---
title: "Your store has been in scope of the Accessibility Act since June 2025"
description: "The European Accessibility Act covers e-commerce services sold to consumers. The microenterprise exemption is narrower than it looks, the 2030 date is not an extension, and the payment step is named explicitly."
author: "Luboš Zápotočný"
published: "2026-07-31"
language: "en"
canonical: "https://zapolu.com/blog/accessibility-act-ecommerce/"
---

# Your store has been in scope of the Accessibility Act since June 2025

The European Accessibility Act has applied to e-commerce services
since June 28, 2025. A year on, the common assumption is still that
accessibility is a public sector obligation, or a deadline somewhere
ahead. Article 2(2)(f) lists e-commerce services among the services
covered, and Article 3(30) defines them as "services provided at a
distance, through websites and mobile device-based services by
electronic means and at the individual request of a consumer with a
view to concluding a consumer contract".

That is a description of an online store selling to consumers. The
definition turns on a consumer contract, and Article 2(2) applies the
directive to services "provided to consumers", so a storefront that
sells only to business customers falls outside it. A mixed store is
inside it for the consumer side.

The directive is [Directive (EU)
2019/882](https://eur-lex.europa.eu/eli/dir/2019/882/oj/eng),
OJ L 151, 7.6.2019. Every article, recital and annex cited below was
read in that text on July 30, 2026, because most of what circulates
about this law is a summary of a summary. We read it as engineers
who have to implement it rather than as lawyers, and the questions
of scope are worth raising with your own counsel, citing the
article numbers.

## The exemption is narrower than "small business"

Article 4(5) exempts microenterprises providing services from the
accessibility requirements "and any obligations relating to the
compliance with those requirements". Article 3(23) then defines a
microenterprise as one "which employs fewer than 10 persons and which
has an annual turnover not exceeding EUR 2 million or an annual
balance sheet total not exceeding EUR 2 million".

The question hangs on the conjunctions, and the two tests are not
symmetrical. Fewer than ten persons is a hard ceiling: eleven people
puts a store in scope whatever its finances. The money test is
satisfied by either limb, so a six-person store turning over
EUR 5 million is still a microenterprise if its balance sheet total
stays under EUR 2 million. Recital 53 adds that a microenterprise
must "genuinely fulfil the requirements of Commission Recommendation
2003/361/EC, and the relevant case law, aimed at preventing the
circumvention of its rules", which is where the rules for counting
staff and financial thresholds actually live. Read those before
concluding you are exempt.

## June 2030 is not an extension

Article 32(1) has Member States provide "a transitional period ending
on 28 June 2030 during which service providers may continue to
provide their services using products which were lawfully used by
them to provide similar services before that date", and allows
service contracts agreed before June 28, 2025 to "continue without
alteration until they expire, but no longer than five years from that
date".

This is the most misread sentence in the directive. It covers
*products* used in providing a service, and Article 3(2) defines a
product as a good produced through a manufacturing process, while
Article 2(1) lists which products are actually in scope: payment
terminals, ticketing and check-in machines, ATMs, interactive
information terminals, e-readers, and consumer computer hardware with
its operating system. It also covers contracts already signed.
Recital 101 settles the reading: the relief runs to products placed
on the market before the application date, and it lapses if the
provider replaces them during the period.

The transitional period does exist, then, and it applies to the
product layer. If you run collection kiosks or in-store payment
terminals, those have until 2030, and Article 32(2) gives
self-service terminals up to twenty years. A website is not a product
under this directive, and an order placed by a customer today is not
a contract agreed before June 2025. The storefront itself gets
nothing from Article 32.

## What the directive asks of a storefront

Annex I, Section III(c) requires making websites, related online
applications and mobile services accessible "in a consistent and
adequate way by making them perceivable, operable, understandable and
robust". Those four adjectives are the four principles of WCAG, which
recital 47 carries in from the Web Accessibility Directive and
declares "also relevant for this Directive".

Section IV(g) then adds three requirements specific to e-commerce:
information about the accessibility of the products and services
being sold, where the responsible economic operator provides it;
accessibility of the functionality for identification, security and
payment "when delivered as part of a service instead of a product";
and identification methods, electronic signatures and payment
services that are themselves perceivable, operable, understandable
and robust.

That last one closes a gap worth knowing about. Article 2(4)(d)
excludes, from the content of websites and mobile applications,
"third-party content that is neither funded, developed by, or under
the control of, the economic operator concerned". A hosted payment
form does not fall under that exclusion, because the exclusion
requires all three to be absent, and a merchant who pays the provider
and configures the integration has both funded it and kept control of
it. Recital 20 says the same thing directly: "Even if a service, or
part of a service, is subcontracted to a third party, the
accessibility of that service should not be compromised and the
service providers should comply with the obligations of this
Directive." In practice the two components most likely to fail an
audit are the two nobody at the company wrote: the hosted card fields
served by the payment provider, and the consent banner. Choosing a
payment provider is now partly an accessibility decision.

