A State Digital Services Agency: Statewide WCAG Compliance Across 23 Agency Websites
One state. Twenty-three executive agency sites. A single compliance dashboard for the CIO's office, Microsoft Entra ID SSO wired in, and a purchase order signed in six weeks through a state co-op contract instead of a fourteen-month RFP.
23
State agency websites deployed
SSO
Microsoft Entra ID integration
1
Compliance dashboard for state CIO
Co-op
Procurement path used
The Problem the State CIO Walked Into
The DOJ's Title II web accessibility rule set a hard compliance deadline for state government agencies. A state government digital services agency (the state's central IT and digital services authority) saw the shape of the problem early. Twenty-three executive branch agency websites. Each one owned by a different communications team. Drupal here, WordPress there, a couple of proprietary CMS installs nobody wanted to talk about. No shared design standard. No common accessibility policy. And no single place a state CIO could look to answer the question every governor eventually asks: are we exposed?
So the agency commissioned a statewide baseline audit in early 2025. The findings weren't pretty.
- 7 of 23 agency sites failed more than 50% of automated WCAG 2.1 AA criteria
- 4 agency sites were running on unsupported CMS platforms with known security vulnerabilities
- Across all 23 sites, 14,200 PDFs were identified. 31% were classified as Critical or High risk
- No agency had an Accessibility Statement published. None had a formal digital accessibility policy
- No agency had run staff training on digital accessibility in the prior 3 years
- 2 agencies had received informal accessibility complaints that the state agency knew about but nobody had formally tracked or responded to
Baseline audit findings across 23 agency sites
14,200 PDFs in scope
Statewide audit results, early 2025, prior to WPPersona deployment.
Governance First, Tools Second
The agency treated this as a governance problem, not a shopping problem. The CIO's office knew a tool alone wouldn't fix anything. They needed a structure that gave the state real oversight without so much friction that agency comms teams would route around it. That happens more often than vendors admit.
Three tiers, clean handoffs:
State CIO Level
Owns the standard (WCAG 2.1 AA), approves platform procurement, reads the aggregate compliance dashboard every month, handles anything that lands from OCR or DOJ, signs off on exceptions.
Agency CIO / Communications Director Level
Runs day-to-day content operations at the agency, watches the agency-specific dashboard, owns staff training inside the agency, decides on agency-level exception requests.
Agency Content Editor Level
Publishes inside approved templates, uploads documents through the platform scanner, keeps the routine content updates moving.
WPPersona's multi-site model maps to that structure without contortions. The state CIO account holds master access to all 23 agency workspaces. Agency CIOs get workspace-level admin for their agency only. Editors publish inside their agency workspace. PDF scanning runs the same way at every level. No editor at any level can turn off the upload scanner. That last piece matters more than it sounds.
Microsoft Entra ID Integration (SAML SSO)
The state runs enterprise identity on Microsoft Entra ID (formerly Azure Active Directory). For a rollout across 23 agencies and hundreds of content editors, native SAML 2.0 SSO wasn't a nice-to-have. It was a hard requirement. The alternative? Standing up and babysitting hundreds of separate platform logins. Ask any state security team how that story ends.
With SAML wired to Entra ID, the state agency can:
- Provision and deprovision editors through Entra ID. When a state employee leaves, WPPersona access drops the moment their Entra ID account is disabled.
- Enforce state MFA policy through Entra ID Conditional Access. The platform inherits the state's existing MFA posture instead of trying to bolt on its own.
- Map Entra ID group membership to WPPersona role assignments. Agency editors land in the right agency workspace based on their Entra group, with no manual account creation.
- Audit every login through Entra ID sign-in logs. The agency security team keeps its authentication trail in the tools they already run reports out of.
Co-Op Procurement: Skipping the 14-Month RFP
State tech procurement is slow. A full RFP runs 6 to 18 months on a good day. With the 2027 deadline in sight, the agency did not have that kind of runway for a platform that still had to be deployed, trained on, and operational before the clock ran out.
The agency procurement team spotted the shortcut. WPPersona was already on the NASPO ValuePoint cooperative purchasing contract and available through the Carahsoft public sector distribution channel, a multi-state vehicle that lets state governments buy from a pool competitively procured at the national level. No duplicate RFP. Same competitive protection.
The co-op path compressed the timeline from an estimated 14 months to 6 weeks. The state's Department of Buildings and General Services legal counsel signed off, confirming that the NASPO ValuePoint contract satisfied the state's competitive procurement requirements at this purchase size. One purchase order. Done.
Procurement timeline: RFP vs. NASPO co-op
14 months to 6 weeks
Weeks required to reach a signed purchase order for a statewide CMS platform.
Enterprise Deployment Details
Deployed on Azure East US 2, the same region as the state's existing Azure tenant. Data residency conversations closed in one meeting.
Standard DPA executed covering FERPA, ADA documentation data, and state data classification requirements.
The state agency got a named CSM. Quarterly compliance reviews and training coordination with agency comms teams run through that one person.
99.95% uptime. 30-minute incident response for critical availability issues that hit multiple agencies at once.
The WPPersona implementation team ran 6 agency-level onboarding sessions covering content migration, editorial workflow, and PDF compliance rules.
State-Level or Multi-Agency Deployment?
Our Enterprise plan handles SAML SSO, custom SLAs, dedicated implementation support, and co-op contract procurement. Bring us your org chart and your deadline.
Talk to Enterprise Team