Standard · v3.2.1
EN 301 549, and what it asks for beyond WCAG
In this library, nine of the laws discharge their web duty through this standard rather than by naming WCAG directly, the European Accessibility Act among them. It is worth knowing what that changes, because the honest answer comes in two halves. For a website, less than people fear. For everything else you sell, considerably more.
For a website, clause 9 is WCAG 2.1 Level AA
Clause 9 does not paraphrase WCAG. It adopts it. Every requirement from 9.1.1.1 onwards is a single line pointing at a named WCAG 2.1 success criterion, and the standard states the equivalence itself. Meeting WCAG 2.1 Level AA is the same thing as conforming to clauses 9.1 through 9.4 plus the conformance requirements in 9.6. So if you have tested against the 55 Level A and AA rules of WCAG 2.2, clause 9 is already covered, because 2.2 adds criteria to the 2.1 set rather than changing what was there. That is the part of this standard most people arrive asking about, and it is the part this whole site already covers.
Two things ride along with the adoption. Clause 9.6 brings the WCAG conformance requirements with it, so complete processes and full pages are part of the duty rather than fine print. And clause 9.5 lists the WCAG 2.1 Level AAA criteria and invites you to consider them, so clause 9 is not only about AA even though AA is what you are held to.
The standard has fourteen clauses, and nine of them carry requirements
The shape of the document matters, because people quote parts of it at each other in procurement and often mean different things by it. Clauses 1 to 3 are scope, references and definitions. Clause 4 sets eleven functional performance statements. Those describe what the product has to let a person do, use it without vision, use it with limited hearing, use it with limited reach and so on, and they are what applies when no specific requirement covers the thing in front of you. Clauses 5 to 13 are the testable requirements, and they are the ones an assessment works through. Clause 14 then says what conformance means. Every applicable clause containing the word "shall" has to be met, and the standard sets no priority order between them, so nothing in here is officially more important than anything else.
So when somebody tells you a product meets EN 301 549, the question worth asking is which clauses were in scope. A website answers to clause 9. A downloadable document answers to clause 10. A mobile app or a desktop application answers to clause 11. Three different clause sets, three different bodies of work, and one sentence that sounds like it covered all of them.
The other eight requirement clauses are what WCAG never mentions
Biometrics, and the rule that no single biological characteristic can be the only way in. Physical buttons, tactile markers and how far somebody has to reach. Key repeat rates, which have to be adjustable down to one character every two seconds. Real-time text during a call. Whether your documentation and your support channels are usable. How a deaf caller reaches emergency services. There is even a limit on how hard a control may be to press, and it is 22.2 newtons. A site that passes WCAG can still fail this standard on any of them, and reading only the WCAG half is the mistake organisations make most.
Clause 12 is the only one you cannot scope your way out of
Every other requirement in this standard is self-scoping. It opens with "Where ICT" and some condition, and when the condition is false the requirement simply does not apply to you. No video means no caption requirements. No hardware means no reach ranges. Clause 14 names one exception to that, and it is clause 12, documentation and support services.
So your product documentation has to be published in a format that conforms to clause 9 or clause 10. Your help desk, your call centre and your training have to accommodate the communication needs of disabled callers, either directly or through a referral point. And none of that switches off because your product happens not to have the feature some other clause is about. This is the clause suppliers lose procurement on, and it is almost never the one they tested.
The nine requirement clauses, 5 to 13
One card per requirement clause, with the sub-clauses listed under each, so you can see the shape of what an assessment would work through. Clause 9 is the web one and it is marked.
Clause 5. Generic requirements
Requirements that apply to any ICT, whatever it is. This is where biometrics, physical controls, key repeat rates and closed functionality live, and none of it appears in WCAG.
- 5.1 Closed functionality
- 5.2 Activation of accessibility features
- 5.3 Biometrics
- 5.4 Preservation of accessibility information during conversion
- 5.5 Operable parts
- 5.6 Locking or toggle controls
- 5.7 Key repeat
- 5.8 Double-strike key acceptance
- 5.9 Simultaneous user actions
Clause 6. ICT with two-way voice communication
Anything that carries two-way voice: calls, conferencing, video calling. Real-time text sits here, which is a legal requirement in Europe and has no WCAG equivalent.
- 6.1 Audio bandwidth for speech
- 6.2 Real-Time Text (RTT) functionality
- 6.3 Caller ID
- 6.4 Alternatives to voice-based services
- 6.5 Video communication
- 6.6 Alternatives to video-based services
Clause 7. ICT with video capabilities
Video capability: captions and audio description as a property of the player and the delivery chain, not only of the content.
- 7.1 Caption processing technology
- 7.2 Audio description technology
- 7.3 User controls for captions and audio description
Clause 8. Hardware
Hardware. Physical buttons, tactile markers, standing and reach ranges, and the parts of a kiosk or terminal a person has to touch.