## The standard a supplier cannot yet sell you

Article 15(1) grants a presumption of conformity to standards "the
references of which have been published in the Official Journal of
the European Union", and Article 15(3) lets the Commission establish
technical specifications that carry the same presumption. EN 301 549
V3.2.1 (March 2021) is published in the Journal under the Web
Accessibility Directive, by Commission Implementing Decision (EU)
2021/1339. Neither route has been used for this directive: the
Commission's index of harmonised standards carries no entry for
Directive (EU) 2019/882, checked on July 30, 2026.

The revision meant to cover the Accessibility Act came out of
standardisation request M/587, reached final draft as V4.1.0 in June
2026, and is in ETSI's approval procedure. So a supplier offering
conformance with EN 301 549 is offering good engineering, not a legal
presumption under this directive. Follow the standard regardless: it
is the technical specification the directive's machinery points at,
and its web chapter is WCAG 2.1 levels A and AA. V4.1.0 retargets
that chapter to WCAG 2.2, so the version you implement to will change
once it is cited.

## The statement most stores have not written

Article 13(2), with Annex V, requires the service provider to explain
how the service meets the accessibility requirements, in the general
terms and conditions or an equivalent document. Annex V asks for
three things: a general description of the service in accessible
formats, the explanations needed to understand how it operates, and a
description of how the Annex I requirements are met. Article 13(2)
adds that this has to be public in written and oral format, itself
accessible, and kept for as long as the service is in operation.

It is the one obligation that can be checked from outside without
touching the code, so it is where an inspection starts. For services
that inspection does not come from a market surveillance authority,
which Article 19 confines to products: Article 23 has each Member
State designate a separate authority responsible for checking the
compliance of services. Article 13(4) adds the last step. On finding
the service non-compliant, the provider takes corrective measures and
immediately informs the competent national authorities.

## What a disproportionate-burden claim requires

Article 14(1) applies the requirements only so far as compliance
avoids a fundamental alteration of the service and a disproportionate
burden on the operator. Annex VI sets three criteria: the ratio of
net compliance costs to overall operating and capital costs; the
estimated costs and benefits for the operator weighed against the
estimated benefit to persons with disabilities, given how much the
service is used; and the ratio of net compliance costs to net
turnover. The second sets one estimate against another, so the
assessment involves judgement, but it is judgement you have to write
down and defend.

Article 14(3) requires the assessment documented, the results kept
five years, and a copy handed to the authority on request.
Article 14(5) requires it renewed whenever the service is altered,
whenever the authority asks, and at least every five years.
Article 14(6) bars any operator that took outside funding for
accessibility work from relying on disproportionate burden at all,
though the fundamental-alteration limb stays open, and Article 14(8)
requires telling the authority you are relying on it. Before choosing
that route, compare the cost of the file and its five-year upkeep
with the cost of the remediation it is meant to avoid.

## Where the failures actually are

The recurring ones in e-commerce, roughly in the order they stop a
purchase:

- **Keyboard alone, end to end.** Category page, product page, cart,
  checkout, payment, confirmation, without touching a mouse. Cart,
  checkout and payment are where this most often stops.
- **Labels and errors.** Fields with placeholder text instead of a
  programmatically associated label, and validation errors signalled
  by a red border rather than tied to the field and announced.
- **Focus in overlays.** Drawers, modals, and cookie dialogs where
  focus never enters, escapes early, or is lost on close.
- **Custom widgets.** Variant swatches, quantity steppers, filter
  facets, and selects rebuilt from generic elements for design
  reasons.
- **Colour carrying meaning alone.** Stock state, discount, validity.
- **Contrast on what gets lightened last.** Sale prices, hint text
  under form fields, secondary labels in the order summary. Disabled
  controls are exempt under WCAG 1.4.3, so leave them out of the
  count.
- **Silent state changes.** Add to cart, cart totals, filter results,
  and asynchronous price recalculation that updates the page without
  announcing anything.

Automated scanners are worth running and will not find most of this.
The test that matters most is a person completing a purchase with a
keyboard, then with a screen reader. It will not settle everything:
reflow at 400 percent, text resizing, and target size need their own
checks.

Enforcement is national. Article 29 requires member states to let
consumers act before the courts or the competent administrative
bodies, and lets organisations with a legitimate interest act on
their behalf; Article 30 leaves the penalties to each member state.
The transpositions covering the markets we work in all apply from
June 28, 2025: Germany's Barrierefreiheitsstärkungsgesetz, Czechia's
zákon č. 424/2023 Sb., Slovakia's zákon č. 351/2022 Z. z., and
Poland's ustawa of April 26, 2024 (Dz. U. z 2024 r. poz. 731).

Two things are worth doing, in this order. Write the Annex V
statement, because it needs no code and it can be checked without
your help. Then walk the purchase path with a keyboard and fix what
stops you. If you would rather have someone walk it with you,
[tell us what you sell and where](/contact/).