Websites

What WCAG 2.1 AA actually requires, and why it matters for your website

Summit Studio · Published September 7, 2026 · Updated September 17, 2026 · 9 min read

An educational walkthrough of WCAG 2.1 AA, what the ADA does and doesn't say about business websites, and how to judge a vendor's accessibility claims. Not legal advice, and no compliance is ever guaranteed.

On this page

This is educational information, not legal advice. Whether your specific website meets any legal obligation is a question for a lawyer or compliance professional who knows your business, your industry, and your risk tolerance. What follows is a plain description of the technical standard regulators point to, and how the law has been applied so far — not a promise that following any checklist makes you compliant or immune from a lawsuit.

What WCAG 2.1 AA actually is

WCAG 2.1 is the Web Content Accessibility Guidelines, published by the W3C, the organization that maintains core web standards. It's organized around four principles: content should be perceivable, operable, understandable, and robust. "Level AA" is the middle of three conformance levels — stricter than the baseline Level A, less strict than Level AAA, which includes requirements most commercial sites don't attempt, like sign language interpretation for video.

A few WCAG 2.1 AA requirements that are concrete and worth knowing exactly: text needs a contrast ratio of at least 4.5:1 against its background, or 3:1 for large-scale text, with narrow exceptions for decorative or incidental text. Every interactive element — menus, forms, custom widgets — needs to be operable from a keyboard alone, not just a mouse. Images that convey information need text alternatives; purely decorative images don't. Forms need labels a screen reader can associate with their fields.

What the ADA actually requires, and of whom

The Department of Justice's 2024 final rule sets a specific, dated legal requirement: state and local government entities (Title II of the ADA) must make their web content and mobile apps conform to WCAG 2.1 Level AA. The compliance dates are staggered by population size — public entities with a population of 50,000 or more must comply by April 26, 2027, and entities under 50,000, along with special district governments, by April 26, 2028, according to the DOJ's interim final rule extending the original dates.

That specific rule, with its fixed WCAG 2.1 AA standard and dated deadlines, applies to Title II government entities. Title III of the ADA covers private businesses that operate as "places of public accommodation," and courts have extended that concept to businesses serving the public online in various rulings over the past decade. But there is no equivalent DOJ regulation setting a fixed technical standard or compliance date for private businesses. That means a private business faces real, ongoing legal exposure through litigation, without a specific rule it can point to and say "we met the deadline." WCAG 2.1 AA is widely treated as the reference standard courts and plaintiffs point to, but a lawyer is the right person to assess what that means for your specific business and jurisdiction.

How to evaluate your own site against the standard

  • Keyboard access — tab through your own site with the mouse unplugged. If you get stuck in a menu or can't close a popup, that's a real barrier for keyboard and screen reader users.
  • Heading structure — headings should follow a logical order (h1, then h2, then h3) rather than being chosen for font size. Screen readers navigate by heading structure.
  • Color contrast — check text against its background using a contrast-checking tool; light gray text on white is a common failure.
  • Alt text — meaningful images need a description that conveys the same information a sighted visitor gets; purely decorative images don't need one.
  • Forms — every field needs a label a screen reader can read, and errors need to be announced, not just shown in red text.
  • Captions — video needs captions; audio-only content needs a transcript.

Why automated scanners aren't the whole answer

Automated tools are a genuinely useful first pass — they catch missing labels, contrast failures, and invalid markup fast. They can't judge whether alt text actually describes an image, whether a tab order makes logical sense, or whether a screen reader user could actually complete your checkout flow. Treat automated scanning as one layer of three: automated scans to catch structural issues, manual testing with a keyboard and a screen reader to catch what scanners miss, and, where possible, feedback from people who use assistive technology daily.

Questions to ask any accessibility vendor

  1. 01Do you test manually with a keyboard and a screen reader, or only run an automated scan?
  2. 02Which WCAG success criteria does your audit actually check, and which does it skip?
  3. 03Do you provide a written report identifying specific failures, or just a pass/fail score?
  4. 04How do you prioritize fixes — by how many users a barrier blocks, or just by how easy the fix is?
  5. 05Does anyone review the site again after new pages or features ship, or is this a one-time engagement?

Be skeptical of anyone who promises "full compliance" or "lawsuit-proof" as a deliverable. Accessibility work reduces known barriers and demonstrates a documented, good-faith effort — it does not extinguish legal risk, because that determination sits with courts and regulators, not vendors.

Why this is an ongoing effort, not a one-time project

A site that passes an audit today can fail tomorrow the moment someone publishes a new page with poor contrast or an unlabeled form field. Accessibility drifts the same way SEO or page speed drifts — quietly, as new content ships without anyone checking it against the same standard the original build met. Treating this as a maintained standard, with someone accountable for it on an ongoing basis, holds up better over time than a single audit-and-fix engagement, precisely because new problems get introduced continuously.

Where to go for the primary source

For the technical standard itself, read the W3C's WCAG 2.1 documentation directly. For the legal side, the Department of Justice publishes its own guidance and the 2024 final rule at ada.gov. Neither source will tell you whether your specific site meets your specific legal obligation — that determination is a job for a lawyer or compliance professional, not a checklist or a vendor.

Source: W3C: Web Content Accessibility Guidelines (WCAG) 2.1

Source: W3C: Understanding Success Criterion 1.4.3: Contrast (Minimum)

Source: ADA.gov: Fact Sheet: New Rule on the Accessibility of Web Content and Mobile Apps Provided by State and Local Governments

Ongoing site review is part of the monthly cycle, which is a better fit for accessibility work than a one-time fix, since new pages can reintroduce old problems.

See how the membership works

More on Websites

Share

All insights