FrameworkMapper has been conducted. We have tried to make the report specific enough to be checked — every determination carries its measurement, and nothing was marked as passing on the strength of a clean automated scan alone — but it is a vendor self-report and should be weighed as one.
Authenticated pages are less thoroughly covered than public ones. Portal interiors are partly exercised through a test harness that substitutes a stub sign-in and fixture data. The harness exercises the delivered markup and scripts, but not server-driven states, permission variations or real data. A full credentialed pass across every authenticated page has not yet been performed.
We do not use an accessibility overlay. There is no accessibility mode, no lite version, no alternate interface and no third-party overlay or AI-based alternate rendering. Everyone gets the same interface, and accessibility is a property of what we ship rather than of a separate path that could drift from it.
9. Report a barrier
If any part of FrameworkMapper is difficult or impossible for you to use, please tell us. Reports go directly to the person who can fix them; they do not sit in a general support queue.
Email: support@frameworkmapper.com
Post: Viosoph, LLC, Attn: Accessibility, 1022 Brickyard Dr, Hooper, NE 68031, United States
It helps us a great deal if you can include:
- The page or screen where you hit the problem, with the web address if you have it.
- What you were trying to do, and what happened instead.
- Your browser and operating system, and the assistive technology you were using, if any.
We aim to acknowledge every accessibility report within five business days and to tell you at that point what we intend to do about it and when. If a fix will take time, we will look for a workaround that unblocks you sooner.
If you are not satisfied with our response, say so in reply and it will be reviewed again. You may also raise the matter through your institution's accessibility or procurement office, which we will engage with directly.
10. For procurement and accessibility offices
If you are evaluating FrameworkMapper on behalf of an institution, the Accessibility Conformance Report in section 4 is the document you want, and the limitations in section 8 are the ones to weigh.
Beyond that, we can provide a completed HECVAT, engage with your own accessibility testing, and discuss contractual accessibility commitments — including a schedule for the open items in section 6. We will commit to remediating identified defects on an agreed timeline. We will not sign a representation that the product fully conforms today, because it does not, and section 3 says so.
Contact support@frameworkmapper.com to start that conversation.
Notice. This statement describes the product as evaluated in September 2026 and is revised as open items close. It is provided for transparency and is not legal advice. Your use of the Service is also governed by our Terms of Service and Privacy Policy.