Skip to main content
16 minutes read

UK Website Accessibility Law in 2026: Equality Act, EAA, WCAG 2.2

One country, three frameworks, different rules depending on who you sell to. Here is the version that helps you decide where to spend.

ARAlex ReesFounder, XIII Studios
Updated
On this page

Equality Act, EAA, WCAG 2.2: what UK businesses actually need to comply with in 2026

Big Ben and the Houses of Parliament in London.
Big Ben and the Houses of Parliament in London.

Someone has probably told you the law on website accessibility changed in the UK last year. Someone else has probably told you it didn't. They are both half right, and the half each of them got wrong is doing real damage to UK businesses' ability to plan.

Most accessibility marketing in the last twelve months has either over-claimed the EAA or under-claimed the Equality Act. Both are wrong, and they are wrong in different directions.

The honest answer is that there is no single UK website accessibility law. There are three frameworks that overlap, and the right one for you depends on who you sell to.

In Great Britain in 2026, the Equality Act 2010 is your baseline whether you sell B2C, B2B, online-only or in person. The Public Sector Bodies Accessibility Regulations 2018 add a stricter overlay if you are a public-sector body. The European Accessibility Act matters if - and only if - you offer covered products or services to consumers in the EU. WCAG 2.2 AA is not a UK statute for the private sector, but it is the de facto technical benchmark everyone - government, regulators, courts, procurement teams - points at when they need to know what "accessible" actually means.

Grounded in the Equality Act 2010 itself (opens in new tab), the EHRC statutory services code (opens in new tab), official UK government guidance (opens in new tab), the GDS 2022–2024 monitoring report (opens in new tab), the W3C WCAG 2.2 specification (opens in new tab), and the European Accessibility Act directive (opens in new tab).


UK website accessibility law: the short version

Three frameworks, not one. They overlap, but they are not the same.

If you are…

A private business in GB

Your baseline obligation

Equality Act 2010 — anticipatory duty to make reasonable adjustments

Technical target

WCAG 2.2 AA (de facto, not statutory)

Enforcement risk

Individual complaints, settlements, reputational

If you are…

A public sector body

Your baseline obligation

Equality Act + PSBAR 2018

Technical target

WCAG 2.2 AA (operational minimum)

Enforcement risk

GDS monitoring, EHRC/ECNI escalation

If you are…

Selling to EU consumers in covered categories

Your baseline obligation

Add EAA (in force since 28 June 2025)

Technical target

EN 301 549 / WCAG 2.1+ aligned

Enforcement risk

Member-state enforcement

Three things to take from this:

  1. There is no single "UK website accessibility law" for the private sector. The Equality Act is the actual rule. WCAG 2.2 is the way you prove you have followed it.
  2. The Equality Act duty is anticipatory - you are expected to remove predictable barriers before any specific disabled person turns up. "We did not know anyone with that impairment used our site" is a weak defence.
  3. The EAA does not magically become UK domestic law after Brexit. It applies to UK businesses only when they offer covered services into the EU market.

The rest of this piece is the detail behind each of those.

If you want the upstream commercial case for accessibility - why this is a growth lever, not just a compliance line - why accessibility actually matters covers it.


The Equality Act is the actual rule

For most UK businesses, the law that matters most is the one that gets discussed least: the Equality Act 2010 (opens in new tab).

Part 3 of the Act makes it unlawful for a service provider to discriminate, harass, or victimise a person in the provision of services. Section 29 applies the duty to make reasonable adjustments to anyone providing a service - paid or free, online or offline, B2C or B2B - and to anyone exercising a public function.

The EHRC statutory services code (opens in new tab) is the formal interpretive source. Three things in it matter for digital teams:

The duty is anticipatory. The code says service providers should not wait until a disabled person tries to use the service before considering what adjustments are needed. The duty applies whether or not the provider knows that a particular individual is disabled. In digital terms: you are expected to design for predictable barriers - keyboard navigation, screen reader compatibility, contrast, non-time-pressured forms - before anyone complains.

Information barriers count. Where a disadvantage relates to the provision of information, reasonable steps include making that information available in an accessible format. PDFs that cannot be read by assistive technology, terms of service buried in unstructured documents, and forms that fail with screen readers are all potentially in scope. The Act also prohibits charging disabled customers for reasonable adjustments.

