İçeriğe atla
Erişilebilirlik

How to Write an Accessibility Statement: What EU and US Rules Actually Require in 2026

An accessibility statement is a dated, public declaration of conformance status, not a marketing page. This guide separates the EU public sector model form, the EAA service information duty and US procurement practice, then gives you the nine elements and three wording patterns to work from.

11 minutes read 13 read Updated:

Short answer: An accessibility statement is a dated, public declaration that names the standard you tested against, states your conformance status honestly, lists known limitations with accessible alternatives, and gives people a working route to report barriers. Three regimes use the term differently: EU public sector bodies publish one in the model form set by Commission Implementing Decision (EU) 2018/1523, private companies in scope of the European Accessibility Act owe service information under Article 13 and Annex V, and the United States has no federal publication mandate but procurement routinely asks for an Accessibility Conformance Report instead. In every regime the safest document says partially conformant with dates and a plan, not fully conformant.

This article is for general information only and is not legal advice. Obligations, enforcement routes and sanctions differ by country, so confirm your own position with qualified counsel in the markets you serve.

Table of contents

The three things people call an accessibility statement

Search for a template and you will find three incompatible documents wearing the same name. Picking the wrong one is the most common reason a statement fails to do its job.

The EU public sector statement is a regulated form. Directive (EU) 2016/2102 requires public sector bodies to publish a detailed accessibility statement for each website and mobile application, and Commission Implementing Decision (EU) 2018/1523 fixes the model those statements follow. The structure is not optional and the headings are largely prescribed.

EAA service information is a private sector obligation with a different shape. Directive (EU) 2019/882 does not order companies to publish a page titled "Accessibility Statement". It requires service providers to prepare information explaining how the service meets the accessibility requirements and to make it publicly available. Most companies satisfy this with a statement page, but the content requirement comes from Annex V, not from the public sector model.

The voluntary statement plus a conformance report is the US and enterprise procurement pattern. Nothing in federal law tells a private company to publish a statement. What buyers ask for is an Accessibility Conformance Report, a criterion-by-criterion technical document usually produced with the ITI VPAT template. The prose statement and the ACR are complementary, not interchangeable.

If you sell into more than one of these markets, write one honest assessment and render it three ways rather than maintaining three unrelated claims.

EU public sector: the model statement, element by element

Commission Implementing Decision (EU) 2018/1523 sets out a model with mandatory content and an optional layer. This is the part most often misquoted, so here it is as the Annex organises it.

Section Status What the model requires
Opening declaration Mandatory Names the public sector body, states its commitment to accessibility, and identifies the website or mobile application covered, under the national law transposing Directive (EU) 2016/2102.
Compliance status Mandatory One of three positions, fully compliant, partially compliant or not compliant with the referenced standard, with the model's explanatory sentence for the position chosen.
Non-accessible content Mandatory Given under three named sub-cases, each used where it applies: (a) non-compliance with the legislation, (b) disproportionate burden, (c) content outside the scope of the applicable legislation.
Preparation of this statement Mandatory The date prepared, the method used to assess conformance (for example self-assessment or third-party evaluation), and the date of the last review.
Feedback and contact information Mandatory A mechanism to notify the body of non-compliance and to request information excluded from scope, plus contact details of the entity responsible for responding.
Enforcement procedure Mandatory A description of and link to the national enforcement procedure to use when a response is unsatisfactory or absent.
Optional layer Optional A commitment explanation, including any intention to exceed the legal minimum and a remediation timeframe; formal approval of the statement; the publication date and the last substantial-revision date of the website or application; a link to an evaluation report; any additional telephone assistance and assistive technology support; and other content deemed appropriate.

Two practical notes. The statement must itself be accessible and easy to find, typically linked from every page footer, which sounds obvious and is routinely missed. And the three sub-cases under non-accessible content are not decoration: an auditor reads them to see whether you have distinguished a defect you must fix from content the law does not reach.

EU private sector: what the EAA actually asks for

Under Article 13 of Directive (EU) 2019/882, service providers in scope must prepare the information described in Annex V and explain how their services meet the applicable accessibility requirements. Annex V asks for an assessment, set out in the general terms and conditions or an equivalent document, covering a general description of the service in accessible formats, the descriptions and explanations needed to understand how the service operates, and a description of how the relevant accessibility requirements in Annex I are met. Point 3 of Annex V additionally asks for information demonstrating that the service delivery process and its monitoring keep the service compliant, which makes this a maintenance duty as much as a drafting one.

