The missing layer in your EAA compliance strategy

On June 28, 2025, the European Accessibility Act (EAA) became enforceable. For years, accessibility was treated as a public-sector obligation or a "nice to have" for private companies. That's no longer true. The EAA now applies to any company selling products or services to EU consumers, regardless of where that company is headquartered.
Here's the paradox: most companies have already run their audits. Many have published accessibility statements. And yet enforcement is underway, and real users with disabilities are still hitting walls in checkout flows, banking apps, and self-service portals. Passing an audit and being accessible are turning out to be two different things. As UserTesting's own accessibility team has put it, the goal has to be experience over compliance—because compliance alone hasn't been protecting anyone.
"A conformance report tells you what a page contains. It doesn't tell you what happens when a real person tries to get through it." — Caroline Vize, Director, Solutions Consulting EMEA at UserTesting
"A conformance report tells you what a page contains. It doesn't tell you what happens when a real person tries to get through it. We keep meeting companies who are compliant on paper and still losing customers at checkout, and those aren't contradictory facts—they're the same problem." — Caroline Vize, Director, Solutions Consulting EMEA at UserTesting
What the EAA actually requires
In plain terms, the EAA says your website, app, and other digital products need to work well for people with disabilities. The legal path there runs through a few layers of technical standards, but the practical target is the same one most digital teams already know: WCAG 2.1, at the AA level. That's the bar for websites, apps, software, and documents alike.
A few things make this law different from what came before it. It doesn't matter where your company is headquartered—if you're selling to customers in the EU, you're in scope. Some industries have more at stake than others: e-commerce, banking, telecom, and transport are all under extra scrutiny, since these are the high-traffic, consumer-facing experiences where one broken flow can shut out a lot of people at once.
And the EAA is really aimed at consumer-facing products; if your business sells purely to other businesses, you have more breathing room, though most companies have at least some consumer touchpoint that puts them in scope anyway.
There are a few exceptions. Very small businesses (under 10 employees and €2 million in revenue) get a pass, along with content that's archived and no longer maintained, and content owned by a third party you don't control.
Companies can also argue that fixing something would be a "disproportionate burden," but that takes real documentation to prove—it's not a free pass just because a fix is inconvenient. And if your site existed before the June 2025 deadline, you get a five-year grace period to bring it up to standard.
None of these exceptions are a reason to wait, though: this is exactly the kind of thing an outside team, like UserTesting's accessibility researchers, can help sort out early, before a regulator forces the question. One detail that catches multinational companies off guard: fines are counted per country, not per company. Sell in ten EU countries with the same unresolved issue, and that's ten separate fines for one problem.
REPORT
Accessibility research and testing
The enforcement reality: it's already happening
Within months of the deadline, enforcement moved from theoretical to active. In early July 2025, disability advocacy groups in France issued formal legal notices against several major grocery retailers over inaccessible digital experiences, a step that can escalate to litigation if issues aren't resolved. One of those retailers is now facing an emergency injunction in Paris. Germany's BFSG created a per-violation fine structure, meaning a single site with a handful of unresolved failures can face fines that stack quickly rather than a single flat penalty. The Netherlands' ACM has launched a formal audit program, and Sweden's PTS is doing the same. Dedicated enforcement bodies are standing up across the bloc, including Germany's market surveillance authority for accessibility and France's DGCCRF.
A detail worth sitting with: in several of these early cases, the companies involved had already declared their products or services accessible, but no one had verified that claim before it was published. Regulators found the gap that the company's own paperwork said didn't exist. That's a preview of where a lot of organizations are exposed—not because they ignored accessibility, but because they trusted an unverified statement to hold up under scrutiny.
"The riskiest sentence in accessibility right now is 'we believe we conform.'" — Caroline Vize, Director, Solutions Consulting EMEA at UserTesting
"The riskiest sentence in accessibility right now is 'we believe we conform.' A statement is only as strong as the evidence behind it, and 'we ran a scan and an audit' isn't the same as 'we watched real assistive-technology users complete the journey.' Regulators are starting to know the difference, even when companies don't." — Caroline Vize, Director, Solutions Consulting EMEA at UserTesting
Roughly a year in, the picture is mixed but trending in one direction: readiness varies widely across organizations, but end-user complaints and reports appear to be rising faster than they did under the EU's earlier Web Accessibility Directive. People are starting to know they have rights here, and they're starting to use them.
