Back to BlogIndustry Guides

Government Software Development: Citizen Portals, Accessibility, Offshore Bids

Rupak Amin

Founder & Lead Engineer, RAITHub

12 min read

Government software development means citizen portals and internal tools that must meet accessibility rules: WCAG 2.2 AA is the current W3C standard, US Section 508 requires WCAG 2.0 AA, and the EU uses EN 301 549. An offshore web team can often build them as a subcontractor, but usually cannot bid alone where tenders require local registration, security clearances, data residency or certifications.

This guide is for public-sector buyers, and for the local firms that win their contracts, who are weighing an offshore team for part of the work. It covers what a citizen portal needs, which accessibility standard applies where, what usually blocks an offshore vendor from bidding directly, and how subcontracting works. It also has a short section on aerospace supplier portals. To be clear from the start: RAITHub holds no certifications and has no government clients. What it can offer is careful web engineering and measured accessibility work, described below.

What does government software development actually involve?

Most public-sector software is not exotic. It is the same web engineering as any serious product, with stricter rules on who can use it, where the data lives and who is allowed to touch it. The common types:

  • Citizen portals. Apply for a permit, book an appointment, pay a fee, track a case. The users are the whole public, including people with disabilities, older people and people on slow phones.
  • Case-management and internal tools. Queues, approvals, document handling and reporting for staff, with role-based access and a full audit trail.
  • Forms and payments. Long multi-step forms that must save progress, validate clearly and work with a keyboard and a screen reader.
  • Open data and information sites. Content-heavy sites where accessible tables, headings and downloads matter most.

The engineering patterns carry over from commercial work: least-privilege roles, which RBAC design for SaaS covers, and tamper-evident logs, covered in audit log design. What changes is the procurement, and accessibility moves from "nice to have" to a legal requirement.

Which accessibility standard applies: WCAG 2.2, Section 508 or EN 301 549?

All three point back to the W3C's Web Content Accessibility Guidelines (WCAG), but they reference different versions. Check which one your contract names.

StandardWhere it appliesWhat it requires for web contentSource
WCAG 2.2Worldwide; the current W3C Recommendation, and the version many new tenders nameLevels A and AA are the usual target; 2.2 added nine success criteria to 2.1 and removed 4.1.1 ParsingW3C WCAG 2.2
Section 508 (Revised 508 Standards)US federal agencies, for ICT they develop, buy, maintain or use"Level A and Level AA Success Criteria and Conformance Requirements in WCAG 2.0"US Access Board, section508.gov
EN 301 549 V3.2.1EU public-sector websites and apps under the Web Accessibility Directive, and ICT public procurementIts web clauses track WCAG 2.1 AA; meeting it gives a presumption of conformity with the directiveETSI EN 301 549, European Commission

In practice, building to WCAG 2.2 AA covers the older versions too, because 2.2 is a superset of 2.1 and 2.0 apart from the removed Parsing criterion. The new AA criteria in 2.2 include Focus Not Obscured (Minimum), Dragging Movements, Target Size (Minimum) and Accessible Authentication (Minimum) (W3C). The EU directive also requires an accessibility statement and a feedback mechanism on each public-sector site, and the Commission notes that overlays alone do not meet the standard (European Commission).

This is general information, not legal advice. Confirm the standard and version your contract requires with the buyer and your own adviser.

What does accessible citizen-portal engineering look like in code?

Most failures are small and repeated on every page: an input without a label, a wide table that a keyboard user cannot scroll, focus hidden behind a sticky header. Two fixes that come up constantly:

<!-- A wide table in a scroll container a keyboard can reach -->
<div role="region" aria-label="Fees by permit type" tabindex="0" class="table-scroll">
  <table>
    <caption>Fees by permit type</caption>
    ...
  </table>
</div>

<!-- Every control has a programmatic label -->
<label for="email">Email address</label>
<input id="email" name="email" type="email" autocomplete="email" required>

And the automated check, run in CI on every page so a regression fails the build. This uses Playwright with the axe-core integration:

import { test, expect } from '@playwright/test'
import AxeBuilder from '@axe-core/playwright'

test('home page has no automated WCAG A/AA violations', async ({ page }) => {
  await page.goto('/')
  const results = await new AxeBuilder({ page })
    .withTags(['wcag2a', 'wcag2aa', 'wcag21a', 'wcag21aa', 'wcag22aa'])
    .analyze()
  expect(results.violations).toEqual([])
})

Automated checks catch only part of the problem. Keyboard-only walkthroughs, screen-reader testing and zoom testing are still needed, and a formal audit by an accessibility specialist is what a public buyer will usually ask for. The pre-launch QA checklist shows where accessibility sits among the other release checks.

