<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: JagheterAlex</title>
    <description>The latest articles on DEV Community by JagheterAlex (@jagheteralex).</description>
    <link>https://dev.to/jagheteralex</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F4087232%2F6f8be1f2-044b-4abc-a847-392fce0fa805.jpg</url>
      <title>DEV Community: JagheterAlex</title>
      <link>https://dev.to/jagheteralex</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/jagheteralex"/>
    <language>en</language>
    <item>
      <title>EN 301 549 is about to move to WCAG 2.2. Six criteria, one date, and one requirement that disappears.</title>
      <dc:creator>JagheterAlex</dc:creator>
      <pubDate>Thu, 10 Sep 2026 14:00:58 +0000</pubDate>
      <link>https://dev.to/jagheteralex/en-301-549-is-about-to-move-to-wcag-22-six-criteria-one-date-and-one-requirement-that-5ae6</link>
      <guid>https://dev.to/jagheteralex/en-301-549-is-about-to-move-to-wcag-22-six-criteria-one-date-and-one-requirement-that-5ae6</guid>
      <description>&lt;p&gt;If you are working to the European Accessibility Act, the standard you are&lt;br&gt;
working to is &lt;strong&gt;EN 301 549 V3.2.1 (2021-03)&lt;/strong&gt;, and it adopts &lt;strong&gt;WCAG 2.1&lt;/strong&gt;. That&lt;br&gt;
is true today. It is scheduled to stop being true &lt;strong&gt;near the end of 2026&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;Here is what changes, what does not, and the one thing worth doing about it now.&lt;/p&gt;
&lt;h2&gt;
  
  
  The date, and why it is the only date that matters
&lt;/h2&gt;

&lt;p&gt;A standard becomes a legal obligation in the EU when it is &lt;strong&gt;cited in the&lt;br&gt;
Official Journal&lt;/strong&gt;, not when the body that wrote it publishes it. That&lt;br&gt;
distinction is the whole story here.&lt;/p&gt;

&lt;p&gt;The sequence, from ETSI's work programme and what has been published so far:&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Milestone&lt;/th&gt;
&lt;th&gt;When&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;V4.1.0 public-enquiry draft&lt;/td&gt;
&lt;td&gt;November 2025 - done&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;V4.1.0 final draft&lt;/td&gt;
&lt;td&gt;June 2026 - done&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;V4.1.1 published by ETSI, CEN and CENELEC&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;&lt;strong&gt;2 September 2026 - done&lt;/strong&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Cited in the Official Journal, replacing V3.2.1&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;&lt;strong&gt;Provisional: late November to mid-December 2026&lt;/strong&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;So the standard itself now exists in final form. What is left is the step that&lt;br&gt;
carries the legal weight: delivery to the European Commission and citation in the&lt;br&gt;
Official Journal. Published estimates for the citation date currently sit between&lt;br&gt;
30 November and 16 December 2026, and they have already moved by weeks as the&lt;br&gt;
standard worked through review. For one point of comparison, V3.2.1 was published&lt;br&gt;
in March 2021 and cited about five months later; on that precedent alone the date&lt;br&gt;
could slip into 2027. Treat the quarter as the plan and the day as provisional.&lt;/p&gt;

&lt;p&gt;Until that citation happens, &lt;strong&gt;V3.2.1 is the yardstick&lt;/strong&gt; and WCAG 2.2 criteria&lt;br&gt;
are good practice rather than obligations. Anyone selling you WCAG 2.2 remediation&lt;br&gt;
as a legal requirement today is ahead of the law. Anyone telling you to ignore 2.2&lt;br&gt;
is setting you up to do the work twice.&lt;/p&gt;
&lt;h2&gt;
  
  
  What actually changes
&lt;/h2&gt;

&lt;p&gt;Clauses 9, 10 and 11 web, non-web documents and software move from WCAG 2.1&lt;br&gt;
to &lt;strong&gt;WCAG 2.2 Level AA&lt;/strong&gt;. For clause 9, that is six new success criteria at A and&lt;br&gt;
AA.&lt;/p&gt;
&lt;h3&gt;
  
  
  3.2.6 Consistent Help (Level A)
&lt;/h3&gt;

&lt;p&gt;If you offer a help mechanism contact details, a chat widget, a help link it&lt;br&gt;
has to appear in the same relative order across pages. In practice this is a&lt;br&gt;
layout consistency rule, and most sites with a stable header already pass it. The&lt;br&gt;
ones that fail are the ones where help moves into a hamburger on some templates&lt;br&gt;
and not others.&lt;/p&gt;
&lt;h3&gt;
  
  
  3.3.7 Redundant Entry (Level A)
&lt;/h3&gt;

&lt;p&gt;Do not ask for the same information twice in one process. If the user typed their&lt;br&gt;
address at step two, step four either pre-fills it or offers it for selection.&lt;br&gt;
Checkout flows and multi-step onboarding are where this bites.&lt;/p&gt;
&lt;h3&gt;
  
  
  2.4.11 Focus Not Obscured, Minimum (Level AA)
&lt;/h3&gt;

&lt;p&gt;When something receives keyboard focus, it must not be entirely hidden behind&lt;br&gt;
sticky headers, cookie bars or floating chat bubbles. This is the criterion most&lt;br&gt;
likely to fail on a modern site, because sticky elements are everywhere and almost&lt;br&gt;
nobody tabs through their own page to check.&lt;/p&gt;
&lt;h3&gt;
  
  
  2.5.7 Dragging Movements (Level AA)
&lt;/h3&gt;

&lt;p&gt;Anything you can do by dragging must also be doable with a single pointer action&lt;br&gt;
that is not a drag. Sliders, kanban boards, reorderable lists, map panning. Add a&lt;br&gt;
click alternative or a set of buttons.&lt;/p&gt;
&lt;h3&gt;
  
  
  2.5.8 Target Size, Minimum (Level AA)
&lt;/h3&gt;

&lt;p&gt;Interactive targets must be at least &lt;strong&gt;24 by 24 CSS pixels&lt;/strong&gt;, with exceptions for&lt;br&gt;
inline links in text and for targets with enough spacing around them.&lt;/p&gt;

&lt;p&gt;This is the one people get wrong when they read old advice. WCAG 2.1 had a target&lt;br&gt;
size criterion2.5.5, but it was &lt;strong&gt;Level AAA at 44 pixels&lt;/strong&gt;, so it was never&lt;br&gt;
in scope for EAA conformance. WCAG 2.2 adds a &lt;em&gt;different, smaller&lt;/em&gt; criterion at&lt;br&gt;
AA. If your design system standardised on 44px because a consultant said so, you&lt;br&gt;
were never obliged to and you still are not. Twenty-four is the number that is&lt;br&gt;
about to matter.&lt;/p&gt;
&lt;h3&gt;
  
