Almost always the audit comes first, and the reason is arithmetic rather than principle. Remediation is priced against a scope, and until somebody has looked at your site nobody knows what the scope is, including you. A quote produced without a findings list is a quote for an unknown quantity of work, which means it is either padded to cover the unknown or it is going to move once the work starts. Both come out of your budget.
But the useful correction to the question is that there are three jobs here rather than two, and the third is the one that goes missing. Somebody finds what is wrong. Somebody changes the code. And somebody confirms the change worked. Bundle all three into one supplier and the third job is being performed by a party with an interest in the answer, which is not verification. It is a formality wearing verification's clothes.
Three Jobs Hiding Behind One Sentence
Get the site fixed is three purchases. They have different outputs, different suppliers and different failure modes, and the words the market uses for them are not stable, so the safest move is to describe what you want rather than to name it.
| The job | The question it answers | What it produces | Who can do it |
|---|---|---|---|
| Diagnosis | What is wrong, where exactly, against which criterion, and how much does each one matter | A dated report with evidence attached to every finding, and nothing about your software has changed | An evaluator, internal or external. It is the only one of the three that can be bought at a published price, because the scope is known before it starts |
| Repair | How do we change the templates, the content and the documents so those barriers stop happening | Changed software, and no document at all unless somebody writes one | Your own developers, your agency, a specialist remediation firm, a document vendor. Very often several of those at once, because the three kinds of repair are different work |
| Verification | Did the changes actually work, on the pages where the problems were, and did anything break on the way | A dated retest with a verdict on every original finding and fresh evidence for each | Somebody who did not do the repair. That is the whole condition, and it is the one most often waived |
Look at the third column. Diagnosis and verification produce documents and change nothing. Repair changes everything and produces no document. That asymmetry is why the verification job disappears so easily. It is the only step whose entire value is that somebody else did it, so it is the only one that becomes worthless when it is folded into the others. And it stays invisible on a project plan until the moment somebody asks you to prove something.
Which One You Need First
Find the row that describes where you are standing. Three of the six start with the diagnosis, which is the ordinary case, and the three that do not are the ones worth understanding before you assume the audit always comes first.
| Where you are | Buy first | Why |
|---|---|---|
| Nobody has looked, and you want to know what you are dealing with | Diagnosis | Nothing can be scoped, priced or sequenced until the list exists. This is the ordinary case and it is most of them |
| A customer or a procurement team has asked what your product does | Diagnosis | The thing being asked for is evidence, and repair produces none. Fixing quietly and answering later leaves the question unanswered for longer |
| You already have a scanner export hundreds of rows long | Diagnosis, narrowly | An export flags what looks wrong rather than what is wrong. Reproducing the flags and striking the false ones is cheaper than repairing them, and it is a smaller purchase than a full audit |
| A specific customer told you they could not use your site | Repair, then diagnosis | Fix the barrier that person hit, today, because a person is waiting. Then find out what else is on that journey, because a complaint is usually where somebody gave up rather than the only place they struggled |
| You know exactly what is broken, on one component, and it is cheap | Repair | Buying a report to tell you what you already know is theatre. Fix it, then audit once the obvious work is done, so the report is about what you cannot see rather than what you can |
| Your team has finished a fix round already | Verification | The list exists and the work is done. What is missing is anybody confirming it, and a retest that can read the original report will find regressions a fresh scan cannot |
The fourth row is the one worth taking seriously. If somebody has written to say they could not buy from you, the ethical order and the commercial order agree for once. Fix what they hit, tell them you fixed it, and then go and find out what else is on that path. Waiting three weeks for an audit before helping a person who has already told you what is wrong gets the sequence exactly backwards.
What Skipping the Diagnosis Costs
Two costs, and the second one is bigger than it looks.
The first is that you pay per page for work that is per template. Forty findings across forty pages are very often one component rendered forty times, so one file changed once collapses the whole list. A supplier quoting without a findings list has no way to know that, so they quote against pages, which is the wrong unit and always the more expensive one. Insisting on a price per template rather than a single figure for the site is the single most useful thing you can do to a remediation quote, and it takes one sentence.
The second is that you fix what is visible. Without a report, repair work goes where somebody can see a problem, which means contrast and alt text get attention while keyboard journeys, announcement quality and error recovery do not. Those are the ones that lock people out entirely, they are the hardest to notice from the outside, and they are precisely what a machine cannot flag. You end up with a site that scores better and works no better for the people it was excluding.
What Skipping the Verification Costs
You get a list of closed tickets and no evidence, which is fine right up until somebody asks. And accessibility fixes fail quietly, which is the part that surprises teams the first time.