Digital channels are explicitly covered. EHRC guidance for service users (opens in new tab) lists websites and internet services, written materials, and telephone access among the ways services are delivered. An online-only business is not in a legal gap. A physical business is not allowed to ignore its booking engine, account portal, or digital forms simply because the shopfront itself is accessible.

The legal question in any Equality Act case is not "did you pass an automated scan?" It is whether your way of providing the service places disabled people at a substantial disadvantage and, if so, whether reasonable steps were taken. Automated tooling can help you find about a third of WCAG issues. The other two thirds - and almost all the substantial disadvantage - needs human judgment, manual testing, and ideally testing with disabled users.

That is the GB baseline. It applies to you whether or not you have ever heard of WCAG.


The public sector overlay

If your organisation is a public sector body, a publicly-funded charity, or a non-governmental body delivering essential public services, the Public Sector Bodies Accessibility Regulations 2018 (opens in new tab) sit on top of the Equality Act. They are stricter, more specific, and actively monitored.

Three things to know:

The technical target is WCAG 2.2 AA. There is a drafting-history wrinkle here. The 2022 post-Brexit amendment process technically referenced WCAG 2.1 AA, but later official UK guidance and GDS monitoring moved to WCAG 2.2 AA from October 2024. Any public-sector body in 2026 should treat 2.2 AA as the operational minimum. Lawyers needing a strict source analysis should note the 2.1 reference, but it is not a licence to stay there.

You must publish an accessibility statement. The statement has a specific form, including known issues, contact routes for raising problems, and disproportionate-burden assessments where relevant. The official guidance (opens in new tab) is prescriptive about what it must contain.

The disproportionate-burden defence is narrow. You can argue it, but the official guidance is deliberately strict. Lack of time, lack of internal knowledge, and low internal priority are explicitly not valid reasons. Even where a public body successfully argues disproportionate burden, the Equality Act still requires reasonable adjustments — for example, providing the same information in another accessible format on request.

The GDS 2022–2024 monitoring report (opens in new tab) is the clearest picture of what enforcement actually looks like at this level. In two years, GDS monitored 1,203 websites and 21 mobile apps, found 29,787 issues, and saw 55.3% fixed during monitoring. The most common issues were exactly the same ones you would expect from the WCAG 2.2 AA list: insufficient contrast, missing visible focus, keyboard access failures, and reflow problems on mobile.

If you are a private business reading this and feeling slightly smug, you should not. The same issues are absolutely present on private-sector sites. The difference is that nobody is publishing a quarterly report about it.


The European Accessibility Act: who it actually applies to

The European Accessibility Act (opens in new tab) (EAA) has been in force across the EU since 28 June 2025. It is genuinely important — and it is also one of the most over-claimed pieces of legislation in current accessibility marketing.

The EAA does not automatically apply to UK businesses after Brexit. It applies to providers offering covered products or services on the EU market, and to UK businesses only when they sell into the EU.

A short decision tree:

  1. Do you sell to consumers based in the EU? If no, the EAA is not your concern. The Equality Act still is.
  2. If yes, are your products or services on the covered list? The list includes e-commerce, consumer banking, e-books, certain transport information services, telecoms services, and some self-service terminals (ATMs, ticketing, payment terminals).
  3. If yes, you are in scope. Member-state enforcement applies.

For most UK SMEs serving UK customers only, the EAA is irrelevant — but you still have a UK accessibility obligation under the Equality Act regardless. For UK businesses with material EU consumer revenue in covered categories, the EAA is now ten months in force and the question is not "should we look at this?" but "what is our compliance position today?"

Worth flagging: the EU-domestic technical benchmark for EAA-style obligations is EN 301 549, which itself references WCAG 2.1 AA at minimum. In practice, designing to WCAG 2.2 AA covers both the UK de facto benchmark and the EU statutory minimum, with headroom.


Why WCAG 2.2 is the benchmark even though it is not the law

WCAG 2.2 is not written into the Equality Act. It is not a statutory safe harbour for private-sector businesses. So why does everyone — government, regulators, courts, procurement teams — point at it?

Because it is currently the only widely-accepted technical definition of "accessible" that survives legal scrutiny. The W3C WCAG 2.2 specification (opens in new tab) is referenced by UK government guidance, by the EU's EN 301 549 standard, by procurement contracts across the public sector, and by the EHRC's own published positions. If you are asked to demonstrate that you have taken reasonable steps to make a digital service accessible, "we conformed to WCAG 2.2 AA" is the strongest evidence you can offer.

