People search for "the accessibility standard" as if there were one. There are three layers, they sit on top of each other, and only the top one can fine you.

The three layers

WCAG is written by the W3C. It is not a law and nobody enforces it. It is the technical document the European standard is built on: numbered success criteria at levels A, AA and AAA. The current published version is WCAG 2.2. EN 301 549 V3.2.1 takes its web requirements from WCAG 2.1, and level AA is the level that matters.

EN 301 549 is the European standard, published by ETSI together with CEN and CENELEC. Its clause 9 covers web content and adopts WCAG 2.1 level AA, criterion for criterion. The rest of the document covers software, documents and hardware, which WCAG does not.

National law is the layer that carries penalties. The European Accessibility Act, Directive (EU) 2019/882, was transposed by each member state into its own act, and its obligations have applied since 28 June 2025. In Czechia that act is zákon č. 424/2023 Sb., in Germany the BFSG, in Poland ustawa z 26 kwietnia 2024 r., in Austria the BaFG and in Slovakia zákon č. 351/2022 Z. z. Public sector bodies were already covered by an earlier directive, 2016/2102.

So the honest answer to "which standard applies to me" is: your national act applies, and it states the requirements in general terms. EN 301 549 is the technical standard used in practice to test them, and its clause 9 is WCAG 2.1 level AA. You test against WCAG and you are judged under the act. Meeting the standard does not by itself establish that you comply with the act.

What "accessibility code" means in practice

The phrase covers the part of the standard a developer actually types. Four things carry most of it.

Semantic HTML. A button that is a button, a heading that is a heading, a list that is a list. A div with a click handler is invisible to assistive technology unless it is given a role, a name and keyboard handling by hand, and that hand-written version is what breaks.

Name, role, value. Every control has to announce what it is and what state it is in. This is criterion 4.1.2, and it is where custom components fail: a toggle that looks pressed and never says so.

Focus order and visible focus. The Tab route through the page has to make sense and has to be visible. Criteria 2.4.3 and 2.4.7.

Text alternatives and contrast. Images carry an alt attribute that says what the image does, not what it shows. Text and background meet the contrast ratio. You can check a pair in our WCAG contrast checker.

None of this is exotic. It is ordinary front-end work that was skipped.

What WAVE and axe can tell you, and what they cannot

WAVE, from WebAIM, and axe, the rule engine from Deque that sits inside many checkers including ours, do the same kind of job: they read the page and apply rules to what they find. A missing form label, an image with no alternative text, a contrast pair that fails: these are states in the markup, and a rule engine finds them reliably, on every page, in seconds.

What a rule engine cannot do is press a key or judge meaning. Whether your alt text is accurate, whether the heading structure matches the page, whether focus escapes your cookie banner: none of those is a property of the markup at rest. We wrote about that at length in why an automated scan cannot find a keyboard trap.

This is why "we ran WAVE and it was clean" is not the same as conformity, and also why running a scanner is still the right first step. It finds the failures that are cheap to find, so your manual effort goes where it is needed.

What to do with this

  1. Find out whether a national act covers you, and which one. The act lists the products and services in scope, and micro-enterprises providing services are exempt. Which act it is follows from where you sell, not from where you are hosted.
  2. Test against WCAG 2.1 level AA. That is what clause 9 of EN 301 549 V3.2.1 contains, and it is the technical reference used in practice.
  3. Scan first, then walk the site with a keyboard. The scan catches the rule failures, the walk catches the behaviour.
  4. Write the accessibility statement. Writing it forces you to say what you actually know.

A scan of your homepage shows which of the rule-based failures above you already have. The keyboard walk covers the rest.

See where your site stands

A free scan checks a page against the automated WCAG 2.1 AA rules and shows the first findings.

Scan your site free Download a sample report

This article is informational and does not constitute legal advice.