  
  3.3.8 Accessible Authentication, Minimum (Level AA)
&lt;/h3&gt;

&lt;p&gt;No cognitive function test in your login unless there is an alternative. That&lt;br&gt;
means: do not require the user to solve a puzzle, transcribe a code from an image,&lt;br&gt;
or remember something, without offering another route. Copy and paste must work in&lt;br&gt;
one-time-code fields. Password managers must not be blocked.&lt;/p&gt;

&lt;p&gt;This one has teeth, because a lot of authentication is deliberately hostile to&lt;br&gt;
automation, and hostility to automation is usually hostility to assistive&lt;br&gt;
technology as well.&lt;/p&gt;
&lt;h2&gt;
  
  
  The requirement that disappears
&lt;/h2&gt;

&lt;p&gt;&lt;strong&gt;4.1.1 Parsing is obsolete in WCAG 2.2.&lt;/strong&gt; Duplicate &lt;code&gt;id&lt;/code&gt; attributes and unclosed&lt;br&gt;
tags are no longer a conformance failure on their own browsers recover from them&lt;br&gt;
predictably and the criterion no longer described a real barrier.&lt;/p&gt;

&lt;p&gt;But it is still in force right now, because V3.2.1 adopts WCAG 2.1, and 2.1 still&lt;br&gt;
contains it. So a duplicate &lt;code&gt;id&lt;/code&gt; is a failure of the currently harmonised standard&lt;br&gt;
today and will quietly stop being one after citation.&lt;/p&gt;

&lt;p&gt;This is the only place where the new version makes your life easier, and it is&lt;br&gt;
worth knowing about mostly so that you do not spend an afternoon close to&lt;br&gt;
citation fixing something that no longer counts.&lt;/p&gt;
&lt;h2&gt;
  
  
  Two changes nobody mentions
&lt;/h2&gt;

&lt;p&gt;&lt;strong&gt;Clause 6 gets much bigger.&lt;/strong&gt; Real-time communication requirements broaden from&lt;br&gt;
two-way voice to real-time bidirectional communication, formally taking in Total&lt;br&gt;
Conversation voice, real-time text and video together with substantially&lt;br&gt;
revised RTT requirements. If your product includes calling, messaging or support&lt;br&gt;
chat, clause 6 deserves a read on its own, separately from anything WCAG says.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Annexes ZA and ZB are new, and they matter more than they sound.&lt;/strong&gt; Annex ZB maps&lt;br&gt;
the technical clauses onto the actual articles of the European Accessibility Act,&lt;br&gt;
and Annex ZA does the same for the Web Accessibility Directive. V3.2.1 had no such&lt;br&gt;
mapping, which is why demonstrating a presumption of conformity against the EAA has&lt;br&gt;
been awkward: you were citing a technical standard at a legal instrument and hoping&lt;br&gt;
the join was obvious. V4.1.1 makes the join explicit.&lt;/p&gt;

&lt;p&gt;For anyone who has had to assemble a conformance argument by hand, that is the&lt;br&gt;
most useful thing in the release.&lt;/p&gt;
&lt;h2&gt;
  
  
  What to do before citation
&lt;/h2&gt;

&lt;p&gt;&lt;strong&gt;Do not remediate WCAG 2.2 as though it were law today.&lt;/strong&gt; It is not, and you&lt;br&gt;
will have spent budget ahead of the obligation.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Do not ignore it either.&lt;/strong&gt; Six new criteria with citation expected around the&lt;br&gt;
turn of the year is a plannable piece of work, and the two that usually require&lt;br&gt;
real design changes focus not obscured, and dragging movements are cheaper to&lt;br&gt;
fix while you are already touching a component than as a year-end emergency.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Measure the gap now, separately.&lt;/strong&gt; You want two numbers: what fails against the&lt;br&gt;
standard that binds you today, and what would additionally fail after citation.&lt;br&gt;
One is a compliance obligation. The other is a roadmap item. Reporting them as a&lt;br&gt;
single red total is how tools inflate a problem into a panic.&lt;/p&gt;

&lt;p&gt;That separation is why I built &lt;a href="https://curbcut.org" rel="noopener noreferrer"&gt;Curbcut&lt;/a&gt; the way I did. It&lt;br&gt;
reports findings as EN 301 549 clauses, and it keeps WCAG 2.2 criteria in their own&lt;br&gt;
band visible, counted, and explicitly marked as not currently obligatory.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;npx curbcut https://example.com &lt;span class="nt"&gt;--crawl&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;It is MIT licensed, runs on your machine, and uploads nothing. When the citation&lt;br&gt;
lands, the mapping updates and the same criteria move bands, which is exactly the&lt;br&gt;
event I would rather have handled in software than in a spreadsheet.&lt;/p&gt;

&lt;h2&gt;
  
  
  The honest caveat
&lt;/h2&gt;

&lt;p&gt;Automated testing finds roughly a third of accessibility barriers, and several of&lt;br&gt;
these new criteria are barely testable by machine at all. Consistent Help and&lt;br&gt;
Redundant Entry are judgements about a flow. Accessible Authentication needs&lt;br&gt;
somebody to actually try logging in with a password manager and a screen reader.&lt;/p&gt;

&lt;p&gt;Curbcut prints the clauses it could not evaluate rather than omitting them,&lt;br&gt;
because a silent pass is the most expensive kind of wrong answer in this field. A&lt;br&gt;
scanner is where this work starts. It is not where it finishes.&lt;/p&gt;




&lt;p&gt;&lt;em&gt;This article reflects EN 301 549 V4.1.1 as published on 2 September 2026 and&lt;br&gt;
ETSI's schedule for Official Journal citation as of September 2026; the citation&lt;br&gt;
date in particular may still move. Nothing here is legal advice.&lt;/em&gt;&lt;/p&gt;

</description>
      <category>a11y</category>
      <category>webdev</category>
      <category>complience</category>
      <category>wcag</category>
    </item>
    <item>
      <title>The accessibility statement template you copied is for a different law</title>
      <dc:creator>JagheterAlex</dc:creator>
      <pubDate>Thu, 03 Sep 2026 13:28:34 +0000</pubDate>
      <link>https://dev.to/jagheteralex/the-accessibility-statement-template-you-copied-is-for-a-different-law-2cnj</link>
      <guid>https://dev.to/jagheteralex/the-accessibility-statement-template-you-copied-is-for-a-different-law-2cnj</guid>
      <description>&lt;p&gt;Search for "EAA accessibility statement template" and you will find the same&lt;br&gt;
twelve-section document over and over. Conformance status, non-accessible&lt;br&gt;
content, preparation date, feedback mechanism, enforcement procedure. It looks&lt;br&gt;
official because it is official.&lt;/p&gt;

&lt;p&gt;It is also written for a different directive, aimed at organisations you are&lt;br&gt;
probably not one of.&lt;/p&gt;

&lt;p&gt;That template comes from &lt;strong&gt;Implementing Decision (EU) 2018/1523&lt;/strong&gt;, which sets out&lt;br&gt;
the model accessibility statement for the &lt;strong&gt;Web Accessibility Directive&lt;/strong&gt;&lt;br&gt;
(2016/2102). The Web Accessibility Directive applies to &lt;em&gt;public sector bodies&lt;/em&gt;&lt;br&gt;
ministries, municipalities, state hospitals, public universities.&lt;/p&gt;