That does not mean automated WCAG conformance equals legal compliance. It does not. The Equality Act is about whether disabled people can actually use your service in practice — which is why testing with disabled users, manual assistive-technology testing, and a credible reasonable-adjustments policy all matter alongside the technical conformance work.

But it does mean that if you only choose one technical target for 2026, choose WCAG 2.2 AA. It is the floor that satisfies the most regimes at once.


The WCAG 2.2 success criteria most likely to bite you in 2026

WCAG 2.2 added nine new success criteria over 2.1. The ones causing most retrofitting pain on commercial sites in 2026 are these:

Accessible Authentication (opens in new tab) (3.3.8, AA). You cannot require users to memorise, transcribe, or solve a cognitive puzzle to log in unless you provide an alternative. That breaks a lot of sites. Common offenders: blocking password manager autofill, requiring CAPTCHAs without alternatives, demanding character-from-password challenges ("3rd, 7th, and 10th characters of your password"), and SMS-only one-time-codes that some users cannot receive.

Focus Not Obscured (opens in new tab) (2.4.11, AA). The keyboard focus indicator must not be hidden by sticky headers, sticky cookie banners, or floating chat widgets. This breaks more sites than people expect, because almost every modern marketing template has a sticky element above and below the fold.

Target Size (Minimum) (opens in new tab) (2.5.8, AA). Interactive targets must be at least 24×24 CSS pixels, with limited exceptions. A lot of mobile UI — small icon buttons, dense navigation, packed link lists — fails this without a redesign pass.

Dragging Movements (opens in new tab) (2.5.7, AA). Anything that requires a drag gesture must have a single-pointer alternative — typically a click-to-select-then-click-to-place pattern. Catches sliders, custom drag-and-drop file uploaders, image comparison tools, and most carousels with drag interaction.

Consistent Help (opens in new tab) (3.2.6, A). If you offer help — contact, FAQ, support chat — it must appear in the same place across pages where it is available. Sounds trivial. Frequently broken on sites where the marketing pages and the authenticated app are run by different teams.

Redundant Entry (opens in new tab) (3.3.7, A). You cannot make users re-enter information they have already provided in the same process — typically a multi-step checkout, signup, or onboarding flow. Either auto-populate or let them confirm.

If you want a quick prioritisation read on a current website, those six criteria cover most of the new-in-2.2 issues that show up on commercial templates. The general-purpose 2.1 issues — contrast, focus visibility, keyboard access, alt text, form labels, reflow — still account for the bulk of failures GDS sees, and they have not gone away.


What enforcement actually looks like (and where it is going)

Public-sector enforcement is structured. Private-sector enforcement is uneven, but it is not absent — and the gap between the two is closing.

In the public sector, GDS runs a working monitoring programme: it samples sites, issues reports, and gives organisations roughly twelve weeks to remediate before issues escalate to EHRC (or ECNI in Northern Ireland). The 2022–2024 figures — 1,203 websites monitored, 29,787 issues identified, 55.3% fixed during monitoring — describe a system that is genuinely active. If you are a public body, the question is not whether you might be sampled. It is what you would do if you were sampled next quarter.

In the private sector, there is no single regulator publishing a stream of website cases. That has misled a lot of businesses into reading the absence of headlines as the absence of risk. It is the wrong read. EHRC has supported a steady stream of negotiated settlements in disability-discrimination cases — covering festival access, software accessibility, and public-facing services — and the pattern is "settle quietly" rather than "fight publicly," which is why the case law looks thinner than the underlying activity actually is. UK accessibility legal practice has grown materially in the last two years; the published judgments lag the work being done.

There are three other vectors that catch private businesses out. The first is contractual: large procurement contracts increasingly require WCAG 2.2 AA conformance and accessibility statements as standard clauses, and failing those clauses is just as expensive as a statutory breach. The second is reputational: a single well-shared complaint can outweigh years of quiet operation. The third is EU-market exposure for any business selling into covered EAA categories, which is a separate enforcement track on top of the UK obligation.

The honest read is that most private businesses have not seen enforcement action because most disabled customers do not pursue formal complaints. That is not a defence. It is a delay. The regulators, the standards bodies, and the government's own evidence base are all moving in the same direction, and the trajectory is one-way.


