DEV Community

Manu Shukla
Manu Shukla

Posted on • Originally published at ecorpit.com

EU Accessibility Act 2026: 5 compliance claims that are wrong, and what the legal text says

EU Accessibility Act 2026: 5 compliance claims that are wrong, and what the legal text says

Summary. The European Accessibility Act has applied to products placed on the EU market and services provided to consumers since 28 June 2025. What most compliance guides get wrong is what happened next: as of 20 July 2026, no version of EN 301 549 has been cited in the Official Journal under the Accessibility Act at all. The draft that would do it, EN 301 549 v4.1.0 dated November 2025, is still in the European standards bodies' combined Public Enquiry and Vote phase, which ETSI's own project site says runs until August 2026. The European Commission's standardisation request set 15 September 2025 as the deadline for adoption. That deadline passed 10 months ago. Meanwhile the penalty most often quoted for Ireland, €60,000 on conviction on indictment, is real and appears in the Irish transposing regulations, while most of the other per-country figures circulating in vendor tables trace back to sources that contradict themselves. The microenterprise exemption that many Indian SaaS teams assume covers them applies to services only, and stops at fewer than 10 employees with turnover or balance sheet total not exceeding €2 million.

This article works through five claims we see repeated in EAA guidance, checks each against the transposed legal text and the standards documents, and sets out what an Indian team selling into the EU should actually do in the next quarter.

Why we went to the source text

Accessibility compliance content has a citation problem. Guides cite each other, dates drift, and a standard that has not been published acquires a publication month through repetition. We read the Irish transposing regulations, the Commission's standardisation request, ETSI's draft and project site, and the W3C's own WCAG 2.2 page. Where the primary text was unreachable, we say so rather than filling the gap.

One honest limitation up front: EUR-Lex now renders as a client-side application and did not return the Directive's article text to us. So for the Directive's own wording we rely on Ireland's transposing instrument, S.I. No. 636/2023, which reproduces the definitions and transitional provisions. Where a claim rests only on that, we say which document it came from.

Claim 1: "EN 301 549 v3.2.1 is the EAA's harmonised standard"

What the sources say: v3.2.1 is harmonised, but under a different directive.

The European Commission's own standards page states that only two versions of EN 301 549 have been harmonised, v2.1.2 in December 2018 and v3.2.1 in August 2021, through Implementing Decision (EU) 2021/1339 of 11 August 2021. That harmonisation is under the Web Accessibility Directive, 2016/2102, which covers public sector bodies. The same page confirms "the version of WCAG that is used in EN 301 549 remains WCAG 2.1".

The Accessibility Act is Directive (EU) 2019/882, a different instrument covering private sector products and services. ETSI's draft v4.1.0 gives the position away in its own foreword, written in the future tense: "Once the present document is cited in the Official Journal of the European Union under that Directive, compliance with the normative clauses of the present document given in the tables in clause A.2 confers ... a presumption of conformity with the corresponding essential requirements of that Directive."

What this means for you. There is currently no presumption-of-conformity route under the Accessibility Act. You cannot point at a harmonised standard and claim the safe harbour, because none has been cited. Conforming to EN 301 549 v3.2.1 and WCAG 2.1 AA remains the sensible engineering target, and it is what most Member State authorities will recognise. It is a defensible position, not a legal presumption. Those are different things, and the difference matters if anyone ever asks you to prove conformity.

Claim 2: "EN 301 549 v4.1.1 arrives in October 2026"

What the sources say: no official date exists.

Here is what is documented. A draft, EN 301 549 V4.1.0 dated November 2025, is published on ETSI's server and describes itself as "submitted for the combined Public Enquiry and Vote phase". ETSI's project repository, checked on 20 July 2026, states the formal voting process is "now underway (until August 2026)". The draft was prepared under Commission standardisation request C(2022) 6456 final, and adds a new Annex ZB and clause A.2 addressing Directive 2019/882. Its clauses 9, 10 and 11 have been updated to align with WCAG 2.2.

What is not documented anywhere we could find: a publication date for v4.1.1, or a date for its citation in the Official Journal. The "October 2026" figure appears in secondary write-ups without a source, and it does not appear on the vendor pages it is usually attributed to.

The timetable that does exist runs the other way. The Commission's standardisation request set 15 September 2025 as the deadline for adoption by the European standards organisations, with a final report due 15 March 2027 and the Decision itself expiring 15 September 2027. The adoption deadline was missed.

