July 31, 2026, Luboš Zápotočný
Your store has been in scope of the Accessibility Act since June 2025
The European Accessibility Act covers e-commerce services sold to consumers. The microenterprise exemption is narrower than it looks, the 2030 date is not an extension, and the payment step is named explicitly.
The European Accessibility Act has applied to e-commerce services since June 28, 2025. A year on, the common assumption is still that accessibility is a public sector obligation, or a deadline somewhere ahead. Article 2(2)(f) lists e-commerce services among the services covered, and Article 3(30) defines them as “services provided at a distance, through websites and mobile device-based services by electronic means and at the individual request of a consumer with a view to concluding a consumer contract”.
That is a description of an online store selling to consumers. The definition turns on a consumer contract, and Article 2(2) applies the directive to services “provided to consumers”, so a storefront that sells only to business customers falls outside it. A mixed store is inside it for the consumer side.
The directive is Directive (EU) 2019/882, OJ L 151, 7.6.2019. Every article, recital and annex cited below was read in that text on July 30, 2026, because most of what circulates about this law is a summary of a summary. We read it as engineers who have to implement it rather than as lawyers, and the questions of scope are worth raising with your own counsel, citing the article numbers.
The exemption is narrower than “small business”
Article 4(5) exempts microenterprises providing services from the accessibility requirements “and any obligations relating to the compliance with those requirements”. Article 3(23) then defines a microenterprise as one “which employs fewer than 10 persons and which has an annual turnover not exceeding EUR 2 million or an annual balance sheet total not exceeding EUR 2 million”.
The question hangs on the conjunctions, and the two tests are not symmetrical. Fewer than ten persons is a hard ceiling: eleven people puts a store in scope whatever its finances. The money test is satisfied by either limb, so a six-person store turning over EUR 5 million is still a microenterprise if its balance sheet total stays under EUR 2 million. Recital 53 adds that a microenterprise must “genuinely fulfil the requirements of Commission Recommendation 2003/361/EC, and the relevant case law, aimed at preventing the circumvention of its rules”, which is where the rules for counting staff and financial thresholds actually live. Read those before concluding you are exempt.
June 2030 is not an extension
Article 32(1) has Member States provide “a transitional period ending on 28 June 2030 during which service providers may continue to provide their services using products which were lawfully used by them to provide similar services before that date”, and allows service contracts agreed before June 28, 2025 to “continue without alteration until they expire, but no longer than five years from that date”.
This is the most misread sentence in the directive. It covers products used in providing a service, and Article 3(2) defines a product as a good produced through a manufacturing process, while Article 2(1) lists which products are actually in scope: payment terminals, ticketing and check-in machines, ATMs, interactive information terminals, e-readers, and consumer computer hardware with its operating system. It also covers contracts already signed. Recital 101 settles the reading: the relief runs to products placed on the market before the application date, and it lapses if the provider replaces them during the period.
The transitional period does exist, then, and it applies to the product layer. If you run collection kiosks or in-store payment terminals, those have until 2030, and Article 32(2) gives self-service terminals up to twenty years. A website is not a product under this directive, and an order placed by a customer today is not a contract agreed before June 2025. The storefront itself gets nothing from Article 32.
What the directive asks of a storefront
Annex I, Section III(c) requires making websites, related online applications and mobile services accessible “in a consistent and adequate way by making them perceivable, operable, understandable and robust”. Those four adjectives are the four principles of WCAG, which recital 47 carries in from the Web Accessibility Directive and declares “also relevant for this Directive”.
Section IV(g) then adds three requirements specific to e-commerce: information about the accessibility of the products and services being sold, where the responsible economic operator provides it; accessibility of the functionality for identification, security and payment “when delivered as part of a service instead of a product”; and identification methods, electronic signatures and payment services that are themselves perceivable, operable, understandable and robust.
That last one closes a gap worth knowing about. Article 2(4)(d) excludes, from the content of websites and mobile applications, “third-party content that is neither funded, developed by, or under the control of, the economic operator concerned”. A hosted payment form does not fall under that exclusion, because the exclusion requires all three to be absent, and a merchant who pays the provider and configures the integration has both funded it and kept control of it. Recital 20 says the same thing directly: “Even if a service, or part of a service, is subcontracted to a third party, the accessibility of that service should not be compromised and the service providers should comply with the obligations of this Directive.” In practice the two components most likely to fail an audit are the two nobody at the company wrote: the hosted card fields served by the payment provider, and the consent banner. Choosing a payment provider is now partly an accessibility decision.