&lt;p&gt;The European Accessibility Act is a different instrument with a different scope,&lt;br&gt;
and it does not prescribe a template at all.&lt;/p&gt;

&lt;p&gt;Copying the public-sector model is not a disaster. Much of it is sensible, and&lt;br&gt;
national transpositions differ yours may well ask for something close to it.&lt;br&gt;
Check what your own member state actually enacted, because that is the text that&lt;br&gt;
binds you, not the directive in the abstract. But if you copy the model believing&lt;br&gt;
it is the EAA requirement, you will&lt;br&gt;
confidently produce a document that satisfies a rule you are not subject to while&lt;br&gt;
missing two obligations you are.&lt;/p&gt;

&lt;p&gt;One caveat with a date on it, because I would rather flag this than have the&lt;br&gt;
article age into a lie. The revision of EN 301 549 is being carried out under&lt;br&gt;
Commission Standardisation Request &lt;strong&gt;M/587&lt;/strong&gt;, which covers both the EAA and the&lt;br&gt;
Web Accessibility Directive. Work under that mandate has included establishing a&lt;br&gt;
model accessibility statement. So "the EAA prescribes no template" is true as I&lt;br&gt;
write this and may not stay true. If a model arrives through the harmonised&lt;br&gt;
standard, use it a template that carries a presumption of conformity is worth&lt;br&gt;
more than any structure I can suggest.&lt;/p&gt;
&lt;h2&gt;
  
  
  Before any of this: does it apply to you?
&lt;/h2&gt;

&lt;p&gt;Microenterprises providing services fewer than ten people, and annual turnover&lt;br&gt;
or balance-sheet total not over €2 million are exempt from the EAA's service&lt;br&gt;
obligations. That exemption does not extend to product manufacturers, and it does&lt;br&gt;
not exempt you from other law.&lt;/p&gt;

&lt;p&gt;If you are under those thresholds, the rest of this article is optional reading&lt;br&gt;
rather than a compliance task. Publishing an honest statement is still a good&lt;br&gt;
idea. It is just not the same as being obliged to.&lt;/p&gt;
&lt;h2&gt;
  
  
  What the EAA actually asks for
&lt;/h2&gt;

&lt;p&gt;Article 13(2) puts the duty on service providers plainly: prepare the information&lt;br&gt;
required by Annex V, and explain how the service meets the applicable&lt;br&gt;
accessibility requirements.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Annex V&lt;/strong&gt; then lists what that information contains:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;&lt;strong&gt;A general description of the service in accessible formats.&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Descriptions and explanations necessary for understanding how the service
operates.&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;A description of how the relevant accessibility requirements in Annex I are
met.&lt;/strong&gt;&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;Three items. No conformance percentage, no prescribed headings, no template.&lt;/p&gt;

&lt;p&gt;That is more demanding than it first appears, because point 3 is not "we ran a&lt;br&gt;
scanner". Annex I is the accessibility requirements themselves. You are being&lt;br&gt;
asked to walk through what applies to you and describe how you meet it.&lt;/p&gt;
&lt;h2&gt;
  
  
  The two obligations the public-sector template will not remind you about
&lt;/h2&gt;
&lt;h3&gt;
  
  
  It goes in your terms and conditions
&lt;/h3&gt;

&lt;p&gt;The directive says the information assessing how your service meets the&lt;br&gt;
accessibility requirements belongs in the &lt;strong&gt;general terms and conditions, or an&lt;br&gt;
equivalent document&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;The pattern you see almost everywhere is a page at &lt;code&gt;/accessibility&lt;/code&gt; linked from&lt;br&gt;
the footer, and nothing else. That page is useful and you should keep&lt;br&gt;
it but on its own it is not where the directive says the information lives.&lt;/p&gt;

&lt;p&gt;If your terms and conditions are a separate document a customer accepts at&lt;br&gt;
checkout, that document, or something equivalent to it, is where this has to&lt;br&gt;
appear.&lt;/p&gt;
&lt;h3&gt;
  
  
  It has to exist in oral format too
&lt;/h3&gt;

&lt;p&gt;Article 13(2) requires the information be available &lt;strong&gt;in written and oral&lt;br&gt;
format&lt;/strong&gt;, and in a manner accessible to persons with disabilities.&lt;/p&gt;

&lt;p&gt;Oral. This is the requirement I have seen discussed least and skipped most.&lt;/p&gt;

&lt;p&gt;It does not mean recording a podcast. In practice it means somebody who telephones&lt;br&gt;
your support line and asks how accessible your service is must be able to get the&lt;br&gt;
answer that way which implies your support staff know it exists and can read it&lt;br&gt;
out or explain it. A statement your own support team has never seen fails this&lt;br&gt;
quietly and completely.&lt;/p&gt;
&lt;h2&gt;
  
  
  What makes a statement survive being read by a hostile expert
&lt;/h2&gt;

&lt;p&gt;The three ways statements fail have nothing to do with formatting.&lt;/p&gt;
&lt;h3&gt;
  
  
  Claiming conformance you cannot support
&lt;/h3&gt;

&lt;p&gt;"This website is fully compliant with WCAG 2.1 AA" is the single most common&lt;br&gt;
sentence in generated statements, and it is almost never true.&lt;/p&gt;

&lt;p&gt;Automated testing detects roughly a third of accessibility barriers. If nobody has&lt;br&gt;
tested with a screen reader, nobody has tabbed the full checkout, and nobody with&lt;br&gt;
a disability has used the thing, then the honest status is &lt;em&gt;partially conformant&lt;/em&gt;,&lt;br&gt;
and saying so costs you far less than the alternative.&lt;/p&gt;

&lt;p&gt;The alternative is documented. In January 2025 the US Federal Trade Commission&lt;br&gt;
brought a case against accessiBe over claims that its widget could make any site&lt;br&gt;
WCAG compliant, and&lt;br&gt;
&lt;a href="https://www.ftc.gov/legal-library/browse/cases-proceedings/2223156-accessibe-inc" rel="noopener noreferrer"&gt;approved a final order in April&lt;/a&gt;&lt;br&gt;
requiring the company to pay &lt;strong&gt;$1,000,000&lt;/strong&gt;. The complaint also covered reviews&lt;br&gt;
presented as independent that were not. Different jurisdiction, same principle: an&lt;br&gt;
accessibility claim is a claim, and unsupported claims are actionable.&lt;/p&gt;

&lt;p&gt;Your statement carries your organisation's name, not your vendor's.&lt;/p&gt;
&lt;h3&gt;
  
  
  Being silent about what was never checked
&lt;/h3&gt;

&lt;p&gt;A statement that lists three known issues implies the rest was examined and passed.&lt;/p&gt;

&lt;p&gt;If your evidence is one automated run, several clauses were never evaluated at all consistent navigation, keyboard operability across a whole journey, whether alt&lt;br&gt;
text actually communicates anything. Silence about them reads as a pass, and that&lt;br&gt;
inference is the thing you did not intend to make and will be held to anyway.&lt;/p&gt;

