# European Accessibility Act Compliance: Monitoring Accessibility Statements and WCAG Conformance

Source: PageCrawl.io Blog
URL: https://pagecrawl.io/blog/european-accessibility-act-compliance-monitoring-wcag

---

On 28 June 2025, the European Accessibility Act became enforceable. A year on, the picture for most in-scope businesses is uncomfortable. Many published an accessibility statement to clear the deadline, then moved on. The statement now describes a version of the product that no longer exists, because three sprint cycles have shipped since, the checkout flow was rebuilt, and nobody re-ran a conformance audit. The statement says the site meets WCAG 2.1 AA. The site no longer does.

That gap is exactly what enforcement bodies look for. Several member states have transposed the EAA with administrative fines that reach into the hundreds of thousands of euros (Ireland's regime allows penalties up to EUR 60,000 with the possibility of imprisonment for officers in serious cases, and other states have set ceilings as high as EUR 500,000). Enforcement in 2025 was light by design, with regulators issuing guidance and warnings. In 2026 the warnings are turning into market-surveillance inspections, and the first thing an inspector reads is your accessibility statement, followed by a quick test of whether the live product matches it.

Accessibility is not a one-time project. The product changes, the standard changes (WCAG 2.2 is now the reference point in most national guidance, and EN 301 549 is revised on a multi-year cycle), and the member-state rules that interpret the EAA change too. Compliance drifts unless something is watching for the drift.

This guide covers what the EAA actually requires, who has to comply, which pages and standards to monitor, and how to set up automated monitoring with PageCrawl so your accessibility statement, your conformance evidence, and the regulatory sources you depend on stay aligned with reality.

<iframe src="/tools/european-accessibility-act-compliance-monitoring-wcag.html" style="width: 100%; height: 500px; border: none; border-radius: 4px;" loading="lazy"></iframe>

### What the European Accessibility Act Requires

The EAA (Directive 2019/882) harmonizes accessibility requirements for a defined set of products and services across the EU. It does not invent a new technical standard. Instead it points at the existing European harmonized standard, EN 301 549, which in turn incorporates the Web Content Accessibility Guidelines (WCAG) at level AA as the conformance baseline for web and mobile content.

The practical obligations break down into a few categories that each generate ongoing monitoring work.

#### Products and services in scope

The EAA covers a specific list. On the product side: computers and operating systems, payment terminals, ATMs, ticketing and check-in machines, and consumer terminal equipment used for electronic communications. On the service side: electronic communications services, audiovisual media service access, elements of air, bus, rail, and waterborne passenger transport, consumer banking services, e-books and dedicated software, and e-commerce services.

E-commerce is the broad one. Any business selling products or services to consumers online in the EU is potentially in scope, which is why the EAA reaches far beyond the companies that think of themselves as "accessibility" businesses.

#### Conformance to EN 301 549 and WCAG

For digital services, conformance means meeting EN 301 549, which adopts WCAG 2.1 level AA as its web baseline (and national guidance increasingly references WCAG 2.2 AA). This covers the four POUR principles: content must be Perceivable, Operable, Understandable, and Robust. In practice that means keyboard navigation, sufficient color contrast, text alternatives for non-text content, captions, predictable focus order, accessible forms, and dozens of other testable success criteria.

The monitoring implication is that any front-end change can break a previously conformant success criterion. A new color in the design system can drop a contrast ratio below 4.5:1. A modal added without focus management can trap keyboard users. A rebuilt checkout can lose its form labels. Conformance is a property of the live product, and the live product changes weekly.

#### The accessibility statement

In-scope services must publish an accessibility statement describing how the service meets the requirements, the conformance level claimed, known limitations, and a feedback mechanism. The statement is a legal representation. If it claims AA conformance and the product does not deliver it, the gap is evidence against you.

The monitoring implication runs both ways. You monitor your own statement so you know when it changes (and when it should change but has not), and you monitor competitor and peer statements to benchmark how the rest of your sector is interpreting the requirement.

#### Exemptions and the microenterprise carve-out

Microenterprises (fewer than 10 employees and annual turnover or balance sheet under EUR 2 million) providing services are exempt from the service obligations, though not from product obligations if they make products. There is also a "disproportionate burden" exemption, but it is narrow, must be documented, and must be reassessed periodically. Member states audit disproportionate-burden claims, so the documentation supporting one is itself something to keep current.

<picture>
<source srcset="/images/blog/previews/european-accessibility-act-compliance-monitoring-wcag.webp" type="image/webp">
[Image: Screenshot of ec.europa.eu in a browser window, an example of a page PageCrawl can monitor for changes]
</picture>
Set up ec.europa.eu once and PageCrawl notifies you whenever the page updates.

