On 2 September 2026 ETSI published EN 301 549 V4.1.1, the version of Europe's ICT accessibility standard that moves the referenced baseline from WCAG 2.1 to WCAG 2.2. WCAG 2.2 adds nine success criteria, six of them at Level A or AA, and all six land inside a checkout or booking flow rather than on a marketing page. Turkey got there first in one respect: Presidential Circular 2025/10, published on 21 June 2025, already names WCAG 2.2 and gives e-commerce providers under Law No. 6563 two years to comply.
This guide is for whoever owns a checkout or booking funnel for consumers in the EU, in Turkey, or both. By the end you will be able to run a six-check pass on your own flow in about an hour, score what you find, and fix it in an order that protects revenue first.
What changed on 2 September 2026
V4.1.1 was adopted on 24 August 2026 and published on 2 September. It was prepared under Commission Implementing Decision C(2022) 6456 final, the standardisation request M/587, in support of Directive (EU) 2019/882 (the European Accessibility Act) and Directive (EU) 2016/2102. Clauses 9, 10 and 11 were realigned to WCAG 2.2. Announcement is due 30 November 2026, endorsement 31 May 2027, and withdrawal of conflicting national standards 31 May 2028.
The correction: you do not have presumption of conformity
Vendor sites repeat that meeting EN 301 549 makes you presumed compliant with the Accessibility Act. Article 15(1) grants presumption only to standards "the references of which have been published in the Official Journal of the European Union" in support of that directive. EN 301 549 is cited in the Official Journal under the Web Accessibility Directive, through Commission Implementing Decision (EU) 2018/2048. We could find no citation in support of Directive (EU) 2019/882, and V4.1.1's own Annex ZB is written in the conditional: presumption applies "once the present document is cited in the Official Journal."
So the standard is your evidence, not your shield. You conform to the functional requirements in Annex I, use EN 301 549 as the technical means, and document that reasoning yourself under Article 13(2).
Does this apply to you?
- Is your service in Article 2(2)? The list covers e-commerce services, elements of air, bus, rail and waterborne passenger transport such as websites, apps, electronic ticketing and travel information, consumer banking, and e-books. Article 3 defines an e-commerce service as one provided at a distance, by electronic means, at the individual request of a consumer, with a view to concluding a consumer contract.
- Are you selling to consumers in the Union? Establishment outside the EU does not take you out. Article 3 defines a service provider as a person "who provides a service on the Union market or makes offers to provide such a service to consumers in the Union." A Turkish retailer shipping to Germany and a Turkish carrier selling seats to EU consumers are both inside.
- Are you a microenterprise? Article 4(5) exempts microenterprise service providers: fewer than 10 employees and either turnover or a balance sheet total of no more than EUR 2 million.
Obligations bite for services provided to consumers after 28 June 2025. Article 32 gives a transition only for contracts agreed before that date and products already lawfully in use, running to 28 June 2030, and up to 20 years of economic life for self-service terminals. In Turkey, Circular 2025/10 set one year for banks, private hospitals, carriers and large telecom operators, now passed, and two years for e-commerce under Law No. 6563. Both regimes point at the same guidelines at different levels, so build once to WCAG 2.2 AA and the Turkish Level A obligation falls out of it. The reverse does not work.
The six criteria that break checkout
These are the WCAG 2.2 additions at Level A and AA. The three AAA additions, 2.4.12, 2.4.13 and 3.3.9, sit outside an AA programme. One deletion matters too: 4.1.1 Parsing is obsolete and removed, so old findings against it can be closed rather than fixed.
| Criterion | Level | What it breaks in checkout | Test in 60 seconds |
|---|---|---|---|
| 3.3.8 Accessible Authentication (Minimum) | AA | Login steps that block clipboard paste, or make the user transcribe an OTP or solve a puzzle with no alternative | Paste a password and an OTP from the clipboard. Blocked paste is a fail. |
| 2.5.8 Target Size (Minimum) | AA | Quantity steppers, remove-item icons, coupon close buttons, small delivery-slot radio cards | At 375px, measure the smallest target. Under 24 by 24 CSS pixels without sufficient spacing is a fail. |
| 2.4.11 Focus Not Obscured (Minimum) | AA | Sticky order summary bars, consent banners and chat launchers covering the focused field | Tab through the form. A completely hidden focused control is a fail. |
| 2.5.7 Dragging Movements | AA | Address map pins, drag carousels, slider date pickers, slide-to-confirm buttons | Complete each drag using single taps only. No path available is a fail. |
| 3.3.7 Redundant Entry | A | Re-typing the billing address after shipping, or the email at payment | Fill the flow once and count values you type twice that the system already had. |
| 3.2.6 Consistent Help | A | Help, chat or contact links placed differently on cart, shipping and payment | Screenshot each step. Help must sit in the same relative order everywhere it exists. |
The playbook
This is the pass we run. It is manual, because five of the six are not reliably detected by automated scanners.