&lt;p&gt;Name them. "These were not assessed" is a defensible sentence. "We are fully&lt;br&gt;
compliant" when they were not assessed is not.&lt;/p&gt;
&lt;h3&gt;
  
  
  Offering a feedback route that does not work
&lt;/h3&gt;

&lt;p&gt;Every model statement includes a contact for reporting barriers. Most of those&lt;br&gt;
addresses go to a mailbox nobody reads.&lt;/p&gt;

&lt;p&gt;The feedback mechanism is not decoration. It is the thing a regulator will test&lt;br&gt;
first, because it takes them thirty seconds and it tells them whether the rest of&lt;br&gt;
the document is real. Send a message to your own accessibility contact and see&lt;br&gt;
what happens.&lt;/p&gt;
&lt;h2&gt;
  
  
  A structure that works
&lt;/h2&gt;

&lt;p&gt;Not a template to paste the EAA prescribes none, and your service is not mine.&lt;br&gt;
But this order holds up:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;What this service is&lt;/strong&gt;, in plain language. Annex V point 1, and the place to be&lt;br&gt;
concrete rather than corporate.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Current status&lt;/strong&gt;, stated exactly as strongly as your evidence supports. If the&lt;br&gt;
evidence is automated testing only, say that in the same sentence as the status.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;How the requirements are met&lt;/strong&gt;, walking the applicable parts of Annex I. This is&lt;br&gt;
the substance, and it is the part a template cannot write for you.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;What is not accessible yet&lt;/strong&gt;, with what you intend to do and roughly when. A&lt;br&gt;
known issue with a date attached reads as competence. The same issue undisclosed&lt;br&gt;
reads as concealment.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;What was not tested&lt;/strong&gt;, named clause by clause rather than left to inference.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;How to tell us&lt;/strong&gt;, with a route somebody actually monitors and a response time you&lt;br&gt;
will actually hit.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;When this was prepared and how&lt;/strong&gt;, including what tooling and what manual&lt;br&gt;
testing. A statement with no date and no method is an assertion.&lt;/p&gt;
&lt;h2&gt;
  
  
  Where a tool helps, and where it does not
&lt;/h2&gt;

&lt;p&gt;&lt;a href="https://curbcut.org" rel="noopener noreferrer"&gt;Curbcut&lt;/a&gt; drafts the evidence-based parts. It maps findings&lt;br&gt;
onto EN 301 549 clauses, ranks them by regulatory exposure rather than by how&lt;br&gt;
loudly a rule engine complains, and generates a statement draft.&lt;/p&gt;

&lt;p&gt;The generator deliberately &lt;strong&gt;will not&lt;/strong&gt; produce a full-conformance claim from scan&lt;br&gt;
data, because scan data cannot support one. Everything requiring a human decision&lt;br&gt;
stays a visible &lt;code&gt;[bracket]&lt;/code&gt; until a human fills it in. Brackets in a draft are&lt;br&gt;
annoying. Brackets are also the only honest output when the input is one automated&lt;br&gt;
run.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;npx curbcut https://example.com &lt;span class="nt"&gt;--crawl&lt;/span&gt; &lt;span class="nt"&gt;--statement&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Or &lt;a href="https://curbcut.org/scan" rel="noopener noreferrer"&gt;check a page in your browser&lt;/a&gt; with nothing installed,&lt;br&gt;
which is the faster way to see what your evidence actually looks like before you&lt;br&gt;
write anything.&lt;/p&gt;

&lt;h2&gt;
  
  
  The honest part
&lt;/h2&gt;

&lt;p&gt;I am not a lawyer and this is not legal advice. Whether the EAA applies to you,&lt;br&gt;
what your national transposition adds, and whether a particular statement&lt;br&gt;
discharges your obligation are legal questions about your business.&lt;/p&gt;

&lt;p&gt;What I can tell you is that automated testing reaches about a third of the&lt;br&gt;
problem, that a statement is a public claim about the other two thirds, and that&lt;br&gt;
the gap between those two facts is where organisations get into trouble.&lt;/p&gt;

&lt;p&gt;Write the statement you can defend, not the one you would prefer to be true.&lt;/p&gt;

</description>
      <category>a11y</category>
      <category>compliance</category>
      <category>webdev</category>
      <category>legal</category>
    </item>
    <item>
      <title>Everyone is getting ready for WCAG 2.2. Two thirds of Europe's biggest sites still fail 2.1 Level A.</title>
      <dc:creator>JagheterAlex</dc:creator>
      <pubDate>Thu, 27 Aug 2026 09:47:26 +0000</pubDate>
      <link>https://dev.to/jagheteralex/everyone-is-getting-ready-for-wcag-22-two-thirds-of-europes-biggest-sites-still-fail-21-level-a-2087</link>
      <guid>https://dev.to/jagheteralex/everyone-is-getting-ready-for-wcag-22-two-thirds-of-europes-biggest-sites-still-fail-21-level-a-2087</guid>
      <description>&lt;p&gt;The next version of the European accessibility standard is scheduled for citation on 30 November 2026. EN 301 549 V4.1.1 swaps WCAG 2.1 for WCAG 2.2, and six new success criteria arrive at levels A and AA. There is a small industry of readiness checklists for it already.&lt;/p&gt;

&lt;p&gt;So I measured what the current version looks like first. The answer is that the deadline people are preparing for is not the one they have missed.&lt;/p&gt;

&lt;p&gt;I scanned the most-visited websites on EU country domains and counted which clauses of EN 301 549 they fail today, under the version cited right now. Not the one arriving. The one in force since before the European Accessibility Act deadline passed in June 2025.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Sixty-four per cent fail clause 9.4.1.2, Name, Role, Value.&lt;/strong&gt; It is Level A, the lowest bar the standard has, and it has been in every version of WCAG since 2008.&lt;/p&gt;

&lt;p&gt;Here is the full picture, and then the reasons to distrust parts of it.&lt;/p&gt;

&lt;h2&gt;
  
  
  What was measured
&lt;/h2&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Clause&lt;/th&gt;
&lt;th&gt;Criterion&lt;/th&gt;
&lt;th&gt;Level&lt;/th&gt;
&lt;th&gt;Sites failing&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;9.4.1.2&lt;/td&gt;
&lt;td&gt;Name, Role, Value&lt;/td&gt;
&lt;td&gt;A&lt;/td&gt;
&lt;td&gt;96 of 149 (64%)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;9.1.4.3&lt;/td&gt;
&lt;td&gt;Contrast (Minimum)&lt;/td&gt;
&lt;td&gt;AA&lt;/td&gt;
&lt;td&gt;66 of 149 (44%)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;9.2.4.4&lt;/td&gt;
&lt;td&gt;Link Purpose (In Context)&lt;/td&gt;
&lt;td&gt;A&lt;/td&gt;
&lt;td&gt;53 of 149 (36%)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;9.2.5.8&lt;/td&gt;
&lt;td&gt;Target Size (Minimum)&lt;/td&gt;
&lt;td&gt;AA&lt;/td&gt;
&lt;td&gt;51 of 149 (34%)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;9.1.1.1&lt;/td&gt;
&lt;td&gt;Non-text Content&lt;/td&gt;
&lt;td&gt;A&lt;/td&gt;
&lt;td&gt;35 of 149 (23%)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;9.1.3.1&lt;/td&gt;
&lt;td&gt;Info and Relationships&lt;/td&gt;
&lt;td&gt;A&lt;/td&gt;
&lt;td&gt;27 of 149 (18%)&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;Target size is the odd one out: it is a WCAG 2.2 criterion and &lt;strong&gt;not&lt;/strong&gt; currently required. It is in the table because it is the only one of the six arriving in V4.1.1 that the rule engine used here has a check for, which is a point I will come back to.&lt;/p&gt;