### Who Must Comply

The EAA applies to economic operators placing in-scope products or providing in-scope services on the EU market, regardless of where the operator is headquartered. A US-based e-commerce company selling to EU consumers is in scope just as much as a French one.

The roles matter for who carries the obligation:

- **Manufacturers and importers** carry the product obligations, including technical documentation and conformity assessment.
- **Service providers** carry the service obligations, including the accessibility statement and ongoing conformance.
- **E-commerce operators** are explicitly named. The checkout, the product pages, the account flows, and the support content all fall under the service requirement.

Note: the EAA sets the floor, not the ceiling. Several member states already had national accessibility laws (Germany's BFSG, France's RGAA-based rules, Italy's Stanca Act) and have transposed the EAA on top of them. The transposing law in the country where you provide the service is the one that binds you, and those national texts differ on deadlines, fine ceilings, and enforcement bodies. That is why member-state guidance is one of the things worth watching, not just the directive itself.

### What to Monitor for EAA Compliance

EAA monitoring divides into three buckets: your own accessibility evidence, the standards and regulatory sources that define conformance, and the competitive and peer benchmark. The most cost-effective program watches all three with the same tooling so changes surface in one feed.

#### Your own accessibility statements and conformance pages

The statement is the document an inspector reads first, so it is the document you most need to keep honest.

**Your published accessibility statement.** Monitor the canonical URL of your own statement so you have a timestamped record of every version. When legal or product updates it, you have proof of when the claim changed. When it should have been updated after a major release but was not, the absence of a change is itself a useful signal in your internal review.

**Conformance audit summaries and VPATs.** If you publish a Voluntary Product Accessibility Template or an audit summary, monitor it. These artefacts have dates and version numbers, and a stale date undercuts a live claim.

**The feedback and contact mechanism.** The EAA requires a working feedback channel. Monitor the page that hosts it so a broken form or a removed email address surfaces before a complainant (or a regulator) finds it broken.

#### Standards and regulatory sources

The conformance target is not fixed, and the bodies interpreting it publish on an ongoing basis.

**WCAG specification pages** at w3.org/TR/WCAG22 and the Understanding and Techniques documents. The success criteria themselves are stable once a version is published, but the supporting Understanding documents and the move from 2.1 to 2.2 as the referenced baseline matter for what you must meet.

**EN 301 549 status** via the ETSI portal and the relevant Commission pages. EN 301 549 is revised on a multi-year cycle, and the harmonized-standard reference cited in the Official Journal is what gives a presumption of conformity. When the referenced version changes, your baseline changes.

**The European Commission EAA pages** at commission.europa.eu, covering the directive, implementing acts, and any guidance the Commission issues on scope and interpretation.

**Member-state transposition and enforcement guidance.** Each EU country has a designated market-surveillance authority and a transposing law. Watch the guidance pages of the authority for every member state where you provide services. Examples include the German BFSG guidance, the French DINUM/RGAA pages, the Irish NDA and CRU material, and the equivalent bodies in Spain, Italy, and the Netherlands. National guidance is where deadlines, fine schedules, and inspection priorities actually get specified.

**WCAG-EM and testing methodology updates** from the W3C. How conformance is evaluated changes alongside what is evaluated, and an updated methodology can change how an inspector reads your evidence.

#### Competitor and peer benchmarks

Accessibility statements across your sector reveal how the rest of the market is reading an ambiguous requirement. If three of your four closest competitors have moved their claimed baseline to WCAG 2.2 AA and added a disproportionate-burden section, that is a signal about where enforcement expectations are settling. Monitoring peer statements is the cheapest competitive-intelligence input a compliance team has.

### Methods Compared

There are a few ways to keep accessibility evidence and regulatory sources current. They are not mutually exclusive, but they differ a lot in coverage and cost.

| Method | Catches statement drift | Catches WCAG / EN 301 549 changes | Catches member-state guidance | Ongoing cost | Audit trail |
|--------|------------------------|-----------------------------------|-------------------------------|--------------|-------------|
| Manual quarterly review | Sometimes | Rarely | Rarely | High (staff time) | Weak |
| Automated accessibility scanner (axe, WAVE, Pa11y) | No (tests the product, not the statement) | No | No | Medium | Per-scan reports |
| Newsletters and regulator mailing lists | No | Partially | Partially | Low | None |
| Page-change monitoring (PageCrawl) | Yes | Yes | Yes | Low | Timestamped, exportable |

The important distinction: accessibility scanners and page-change monitoring solve different problems. A scanner like axe or Pa11y tests whether the live product meets success criteria, and you should run one in CI. Page-change monitoring watches the documents and regulatory sources around the product (your statement, the standard, the national guidance, peer statements) and tells you when any of them moves. A complete program runs both. This guide is about the second half, which is the half most teams have no system for.