Milestone Status as of 20 July 2026 Source
EN 301 549 v3.2.1 harmonised under WAD 2016/2102 Done, August 2021 Commission standards page
Commission deadline for ESO adoption of the revision Missed, was 15 September 2025 Standardisation request C(2022) 6456
Draft v4.1.0 published for Public Enquiry and Vote Done, dated November 2025 ETSI deliver server
Formal vote closes Running until August 2026 ETSI project repository
v4.1.1 published by ETSI Not published No ETSI artefact exists
v4.1.1 cited in the Official Journal under the EAA Not cited ETSI draft foreword, future tense

What this means for you. Plan for WCAG 2.2 AA because the draft aligns to it and the direction is settled. Do not put a dated compliance deadline in a board pack on the strength of a month nobody can source. If your roadmap says "must be WCAG 2.2 AA by October 2026 or we are non-compliant", that sentence is not supported.

One more gap worth knowing: the standardisation request explicitly excludes e-books and dedicated software from the EN 301 549 revision, even though e-books are inside the Accessibility Act's scope. If you publish e-books, the revised standard will not cover that part of your obligation.

Claim 3: "Non-EU companies must appoint an EU authorised representative"

What the sources say: appointment is optional. The transposed text uses "may".

The relevant definition in S.I. No. 636/2023 reads: "a manufacturer may, by a written mandate ... appoint a natural or legal person established within the Union to be an authorised representative." Not "shall".

The reach of the law does extend to companies outside the EU, but through market access rather than establishment. The same instrument defines "make available on the market" as "any supply of a product for distribution, consumption or use on the Union market in the course of a commercial activity, whether in return for payment or free of charge", and defines a service provider as "any natural or legal person who provides a service on the Union market or makes offers to provide such a service to consumers in the Union". For physical products, a third-country manufacturer's goods enter through an EU-established importer, and the regulations place conformity obligations on that importer.

What this means for you. A Gurugram SaaS company selling subscriptions to consumers in the EU is caught by the services limb directly, because it offers a service to consumers in the Union. There is no representative to appoint that would change that, and no representative you are required to appoint. Budget for the engineering work, not for a compliance intermediary somebody told you was mandatory.

Claim 4: "Service contracts signed before June 2025 must comply by 2027"

What the sources say: the legal text says five years, which is 2030.

Regulation 38 of the Irish instrument, mirroring the Directive's transitional article, states that "service contracts agreed before 28 June 2025 may continue without alteration until they expire, but no longer than 5 years from that date." Five years from 28 June 2025 is 28 June 2030.

Self-service terminals get a longer tail: those lawfully in use before 28 June 2025 "may continue to be used in the provision of similar services until the end of their economically useful life, but no longer than 20 years after their entry into use." The Commission's AccessibleEU guidance draws the conclusion, stating that by 28 June 2045 all inaccessible self-service terminals will need to be removed.

The 2027 date that circulates appears to be a conflation. The Accessibility Act allows a possible two-year extension specifically for answering emergency communications to 112, which is a different provision entirely.

What this means for you. If you are relying on a transitional period, read which one applies to you. Most software teams are not: the transitional provisions cover existing contracts and existing hardware, not your product roadmap. New services provided to consumers on or after 28 June 2025 are in scope now.

Claim 5: "WCAG 2.2 adds these criteria at level AA"

What the sources say: the list in circulation promotes three AAA criteria to AA.

The W3C published WCAG 2.2 as a Recommendation on 5 October 2023, adding 9 success criteria over WCAG 2.1. The commonly circulated summary lists Focus Appearance and the Enhanced variants among the AA additions. The W3C's own page places them at AAA.

Success criterion Level Required for AA conformance
2.4.11 Focus Not Obscured (Minimum) AA Yes
2.5.7 Dragging Movements AA Yes
2.5.8 Target Size (Minimum) AA Yes
3.3.8 Accessible Authentication (Minimum) AA Yes
3.2.6 Consistent Help A Yes
3.3.7 Redundant Entry A Yes
2.4.12 Focus Not Obscured (Enhanced) AAA No
2.4.13 Focus Appearance AAA No
3.3.9 Accessible Authentication (Enhanced) AAA No

Six criteria, not nine, sit on the path to AA: four new at AA and two new at A, since A criteria are required for AA conformance. WCAG 2.2 also removes 4.1.1 Parsing, which is now obsolete.

