Introduction
For most of the last decade, accessibility on an e-commerce site was a thing teams intended to get to. In the EU it is now a legal obligation with a date that has already passed, a standard it points at, and courts that have started issuing orders.
This is unusual among quality attributes, and it changes who has to care. A flaky test suite is an engineering problem. A checkout that a blind customer cannot complete is a product owner's problem, because the decision to ship it, the budget to fix it, and the exposure when it is not fixed all sit in the same place.
This guide covers what the Act requires, what enforcement has actually looked like, and what a product owner can check without waiting for a specialist.
The deadline has already passed
The European Accessibility Act's compliance date for services was 28 June 2025. There is no phase-in for new e-commerce services — that date was the deadline, and enforcement began after it.
Two things follow. First, "we have it on the roadmap for next year" is now a statement about accepted legal exposure, not a plan. Second, the question worth asking is not whether to comply but what evidence of compliance exists, because several member states require it in writing.
Who is in scope
Any business selling online to EU consumers, regardless of where the business itself is based. A US or UK retailer that accepts orders from customers in the EU is covered by the same obligations as a company headquartered in Paris.
Microenterprises providing services are exempt: fewer than 10 employees and an annual turnover or balance sheet total under €2 million. The threshold is small enough that most teams reading this are not under it, and it is worth checking against the actual numbers rather than assuming.
The Act covers services "provided at a distance… through websites and mobile device-based services", which is the definition that pulls in e-commerce, banking, ticketing, and most subscription products.
The standard it points at
In practice, compliance means EN 301 549, the European standard for accessibility of ICT, which incorporates WCAG 2.1 Level AA. WCAG 2.2 AA is a superset and satisfies it comfortably.
That matters because WCAG AA is specific enough to test. It is not a philosophy; it is a list of success criteria with pass and fail conditions — labels associated with form fields, contrast ratios with numbers in them, keyboard operability of every control, focus that remains visible. Our accessibility testing with axe and the keyboard walks through checking those on a real shop.
What the Act names for e-commerce specifically
Beyond the general WCAG obligations, the Act calls out requirements that map directly onto a checkout flow:
- Identification, security, and payment must be accessible. The parts most likely to be a third-party widget or an iframe are explicitly in scope — which means a payment provider's inaccessible form is still your problem.
- Electronic identification and signature methods used in the transaction have to be accessible too.
- Accessibility information about the products themselves has to be passed on to the customer where the manufacturer provides it.
- An accessibility statement has to be published.
- Compliance documentation has to be kept for five years.
The last two are the ones teams forget, and they are the cheapest to satisfy. They are also the first thing an enforcement body asks for.
What enforcement has actually looked like
This is the part that turns the Act from a memo into a budget line, and France is the clearest example.
On 7 July 2025, nine days after the deadline, the disability rights organisations ApiDV and Droit Pluriel, supported by the legal collective Intérêt à Agir, issued formal notices to four of France's largest grocery retailers — Auchan, Carrefour, E. Leclerc, and Picard — over inaccessible online shopping. The complaints named concrete failures: screen readers unsupported, keyboard navigation blocked, blind customers unable to use click-and-collect.
The retailers were given until 1 September 2025. When remediation was judged insufficient, emergency injunctions were filed on 12 November 2025.
On 4 June 2026, a French judicial tribunal ordered Carrefour to make its e-commerce services fully accessible, with a six-month compliance deadline and daily fines for delay.
The picture is not uniformly one-directional, and it is worth being accurate about that: in a parallel action, the court found Auchan E-Commerce was not subject to the digital accessibility obligations as argued, and that decision has been appealed. Enforcement is real, and its boundaries are still being drawn.
Elsewhere, Sweden's Post and Telecom Authority opened market surveillance in October 2025, focusing first on administrative requirements and consumer information — meaning the accessibility statement and documentation, not the interface. That is a reminder that the paperwork is enforceable on its own.
Penalties vary by member state and can reach €500,000 or more, alongside daily fines and public notices of non-compliance.
Overlays are not compliance
A category of product promises accessibility compliance from a single JavaScript snippet: a widget that overlays the site and offers contrast, font size, and screen reader controls.
German auditors reject overlays as evidence of EAA compliance, and the BIK methodology that regulators treat as credible does not accept them. The reasoning is straightforward once stated: an overlay sits on top of the markup that is the problem. If a form field has no label, a widget that increases font size has not fixed it.
For a product owner, this is the most useful thing to know before the procurement conversation, because an overlay is the cheapest-looking option on the table and the one most likely to leave the exposure exactly where it was.
Five checks you can run yourself
These take about fifteen minutes on your own checkout, need no tools, and find the failures that show up in complaints.
- Unplug the mouse. Put your cursor in the address bar and use only
Tab,Shift+Tab,Enter, and the arrow keys. Can you get from the product page to a completed order? If a step is unreachable, that is the failure the French complaints named first. - Watch the focus ring. As you tab, can you always see where you are? A focus indicator removed for looking untidy is a WCAG AA failure and makes keyboard use practically impossible.
- Click every form label. Clicking the word "Postcode" should put the cursor in the postcode box. If nothing happens, the label is not associated with the field, and a screen reader will not announce it.
- Check the error messages. Trigger a validation error. Is the message next to the field, in text, and does it say what to do? Colour alone is not enough, and neither is a red border.
- Open the payment step. This is the one most likely to be a third-party iframe, and the one the Act names explicitly. Run checks 1 to 4 inside it.
Anything that fails here is worth a story before anything else, because these are the failures that stop a purchase completely rather than making it awkward.
What to ask your team for
- An automated scan in CI, failing the build on new serious or critical violations. This is a day of work with axe-core and it stops the problem growing while you fix the backlog.
- A manual keyboard pass on the checkout, written as test cases and run each release.
- The accessibility statement, published, with a contact route for people who hit a barrier.
- The compliance documentation, kept — five years is the requirement.
Be clear about what the automated part buys you. Automated rules catch a real and worthwhile set of problems, and they catch none of the others: a scan cannot tell you whether a label makes sense, whether the tab order follows the visual order, or whether an error message explains anything. Our own walkthrough includes a bug that passed every automated check and still broke the page for a keyboard user. Treat the scan as the floor.
What this is not
This is not legal advice, and the details vary by member state — the transposition, the penalties, and the enforcement body are national. What is consistent is the standard, the date, and the fact that the documentation obligations are enforceable separately from the interface.
If you need a defensible position rather than an improvement, the route is an audit against EN 301 549 by someone who does it professionally, and a record of what was found and fixed.
Conclusion
The European Accessibility Act moved accessibility out of the backlog's "nice to have" section and into the category of requirements that have a date and a penalty. The deadline passed in June 2025, a French court has already ordered a major retailer to remediate with daily fines attached, and the paperwork alone is enough to attract market surveillance.
For a product owner, the first useful step costs fifteen minutes: unplug the mouse and try to buy something on your own site. Whatever stops you is the first story. After that, the checks belong in CI so the problem stops growing — see accessibility testing with axe and the keyboard — and the criteria belong in the stories themselves, where they can be checked before they ship rather than after, as in how to write acceptance criteria a tester can't misread.
Sources and further reading
- Accessible.org: EAA e-commerce services requirements
- Law Office of Lainey Feingold: EAA enforcement and implementation tracking
- Bird & Bird: navigating the EAA for online retailers and platforms
- Level Access: EAA requirements and penalties
- Siteimprove: the EAA for e-commerce, a technical guide
- W3C: Web Content Accessibility Guidelines 2.1