Can an offshore software company bid for government contracts?

Sometimes, but the barriers are real, and most of them are there on purpose. What usually stands in the way:

RequirementWhat it meansCan an offshore vendor meet it?
Supplier registrationRegistration in the buyer's supplier system, often with a local legal entity, tax number and bank accountOften not without a local entity; check each tender
Security clearancesStaff vetting for anyone with access to systems or data; national clearances are usually tied to citizenship or residencyUsually not for offshore staff
Data residencyData must stay in the country or an approved region, and sometimes only local staff may access itHosting can be local; remote access by offshore staff may still be prohibited
ISO/IEC 27001A certified information security management system, audited by an accredited bodyOnly if the vendor is certified; RAITHub is not
FedRAMPUS government authorisation for cloud services used by federal agencies (FedRAMP)Applies to the cloud service, not the developer; a custom app is hosted on an authorised platform
Cyber Essentials / Plus (UK)A UK scheme covering five technical controls; Plus adds independent testing (NCSC)Only if the vendor is certified; RAITHub is not

On the UK point specifically: PPN 09/14 made Cyber Essentials mandatory for central government contracts advertised after 1 October 2014 that involve handling personal information and providing certain ICT products and services (Cabinet Office PPN 09/14). PPN 014 (February 2025) now replaces it for procurements under the Procurement Act 2023: for contracts with certain higher-risk characteristics, such as handling citizens' personal information, central government bodies and NHS bodies must require Cyber Essentials or Cyber Essentials Plus, or equivalent controls. Plus is not a blanket requirement; it is the more rigorous option for higher-risk contracts. Check the tender itself for the level it asks for. The same applies to every row above: requirements vary by country, agency and contract, and this is general information, not legal advice.

How does subcontracting to a local prime contractor work?

This is the realistic route for an offshore web team. A local prime contractor holds the contract, the registration, the certifications and the cleared staff. It subcontracts a defined piece of work, such as the front end of a citizen portal or an internal tool that holds no sensitive data, to a specialist team.

  • The buyer must allow it. Many contracts restrict subcontracting, or require the buyer's approval of each subcontractor and of where work is done.
  • Flow-down clauses apply. Security, confidentiality and data-handling terms in the prime contract pass down to the subcontractor.
  • Scope the data out. The cleanest arrangement is one where the offshore team works on code and synthetic test data only, with no access to production or personal data.
  • IP and handover. Code is assigned to the prime or the buyer, with runbooks and a clean handover.

If a prime asks for a security questionnaire from an uncertified subcontractor, the answers still need to be honest and specific. Answering your first security questionnaire without SOC 2 explains how RAITHub approaches that.

What about aerospace supplier and MRO portals?

Aerospace supplier portals and MRO (maintenance, repair and overhaul) portals are, technically, ordinary B2B portals: supplier onboarding, purchase orders, invoices, quality documents and work-order status, behind role-based access. The engineering is close to a B2B platform.

The data is what changes things. Under the US International Traffic in Arms Regulations (ITAR), an export includes "releasing or otherwise transferring technical data to a foreign person", and a release to a foreign person in the US is deemed an export to their countries of citizenship (22 CFR 120.50; DDTC). Under the Export Administration Regulations, the Bureau of Industry and Security treats "the sharing or release of controlled technology or source code to a foreign person" as a deemed export (BIS).

So ITAR- or EAR-controlled technical data cannot go to an offshore team without the right authorisation. RAITHub handles no ITAR/EAR-controlled data and does not take that work. A portal that carries controlled drawings, specifications or source code needs an export-cleared vendor. Whether any particular data is controlled is a question for your export compliance officer, not for a developer.

What proof does RAITHub have for this kind of work?