It's worth calling out that enforcement isn't uniform across the EU. Penalty structures, oversight bodies, and even reporting obligations vary by member state, and by market outside the EU, too—Switzerland's BehiG and the UAE's Dubai Universal Design Code follow a similar logic on different timelines. A compliance strategy built for one country's regulator won't automatically hold up in another.
The compliance stack, and its gap
Most organizations approach EAA compliance in two layers.
Layer 1: Automated scanning. Tools like Axe, Lighthouse, and SiteImprove catch somewhere between 30% and 50% of WCAG failures, depending on whose numbers you use. They're fast, cheap, and scalable, but no regulator accepts a scan report alone as evidence of conformance.
Layer 2: Expert audit. Certified accessibility specialists manually test against EN 301 549 criteria and produce the VPAT or conformance report that becomes the required Accessibility Statement. This layer tests at the code level, not the experience level.
Here's the honest part: layers 1 and 2 combined still leave 60–70% of real-world barriers undetected. A page can pass every automated check and every code-level audit criterion and still be functionally unusable for someone navigating it with JAWS.
Consider a real, common failure: a button in an image carousel with no alt text. A sighted code reviewer glances at it and moves on. A screen reader announces "graphic 11," then "graphic 12," then "graphic 846," with no indication of what any of them do. That's not a hypothetical; it's the kind of thing that shows up constantly once an actual screen reader user sits down with the product—and almost never shows up in a code-level review. Technical conformance and actual accessibility of experience are not the same thing, and regulators are increasingly drawing that distinction. Level Access's Karen Hawkins made a similar point on UserTesting's Insights Unlocked podcast: automated scans are fine for a quick check, but a thorough audit has to involve real people, and accessibility only works as an ongoing practice rather than a one-time fix.
Insight approach fills the gap that automated tools and code audits leave open. Recruiting assistive-technology users is often the hardest part of this work; it typically takes months of specialist outreach to build a panel that covers the range of tools and needs an EN 301 549 audit is expected to address. As User Interviews has noted, people who rely on assistive technology represent a skilled participant pool, and finding and fairly compensating them takes real specialist effort—which is exactly why most teams don't have this covered in-house. UserTesting removes that bottleneck with a vetted panel already built for this kind of research, so teams can go from question to evidence in a matter of days rather than months.
"Nobody designs a checkout flow that announces itself as 'graphic 846.' It happens by accumulation—one missing label at a time. That's the layer no scanner can see." — Caroline Vize, Director, Solutions Consulting EMEA at UserTesting
That gap is layer three: human evidence.
What human evidence actually means
Human evidence means testing with the people the EAA exists to protect: screen reader users on JAWS, NVDA, VoiceOver, or TalkBack; keyboard-only navigators; switch-access and voice-control users like those using Dragon NaturallySpeaking. In practice, this looks like recruiting a diverse panel of assistive-technology users, running moderated task flows against the same journeys customers actually use, capturing video evidence of where and how barriers occur, and severity-mapping the findings so remediation work can be prioritized.
This is where UserTesting's Human Insight approach fills the gap that automated tools and code audits leave open. Recruiting assistive-technology users is often the hardest part of this work; it typically takes months of specialist outreach to build a panel that covers the range of tools and needs an EN 301 549 audit is expected to address. As User Interviews has noted, people who rely on assistive technology represent a skilled participant pool, and finding and fairly compensating them takes real specialist effort—which is exactly why most teams don't have this covered in-house. UserTesting removes that bottleneck with a vetted panel already built for this kind of research, so teams can go from question to evidence in a matter of days rather than months.
DOWNLOAD NOW
2026 Panel Book
Get fast, reliable access to the people who matter most to your business—so you can create exceptional customer experiences.
The output isn't just a checklist. It's a timestamped, video-backed record that validates the audit and creates the kind of defensible documentation a National Enforcement Authority can actually review. An accessibility statement backed by human-evidence sessions is a compliance document. Without it, it's a liability document.