Article 13(2) requires the information to be kept available for as long as the service is offered, and to be made available to the public in written and oral format, including in a manner accessible to persons with disabilities. That has a practical consequence: the statement page must survive a screen reader, keyboard navigation and 200 percent zoom, and a spoken route to the same information has to exist. A statement locked inside a scanned PDF fails its own subject matter.

Note what Annex V does not say. It does not prescribe headings, a compliance percentage or a review cadence. Those come from good practice and from the public sector model, which is why so many private companies borrow that structure: it is the format a regulator or a procurement reviewer will recognise.

Enforcement is where teams tend to over-read a single European procedure into the text. There is no single European procedure. The EAA is a directive, so the supervisory authority, the complaint route and any sanction are set nationally by each member state, and you are exposed separately in each market you serve. For scope, exemptions and the remediation programme itself, see our EAA compliance checklist and the European Accessibility Act guide; this article stays on the document.

United States: no statement mandate, two real pressures

No US federal law requires a private company to publish an accessibility statement, and publishing one neither creates nor removes liability by itself. Two pressures still shape what US-facing teams write.

Public sector web content has a named technical standard. The Department of Justice published its ADA Title II rule in the Federal Register on 24 April 2024, adopting WCAG 2.1 Level AA for the web content and mobile applications of state and local government entities. An interim final rule published on 20 April 2026, with a 60-day comment period that closed on 19 June 2026, extended the compliance dates: entities with a total population of 50,000 or more comply from 26 April 2027, and entities under 50,000 together with special district governments from 26 April 2028. The rule sets a conformance standard, not a statement obligation, but covered entities publish statements anyway, because a named standard invites the question of where you stand against it.

Procurement asks for a report, not prose. Federal agencies buy under Section 508, whose standards incorporate WCAG by reference, and they ask vendors for an Accessibility Conformance Report. Large private buyers copied the habit. An ACR walks the success criteria one by one and records Supports, Partially Supports, Does Not Support or Not Applicable, with remarks. A well-written statement will not pass that gate, and an ACR is too dense to serve as the public page. Publish the statement, keep the ACR ready for the questionnaire.

Turkey: a short note for international readers

If your estate includes Turkish-facing properties, Presidential Circular 2025/10 (Official Gazette, 21 June 2025, issue 32933) made digital accessibility binding for a defined set of sectors, referencing WCAG 2.2 Level A together with the Ministry's control list of 31 criteria and 126 questions. The first wave of obligations took effect on 21 June 2026 and has been in force since then. E-commerce providers have until 21 June 2027. The sector list and the checklist structure are covered in our guide to Circular 2025/10. For the statement itself, the difference is the referenced standard and the escalation contact, not the document's shape.

The nine elements a defensible statement contains

Strip the regimes back and the same nine elements appear. A statement missing any of them is either unverifiable or unusable.

# Element What it answers Most common failure
1 Scope Which domains, subdomains, apps and document types the assessment covers "Our website", so nobody knows whether the booking subdomain is included
2 Standard and level WCAG 2.1 or 2.2, Level A or AA, and any European or national standard such as EN 301 549 (adopted nationally, for example as TS EN 301 549 in Turkey) Naming "WCAG" with no version and no level
3 Conformance status Fully, partially or non-conformant against that standard A vague "we strive to be accessible" that states nothing
4 Known non-conformances The specific content and functions that fail today An empty list next to a partial status, which reads as untested
5 Reasons and alternatives Why each gap exists and how an affected user gets the same outcome another way Barriers listed with no alternative route offered
6 Assessment method and author Self-assessment, third-party evaluation or both, and by whom Omitting that it was automated only, which overstates coverage
7 Assessment and review dates When it was assessed and when it was last reviewed An undated page, which an auditor treats as no evidence
8 Feedback channel A monitored address or form, with a stated response time A generic info@ mailbox nobody owns
9 Escalation path Where to go if your response is unsatisfactory or absent Silence, which in the EU public sector model is a compliance defect

Element 5 carries more weight than its length suggests. A statement that says "our historical PDF archive is not fully tagged, and you can request an accessible version at this address within five working days" describes a working service. The same gap with no alternative describes an unresolved exclusion.