### Setting Up EAA Monitoring with PageCrawl

The pages worth watching span your own site, several W3C and EU pages, and a market-surveillance authority for every country you serve. That is exactly the kind of diverse, low-frequency-but-high-stakes monitoring that breaks under manual coverage and works well with automated change detection.

[Image: PageCrawl change diff for Accessibility Statement - WCAG Conformance, highlighting the added and removed text]

#### Building the source list

Start with the three buckets and add the canonical URL for each as a separate monitor, tagged so per-tag defaults handle frequency and routing.

A tag taxonomy that scales:

- `source:own`, `source:standard`, `source:regulator`, `source:peer`
- `region:eu`, `region:de`, `region:fr`, `region:ie`, one per member state you serve
- `artefact:statement`, `artefact:vpat`, `artefact:guidance`, `artefact:standard`
- `priority:high`, `priority:normal`

Your own statement and the WCAG/EN 301 549 baseline are `priority:high`. Member-state guidance pages can run daily. Peer statements can run weekly. Tags let you set frequency, AI brief style, and notification routing once per group instead of per monitor.

#### Configuring each monitor

**Step 1: Add your own accessibility statement.** Create a monitor on the canonical statement URL. New monitors default to full-page text tracking with screenshots enabled, so every version is captured with a timestamped image, not just the text diff. That screenshot is the evidence an inspector or your own auditor wants to see.

**Step 2: Add the standards pages.** Add w3.org/TR/WCAG22 and the relevant ETSI/EN 301 549 status page. These change rarely, so a daily check is plenty, but when they change it is the most material change of the year.

**Step 3: Add a market-surveillance authority page per member state.** For each country where you provide services, add the transposing-authority guidance page. Tag with `source:regulator` and the region.

**Step 4: Add peer statements.** Add the accessibility statement URL of your three or four closest competitors. Tag `source:peer` and run weekly.

#### Telling PageCrawl what your business looks like

Workspace instructions change how every change is summarized. A short paragraph (something like "EU-facing e-commerce service selling consumer electronics, in scope of the EAA service requirements, claiming WCAG 2.1 AA, primary markets Germany, France, and Ireland, no microenterprise or disproportionate-burden exemption") makes the AI summary of a detected change specific to your situation. The same WCAG 2.2 reference update produces a different brief for a transport operator than for an e-book seller, because the AI knows which obligations apply to you.

Workspace instructions live under Settings > Workspace > Integrations > AI. Set them once and refine when your market footprint changes.

#### Routing signals to the right people

Changes to your own statement and to the standards baseline should route to whoever owns accessibility (often legal plus an engineering lead) in real time. Member-state guidance changes route to regulatory affairs on a daily or weekly digest. Peer-statement changes route to a weekly benchmark email. PageCrawl supports per-source and per-tag notification channels, so Slack and Microsoft Teams handle the urgent signals, scheduled email digests handle the slow ones, and webhooks push changes into the GRC or ticketing system where you track remediation.

#### Keeping the audit trail in shape

Every detected change is timestamped and stored with before/after snapshots and a screenshot. The change history exports to PDF, Excel, or CSV. For EAA evidence, the most useful pattern is to schedule a periodic export of your own statement's change log and attach it to your conformance file, so you can show an inspector exactly when each claim was made and what the product looked like at the time.

The change history page is also shareable as a read-only public link, which is useful for handing an external accessibility auditor or your legal counsel the version timeline of a statement without granting them a workspace seat.

#### Attested records when fabrication is cheap

When generative tools can produce a plausible screenshot or PDF in seconds, a self-stored archive proves little to an inspector on its own. PageCrawl can enable audit-ready archiving for your account on request, capturing each page as a WACZ file with cryptographic attestations from independent providers: an embedded WACZ Auth signature plus sidecar timestamp proofs (an OpenTimestamps Bitcoin anchor and RFC 3161 timestamps from independent commercial Trust Service Providers). Each proof is independently verifiable offline. For organizations that need the strongest evidentiary credential, eIDAS qualified timestamps under Regulation 910/2014 are available as a Custom plan add-on, carrying a statutory presumption of the date, time, and integrity of the captured page.

### A Worked Example: Keeping a Statement Honest

The most common EAA failure is the statement that quietly stops being true. Here is a pattern that prevents it.

#### Initial setup

Create a folder named "EAA". Inside it, add a monitor on your own accessibility statement (`source:own`, `artefact:statement`, `priority:high`, screenshots on). Add the WCAG 2.2 and EN 301 549 pages (`source:standard`). Add the guidance page for each member state you serve (`source:regulator`, region-tagged). Add peer statements (`source:peer`). Set workspace instructions describing your service and claimed conformance level.