"When a regulator asks how you know your product is accessible, 'we scanned it' is not a great answer. 'Here's video of a JAWS user completing the exact flow you're asking about, and here's what we fixed when they couldn't' is a very good answer. That's the difference between hoping you'd hold up and knowing you would." — Caroline Vize, Director, Solutions Consulting EMEA at UserTesting
The business case beyond the fine
Compliance is the reason most teams start this work, but it's not the only reason to finish it. People with disabilities and their networks control an estimated €2.6 trillion in disposable income across North America and Europe. Roughly 1 in 4 people now live with some form of disability, up from about 1 in 6 two decades ago, and that number continues to climb.
A product that's inaccessible isn't just exposed to fines; it's locked out of a substantial and growing share of its addressable market.
The customer behavior underneath that figure is stark. Surveys of shoppers with disabilities have found that a majority will leave a site altogether if it's difficult to use, that most are more likely to stay loyal to brands that get accessibility right, and that a large share would pay more for the identical product on a site they can actually navigate.
Three out of four disabled customers say they've walked away from a business entirely because of an inaccessible experience. That's not a compliance statistic. That's churn.
There's also the curb-cut effect: barriers removed for an assistive-technology user tend to improve the experience for a much wider audience, including elderly users, people with low vision, and anyone dealing with a situational impairment, like trying to check out on a phone in bright sunlight with one hand full of groceries. It's not just anecdotal—in one mobile study, more than 6 in 10 users on Android had at least one accessibility setting turned on, meaning most "edge case" accommodations are already mainstream behavior. Insights are only as good as the people who provide them—and testing with the users who encounter the sharpest edges of a product tends to surface issues that benefit everyone downstream. Compliance research, done well, doubles as market research.
"You're rarely fixing something for a narrow group. You're usually fixing something for everyone and just noticing it because of the narrow group first." — Caroline Vize, Director, Solutions Consulting EMEA at UserTesting
"Teams treat accessibility fixes like a tax they pay for one audience. In practice, every barrier you remove for a screen reader user tends to clean up the experience for someone one-handed, someone in a hurry, someone with a cracked screen. You're rarely fixing something for a narrow group. You're usually fixing something for everyone and just noticing it because of the narrow group first." — Caroline Vize, Director, Solutions Consulting EMEA at UserTesting
PODCAST
Designing for diverse audiences
Making it continuous, not ceremonial
One of the more common mistakes teams make is treating EAA compliance as a certification event: run the audit, publish the statement, move on. The EAA doesn't work that way. Article 30 of the directive pairs penalties with ongoing corrective action requirements, which means organizations need to demonstrate continuous improvement, not a single point-in-time snapshot. That also means documentation matters well beyond the initial statement—being able to show what was tested, what was found, and what was fixed is what turns a good-faith effort into a defensible record if a regulator or advocacy group comes asking. It also reframes the goal. As accessibility advocate Cat Noone argues, compliance is really a side effect of inclusive design rather than the objective itself—get the inclusive design practice right, and the compliance follows.
That argues for building assistive-technology testing into sprint cycles rather than treating it as a pre-launch gate. Running pre- and post-release sessions against the same task flows gives engineering and product teams reproducible, prioritized evidence that remediation actually worked, instead of an abstract reference to a WCAG criterion. Accessibility becomes a living practice rather than a box checked once a year.
"The EAA was written for a world where products keep changing, so the evidence has to keep getting refreshed too." — Caroline Vize, Director, Solutions Consulting EMEA at UserTesting
"The companies that get caught off guard by this aren't the ones who skipped accessibility. They're the ones who did it once, filed it away, and assumed the job was done. The EAA was written for a world where products keep changing, so the evidence has to keep getting refreshed too." — Caroline Vize, Director, Solutions Consulting EMEA at UserTesting
Where to start
Full-scale, portfolio-wide accessibility programs are the eventual goal for most organizations, but they don't have to be the starting point. A single, well-chosen user flow—a checkout, an onboarding sequence, a claims process—is enough to see where the real gaps are and to build a defensible evidence trail while remediation is still manageable.
If your team is ready to see where your own product stands, UserTesting's accessibility testing service is a good place to start the conversation, or reach out directly to speak with the accessibility research team.
%20Calculator-1240x500px.png?w=672&v=080acb64-e011-4326-8b64-b82003f132fd&itok=DIU6Bq1o)