A label gets attached to the wrong field, which satisfies the rule about labels and breaks the one about relationships. A focus style comes back in one browser and not another. An aria attribute satisfies the scanner and baffles the screen reader. A message gets announced twice because two correct fixes were applied at once. Every one of those looks like diligence in a pull request, and every one of them is a new finding. Your ticket system says done, and a person on NVDA decides whether that is true.
Published practice treats this as a named step rather than a nicety. In US federal guidance, a defect remediation plan has to include testing and verification steps to confirm the fixes meet the standard. The plan is not retired until every defect is resolved and compliance is validated by testing. Resolution and validation are two events with two owners. Our page on what a retest report proves covers what that document should contain.
The Fourth Job Almost Nobody Buys
There is a job sitting between find and fix that hardly anyone in the private sector has heard of, and once you see it you will notice it missing everywhere.
Remediation takes time. Documents take longer. Some things are never going to be fixed, because the system is being retired or the supplier will not move. So what happens to the person who needs the thing today? US federal agencies answer that with a plan of its own, running alongside the repair work, that documents how people reach the affected content by another route while the fixing happens, and permanently where fixing will not.
The shape is worth stealing whatever size you are, because it is mostly free. Name a route through, so a transcript, an accessible version of the document, a phone number, a person, an alternate flow. Say how quickly a request gets answered. Put the contact somewhere findable rather than in a footer nobody reads. Track what gets asked for, because the requests tell you which fix to do next. Those response times in the federal version are that government's own examples rather than any standard, and the idea transfers even where the timings do not.
This also happens to be the honest thing to put in an accessibility statement while the work is underway. A statement that names what is broken, what is planned and how to get help in the meantime reads as a business dealing with a real situation. A statement that says everything is fine reads as one that has not looked.
How to Buy Three Jobs Without Buying a Conflict
The tension is real and worth stating from both sides, because the guidance does not all point one way.
UK government guidance for teams buying an audit actively recommends choosing a supplier who can also help with the fixing, and says it is worth paying extra for one. The reasoning is good. A supplier who found the problem understands it, can prioritize it and can hand it to a developer without a translation step, and for a team with no internal capability that is a genuine saving.
The counter-argument is about the third job rather than the second. A firm paid by the length of the repair job is the firm writing the list of repairs, and every extra finding is extra billable hours. That does not make their findings wrong. It makes them unchecked, and you are about to spend real money on their word. Then the same firm signs off its own work, and the chain has no independent link in it anywhere.
You do not have to pick a side. Split the third job and keep the first two wherever they are most convenient.
- Buy diagnosis and repair from whoever suits you, including from the same supplier if that is what your team needs.
- Buy verification from somebody with no stake in the repair. It is the smallest of the three purchases and it is the only one whose value depends on who performed it.
- Ask for the repair price per template and per document, never as one figure for the site. A supplier who can quote that way has opened your pages. One who cannot has not.
- Ask who owns the code afterwards, and what still works if you stop paying. A fix that lives inside a vendor's script leaves when the invoice does.
What We Sell, and What We Refuse To
We do the first job and the third one. We do not do the second, at any price, and that is a decision rather than a gap in the product line.
An audit here is flat-rate and the price is published before anybody opens your site, which means a longer findings list never earns us a cent more. There is no repair work behind it for a long list to be pointing at. And because we did not write your fixes, our retest is a check rather than a firm grading its own homework, which matters most exactly when the verdict matters most.
It costs us the part of this trade where the real money is, and it means we cannot hand you the thing you probably want most, which is somebody to give the list to. What we wrote instead is how to buy remediation, which is the shape of the job and the four questions to ask, written by the people who open the code afterwards. We keep no partner list and take no referral fee, because quietly earning a cut is the arrangement that whole page argues against.
The number this page cannot give you
The audit is the smaller half of your accessibility budget and it is the only half anybody can publish a price for. There is no price index for remediation, no benchmark and no published average, which is a structural fact rather than an immature market. Our guide to what remediation costs explains why, and how to cost your own findings list turns a report you already hold into a number with its assumptions written on the front. Neither one invents a rate, because nobody honestly can.
The Order That Works for Most Sites
Diagnose once. Collapse the findings to their causes, because the causes are what you are paying to change. Repair in template order rather than in report order, so one component fix clears many pages. Verify with somebody who did not repair. Then keep the checks running so the next release does not undo it, which is the cheapest part of the whole sequence and the one everybody drops.
Read the report before you buy it. Fix in the order that helps people first. Get somebody else to check.