What this means for you. Scoping an audit against the wrong six criteria wastes a sprint. In our experience the four that actually bite on a modern product are Dragging Movements, Target Size, Accessible Authentication and Redundant Entry, because they hit patterns teams ship without thinking: drag-to-reorder with no button alternative, 32-pixel icon buttons, CAPTCHA-style authentication that requires a cognitive test, and checkout flows that ask for the same address twice.

What is actually in scope

The Accessibility Act covers a defined list, not "all websites". The products are consumer computer hardware and operating systems, self-service terminals including payment terminals and ATMs, consumer terminal equipment for electronic communications and for audiovisual media services, and e-readers. The services are electronic communications services, services providing access to audiovisual media, defined elements of air, bus, rail and waterborne passenger transport, consumer banking services, e-books and dedicated software, and e-commerce services. Answering emergency communications to 112 is covered separately.

For Indian companies, the two limbs that catch the most teams are e-commerce services and consumer banking services. A D2C brand shipping to EU consumers is providing an e-commerce service. A fintech offering consumer accounts to EU residents is providing a consumer banking service. Neither depends on having an EU entity.

The microenterprise exemption is narrower than most assume. The definition is an enterprise employing fewer than 10 persons with an annual turnover not exceeding €2 million or an annual balance sheet total not exceeding €2 million. That exemption applies to services. For products, microenterprises get mitigation rather than exemption: the regulations require authorities to provide guidelines and tools, and say documentation requirements must not impose an undue burden.

A funded Indian SaaS company with 30 engineers is not a microenterprise. Most teams asking us this question are already outside it.

Penalties, and why the tables are unreliable

Penalties are set by each Member State, not at EU level. The Commission's own material describes the requirement as penalties that are "effective, proportionate and dissuasive", with consumers able to take action before a court and public bodies or private associations with a legitimate interest able to act.

We could verify exactly one national figure from an official source. Ireland's S.I. No. 636/2023 provides that a person committing an offence is liable, on summary conviction, to a class A fine or imprisonment up to 6 months or both, and on conviction on indictment to a fine not exceeding €60,000 or imprisonment up to 18 months or both. Directors and officers can be personally liable, and the regulations list the extent and seriousness of the failure, the number of units affected and the number of persons affected as sentencing factors.

The per-country tables that circulate, listing figures for Sweden, Spain, France, Germany, the Netherlands, Austria and Italy, we could not verify from official national sources. At least one widely shared table contradicts itself within the same page, capping one country's fines at roughly €900,000 in its table and citing a figure of three million euros in its prose. Germany's official statute text did not return content for us, so we are not repeating the figure attributed to it.

Treat those tables as orientation, not evidence. If your risk assessment needs a number for a specific market, get it from that country's transposing law or from local counsel.

What to do in the next quarter

A practical order of work for a team that sells into the EU and has not started.

1. Confirm you are in scope, in writing. Which limb catches you: e-commerce, consumer banking, transport, e-books? Write the sentence down. Half the teams we talk to have never done this and are either over-scoping or assuming they are out.

2. Audit against WCAG 2.1 AA first. That is what EN 301 549 v3.2.1 incorporates, and it is the recognised baseline today. It is also roughly 90% of the work.

3. Layer the six WCAG 2.2 additions on top. Four AA plus two A, from the table above. This is the delta that the draft standard points at, and doing it now means the eventual citation is not a project.

4. Fix authentication before anything else. Accessible Authentication (Minimum) tends to be the most expensive to retrofit because it touches the login flow, and login flows carry the most fear of regression. Doing it first means the rest is layout work.

5. Write an accessibility statement and keep the evidence. France's regime, on the accounts we read, attaches penalties to a missing accessibility statement specifically. Whether or not that figure is verified, an audit report with a date on it is the cheapest defensible artefact you can hold.

6. Put it in CI. Automated checks catch perhaps a third of issues, which is not compliance, but it stops regressions between manual audits. Our QA and test automation work covers where those gates belong in a pipeline.

The engineering judgement worth carrying: accessibility failures are mostly component-level, so they are cheap to fix once and expensive to fix repeatedly. Fix the design system, not the pages.

India-specific considerations

Two things make this different for a team building from India.

Your obligation is triggered by your customers' location, not your own. That is the same structure Indian teams already navigate for data protection, where the Digital Personal Data Protection Act 2023 governs domestic processing while EU customers bring separate obligations. Teams that have built a DPDP record already have the habit; our DPDP Act engineering playbook covers what that documentation looks like in practice.