1. Freeze one route. Guest checkout, one item, standard delivery, card payment, across cart, shipping address, delivery method, payment and confirmation. Run it twice: a 375px mobile viewport with touch, then desktop with the mouse unplugged.
2. Keyboard pass. Tab from the top of each step to the submit button. Watch for 2.4.11 failures at the moment a sticky element appears, usually when the summary bar pins itself. Note where help sits on each step for 3.2.6.
3. Pointer pass. On mobile, measure targets for 2.5.8 and attempt every drag without dragging for 2.5.7. Address maps and carousels are the usual failures.
4. Data entry pass. Complete the flow as a first-time customer. Every field you fill with a value the system already holds is a 3.3.7 finding. Then try authenticating with a password manager and clipboard paste for 3.3.8.
5. Score before you fix. Rank each finding as severity multiplied by that step's share of funnel exits in your own analytics.
| Severity | Definition | Score |
|---|---|---|
| Blocking | The user cannot complete the purchase at all | 3 |
| Degrading | Completion needs a workaround or repeated attempts | 2 |
| Friction | Extra effort, little abandonment risk | 1 |
6. Fix in this order. Authentication first, because 3.3.8 can stop a purchase outright. Then target size, focus obscuring, dragging alternatives, redundant entry, consistent help. That is the order of revenue exposure, not legal severity, and the one a sponsor will fund without argument.
7. Write the statement. Article 13(2) requires information under Annex V explaining how the service meets the requirements, public in written and oral format and in an accessible manner. If you invoke disproportionate burden under Article 14, document it against the Annex VI criteria and renew it at least every five years. An undocumented decision not to fix something is not a burden claim, it is an unremediated defect.
8. Put the six checks into release QA. Checkouts regress on 2.4.11 the first time someone ships a promotional banner.
Where this breaks down
- Six checks are not conformance. This is a delta pass on top of WCAG 2.1 AA, and if you never reached 2.1 AA it will hide the real problem.
- It is not a screen reader audit. A keyboard pass finds focus and order problems, not a mislabelled payment field.
- Your payment iframe may not be yours. If the card form belongs to your PSP, ask them for their EN 301 549 clause 9 position in writing.
- Native apps map differently. Clause 11 covers software, where target size and dragging behave differently under platform accessibility APIs.
- Overlays fix none of these. Each of the six is a property of your flow's structure or authentication design, which an injected script cannot restructure.
- Enforcement is national. Article 30 requires penalties to be effective, proportionate and dissuasive, but levels and surveillance practice are set per Member State.
FAQ
Does EN 301 549 V4.1.1 bind me today?
Not on its own. The Act binds you; the standard describes a technical route to it. National adoption runs to 31 May 2027 and withdrawal of conflicting standards to 31 May 2028. Its content is the best available reading of the Annex I requirements, so build against it now.
If we meet EN 301 549, are we EAA compliant?
You are in a strong evidential position but you do not have legal presumption of conformity. Article 15(1) requires the reference to be published in the Official Journal in support of Directive (EU) 2019/882, and we found no such citation. Document your own reasoning under Article 13(2).
We are a Turkish company with no EU establishment. Are we in scope?
If you offer your service to consumers in the Union, yes. Article 3 ties the obligation to offering a service to consumers in the Union, not to where you are registered. Circular 2025/10 may apply separately for the Turkish market.
Does the 2030 date mean we have until 2030?
No. The Article 32 transition covers contracts agreed before 28 June 2025 and products already lawfully in use. New services provided to consumers after that date were in scope from that date.
Should we still fix old 4.1.1 Parsing findings?
No. 4.1.1 is obsolete and removed in WCAG 2.2. Close those findings, but check the underlying markup was not also causing a name, role or value failure under 4.1.2, which is still current.
What if a fix really is too expensive?
Article 14 allows a disproportionate burden argument, but only as a documented assessment against the Annex VI criteria, renewed at least every five years. A market surveillance authority will ask to see it.
Run the pass
Run these six checks on your checkout this week, or send us the URL and we will run the audit and hand back the scored findings. Our scanner at wcag.switas.com covers the automated portion against WCAG 2.0, 2.1 and 2.2, and gives you the baseline the manual pass sits on.
Sources
- ETSI EN 301 549 V4.1.1 (2026-09)
- ETSI EN 301 549 version index
- Directive (EU) 2019/882, European Accessibility Act
- Standardisation request M/587
- Commission Implementing Decision (EU) 2018/2048
- WCAG 2.2, W3C Recommendation
- What's New in WCAG 2.2, W3C WAI
- WCAG 2.2 becomes a W3C Recommendation, 5 October 2023
- Presidential Circular 2025/10 (Turkey), 21 June 2025
- Legalithm on the missing Official Journal citation