&lt;p&gt;Thirty-two sites of the 149, about one in five, failed nothing that automated testing can detect. That is not the same as passing.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Two of those rows are not independent.&lt;/strong&gt; The rule that most often breaks Name, Role, Value is a link with no accessible name, and the same defect also fails Link Purpose. One missing label lands in two rows of that table. I am pointing this out because a table of six numbers implies six problems, and some of them are the same problem counted twice under different clauses — which is, incidentally, why conformance is claimed against clauses rather than rule counts.&lt;/p&gt;

&lt;h2&gt;
  
  
  What the failures actually are
&lt;/h2&gt;

&lt;p&gt;Clause names are abstract. On a second pass I recorded which underlying rule produced each failure, so the table above turns into something you can picture. That pass covered the top 120 domains and measured 59 of them.&lt;/p&gt;

&lt;p&gt;It is a worse-performing group than the full sample, and predictably so: it is the more-visited end of the list, which the section above already found does worse. Name, Role, Value fails on 73% of it against 64% overall. Read the shares below as proportions within that group, not as headline rates.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;What breaks Name, Role, Value&lt;/strong&gt;, on the 43 sites of 59 that failed it:&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;What is wrong&lt;/th&gt;
&lt;th&gt;Share of the sites failing this clause&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;A link a screen reader announces as nothing&lt;/td&gt;
&lt;td&gt;49%&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;An &lt;code&gt;&amp;lt;iframe&amp;gt;&lt;/code&gt; with no title&lt;/td&gt;
&lt;td&gt;30%&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;A button with no accessible name&lt;/td&gt;
&lt;td&gt;28%&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;ARIA attributes that are invalid or not allowed&lt;/td&gt;
&lt;td&gt;16%&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;The first one is usually an icon: a magnifier, a basket, a social media glyph, marked up as a link with an image inside and no text anywhere. The second is usually an advert. Neither is an architectural problem. Both are a missing attribute.&lt;/p&gt;

&lt;p&gt;The rest are simpler still. In that same group, every single contrast failure came from one rule, every target-size failure from one rule, and every non-text-content failure was an image with no alternative text. Not a long tail of exotic problems. One thing, repeated.&lt;/p&gt;

&lt;p&gt;None of this is hard. That is the uncomfortable part: it is not hard, and two thirds of the most-visited sites in Europe have it anyway.&lt;/p&gt;

&lt;h2&gt;
  
  
  The finding I did not expect
&lt;/h2&gt;

&lt;p&gt;I assumed the biggest sites would do best. They have the most money and the most staff.&lt;/p&gt;

&lt;p&gt;Splitting the measured sites at the median rank:&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;&lt;/th&gt;
&lt;th&gt;Failing nothing detectable&lt;/th&gt;
&lt;th&gt;Median clauses failing&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;More-visited half&lt;/td&gt;
&lt;td&gt;11%&lt;/td&gt;
&lt;td&gt;2&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Less-visited half&lt;/td&gt;
&lt;td&gt;32%&lt;/td&gt;
&lt;td&gt;1&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;The more popular half is roughly three times less likely to come back clean. I cannot prove the mechanism from this data, but the plausible one is unglamorous: big sites carry more third-party widgets, more legacy, more teams shipping into the same page, and more of everything that goes wrong. Budget does not appear to be the constraint.&lt;/p&gt;

&lt;h2&gt;
  
  
  The one WCAG 2.2 criterion a scanner can reach
&lt;/h2&gt;

&lt;p&gt;Thirty-four per cent fail target size, and that number needs a caveat before anyone repeats it.&lt;/p&gt;

&lt;p&gt;A third of the sites showed a cookie consent dialog to an anonymous visitor, and on one in five the dialog covered more than 40% of the screen. I did not dismiss them. Clicking "accept all" on somebody else's site, unattended and at scale, is not something a research script should be doing, and it would also have changed what I was measuring.&lt;/p&gt;

&lt;p&gt;So the target-size number partly describes consent dialogs. Splitting it:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Sites showing a consent dialog: &lt;strong&gt;40%&lt;/strong&gt; fail target size&lt;/li&gt;
&lt;li&gt;Sites without one: &lt;strong&gt;31%&lt;/strong&gt;
&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;The gap is real and the finding survives it. Consent dialogs are worse than the pages behind them, and the pages behind them are not fine.&lt;/p&gt;

&lt;p&gt;The other five criteria arriving in November — focus not obscured, dragging movements, consistent help, redundant entry, accessible authentication — were not measured here at all. Each is a judgement about behaviour that the page source does not contain: whether a sticky header covers the control that just took focus, whether every drag has a single-pointer alternative, whether a login demands something a person cannot be expected to do. axe-core has no rule for any of them, and I am not aware of a scanner that does.&lt;/p&gt;

&lt;p&gt;That is the single most useful thing to know about this transition. &lt;strong&gt;Five of the six need a person.&lt;/strong&gt; Any tool advertising a WCAG 2.2 readiness check is checking one criterion in six and staying quiet about the other five.&lt;/p&gt;

&lt;h2&gt;
  
  
  Two loads, two answers
&lt;/h2&gt;

&lt;p&gt;Every page was loaded twice, seconds apart, and only criteria that failed both times were counted.&lt;/p&gt;

&lt;p&gt;That rule exists because the pilot caught a large retailer passing target size on one load and failing it on the next, with nothing changed in between. In the full run, nine sites of 149 disagreed with themselves that way. Six per cent.&lt;/p&gt;

&lt;p&gt;Six per cent turned out to be the flattering number.&lt;/p&gt;

&lt;p&gt;I ran a second, smaller pass over the top of the same list a few hours later. On the first 120 domains, the disagreement rate was &lt;strong&gt;10% in the first run and 19% in the second&lt;/strong&gt;. And 57 sites were measured in both passes, hours apart: &lt;strong&gt;eight of them, one in seven, produced a different set of failing clauses the second time.&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Nobody deployed anything in the seconds between two loads. Rotating promotional content, A/B tests and consent variants move the geometry of a page across a threshold on their own. Over hours, an editorial site simply becomes a different page.&lt;/p&gt;

