
Most EAA coverage is written for legal and compliance teams. It tells you the directive number, the transposition dates, and the maximum fine in Hungary.
None of that tells a product team what to change on Tuesday.
This guide is the other version: what the European Accessibility Act actually demands of an interface, which common UI patterns fail it, what enforcement has genuinely looked like in the first year, and how to sequence remediation without stopping your roadmap.
The short answer
The European Accessibility Act (Directive 2019/882) has been enforceable since 28 June 2025 across all 27 EU member states. It applies to any company selling covered digital products or services to EU consumers, regardless of where that company is based. The technical baseline is EN 301 549, which incorporates WCAG 2.1 Level AA. For product teams, compliance is mostly a UI and front-end problem: keyboard operability, focus visibility, form error handling, contrast, and screen reader semantics.
Three things product leaders usually get wrong about it:
- It’s not a public sector rule. Earlier EU accessibility law covered government sites. This one targets private, consumer-facing commerce.
- It’s not a one-time audit. A clean audit last year is not a defence if this quarter’s release introduced new barriers.
- It’s not primarily about fines yet. The first year of enforcement has been remediation orders, market surveillance programmes, and private legal letters — which is a different risk profile, and in some ways a more immediate one.
Who is actually in scope
The EAA covers consumer-facing products and services sold in the EU. In practice, the digital ones that matter most are:
- E-commerce websites and mobile shopping
- Consumer banking and financial services
- E-books and reading software
- Ticketing, transport, and travel services
- Telecoms services
- Consumer-facing digital services more broadly
Two points product teams routinely miss.
Geography follows the customer, not the company. The EAA applies based on where the service is offered, not where the business is headquartered. A product team in Bengaluru or Boston selling to EU consumers is in scope.
There is a small-business threshold, not a small-business exemption. Reporting on the scope threshold generally describes microenterprises providing services as having limited relief, with obligations attaching to businesses above roughly 10 employees or €2 million annual turnover. Thresholds and how exemptions apply vary by national transposition, so this is one to verify in each market you sell into rather than assume.
The standard you’re actually being measured against
EN 301 549 is the harmonised European standard, and version 3.2.1 incorporates WCAG 2.1 Level AA as the technical baseline for digital content. A WCAG 2.2-aligned update to EN 301 549 has been anticipated during 2026, which would raise the bar — worth tracking rather than assuming today’s target is permanent.
Practically: if your product meets WCAG 2.1 AA and you can evidence it, you are in good shape. If nobody on your team can say what level you’re at, you have an unmeasured liability.
What this means for your UI
This is the part the legal guides skip. WCAG 2.1 AA translates into a fairly specific set of interface decisions, and in enterprise products the same handful fail repeatedly.
Keyboard operability. Every interactive element must be reachable and usable without a mouse. The usual failures are custom dropdowns, modals that don’t trap focus, date pickers, drag-and-drop interfaces with no alternative, and infinite-scroll tables. This is the single most cited category in early enforcement activity — Norway’s equality ombud has been running daily penalties against a health portal specifically over persistent keyboard accessibility failures, at NOK 50,000 per day since August 2025, accumulating past NOK 3.5 million by December 2025 (Web Accessibility Checker, 2026).
Visible focus states. Design teams remove focus outlines because they look untidy. That single decision breaks keyboard navigation for everyone who depends on it. If you’ve styled outline: none anywhere without a replacement, that’s a finding.
Form errors that don’t rely on colour or position. Errors must be programmatically associated with their field and announced, not just shown as red text below the input. Checkout and onboarding flows are where this hurts most, and checkout flows were explicitly among the targets in the first French enforcement cases.
Contrast. 4.5:1 for body text, 3:1 for large text and for the visual boundaries of UI components. Light grey placeholder text and low-contrast disabled states are near-universal failures in modern enterprise UI.
Screen reader semantics. Correct heading order, labelled inputs, meaningful link text, ARIA used correctly rather than decoratively, and live regions for dynamic content. Single-page applications that update content without announcing it are a recurring problem.
Accessibility statements. Missing statements were among the specific issues cited in the first EAA enforcement actions in France. This is the cheapest thing on the list to fix and one of the most visible to a regulator.