The standard a supplier cannot yet sell you
Article 15(1) grants a presumption of conformity to standards “the references of which have been published in the Official Journal of the European Union”, and Article 15(3) lets the Commission establish technical specifications that carry the same presumption. EN 301 549 V3.2.1 (March 2021) is published in the Journal under the Web Accessibility Directive, by Commission Implementing Decision (EU) 2021/1339. Neither route has been used for this directive: the Commission’s index of harmonised standards carries no entry for Directive (EU) 2019/882, checked on July 30, 2026.
The revision meant to cover the Accessibility Act came out of standardisation request M/587, reached final draft as V4.1.0 in June 2026, and is in ETSI’s approval procedure. So a supplier offering conformance with EN 301 549 is offering good engineering, not a legal presumption under this directive. Follow the standard regardless: it is the technical specification the directive’s machinery points at, and its web chapter is WCAG 2.1 levels A and AA. V4.1.0 retargets that chapter to WCAG 2.2, so the version you implement to will change once it is cited.
The statement most stores have not written
Article 13(2), with Annex V, requires the service provider to explain how the service meets the accessibility requirements, in the general terms and conditions or an equivalent document. Annex V asks for three things: a general description of the service in accessible formats, the explanations needed to understand how it operates, and a description of how the Annex I requirements are met. Article 13(2) adds that this has to be public in written and oral format, itself accessible, and kept for as long as the service is in operation.
It is the one obligation that can be checked from outside without touching the code, so it is where an inspection starts. For services that inspection does not come from a market surveillance authority, which Article 19 confines to products: Article 23 has each Member State designate a separate authority responsible for checking the compliance of services. Article 13(4) adds the last step. On finding the service non-compliant, the provider takes corrective measures and immediately informs the competent national authorities.
What a disproportionate-burden claim requires
Article 14(1) applies the requirements only so far as compliance avoids a fundamental alteration of the service and a disproportionate burden on the operator. Annex VI sets three criteria: the ratio of net compliance costs to overall operating and capital costs; the estimated costs and benefits for the operator weighed against the estimated benefit to persons with disabilities, given how much the service is used; and the ratio of net compliance costs to net turnover. The second sets one estimate against another, so the assessment involves judgement, but it is judgement you have to write down and defend.
Article 14(3) requires the assessment documented, the results kept five years, and a copy handed to the authority on request. Article 14(5) requires it renewed whenever the service is altered, whenever the authority asks, and at least every five years. Article 14(6) bars any operator that took outside funding for accessibility work from relying on disproportionate burden at all, though the fundamental-alteration limb stays open, and Article 14(8) requires telling the authority you are relying on it. Before choosing that route, compare the cost of the file and its five-year upkeep with the cost of the remediation it is meant to avoid.
Where the failures actually are
The recurring ones in e-commerce, roughly in the order they stop a purchase:
- Keyboard alone, end to end. Category page, product page, cart, checkout, payment, confirmation, without touching a mouse. Cart, checkout and payment are where this most often stops.
- Labels and errors. Fields with placeholder text instead of a programmatically associated label, and validation errors signalled by a red border rather than tied to the field and announced.
- Focus in overlays. Drawers, modals, and cookie dialogs where focus never enters, escapes early, or is lost on close.
- Custom widgets. Variant swatches, quantity steppers, filter facets, and selects rebuilt from generic elements for design reasons.
- Colour carrying meaning alone. Stock state, discount, validity.
- Contrast on what gets lightened last. Sale prices, hint text under form fields, secondary labels in the order summary. Disabled controls are exempt under WCAG 1.4.3, so leave them out of the count.
- Silent state changes. Add to cart, cart totals, filter results, and asynchronous price recalculation that updates the page without announcing anything.
Automated scanners are worth running and will not find most of this. The test that matters most is a person completing a purchase with a keyboard, then with a screen reader. It will not settle everything: reflow at 400 percent, text resizing, and target size need their own checks.
Enforcement is national. Article 29 requires member states to let consumers act before the courts or the competent administrative bodies, and lets organisations with a legitimate interest act on their behalf; Article 30 leaves the penalties to each member state. The transpositions covering the markets we work in all apply from June 28, 2025: Germany’s Barrierefreiheitsstärkungsgesetz, Czechia’s zákon č. 424/2023 Sb., Slovakia’s zákon č. 351/2022 Z. z., and Poland’s ustawa of April 26, 2024 (Dz. U. z 2024 r. poz. 731).
Two things are worth doing, in this order. Write the Annex V statement, because it needs no code and it can be checked without your help. Then walk the purchase path with a keyboard and fix what stops you. If you would rather have someone walk it with you, tell us what you sell and where.