The commercial pressure usually arrives before the regulator does. EU enterprise buyers have begun asking for accessibility conformance reports in procurement, and a missing report loses deals well before any authority sends a letter. For Indian e-commerce and SaaS teams, this is a sales blocker with a compliance deadline attached, which is a better reason to schedule the work than the fine table is.

FAQ

Has EN 301 549 been cited in the Official Journal under the EAA?

No. As of 20 July 2026 no version has been cited under Directive (EU) 2019/882. ETSI's draft v4.1.0 states in the future tense that a presumption of conformity applies once the document is cited. Version 3.2.1 is harmonised, but under the Web Accessibility Directive 2016/2102, which covers public sector bodies rather than private companies.

When will EN 301 549 v4.1.1 be published?

No official date has been announced. The draft v4.1.0, dated November 2025, is in the combined Public Enquiry and Vote phase, which ETSI's project site says runs until August 2026. The October 2026 date circulating in compliance guides has no primary source that we could find, and should not be used for planning.

Does the EAA apply to an Indian company with no EU entity?

Yes, if you offer services to consumers in the Union or place products on the Union market. The transposed definitions turn on market access rather than establishment. Appointing an EU authorised representative is optional under the text we read, expressed as "may", not a requirement as several compliance guides state.

Which WCAG 2.2 criteria do we actually need for AA?

Six. Four are new at AA: Focus Not Obscured (Minimum), Dragging Movements, Target Size (Minimum) and Accessible Authentication (Minimum). Two are new at A and therefore required for AA: Consistent Help and Redundant Entry. The three Enhanced and Focus Appearance criteria sit at AAA and are not required.

Does the microenterprise exemption cover our startup?

Only if you employ fewer than 10 persons and your annual turnover or balance sheet total does not exceed €2 million, and only for services. For products, microenterprises receive mitigation such as guidelines and reduced documentation burden rather than exemption. Most funded Indian SaaS companies are outside this threshold already.

What are the penalties for non-compliance?

Member States set them, guided by a requirement that penalties be effective, proportionate and dissuasive. Ireland's transposing regulations provide for a fine up to €60,000 on conviction on indictment, or imprisonment up to 18 months, or both. Per-country tables circulating online could not be verified against official national sources and one contradicts itself internally.

We signed EU contracts before June 2025. When do they need to comply?

Service contracts agreed before 28 June 2025 may continue unaltered until they expire, but no longer than five years from that date, which is 28 June 2030. The 2027 date that appears in some guides appears to conflate this with a separate two-year extension available for answering emergency communications to 112.

Where should we start if we have done nothing?

Confirm in writing which scope limb catches you, then audit against WCAG 2.1 AA, which EN 301 549 v3.2.1 incorporates and which represents most of the work. Layer the six WCAG 2.2 additions on top, fix authentication first because it is costliest to retrofit, and add automated checks to CI to stop regressions.

How eCorpIT can help

eCorpIT audits and remediates web and mobile products against WCAG 2.1 AA and the WCAG 2.2 additions, for Indian teams selling into the EU and for EU buyers asking their vendors for conformance evidence. Founded in 2021 and based in Gurugram, our senior engineering teams work at the design-system level rather than page by page, so a fix lands once, and we design applications aligned with EN 301 549 requirements while being clear about what the standard does and does not currently confer. Engagements usually run as a scoped audit with a prioritised remediation plan, then implementation alongside your team, with automated checks left behind in your pipeline. If you need a conformance report for a procurement conversation, or an honest read on how far your product is from AA, get in touch.

References

  1. European Commission: European Accessibility Act overview
  2. Ireland S.I. No. 636/2023, European Union (Accessibility Requirements of Products and Services) Regulations 2023
  3. Commission Implementing Decision C(2022) 6456 final, standardisation request M/587
  4. European Commission: Web Accessibility Directive, standards and harmonisation
  5. European Commission: latest changes to the accessibility standard
  6. ETSI Draft EN 301 549 V4.1.0, November 2025
  7. ETSI EN 301 549 V3.2.1
  8. ETSI EN 301 549 project repository
  9. W3C WAI: What's New in WCAG 2.2
  10. AccessibleEU: guidance on accessibility legislation
  11. European Commission DG EMPL: European Accessibility Act presentation
  12. European Commission DG EMPL, ITU-hosted EAA briefing

Last updated: 20 July 2026.

Top comments (0)