&lt;p&gt;I would rather quote the six per cent. It is the number I found first and it makes the sample look tidiest. The other three come from the same data and they all say the effect is larger.&lt;/p&gt;

&lt;p&gt;If you commissioned a dated accessibility audit, you bought a description of one moment. You can test that for nothing, and without believing me, because I sell a scanner and have an obvious stake in the answer: run any free checker over your own homepage twice in a row, then again this afternoon.&lt;/p&gt;

&lt;h2&gt;
  
  
  Half the sample never got measured
&lt;/h2&gt;

&lt;p&gt;Of 300 domains sampled, 151 were excluded. This is where a study either tells you what it threw away or quietly rounds its own numbers up.&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Reason&lt;/th&gt;
&lt;th&gt;Count&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Redirects to a different domain&lt;/td&gt;
&lt;td&gt;43&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;A stylesheet failed to load&lt;/td&gt;
&lt;td&gt;34&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Blocked the request (HTTP 403)&lt;/td&gt;
&lt;td&gt;32&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Domain does not resolve&lt;/td&gt;
&lt;td&gt;20&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;robots.txt disallows it&lt;/td&gt;
&lt;td&gt;6&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Connection, certificate or timeout errors&lt;/td&gt;
&lt;td&gt;8&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Blocked our test script via Content Security Policy&lt;/td&gt;
&lt;td&gt;4&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Other HTTP errors&lt;/td&gt;
&lt;td&gt;4&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;Three of these are worth a comment.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;The stylesheet exclusions are self-protection.&lt;/strong&gt; A page that renders unstyled fails layout rules that the real page passes, and target size is exactly such a rule. I know this because it happened to me in August: a scan caught our own site mid-deploy and reported sixteen violations that vanished on the next run. Reporting invented failures is the same category of error as inventing a passing grade, so any page whose CSS did not arrive is thrown out rather than counted.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Eleven per cent of the sample blocked us outright.&lt;/strong&gt; Bot protection does not distinguish between a scraper and an accessibility audit. If you are wondering why third-party research on this subject is thin, that is part of the answer.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Four sites were excluded because our scanner obeyed their Content Security Policy — and that turned out to be our bug, not their barrier.&lt;/strong&gt; This paragraph originally said that a strict CSP prevents anybody from auditing your accessibility from outside. That was wrong, and it is corrected here on 22 August. A strict policy refuses to execute a &lt;code&gt;&amp;lt;script&amp;gt;&lt;/code&gt; element appended to the document, which is exactly how this tool was loading its rule engine. Auditors built as browser extensions never had the problem, because they run outside the document. Neither do we any more: the loader was changed the same day to go through the debugging protocol instead, which is one line. Read those four as a limitation of the tool on the day, not as a property of the sites, and expect the category to be absent from the next dated run.&lt;/p&gt;

&lt;p&gt;The exclusions are not random. A site with sophisticated bot protection is probably a different kind of organisation from one without. &lt;strong&gt;The 149 sites I could measure are the ones that let me in&lt;/strong&gt;, and if anything I would expect that group to skew toward the simpler end.&lt;/p&gt;

&lt;h2&gt;
  
  
  What this is not
&lt;/h2&gt;

&lt;p&gt;&lt;strong&gt;It is not a compliance rate.&lt;/strong&gt; The EAA covers e-commerce, banking and payments, electronic communications, transport ticketing and information, audiovisual media services and e-books. It does not cover every website. A news portal is outside scope unless it sells subscriptions — and nearly every large European newspaper does, which pulls most of them back in, but "most" is not "all" and I did not check them one by one. Microenterprises under ten staff are exempt from the service requirements entirely.&lt;/p&gt;

&lt;p&gt;So read the numbers as a picture of the European web, not as an audit of the regulated subset of it.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Failing a criterion is not the same as breaking the law.&lt;/strong&gt; The harmonised standard gives a presumption of conformance. Missing it means you no longer have that presumption, not that a penalty follows.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Automated testing finds roughly 30 to 40% of WCAG failures.&lt;/strong&gt; Every number here is a floor. The 21% that came back clean did not pass an accessibility audit; they passed the third of one that a machine can perform.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;One page per site.&lt;/strong&gt; The homepage. A conformance claim covers a service, and I measured a front door.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Clause 9 only.&lt;/strong&gt; EN 301 549 has more than web pages in it. Clause 10 applies the same success criteria, through WCAG2ICT, to documents a service delivers rather than renders: the invoice, the ticket, the statement of account, the e-book. For most of the categories the EAA names, that is a large share of what a customer actually reads, and nothing here looked at any of it. So the 30 to 40% above is a share of failures in &lt;em&gt;web content&lt;/em&gt;, not a share of the obligation — read it as generous rather than conservative.&lt;/p&gt;

&lt;h2&gt;
  
  
  Method
&lt;/h2&gt;

&lt;p&gt;Sample: the &lt;a href="https://tranco-list.eu/" rel="noopener noreferrer"&gt;Tranco&lt;/a&gt; research list, id 74V8X generated 21 August 2026, filtered to domains whose TLD belongs to an EU member state, taken in rank order. Tranco averages five ranking providers over thirty days specifically to resist the manipulation that single-source top-site lists suffer from, and it pins every list to an id so the sample can be reconstructed exactly.&lt;/p&gt;

&lt;p&gt;Top 300 such domains. One page each, the apex URL, loaded twice with roughly a second between, and a criterion counted only when it failed both times. Detection by &lt;a href="https://github.com/dequelabs/axe-core" rel="noopener noreferrer"&gt;axe-core&lt;/a&gt; 4.13.0, with results mapped onto EN 301 549 clauses. robots.txt was respected, the user agent identified the crawler and pointed at a page explaining it, and no site was crawled beyond its front page.&lt;/p&gt;

&lt;p&gt;A second pass a few hours later repeated the method over the top 120 domains and additionally recorded which rule produced each failure. It measured 59 sites. Every figure above says which pass it comes from; the headline table is the 300-domain run.&lt;/p&gt;

&lt;p&gt;No company is named. Naming them would travel further and it would turn a measurement into an accusation from someone who sells the remedy. WebAIM has published &lt;a href="https://webaim.org/projects/million/" rel="noopener noreferrer"&gt;the same shape of study&lt;/a&gt; annually for years without naming anybody, and that seems like the right precedent.&lt;/p&gt;

&lt;p&gt;The &lt;a href="https://curbcut.org/research" rel="noopener noreferrer"&gt;data is published&lt;/a&gt;: every site as a row, with its rank bucket, its country, the clauses it failed, whether it disagreed with itself between loads, and for the 151 excluded ones, why. The rows carry no domains. That is not a hedge — the sample is reconstructible from the Tranco id and the selection rule above, so anyone can rebuild the exact list and re-run it, which is the part that matters for checking my work. The tool is &lt;a href="https://github.com/JagheterAlex/curbcut" rel="noopener noreferrer"&gt;MIT licensed&lt;/a&gt; and the script that produced this is in the repository at &lt;code&gt;scripts/benchmark.mjs&lt;/code&gt;.&lt;/p&gt;