Mobile apps count. The French injunctions covered both websites and mobile applications. Teams that remediated web and left the app alone have not finished.
What enforcement has actually looked like
Here the honest picture is more useful than the alarming one.
Enforcement powers took effect 28 June 2025. Since then:
- France: the DGCCRF issued formal legal notices to Auchan, Carrefour, E.Leclerc and Picard in November 2025, and when they didn’t act, emergency injunctions were filed before the Commercial Court on 12 November 2025. These were the first EAA enforcement actions in the EU, targeting checkout flows, product browsing, and missing accessibility statements. As of April 2026 the cases remained pending with no ruling issued and no fines imposed (Auditsu, 2026).
- Germany: within weeks of the BFSG taking effect, e-commerce operators began receiving private warning letters (Abmahnungen) citing accessibility violations. These came from law firms using Germany’s unfair competition framework rather than from regulators under the BFSG directly (Auditsu, 2026).
- Sweden: the PTS published a list of 200 e-commerce platforms to audit by Q3 2026, with methodology combining automated WCAG 2.1 AA testing, manual keyboard navigation, and screen reader testing (Web Accessibility Checker, 2026).
- Netherlands: the ACM set an October 2025 non-conformance reporting deadline and prioritised non-reporters for audits, with active enforcement expected in the second half of 2026.
One accessibility vendor reviewing the record noted that as of mid-2026, no confirmed fines issued specifically under national EAA implementing laws could be verified (Webyes, 2026). That is worth stating plainly rather than pretending otherwise.
The correct read isn’t “nothing is happening.” It’s that enforcement in year one has taken the shape regulators usually start with: notification, investigation, and remediation orders, with penalties held in reserve. Meanwhile the fastest-moving risk has come from a direction most teams didn’t model — competitor and law-firm action under national competition law, and civil society litigation, neither of which waits for a regulator’s timetable.
Penalty exposure by country
Each member state sets its own penalties. These are reported statutory maximums, not typical outcomes, and figures vary between sources — verify against local law before making a business case on any specific number.
| Country | Reported maximum | Notes |
| Hungary | ~€1,260,000 | Among the highest ceilings reported |
| Spain | €1,000,000 | Tiered by severity; business suspension up to three years possible |
| Sweden | SEK 10,000,000 (~€900,000) | Active market surveillance programme |
| Netherlands | up to ~€900,000 | Audit programme underway |
| France | €250,000 | Plus annual penalties reported for missing accessibility information |
| Germany | €100,000 per violation | Per-violation structure; regulators apply proportionality |
| Italy | Tiered, up to ~5% of annual turnover for large companies | Under the Stanca Law framework |
| Ireland | €60,000 | The only confirmed member state where violations can carry criminal liability, up to 18 months |
Compiled from Level Access, Web Accessibility Checker, Auditsu and AEL Data, 2026. Figures are reported ceilings and change as member states update implementation.
The compounding risk matters more than any single ceiling. If you sell into five EU countries, you answer to five enforcement systems simultaneously, with no cross-border penalty cap and no single settlement that closes all of them. Several countries also apply daily penalties for ongoing non-compliance. And financial penalties aren’t the only lever — authorities can order product withdrawal, ban non-compliant products from national markets, mandate audits, and publish the names of non-compliant organisations.
Why your accessibility scan isn’t enough
Automated scanners are useful and insufficient. Reported detection rates put them at catching only around a quarter to a third of WCAG issues (Optimum Web, 2026). Everything in the list above that involves judgement — whether link text is meaningful, whether a focus order makes sense, whether an error message actually explains the error — requires manual testing.
Sweden’s audit methodology is instructive precisely because it mirrors this: automated testing plus manual keyboard navigation plus screen reader testing. If that’s how you’ll be assessed, that’s how you should be testing.
A realistic 90-day sequence
You don’t need to fix everything at once. You need to be demonstrably in motion, on the highest-risk surfaces first.
Days 1–15: Establish position. Run an audit against EN 301 549 / WCAG 2.1 AA on your highest-traffic revenue flows — signup, checkout, account management. Automated plus manual. Produce a written baseline. This document is your evidence of good faith if a regulator or complainant arrives.