Why "fully compliant" is the riskiest sentence in the document

Claiming full conformance converts every future defect into a contradiction of your own published statement. WCAG has criteria that automated tools cannot judge, sites change weekly, and third-party embeds arrive with their own barriers. A public claim of full conformance is a claim about a moving target, made in writing, with a date on it.

There is a documented market signal here. In 2025 the US Federal Trade Commission finalised an order requiring accessibility overlay vendor accessiBe to pay USD 1 million over allegations that it misrepresented its product's ability to make any website WCAG compliant, and the order bars such representations absent supporting evidence. That case concerns the claims of one company and says nothing about any other vendor. What it does establish is that accessibility claims are treated as ordinary advertising claims, subject to the ordinary substantiation rule. An unsupported conformance claim published on your own site can be read the same way, depending on how and to whom it is presented. If you are weighing an overlay as part of your answer, our overlay versus scanner comparison sets out what each approach can and cannot fix.

The counterintuitive part is that partial conformance reads better to the people who matter. A regulator handling a complaint wants to know whether you knew about the barrier and what you were doing about it. A procurement reviewer trusts the report showing Partially Supports with remarks over the one whose every row says Supports.

Three wording patterns you can adapt

These are drafting starting points, not approved or official templates. Adapt them to your facts and have counsel review the result before you publish, particularly if you are a public sector body bound to the model form.

Pattern A, fully conformant. Use only when an independent evaluation covering the stated scope found no outstanding non-conformances.

This website is fully conformant with WCAG 2.2 Level AA. Full conformance means that the content covered by the scope above satisfies all applicable success criteria without exceptions. The assessment was carried out by [evaluator] on [date] using automated testing, manual expert review and assistive technology testing.

Pattern B, partially conformant with a remediation date. The right pattern for most organisations most of the time.

This website is partially conformant with WCAG 2.2 Level AA. Partially conformant means that some parts of the content do not fully conform to the standard. The known non-conformances are listed below, with the reason for each and the accessible alternative available today. We expect the [named group] to be resolved by [date]. This statement was prepared on [date] and last reviewed on [date].

Pattern C, non-conformant with an active plan. Use it when you are early in the work. It is uncomfortable to publish and far more defensible than silence.

This website is not yet conformant with WCAG 2.2 Level AA. An assessment carried out on [date] identified [number] issues, of which [number] are critical or serious. A remediation programme began on [date] and is prioritised by user impact; the first milestone covers [named journeys] and is scheduled for [date]. Until then, you can reach the following services through these alternative channels: [list].

Whichever pattern you start from, resist adjectives. "Substantially accessible" and "committed to full accessibility" are not conformance states, and a reader looking for a status will read them as evasion.

Keeping the statement current

The failure mode auditors see most often is not a badly written statement. It is a well-written statement dated three years ago, describing a site that has since been redesigned. A stale statement is worse than none, because it documents that you stopped looking.

Cadence and versioning. Re-assess at least annually and whenever a significant change ships: a redesign, a new checkout flow, a migration to a different CMS. Record the assessment date and the last review date separately, because they answer different questions, and keep previous versions retrievable. When a complaint arrives about a barrier you fixed eight months ago, the archived statement showing the barrier declared and the fix dated is your evidence.

Feedback that lands in the backlog. The address in element 8 must terminate in your defect tracker, not in a shared mailbox. Every report should become a ticket with a severity and an owner, and the response time you published should be a service level someone is measured against. A published escalation path that nobody staffs converts a user's complaint into a regulator's complaint. When a listed non-conformance is fixed, remove it and move the review date; a known-issues list that never changes tells the reader that the plan is fictional.

Producing and maintaining one with cerez.io

Drafting the document and engineering the conformance are different jobs, and it is worth being blunt about which one tooling does.

The free public version of cerez.io's accessibility statement generator runs a lightweight static check of one URL and drafts six sections: scope, conformance status, a flat list of the detected issues, the preparation date, a feedback contact, and the enforcement route with the legal basis. It outputs in Turkish or English, is rate limited per IP, and shows only the first few findings to anonymous visitors, so treat it as a starting draft rather than an assessment.