- 8.1 General
- 8.2 Hardware products with speech output
- 8.3 Stationary ICT
- 8.4 Mechanically operable parts
- 8.5 Tactile indication of speech mode
Clause 9. Web
The web. Clauses 9.1 to 9.4 restate WCAG 2.1 Level A and AA clause by clause, which is why meeting WCAG is most of meeting this standard for a website. Clause 9.5 then names the WCAG 2.1 Level AAA criteria and 9.6 carries the WCAG conformance requirements, so the chapter is not only about AA.
- 9.0 General (informative)
- 9.1 Perceivable
- 9.2 Operable
- 9.3 Understandable
- 9.4 Robust
- 9.5 WCAG 2.1 AAA Success Criteria
- 9.6 WCAG conformance requirements
Clause 10. Non-web documents
Documents that are not web pages: PDFs, office files, anything downloaded rather than browsed.
- 10.0 General (informative)
- 10.1 Perceivable
- 10.2 Operable
- 10.3 Understandable
- 10.4 Robust
- 10.5 Caption positioning
- 10.6 Audio description timing
Clause 11. Software
Software, including mobile apps and desktop applications. WCAG applied outside the browser, plus interoperability with assistive technology, user preferences and authoring tools.
- 11.0 General (informative)
- 11.1 Perceivable
- 11.2 Operable
- 11.3 Understandable
- 11.4 Robust
- 11.5 Interoperability with assistive technology
- 11.6 Documented accessibility usage
- 11.7 User preferences
- 11.8 Authoring tools
Clause 12. Documentation and support services
Documentation and support. Your help pages, manuals and support channels have to be accessible too, which is the requirement organisations forget most often.
- 12.1 Product documentation
- 12.2 Support services
Clause 13. ICT providing relay or emergency service access
Relay and emergency services. How a deaf or speech-impaired person reaches emergency help, which is regulated separately and seriously.
- 13.1 Relay services requirements
- 13.2 Access to relay services
- 13.3 Access to emergency services
Only one of those has anything to say about a web page, which is the arithmetic behind the warning further up. A WCAG audit answers that clause completely and leaves the other eight untouched.
Which version you are actually held to
V3.2.1 is the published version and the one in force. A newer edition has been drafted, and it moves the web, document and software clauses up to WCAG 2.2 Level AA. It is not published, and the date it lands is not the thing that matters. What matters is the mechanism. Until a reference to the new version is cited in the Official Journal of the European Union, the harmonised standard stays at V3.2.1 and the legal bar for a website stays WCAG 2.1 Level A and AA. Anybody quoting WCAG 2.2 as the current European legal requirement is quoting a future one.
None of which is a reason to test at 2.1. Test at WCAG 2.2 Level AA and you have cleared today's bar and the next one in the same pass, because 2.2 contains 2.1. What you cannot do is claim the new version early. There is a second half to that, and it is the one that costs money. No VPAT edition covers EN 301 549 v4 yet. The EU and international editions both reference V3.1.1 and V3.2.1 and nothing later, so a conformance report sold to you today as EAA-ready is a V3.2.1 report against WCAG 2.1 Level AA, whatever the cover page says it is.
If you are the supplier on the other side of that request, the version question is the fourth row of the VPAT request triage sheet, because the edition you pick decides the WCAG version you end up reporting against. Where your product does not meet the bar yet, the roadmap guide covers what to send instead, and why a plan is filed beside a conformance report rather than in place of one.
The nine laws that run through this standard
Some name it outright and some adopt it under their own designation carrying the same requirements, which is why the name on the cover changes from country to country and the criteria underneath do not. Canada's CAN/ASC-EN 301 549:2024 is identical to the European EN 301 549:2021. Spain publishes it as UNE-EN 301549. France tests it through the RGAA.
- European Accessibility Act (EAA)
- Germany: BFSG (Accessibility Strengthening Act)
- France: RGAA & EAA Enforcement
- Italy: Stanca Act
- Spain: Royal Decree 1112/2018 and the EAA
- Netherlands: Digital Accessibility Decree and the EAA
- Ireland: Disability Act 2005 and the EAA
- Denmark: Web Accessibility Act and the EAA
- Accessible Canada Act (ACA)
Three more sit alongside it without their duty running through it, and the difference is worth holding onto. The UK public sector regulations used to route their presumption of conformity through this standard and stopped on October 26, 2022, when an amendment replaced regulation 9 with a direct reference to WCAG Level A and AA. A British public body is measured against the guidelines themselves now, not against this document. Norway's universal design regulation puts the public sector on V3.2.1 and leaves the private sector on WCAG 2.0 AA with three criteria excepted by name. And Australia's Disability Discrimination Act reaches it only through regulator guidance that binds nobody.
Reading the standard yourself
The requirement text belongs to ETSI and stays there. What is on this page is the clause structure and our own description of what each clause is for. The standard itself is a free download with no account and no fee, which is unusual enough to be worth saying out loud, and it runs to 186 pages with most of that volume being the test procedures rather than the requirements. Read EN 301 549 v3.2.1 at ETSI, or start with the short definition of EN 301 549 if you only need to know what it is.