What "compliant" actually requires

Most accessibility programmes fail not because the WCAG fixes are wrong, but because the surrounding controls are missing. A defensible 2026 compliance posture has six parts.

1. Real-user accessibility testing. Automated tools catch roughly a third of WCAG issues. Manual testing — keyboard, screen reader, mobile assistive tech — catches another large share. Testing with disabled users catches what the other two methods miss, and is the only way to surface the real-life "substantial disadvantage" the Equality Act actually asks about. Government service manual guidance (opens in new tab) treats this as a core control, not a nice-to-have.

2. A reasonable-adjustments policy that works in practice. The EHRC services code is sharp on this. A reasonable-adjustments policy is not just a clause in the terms of service. It needs to make it easy to ask for help, offer alternative formats and assisted routes without arguing about entitlement, record recurring needs so the same person does not have to ask repeatedly, and ensure the customer is never charged for the adjustment.

3. An accessibility statement, or its commercial equivalent. For public-sector bodies, this is statutorily required. For private businesses, it is not — but a credible accessibility statement is one of the most useful pieces of evidence you can produce if a complaint surfaces, and it sets a clear contact route for users who hit a barrier before the barrier becomes a complaint.

4. Procurement clauses that actually transfer obligations. Government guidance is explicit: an organisation remains legally responsible for accessibility even when the website or app is outsourced. The minimum credible 2026 contract clause set requires conformance to WCAG 2.2 AA, an accessibility audit and remediation log, pre-release testing across keyboard, screen reader, and mobile, no supplier-imposed barriers in authentication flows, accessible documentation, and a remediation SLA for critical defects. If your existing contracts do not include these, the supplier's failures become your problem.

5. Ongoing monitoring, not point-in-time audits. Accessibility regressions ship with every release. A one-shot audit goes stale within months on any actively-developed product. Effective programmes pair an initial audit with ongoing automated checks in CI, manual testing on key flows each release, and periodic external review.

6. Honest documentation of what is not yet fixed. The disproportionate-burden defence — to the extent it exists — depends on a documented assessment of cost, benefit, and proportionality, not a vague feeling that something was hard. Public-sector accessibility statements model this well; private businesses can borrow the same structure for their own internal records.


The decision framework: what to do in what order

A defensible 2026 plan, scoped by the size and exposure of the business:

If you sell to UK customers only and you are not a public sector body:

  1. Map your digital touchpoints — public site, account areas, forms, transactional flows, important PDFs.
  2. Run a WCAG 2.2 AA audit (automated + manual + assistive technology) prioritised by traffic and revenue.
  3. Build a reasonable-adjustments policy with a real contact route and SLA.
  4. Add accessibility clauses to any new supplier and platform contracts.
  5. Set up ongoing monitoring on the highest-traffic flows.
  6. Keep an internal record of known issues, planned fixes, and proportionality assessments.

If you are also selling to EU consumers in EAA-covered categories:

  1. Confirm scope — covered service, EU market activity, consumer (not B2B-only) audience.
  2. Add EN 301 549 / EAA conformance to your audit and procurement scope.
  3. Ensure your accessibility statement covers EU-market obligations.

If you are a public sector body:

  1. WCAG 2.2 AA is the operational minimum. Treat it as such.
  2. Publish a compliant accessibility statement.
  3. Assume GDS monitoring may sample you. The 12-week remediation window is real.
  4. Document any disproportionate-burden positions formally — lack of internal capacity is not a valid reason.

In every case, the same underlying principle: anticipate the barrier, evidence the work, and make it cheaper for a disabled customer to reach you about a problem than to file a complaint about one.


What this means for the next twelve months

Three things changed in the last year that will keep changing.

The EAA is now in force. UK businesses with EU consumer revenue in covered categories that have not done compliance work are visibly exposed. Member-state enforcement is now active.

WCAG 2.2 has consolidated as the benchmark. The drafting wrinkle around 2.1 versus 2.2 in UK public-sector regulations is more lawyerly than practical: any organisation working to 2.2 AA in 2026 is on safe ground for either reading.

Procurement clauses are tightening. Public-sector tenders increasingly require WCAG 2.2 conformance evidence as a hard gate. Large corporate buyers have started doing the same. If you sell into either, your accessibility position is now a commercial constraint, not just a regulatory one.

The trajectory is one-way. Treating accessibility as a 2027 problem — or worse, as a problem that will stay quiet because it has been quiet — is a steadily worse bet each year.