Inside the product, the generator works from the WCAG scan attached to your domain. It splits non-accessible content into the three sub-cases, records both the preparation and the last review dates, writes the number of pages scanned, the scan date and the conformance score into the preparation section, produces the document in Turkish, English and German, publishes it at a hosted URL your widget can link to, and exports an ACR for procurement. One deliberate constraint: if the latest scan still has open violations, the generator will not let the document claim full conformance.

The boundaries matter as much as the features. The scanner performs static HTML analysis across multiple pages, with per-plan page limits. It does check contrast where the colours are set in inline styles, but contrast defined in external stylesheets, visible focus at runtime and target size measured in the DOM are outside what it can judge today, and manual expert testing remains necessary for the judgment-dependent criteria in any case. The generator drafts and dates the document from scan evidence; it does not deliver legal compliance and does not certify conformance. Your team engineers the conformance, and your counsel signs off on the wording. Details of the widget and scanner sit on the accessibility product page.

Frequently Asked Questions

Is an accessibility statement legally required for a private company website?

Short answer: Not as a page with that title in most jurisdictions. EU public sector bodies must publish one under Directive (EU) 2016/2102. Private service providers in scope of the European Accessibility Act must prepare and make available information explaining how the service meets the accessibility requirements, which a statement page satisfies in practice. In the United States there is no federal publication mandate for private companies, though buyers frequently ask for conformance documentation.

What is the difference between the EU public sector accessibility statement and the information the EAA requires from service providers?

Short answer: The public sector statement follows a prescribed model form set by Commission Implementing Decision (EU) 2018/1523, with fixed sections for compliance status, non-accessible content, preparation, feedback and enforcement. The EAA asks service providers, under Article 13 and Annex V, for an assessment of how the service meets the accessibility requirements, without prescribing headings, and requires that information to be public in written and oral format. Many private companies borrow the public sector structure because it is the format regulators and buyers recognise.

Can I say my website is fully WCAG compliant in the statement?

Short answer: Only if an evaluation covering your stated scope found no outstanding non-conformances, and you can produce that evidence on request. Automated testing alone cannot support the claim, because a substantial share of WCAG success criteria require human judgment. Conformance claims are advertising claims: the FTC's 2025 order against accessiBe over unsupported WCAG compliance representations is the documented signal on that point.

How often should an accessibility statement be updated?

Short answer: At least once a year and whenever something significant changes, such as a redesign, a new transactional flow or a platform migration. Record the assessment date and the last review date separately, keep older versions retrievable as evidence, and remove non-conformances from the list as they are fixed. A statement that has not moved in years reads as abandoned.

Do I need an accessibility statement and a VPAT, or does one replace the other?

Short answer: They serve different readers and neither replaces the other. The statement is a public, plain-language page for users and regulators covering status, known barriers, alternatives and how to complain. A VPAT-based Accessibility Conformance Report is a criterion-by-criterion technical document for procurement, recording Supports, Partially Supports, Does Not Support or Not Applicable with remarks. If you sell to public agencies or large enterprises, expect to maintain both from the same underlying assessment.

Sources


A statement is only as good as the assessment behind it, so start with the measurement: a dated scan gives you the conformance status, the known-issues list and the evidence line your document needs. Start free with a WCAG scan and a generated accessibility statement, or compare plans and pricing. This article is for information purposes and is not legal advice.

Author
cerez.io

cerez.io içerik ekibi; KVKK, GDPR, WCAG 2.2 ve EAA uyumluluk uzmanı. Balıkesir merkezli Türkiye'nin uyumluluk platformu.

Turkey's Compliance Platform

Achieve the compliance in this article right away

cerez.io with in 5 minutes Become KVKK, GDPR, WCAG 2.2 and EAA compliant. 14-day Pro trial, no credit card required.

No credit card · Data hosted in Turkey · Turkish-language support · KVKK assurance

⚡ LEGAL OBLIGATION Presidential Circular 2025/10: For public institutions, municipalities, banks, universities, hospitals and schools, the WCAG 2.2 A obligation is now in force (the deadline passed on 21 June 2026) · E-commerce deadline: 21 June 2027