WCAG 2.2 · Guideline 2.2 · Operable
Enough Time
Time limits and moving content have to be under the reader's control.
Some people read slowly, type slowly, or work through a page slowly, and a disability, an unfamiliar language, or a screen reader grinding through dense markup will all do that. A page that expires, refreshes, or scrolls away on its own clock punishes them for it. So this guideline hands the clock over. A time limit has to be one the reader can turn off, adjust, or extend, and content that starts moving beside other content has to be something they can pause, stop, or hide.
Two A/AA success criteria live here, and that is the whole audited guideline. There is no Level AA rule, and four of the six criteria sit at Level AAA. That split matters more than a count usually does. The thing an owner actually loses money to is a session that expires and throws away a filled-in form. Level A only half covers that. 2.2.1 asks for a warning and a way to extend, and says nothing about keeping the work. Preserving the work is 2.2.5 and 2.2.6, both Level AAA. So a page can pass an A and AA audit while the session layer quietly destroys somebody's afternoon. Guideline 2.2 is the goal that gap sits inside. It is not a rule anyone can mark.
- Rules
- 2
- Level A
- 2
- Level AA
- 0
- Human testing only
- 0
All 2 Enough Time rules
- 2.2.1Level ATiming AdjustableWhere the content sets a time limit, six things can satisfy this rule and any one of them is enough.Partly scannable11 fixes
- 2.2.2Level APause, Stop, HideMotion that starts on its own, runs longer than five seconds and sits alongside other content needs a way for the user to pause, stop or hide it.Partly scannable11 fixes
Level AAA in this guideline
4 enhanced criteria sit under 2.2. They are outside the level almost every law names, so our audits treat them as reference rather than scope. Some are still worth adopting, and the Level AAA hub says which.
- 2.2.3Level AAANo TimingThis rule removes time limits rather than making them adjustable.Not graded1 fixes
- 2.2.4Level AAAInterruptionsAnything that interrupts the reader has to be postponable or suppressible, unless it involves an emergency.Not graded5 fixes
- 2.2.5Level AAARe-authenticatingWhen an authenticated session ends, the user has to be able to log back in and carry on with their data intact.Not graded3 fixes
- 2.2.6Level AAATimeoutsWarn people up front how long they can sit inactive before their data is lost.Not graded
What goes wrong here
These are the failures we find repeatedly under 2.2, across sites of every size.
- A session ends without warning and takes the form with it. The person was still reading the page.
- A carousel starts on its own, runs past five seconds, sits beside other content, and offers no way to pause it. All four conditions matter, because the rule only bites when they are all true.
- A countdown pressures somebody to decide faster. It is a conversion tactic, and for a reader who needs more time it is a wall.
- A live feed or ticker refreshes under the pointer and moves the thing somebody was about to click. Auto-updating gets no five-second grace, so this one is stricter than moving content.
- A timeout can be met and still be badly built. Warning at the last moment technically clears the rule and still loses people, so the six routes below are a floor rather than a design.
Who it affects
- People with cognitive disabilities, who may need several times longer to read the text and decide what to do with it.
- People with motor disabilities, for whom every interaction costs measurably more time than the designer assumed.
- Screen reader users, who hear content in sequence rather than taking it in at a glance and so meet moving content at a disadvantage.
- Anyone interrupted mid-task. Over a long enough day, that is everyone.
How to work through it
- 1Find every time limit in the product, including the ones the session layer sets rather than the page. Teams routinely miss those, because nobody wrote them.
- 2Check each limit against the six routes the rule accepts, since any one of them is enough. The user can turn the limit off, or adjust it to at least ten times the default before meeting it, or get a warning with at least 20 seconds to respond and a simple way to extend at least ten times. The other three need nothing built: a real-time event where the limit is genuinely required, a limit whose extension would invalidate the activity, and anything longer than 20 hours.
- 3Find everything that moves, blinks, scrolls or updates on its own. Then check the gates before writing it up: movement counts when it starts automatically, lasts more than five seconds and runs alongside other content. Auto-updating counts without the five-second allowance.
- 4For each one that qualifies, confirm the reader can pause, stop or hide it, or control how often it updates. Where the movement is essential to the activity, none of that is owed.
- 5Fill a long form, wait out the timeout on purpose, and see what survives. Whatever the standard says, this is the test that tells you what your users lose.
- 6Treat the AAA checks separately when you get to them. Interruptions, re-authentication and inactivity warnings are real improvements, and none of them turns into an A or AA finding on a paid audit.
How the levels build
Level A holds two criteria and does the work. Time limits are adjustable through one of six routes, and content that moves or auto-updates can be paused, stopped or hidden. Level AA adds nothing at all, which makes this one of two guidelines where an AA audit and an A audit look identical. Level AAA adds four. Timing is not essential to any activity except non-interactive synchronized media and real-time events. Interruptions can be postponed or suppressed except in an emergency. A session resumed after re-authentication keeps the work already done. And where a period of inactivity could destroy data, the user is told how long that period is, unless the data is preserved for more than 20 hours. That last one is a warning requirement, not a blanket instruction to keep everybody's data forever, and how long you should keep it is a privacy question as much as an accessibility one.
Other Operable guidelines
- 2.1Keyboard AccessibleEvery task has to be finishable from the keyboard alone.
- 2.3Seizures and Physical ReactionsNothing on the page may flash or move in a way that can hurt somebody.
- 2.4NavigableReaders have to be able to find their way around and know where they are.
- 2.5Input ModalitiesTouch, pointer, voice, and motion all have to work, not only the keyboard.
Part of the Operable principle · browse by level: Level A · Level AA · or the full 55-rule library.
See how your site does against these rules.
An expert review plus a real blind screen-reader user, on up to 10 pages, every finding with its screenshot, criterion, and fix. $499, report in 5 business days.