The core EAA compliance deadline, June 28, 2025, has already come and gone. If your business sells covered products or services to EU consumers and hasn’t addressed accessibility yet, you’re not early, you’re already behind, though two later transition dates (2027 and 2030) still give some breathing room depending on your situation.
The deadline that already passed
June 28, 2025 is the date European Accessibility Act enforcement began for new products and services placed on the market after that point. This wasn’t a soft launch or a warning period. Member states had already transposed the directive into national law well before this date, and enforcement bodies in several countries were active from day one. Any e-commerce site, banking service, e-book platform or consumer electronics product newly brought to market after June 2025 needed to already meet EAA requirements.
For businesses that treated the run-up to June 2025 as a distant compliance project rather than an active deadline, the practical consequence now is that any gap in accessibility on a new offering is already a live compliance issue, not a future risk to plan around. That distinction matters for how urgently a business should be treating remediation work today: this is current-state exposure, not forward planning.
The two dates that still matter
Two transition deadlines remain relevant depending on your situation. Service contracts that were already signed and in place before June 28, 2025 have until June 28, 2027 to bring those services into compliance. Separately, certain self-service terminals (think ATMs and ticketing machines) that were already lawfully in use before the 2025 date get until June 28, 2030 under a transitional provision.
In practice this means a lot of businesses are operating under a false sense of runway. If you launched a new EU-facing service last month, the 2027 date doesn’t apply to you, only the 2025 one does, and it’s already in the past.
Who actually has to comply
The EAA applies based on where your customers are, not where your company is registered. A company headquartered in the United States or elsewhere still falls under the EAA if it sells covered products or services to consumers in the EU. Covered categories include computers and operating systems, e-commerce, banking services, e-books, audiovisual media services, transport information systems, and consumer terminals like ATMs and ticketing kiosks.
There’s a narrower exemption for microenterprises (fewer than 10 employees and under 2 million euros in annual turnover), but it applies specifically to service requirements and doesn’t blanket-exempt a small company from every obligation. A microenterprise that sells hardware products rather than services, for example, can still fall under product-side requirements even where the service exemption would otherwise apply, which is a distinction a lot of small businesses miss when they read a summary of the exemption rather than the actual text.
The products and services most businesses overlook
When people think “EAA,” e-commerce is usually the first thing that comes to mind, and it is squarely covered. But the directive’s reach is broader than most business owners realize. Banking and financial services fall under it, including consumer banking websites and apps, ATMs, and payment terminals. E-readers and the e-books sold through them are covered, along with the platforms that distribute them. Audiovisual media services, think streaming platforms and their associated apps and interfaces, fall under it too. Transport services have to provide accessible travel information, including real-time information at stations and through apps. And telecommunications services and the equipment used to access them are covered as well. A business that only checked whether its main storefront was accessible, while leaving a separate booking portal, a banking integration, or a document library unaddressed, may have a narrower view of its own exposure than the law actually requires.
What non-compliance actually costs
Enforcement and penalties are set at the member state level rather than centrally, so the numbers vary by country. Reported maximum fines range from roughly €60,000 to around €900,000 depending on the jurisdiction, and some countries add daily penalties for continued non-compliance on top of that. Beyond direct fines, authorities can order product withdrawal or a full market ban, which is a more disruptive outcome for most businesses than the fine itself.
What compliance is actually measured against
The EAA doesn’t invent its own technical standard. The harmonized standard, EN 301 549, fully incorporates WCAG 2.1 Level AA, and conforming to EN 301 549 creates a presumption of EAA compliance. That’s a useful anchor point: if you’re not sure where to start, a WCAG 2.1 AA audit against your actual site or product is the practical starting point, not a separate EAA-specific checklist.
How far behind the average site still is
Broader research gives a sense of the gap most businesses are working from. The 2026 WebAIM Million report found 95.9% of home pages had at least one detectable WCAG 2 failure, averaging 56.1 errors per page. That’s not an EU-only figure, but it’s a fair proxy for how much remediation work is typically outstanding even on sites that assume they’re mostly fine.
Wawsome’s own scan of Romanian company websites, conducted a year after the EAA took effect, found that 9 in 10 still failed basic accessibility checks, a sobering data point given the deadline had already passed by the time that scan was run.
What to do if you haven’t started
Start with an audit against WCAG 2.1 AA and EN 301 549 rather than assuming a quick widget install closes the gap on its own. Tools built specifically around EU compliance, such as Wawsome (which pairs a widget with continuous monitoring and a human-reviewed checker mapped to EAA and EN 301 549) or EqualWeb (which offers a widget alongside a separate manual remediation service), can help close both the quick-fix and the deeper structural gaps, but neither replaces an honest assessment of where your site currently stands.
A realistic timeline for catching up
If your business missed the June 2025 date, the priority is closing the gap quickly rather than treating this as a project with no urgency, since enforcement is already live rather than pending. A workable sequence looks like: get a WCAG 2.1 AA and EN 301 549 audit scoped and started within weeks, not months; triage the findings by severity and fix the highest-impact, highest-risk issues first, things like unlabeled forms on core conversion flows or completely inaccessible checkout processes; and put some form of ongoing monitoring in place so new content doesn’t quietly reintroduce issues you just fixed. Businesses that treat this as a one-time project rather than an ongoing practice tend to drift back out of compliance within a year or two as their site changes, which defeats the purpose of doing the work in the first place.
Documenting your compliance effort
Beyond the technical fixes, it’s worth keeping a written record of what you’ve assessed, what you’ve fixed, and when, particularly for larger organizations. If a regulator or a customer ever asks about your accessibility posture, being able to point to a documented audit, a remediation timeline, and an accessibility statement is a meaningfully stronger position than having done the work informally with no paper trail. If you’re weighing whether a widget alone is enough or whether you need a deeper audit first, our guide comparing widgets to manual audits walks through when each approach genuinely fits, and our EN 301 549 guide covers the technical standard itself in more depth.