Days 16–30: Publish an accessibility statement. Honest about current conformance level, with a remediation timeline and a contact route. Missing statements were cited in the first enforcement actions; this is cheap and highly visible.
Days 31–60: Fix the revenue path. Keyboard operability, focus states, form errors, and contrast on the flows that make money. These are also the flows regulators and complainants look at first.
Days 61–90: Move enforcement into the pipeline. Accessibility regression testing on every pull request, accessibility acceptance criteria in your definition of done, and conformance built into your design system components so new work is compliant by default rather than remediated later.
That last step is what stops this recurring. As one 2026 analysis of the first enforcement year put it, “we ran an audit last year” is not a strong defence if subsequent updates introduced new barriers — monitoring, regression prevention, and repeat testing are now table stakes.
Where f1Studioz fits
We work on enterprise product interfaces, and accessibility conformance is part of how we build rather than a service bolted on afterwards.
The engagements we’re a good fit for usually look like one of these: a product with EU exposure and no clear picture of where it stands, a remediation programme that keeps regressing because conformance isn’t built into the design system, or a redesign where getting accessibility right from the start is cheaper than retrofitting it twice.
What that involves in practice is auditing against EN 301 549 with both automated and manual testing, prioritising findings by revenue exposure rather than by issue count, rebuilding the failing patterns properly, and embedding conformance into components and acceptance criteria so the next release doesn’t reopen what you just closed.
We’re not a legal advisor and we don’t pretend to be — scope determinations, national thresholds, and enforcement correspondence need a lawyer in the relevant jurisdiction. What we handle is the part that’s an interface problem, which is most of it.
If you don’t currently know what conformance level your product is at, that’s the first thing worth finding out.
[CTA: Request an accessibility audit →]
Frequently asked questions
What is the European Accessibility Act?
The European Accessibility Act (Directive 2019/882) is EU legislation requiring a broad range of consumer-facing digital products and services to be accessible to people with disabilities. It has applied since 28 June 2025 and is enforced individually by each of the 27 member states.
Does the EAA apply to companies outside the EU?
Yes. The EAA applies based on where a product or service is offered, not where the company is headquartered. A business selling covered services to EU consumers is in scope regardless of its location.
What accessibility standard does the EAA require?
EN 301 549, the harmonised European standard, which in version 3.2.1 incorporates WCAG 2.1 Level AA for digital content. An update aligned to WCAG 2.2 has been anticipated in 2026.
What are the penalties for EAA non-compliance?
Penalties are set nationally and vary widely, with reported maximums ranging from around €60,000 in Ireland to roughly €1,260,000 in Hungary. Non-financial sanctions include product withdrawal, market bans, mandated audits, and public naming. Most authorities issue remediation orders before financial penalties.
Have any EAA fines actually been issued?
As of mid-2026, no confirmed fines under national EAA implementing laws had been verified by accessibility vendors tracking enforcement. Enforcement so far has taken the form of formal notices, litigation, market surveillance programmes, and private legal letters. In Norway, which is in the EEA, daily penalties have been imposed on a non-compliant health portal.
Is an automated accessibility scan enough for EAA compliance?
No. Automated tools catch roughly a quarter to a third of WCAG issues. Conformance requires manual keyboard navigation and screen reader testing alongside automated scanning — which is also how national audit programmes are testing.
What should a product team fix first?
The revenue path. Keyboard operability, visible focus states, accessible form error handling, and colour contrast on signup, checkout, and account management flows. These are both the highest business risk and the first place complainants and regulators look.
Does the EAA apply to mobile apps?
Yes. Covered services delivered through mobile applications are in scope, and the first French enforcement actions targeted both websites and mobile apps.
Conclusion
The EAA stopped being a deadline and became an operating condition. The first year of enforcement was slower and stranger than most predictions — fewer regulator fines, more competition-law letters and civil litigation — but the direction is consistent across all 27 member states, and the audit programmes now running will produce decisions through the rest of 2026.
For a product team the practical takeaway is small: find out where you stand, publish an honest statement, fix the revenue path, and put conformance into the pipeline so it stays fixed. None of that requires stopping your roadmap. All of it gets more expensive the longer it waits.
Accessibility Requirements.