The honest answer: no government clients, no certifications, and no aerospace work. What RAITHub can show is accessibility engineering on this website, which you can check yourself:

  • It passes automated WCAG A/AA checks (axe-core: 0 violations). That is a measured result from automated testing, not a certification, and it does not replace a manual audit.
  • Tables are keyboard-scrollable, using focusable, labelled scroll regions like the example above.
  • Form controls are labelled, so screen readers announce what each field is for.
  • It has 400+ tests in CI, so fixes stay fixed.

Beyond this site, RAITHub has built role-heavy platforms: Sundor Skin, a B2B wholesale platform, has 146 PostgreSQL tables with row-level security, 88 permission codes and 12 staff roles. Details are on the work page. None of this is public-sector work, and it is offered as evidence of engineering practice only.

Why RAITHub for this

  • Accessibility is tested, not promised. Automated WCAG A/AA checks run as part of QA, followed by keyboard walkthroughs; see QA and test automation.
  • A good fit as a subcontractor. RAITHub works on a defined scope, with code and synthetic data, under the prime's controls. It signs DPAs and follows the client's security controls.
  • Accessible front ends on a modern stack. Citizen-facing web apps and PWAs in Next.js; see Next.js development.
  • Founder-reviewed work. Rupak Amin, Founder & Lead Engineer, reviews the architecture on every engagement.

When you don't need us

  • You need a vendor to bid directly on a tender requiring local registration, cleared staff or certifications. RAITHub has none of those.
  • You need ISO 27001, Cyber Essentials Plus or FedRAMP from the vendor itself. RAITHub holds no certifications.
  • The work involves ITAR/EAR-controlled data, classified information, or production access to citizens' personal data from offshore. Use a cleared, local vendor.
  • You need a formal accessibility audit or conformance report. Use a specialist accessibility auditor; RAITHub can fix what the audit finds.
  • You need native mobile apps or non-English delivery. RAITHub builds web apps and PWAs and delivers in English.

If you are a prime contractor or a buyer with a defined, non-sensitive piece of web work, or you want an accessibility and QA review of an existing portal, book the free 15-minute technical audit.

Standards and rules checked against the linked W3C, US Access Board, section508.gov, ETSI, European Commission, NCSC, Cabinet Office, eCFR text and BIS pages. This is general information, not legal or export-control advice; confirm with your adviser and the regulators linked above.

Frequently asked questions

Which accessibility standard should a government website meet?

Check the contract. US federal sites must meet WCAG 2.0 A and AA under Section 508; EU public-sector sites use EN 301 549, which tracks WCAG 2.1 AA. Building to WCAG 2.2 AA covers both.

Can an offshore company bid for government software contracts?

Sometimes, but local registration, security clearances, data residency and certifications such as ISO 27001 or Cyber Essentials often rule it out. Subcontracting a defined, non-sensitive scope to a local prime is the usual route.

Does RAITHub have government clients or certifications?

No. RAITHub has no government clients and holds no certifications, including ISO 27001, SOC 2 and Cyber Essentials. It can work as a subcontractor under a prime's controls on non-sensitive web work.

Is this website WCAG certified?

No. It passes automated WCAG A/AA checks (axe-core: 0 violations), with keyboard-scrollable tables and labelled form controls. Automated checks do not replace a manual audit, and there is no official WCAG certification from W3C.

Can an offshore team build an aerospace supplier or MRO portal?

The portal itself is ordinary B2B web work, but ITAR- or EAR-controlled technical data cannot go to an offshore team without authorisation. RAITHub handles no controlled data and does not take that work.

Does FedRAMP apply to a custom-built web app?

FedRAMP authorises cloud services used by US federal agencies. A custom app is usually hosted on an authorised cloud platform, and the agency decides what else it needs. Confirm with the agency.

What is the Web Accessibility Directive?

An EU directive requiring public-sector websites and apps to be accessible, publish an accessibility statement and offer a feedback mechanism. EN 301 549 V3.2.1 is the harmonised standard behind it.

Government softwareCitizen portalsAccessibilityWCAG 2.2Section 508EN 301 549Public procurement

Ready to discuss your project?

Book a free 15-minute technical audit with our engineering team.