&lt;p&gt;If this crawler turned up in your logs, &lt;a href="https://curbcut.org/research" rel="noopener noreferrer"&gt;the same page&lt;/a&gt; says what it requested and how to refuse it in one line of &lt;code&gt;robots.txt&lt;/code&gt;.&lt;/p&gt;

&lt;h2&gt;
  
  
  The part that matters
&lt;/h2&gt;

&lt;p&gt;November is a real deadline and the six criteria are real work, five sixths of which no tool will do for you.&lt;/p&gt;

&lt;p&gt;But if you are choosing what to fund this quarter, the standard you are already measured against has been sitting there since June 2025, and two thirds of the most-visited sites in Europe do not meet its lowest bar. The unlabelled button is not waiting for a new version of anything.&lt;/p&gt;




&lt;p&gt;&lt;em&gt;Updated 31 August 2026. A reader pointed out that the piece said "EN 301 549"&lt;br&gt;
while measuring clause 9, and that clause 10  the documents a service hands&lt;br&gt;
you is both a large part of the obligation and a place no scanner is pointed.&lt;br&gt;
He was right, and the omission flattered the numbers. The paragraph about it in&lt;br&gt;
"What this is not" was added that day, along with the same admission in the&lt;br&gt;
tool's own output, which named clause 12 and skipped clause 10 in exactly the&lt;br&gt;
same way. Nothing else was changed: the figures are as first published.&lt;/em&gt;&lt;/p&gt;

</description>
      <category>webdev</category>
      <category>a11y</category>
      <category>eu</category>
      <category>testing</category>
    </item>
    <item>
      <title>Your accessibility scanner found 47 issues. A regulator will ask about clause 9.1.4.3.</title>
      <dc:creator>JagheterAlex</dc:creator>
      <pubDate>Fri, 21 Aug 2026 08:49:16 +0000</pubDate>
      <link>https://dev.to/jagheteralex/your-accessibility-scanner-found-47-issues-a-regulator-will-ask-about-clause-9143-1jfm</link>
      <guid>https://dev.to/jagheteralex/your-accessibility-scanner-found-47-issues-a-regulator-will-ask-about-clause-9143-1jfm</guid>
      <description>&lt;p&gt;Enforcement of the European Accessibility Act started on 28 June 2025, and it&lt;br&gt;
started for real. French disability organisations issued formal notices to four&lt;br&gt;
major grocery retailers within days. Sweden opened market surveillance that&lt;br&gt;
October. The first EAA cases reached a French commercial court in November.&lt;/p&gt;

&lt;p&gt;If you sell into the EU and you are not a microenterprise providing services,&lt;br&gt;
somebody can now ask you what you have done about it.&lt;/p&gt;

&lt;p&gt;The awkward part is that the tooling most teams reach for does not produce an&lt;br&gt;
answer to that question. It produces a different, adjacent answer, and the gap&lt;br&gt;
between the two is where a lot of otherwise diligent teams are about to get&lt;br&gt;
caught.&lt;/p&gt;
&lt;h2&gt;
  
  
  The mismatch
&lt;/h2&gt;

&lt;p&gt;You run axe, or Lighthouse, or Pa11y. You get output like this:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;color-contrast          10 nodes   serious
label                    1 node    critical
image-alt                1 node    critical
link-name                1 node    serious
html-has-lang            1 node    serious
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Correct, useful, and not a conformance claim.&lt;/p&gt;

&lt;p&gt;Conformance under the EAA is claimed against &lt;strong&gt;EN 301 549&lt;/strong&gt;, the harmonised&lt;br&gt;
European standard, clause by clause. Nobody has ever been asked to demonstrate&lt;br&gt;
conformance with &lt;code&gt;color-contrast&lt;/code&gt;. They get asked about clause 9.1.4.3.&lt;/p&gt;

&lt;p&gt;So the translation has to happen somewhere. Usually it happens in a spreadsheet,&lt;br&gt;
by hand, by whoever drew the short straw, and it happens again every time the&lt;br&gt;
site changes.&lt;/p&gt;
&lt;h2&gt;
  
  
  Three things that make this worse than a naming problem
&lt;/h2&gt;

&lt;p&gt;&lt;strong&gt;Not all of WCAG is binding, and the binding part is about to move.&lt;/strong&gt; The&lt;br&gt;
harmonised standard today is EN 301 549 V3.2.1 (2021-03), which adopts &lt;strong&gt;WCAG&lt;br&gt;
2.1&lt;/strong&gt;. Criteria introduced in WCAG 2.2 — target size, dragging movements,&lt;br&gt;
accessible authentication — are good practice, not current EAA obligations.&lt;br&gt;
Plenty of tools report 2.2 findings with the same red badge as everything else,&lt;br&gt;
which inflates your problem and burns engineering time on work no regulator is&lt;br&gt;
asking for yet.&lt;/p&gt;

&lt;p&gt;The word doing the work there is &lt;em&gt;yet&lt;/em&gt;. &lt;strong&gt;EN 301 549 V4.1.1 adopts WCAG 2.2 and&lt;br&gt;
is expected to be cited in the Official Journal around the end of 2026.&lt;/strong&gt; An&lt;br&gt;
obligation begins when a version is cited there, not when ETSI publishes it, so&lt;br&gt;
V3.2.1 is still the yardstick as I write this and will not be for much longer.&lt;br&gt;
Anyone telling you 2.2 is already mandatory is wrong today. Anyone telling you to&lt;br&gt;
ignore it is setting you up for a rewrite.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Severity is not exposure.&lt;/strong&gt; Rule engines sort by how confidently they can&lt;br&gt;
complain. Ten contrast failures in a footer will outrank one unlabelled password&lt;br&gt;
field in the checkout, and that ordering is exactly backwards from the one that&lt;br&gt;
matters. One of those stops a person from buying something. The other is real,&lt;br&gt;
required, and not an emergency.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;A clean automated run is not a pass.&lt;/strong&gt; Automated testing detects roughly a&lt;br&gt;
third of accessibility barriers. Keyboard traps, focus order, whether alt text&lt;br&gt;
actually says anything useful, whether a screen reader can make sense of your&lt;br&gt;
custom component — none of that is decidable by a rule engine. The clauses your&lt;br&gt;
scanner cannot evaluate do not appear in its output at all, which reads as&lt;br&gt;
silence, which reads as fine.&lt;/p&gt;
&lt;h2&gt;
  
  
  The part where money is being wasted
&lt;/h2&gt;

&lt;p&gt;Two products are sold to make this go away, and neither does.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Overlay widgets.&lt;/strong&gt; One line of JavaScript, a promise of compliance, and a&lt;br&gt;
subscription around $490 a year.&lt;/p&gt;

