The client from my last article had a follow-up question.
Once she believed the warning was real, she wanted to know what she was actually supposed to do about it. “Okay, so what do I actually need?”
I want to answer that here the way I answered it for her, that’s more useful than the version that would make a better headline.
What actually changed, and what it doesn’t mean for you
In April 2024, the Department of Justice finalized a rule under Title II of the Americans with Disabilities Act. It requires state and local government websites and mobile apps to meet a specific technical standard: WCAG 2.1, Level AA.
That is significant. It is the first time a federal rule has named a specific accessibility standard for the web and attached deadlines to it.
That rule applies to government entities. It does not make WCAG compliance the law for a private businesses.
(If you want a sense of how heavy a lift this is even for well-resourced organizations: in April 2026 the DOJ pushed both compliance deadlines back a year, to April 2027 for larger entities and April 2028 for smaller ones. Among the reasons it gave were staffing, cost, and the fact that automated tools, generative AI included, have not delivered the remediation shortcut everyone hoped for. Worth remembering the next time something promises to fix your site automatically.)
So if the rule does not apply to your business, why does any of this matter?
Because of the lawsuits. When someone sues a private business over an inaccessible website, the ADA itself does not spell out technical requirements for websites. So courts, plaintiffs, and settlement agreements reach for the standard that does exist. That standard is WCAG 2.1 AA. It has become the reference point by default, whether or not a statute names your business.
What WCAG 2.1 AA asks for
The name sounds like a technical document you would need a specialist to interpret. Most of it is not.
- Alt text on images that carry meaning, so a screen reader can describe them.
- Labels attached to form fields, so “First name” is programmatically tied to the box you type in.
- Color contrast that clears a measurable threshold. Light gray text on white is the single most common failure I see.
- Heading structure that describes the page, H1 down through H2 and H3 in order, instead of headings picked because they looked the right size.
- Keyboard navigation that reaches every link, button, and field in a logical order, with a visible focus indicator.
- Captions on video.
- Screen reader compatibility, which is mostly the sum of everything above rather than a separate task.
When I audited my client’s site, there were some failures, but not overly significant. Thankfully, Cepora Digital built the site according to current web standards and that reduced the accessibility compliance gap.
By the way, there is no certificate
There isn’t one. No official certification or badge exists for ADA web compliance.
What counts is evidence, and it comes in four parts:
- Code that meets the criteria.
- A published accessibility statement on your site, saying what standard you are working toward, how far along you are, and how someone can reach you if they hit a barrier.
- Documented audits, automated and manual. Automated tools catch a useful fraction of issues, nowhere near all of them. The rest needs a person with a keyboard and a screen reader.
- A record of good-faith effort over time. Dates, findings, what you fixed and when.
That fourth one is worth more than it sounds. A business that can produce a dated audit, a remediation log, and a public statement is in a materially different position from one that can produce nothing.
Which also means there is no finish line. Accessibility is a maintenance item, like backups and updates. Every new page can reintroduce something you already fixed.
What I told her we would do
Four steps, in this order:
- Run the audit first. You cannot scope work you have not measured, and the results are almost always less frightening than the imagination.
- Publish an accessibility statement. It is the fastest visible step, it is honest about being in progress, and it gives a frustrated visitor a way to reach you instead of a lawyer.
- Fix in priority order. Anything blocking a core task comes first: contact forms, booking, checkout, navigation. A decorative image missing alt text can wait a week, a booking form a differently abled person is unable to complete cannot.
- Build it in from here on. Every new page gets built to the standard.
Long story short
My client started with “what do I actually need to do?” and what she has now is a measured site, a published statement, a list worked through in order, and a rule for new pages.
WCAG 2.1 AA is the standard now, and it will still be the standard next year. The businesses treating this as ordinary maintenance now are the ones who will not be blindsided by a demand letter asking for a five figure settlement.