XIII Studios point of view

Most of the businesses we meet are not in legal trouble on accessibility. They are in evidence trouble. They have an Equality Act obligation they have never written down, a website built before WCAG 2.2 existed, no accessibility statement, no reasonable-adjustments process, and supplier contracts that quietly leave the responsibility with them. That is a normal 2026 position. It is also a fragile one — fine until something happens, expensive once it does.

Our accessibility-first development work treats compliance as an outcome of a sound design and engineering process, not as a separate audit-and-fix project bolted on at the end. That means accessibility considered from the brief, real-user testing alongside automated checks, procurement clauses that protect you when you outsource, and an honest written record of what is fixed and what is not.

AI-assisted workflows make the evidence side of compliance significantly cheaper. We use them to run automated regression checks across templates after every release, cluster findings against WCAG 2.2 success criteria, and keep the accessibility statement up to date as a living document rather than a once-a-year exercise. Manual testing — keyboard, screen reader, real users — still decides what is actually accessible. The AI side keeps the paper trail current so that, if EHRC or a customer ever asks for evidence, you have it.

If you want the upstream commercial case for accessibility, why accessibility actually matters covers it.


FAQ: UK website accessibility law in 2026

Not directly for the private sector. WCAG 2.2 is the de facto technical benchmark courts, regulators and procurement teams point at when defining "accessible". The Equality Act 2010 is the actual legal duty, and conformance to WCAG 2.2 AA is the strongest evidence you have followed it.

Does the European Accessibility Act apply to UK businesses?

Only if you sell covered products or services into the EU. The EAA does not automatically apply to UK companies after Brexit, but UK businesses with EU consumer revenue in covered categories — e-commerce, consumer banking, e-books, certain transport information services, and some self-service terminals — are in scope. It has applied across the EU since 28 June 2025.

What WCAG version do I need to comply with in 2026?

For private-sector UK businesses, design and test to WCAG 2.2 AA. For public-sector bodies, the operational minimum is also WCAG 2.2 AA from October 2024. Working to 2.2 AA covers you under either reading of the public-sector regulations.

Can a private UK business be sued for an inaccessible website?

Yes — under the Equality Act 2010. Published UK case law on digital accessibility is still relatively thin compared with the US, so the visible risk is mostly individual complaints, negotiated settlements, reputational damage, and contractual breach rather than headline judgments. EHRC's powers focus heavily on the public sector and structured agreements rather than a stream of private-sector lawsuits. The bigger commercial risk for most private businesses in 2026 is procurement: public-sector tenders and larger corporate buyers increasingly require WCAG 2.2 conformance evidence as a hard gate.

Do I need an accessibility statement?

Public-sector bodies must publish one. Private-sector businesses are not legally required to, but a clear, dated accessibility statement and a route to request reasonable adjustments is one of the cheapest and strongest pieces of evidence you can have if challenged.

How often should we test for accessibility?

Continuously, not annually. Treat it like security: automated checks in CI, manual keyboard and screen reader sampling on critical journeys, and a re-audit when you ship a major template change or a new third-party integration.


Closing thought

There is no single UK website accessibility law for the private sector. There is the Equality Act 2010 — which is broader and more demanding than most businesses realise — plus a public-sector overlay, plus an EU regime that catches you if you sell across the channel.

WCAG 2.2 is not the law. It is the most defensible technical answer to the question the law actually asks: can disabled people use this service in practice, and have you taken reasonable steps to make sure they can?

The boring version: design to WCAG 2.2 AA, evidence the work, give people a clear way to ask for help, and keep your contracts honest about who is responsible. Most of the cost is in deciding to do this properly. Most of the risk is in deciding not to.


XIII Studios builds high-performance websites and software without the usual agency overhead.

If you are not sure whether your current site is defensible under the Equality Act, or whether the EAA applies to you, start with a website audit (opens in new tab). We will review your site and give you clear, actionable feedback on accessibility, performance, SEO, and conversion — and a straight answer on which of the three regimes you actually need to plan around.



Photo credits

Hero and section images use Unsplash (opens in new tab) community photography. See Unsplash license (opens in new tab).


ShareX / TwitterLinkedIn

Explore other categories

Let's build something better

If your current website or software isn't delivering, we think it's time to talk. We'll review what you have, identify what's not working and show you how to improve it.

Book a call with us (opens in new tab)