&lt;p&gt;The US Federal Trade Commission brought a case over exactly that promise in&lt;br&gt;
January 2025 and &lt;a href="https://www.ftc.gov/legal-library/browse/cases-proceedings/2223156-accessibe-inc" rel="noopener noreferrer"&gt;approved the final order in April&lt;/a&gt;,&lt;br&gt;
requiring accessiBe to pay &lt;strong&gt;$1,000,000&lt;/strong&gt;. The complaint also covered third-party&lt;br&gt;
articles and reviews formatted to look like independent opinions when the company&lt;br&gt;
had an undisclosed connection to them.&lt;/p&gt;

&lt;p&gt;Separately, &lt;a href="https://blog.usablenet.com/2025-midyear-accessibility-lawsuit-report-key-legal-trends" rel="noopener noreferrer"&gt;UsableNet's 2025 midyear report&lt;/a&gt;&lt;br&gt;
counted &lt;strong&gt;456 US accessibility lawsuits, 22.6% of the total&lt;/strong&gt;, filed against sites&lt;br&gt;
that already had an overlay installed. The National Federation of the Blind has&lt;br&gt;
been saying this publicly for years. The widget is a liability, not a shield.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Free statement generators.&lt;/strong&gt; They emit "this website is fully compliant"&lt;br&gt;
without testing anything. An accessibility statement is a public claim, and it&lt;br&gt;
carries your organisation's name, not the generator's. An unsupported one is the&lt;br&gt;
first document anybody investigating you will read.&lt;/p&gt;
&lt;h2&gt;
  
  
  What I built instead
&lt;/h2&gt;

&lt;p&gt;&lt;a href="https://curbcut.org" rel="noopener noreferrer"&gt;Curbcut&lt;/a&gt; is a small MIT-licensed CLI that does the&lt;br&gt;
translation and nothing else. It runs axe-core in a real headless browser on your&lt;br&gt;
machine, then reports what it found the way a conformance claim has to be&lt;br&gt;
written.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;npx curbcut https://example.com &lt;span class="nt"&gt;--crawl&lt;/span&gt; &lt;span class="nt"&gt;--pdf&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Same findings as above, restated:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;P1  Clause 9.4.1.2 — Name, Role, Value          3 elements
P1  Clause 9.1.1.1 — Non-text Content           1 element
P2  Clause 9.3.1.1 — Language of Page           1 element
P3  Clause 9.1.4.3 — Contrast (Minimum)        10 elements
P3  Clause 9.2.4.4 — Link Purpose (In Context)  1 element
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Four things are deliberate here.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Bands are exposure, not severity.&lt;/strong&gt; P1 means a person cannot finish what they&lt;br&gt;
came to do and the clause is in the harmonised standard. Ten contrast failures&lt;br&gt;
sit below one missing form label, because that is the order somebody will ask&lt;br&gt;
about them in.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;WCAG 2.2 is reported separately.&lt;/strong&gt; It is in the output, clearly marked as not a&lt;br&gt;
current obligation, so you can decide rather than be alarmed.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;It prints what it did not check.&lt;/strong&gt; Every run lists the clauses no automated&lt;br&gt;
tool can evaluate — 9.2.1.1 keyboard operability across a whole journey, 9.3.2.3&lt;br&gt;
consistent navigation, and so on — as never assessed, rather than omitting them&lt;br&gt;
and letting the silence imply a pass.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;The statement draft refuses to overclaim.&lt;/strong&gt; It will not produce a&lt;br&gt;
full-conformance claim out of scan data, because scan data cannot support one.&lt;br&gt;
Everything needing a human decision stays a visible &lt;code&gt;[bracket]&lt;/code&gt; until a human&lt;br&gt;
fills it in.&lt;/p&gt;

&lt;p&gt;There is a &lt;code&gt;--pdf&lt;/code&gt; flag that writes a dated A4 report you can hand to a client or&lt;br&gt;
attach to an email. It is deliberately plain: no cover art, no score out of ten,&lt;br&gt;
no badge. The words "not a certificate" and "not legal advice" are on the first&lt;br&gt;
page, above the findings, because a document that looks like a certificate would&lt;br&gt;
misrepresent what automated testing can establish. That is the accessiBe&lt;br&gt;
mistake, and it is not one worth repeating in a smaller font.&lt;/p&gt;
&lt;h2&gt;
  
  
  Try it against a known answer
&lt;/h2&gt;

&lt;p&gt;Rather than ask you to trust a screenshot, there is a deliberately broken page&lt;br&gt;
published for this:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;npx curbcut https://curbcut.org/demo/broken.html
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;It should report five failing clauses across sixteen elements — two P1, one P2,&lt;br&gt;
two P3. If it reports something else, that is a bug and I would like the issue.&lt;/p&gt;
&lt;h2&gt;
  
  
  Proving a fix actually happened
&lt;/h2&gt;

&lt;p&gt;A single scan is a snapshot. It says nothing about direction, which is the thing&lt;br&gt;
an auditor, a client or your own manager is actually asking about.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;npx curbcut https://example.com &lt;span class="nt"&gt;--crawl&lt;/span&gt; &lt;span class="nt"&gt;--json&lt;/span&gt;
&lt;span class="c"&gt;# ... do the work ...&lt;/span&gt;
npx curbcut https://example.com &lt;span class="nt"&gt;--crawl&lt;/span&gt; &lt;span class="nt"&gt;--baseline&lt;/span&gt; curbcut-report/analysis.json
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Findings are matched by clause, not by axe rule, because a clause can start&lt;br&gt;
failing for a different reason than it did last month. A rule-keyed diff would&lt;br&gt;
call that one fix plus one new break, which badly describes a page that never&lt;br&gt;
stopped failing 9.4.1.2.&lt;/p&gt;

&lt;p&gt;And if the later scan reached fewer pages than the baseline, the comparison says&lt;br&gt;
so before anything else. Fewer failures can simply mean fewer pages were&lt;br&gt;
assessed, and presenting that as progress would be a lie by arithmetic.&lt;/p&gt;

&lt;h2&gt;
  
  
  What this does not do
&lt;/h2&gt;

&lt;p&gt;It does not make you compliant, and you should be suspicious of anything that&lt;br&gt;
says it will. It finds what automation can find, names the clauses, and shows&lt;br&gt;
you the gaps it could not test. Closing those gaps is engineering work, and some&lt;br&gt;
of it needs a person using assistive technology.&lt;/p&gt;

&lt;p&gt;I am also not a lawyer, this is not legal advice, and Curbcut is not affiliated&lt;br&gt;
with ETSI, CEN, CENELEC or the European Commission in any way. It is software&lt;br&gt;
that references a standard those bodies publish.&lt;/p&gt;

&lt;p&gt;Source is on &lt;a href="https://github.com/JagheterAlex/curbcut" rel="noopener noreferrer"&gt;GitHub&lt;/a&gt;, MIT, and the&lt;br&gt;
clause mapping is the part worth reading critically. If a mapping is wrong, that&lt;br&gt;
is the highest-value bug you could file.&lt;/p&gt;

</description>
      <category>webdev</category>
      <category>opensource</category>
      <category>compliance</category>
      <category>a11y</category>
    </item>
  </channel>
</rss>