#### Continuous monitoring

When your own statement changes, you get an alert with a summary of exactly which claims, limitations, or contact details moved, and a screenshot of the new version. Compliance logs the version in the conformance file.

When the referenced WCAG or EN 301 549 baseline shifts, you get the leading indicator that your claimed conformance level needs re-evaluation against the new criteria before an inspector tests it against them.

When a member-state authority publishes new guidance (an inspection-priority list, a revised fine schedule, a clarification on the e-commerce scope), regulatory affairs sees it in the daily digest and can assess the impact on your markets.

When a peer moves their claimed baseline or adds a disproportionate-burden section, the weekly benchmark surfaces it, and you can decide whether your position needs to move with the sector.

#### Inspection readiness

At a market-surveillance inspection, the timestamped change history of your own statement is the evidence that you maintained it deliberately, not retrofitted it the night before. The regulatory-source change log shows you tracked the standard and the national guidance as they evolved. That is the difference between a compliant posture and a compliant-looking one.

### Common Pitfalls

#### Treating the statement as a launch artefact

The statement is published once for the deadline and then forgotten while the product keeps shipping. Six months later it describes a flow that no longer exists. Monitoring your own statement (and noticing when it should change but has not) is the cheapest guard against this.

#### Confusing scanning with monitoring

Running axe in CI tells you whether the product meets success criteria today. It tells you nothing about whether the standard, the national guidance, or your own statement has changed. Teams that only scan are blind to the regulatory half of the obligation. Run both.

#### Watching the directive, ignoring the transposition

The EAA directive is stable. The transposing laws and the market-surveillance authorities are where deadlines, fines, and inspection priorities actually live, and they change. Tracking only the EU-level text misses the rules that bind you.

#### Ignoring slow-moving sources

EN 301 549 revisions and the WCAG baseline reference change rarely, so teams stop watching them. When the change comes it resets your conformance target. Low-frequency continuous monitoring is cheap and only alerts when something actually moves.

### Choosing your PageCrawl plan

PageCrawl's **Free plan** lets you monitor **6 pages** with **220 checks per month**, which is enough to validate the approach on your most critical pages. Most teams graduate to a paid plan once they see the value.

| Plan | Price | Pages | Checks / month | Frequency |
|------|-------|-------|----------------|-----------|
| Free | $0 | 6 | 220 | every 60 min |
| Standard | $8/mo or $80/yr | 100 | 15,000 | every 15 min |
| Enterprise | $30/mo or $300/yr | 500 | 100,000 | every 5 min |
| Ultimate | $99/mo or $999/yr | 1,000 | 100,000 | every 2 min |

Annual billing saves two months across every paid tier. Enterprise and Ultimate scale up to 100x if you need thousands of pages or multi-team access.

Compliance monitoring is the cheapest insurance you can buy. A single missed regulatory change can trigger fines in the tens or hundreds of thousands, not to mention the audit overhead of proving you did not see it coming. Enterprise at $300/year covers 500 regulatory pages with unlimited history and timestamped screenshots, which is usually exactly what an assessor wants to see. All plans include the **PageCrawl MCP Server**, so your compliance team can ask Claude to summarize every change to a specific regulation over the last quarter and pull the exact diff, turning your monitoring history into a queryable audit trail. AI assistants can create monitors through conversation on every plan, including Free. Standard at $80/year is enough to cover 100 pages across your primary regulatory bodies if your program is smaller.

### Getting Started

Set up EAA monitoring in three steps:

1. **Add your own accessibility statement first.** It is the document an inspector reads first and the one most likely to drift out of date. Turn screenshots on so every version is captured with a timestamped image.
2. **Add the standards and the member-state guidance pages for the countries you serve.** Tag them `source:standard` and `source:regulator`, and route them to a daily or weekly digest.
3. **Set workspace instructions describing your service and claimed conformance level** so every change summary speaks to your specific obligations.

Run it on the free tier for a couple of weeks against your statement, the WCAG baseline, and one regulator page. Once you see the value, expand to peer benchmarks and every member state you operate in. The monitoring is not a project. It is a piece of infrastructure your accessibility program runs on.

For related guides, see [regulatory compliance monitoring](/blog/regulatory-compliance-monitoring), [monitoring privacy policy and terms of service changes](/blog/monitoring-privacy-policy-terms-of-service-changes), [GDPR and CCPA change tracking](/blog/gdpr-ccpa-privacy-law-change-tracking), [DORA compliance monitoring](/blog/dora-compliance-monitoring), and [EU AI Act regulation monitoring](/blog/ai-regulation-monitoring-eu-ai-act).

---

Need more? The complete PageCrawl.io help center, with every article, is available as a single document at https://pagecrawl.io/llms-full.txt. Read it for context on anything this page does not cover.
