Skip to main content
WCAGrules
Quick navigation

Services · Focused audits

A Session Timeout Audit Weighs the Clock Against the Careful User

For the product with security-driven session limits that wants them to coexist with users who type slowly, read by ear, and deserve to finish.

What We Keep Finding

Session policies are written for security and experienced as a race. A screen reader user filling a long form works at the speed of speech. A user with a motor disability works at the speed of their hands. The timeout does not care, fires mid-entry, and the work is gone.

The Level A rule here asks for less than people fear, and it is specific enough to check before you order. You satisfy it by letting the user turn the limit off, or adjust it, or extend it. The extend route is the one most products need, and it has two numbers in it. The user gets warned before time runs out, gets at least 20 seconds to extend with something as simple as pressing the space bar, and can do that at least ten times. Ten. Not once, which is what most implementations offer.

Now the part that gets sold wrongly everywhere, and we would rather lose the argument in advance than in your report. That rule has exactly three exceptions. The limit is part of a real-time event, or extending it would invalidate the activity itself, or it is longer than twenty hours. Security is not one of them. A timeout your bank or your card processor imposes may be genuinely immovable as a business fact, and it is still a Level A failure, and no auditor can make that go away by sympathising with you. What we can do is say so plainly and show you the warning and extension behavior you can still build around it.

Two other things people assume are part of this rule are not, and both sit at Level AAA, which is outside the 55 rules our audits grade. Preserving what the user typed is its own rule. So is letting them re-authenticate and carry on where they left off, which is the exact scenario in the paragraph above. We test both because they matter more to your customer than the level does, and we mark them as observations rather than conformance findings so nobody files a AAA nice-to-have as a legal exposure.

One warning if data preservation is the route you pick. The standard attaches a note to it about consent. Holding a half-finished form full of somebody's details is a privacy decision before it is an accessibility one, and it gets sharper where the user might be a minor. Talk to whoever handles that at your end before you build it.

What We Check

  • Map every timeout, so session, form, payment, and verification code
  • Test the warning for whether it arrives in time, is announced, and is answerable by keyboard
  • Verify the extension really extends, with at least 20 seconds to act and at least ten goes
  • Check the one-time-code inputs, since split character boxes that block pasting are a named failure
  • Check what survives expiry, and mark that finding as the AAA observation it is
  • Audit the auto-logout message, so users know what happened rather than guessing

What You Get

Every service on this site runs the same three-pass engine: an automated scan, an expert review of all 55 WCAG 2.2 A and AA rules, and a hands-on session with a professional blind screen-reader user. You get one report with every finding screenshotted, ranked by user impact, and linked to its fix. Your team fixes, we verify: the re-audit is half price within 3 months.

The format is not a mystery either. Read the sample report before you spend anything.

The Honest Limit

One honest limit, stated the way the rule states it rather than the way it would suit us. Some timeout floors really are imposed by payment networks or by your own security policy, and that is a fact about your business rather than an exception in the standard. Where a limit genuinely cannot move, we say so, and we report the warning and extension behavior around it. We still record the finding, because a report that quietly forgave it would be worth less to you the day somebody else reads it.

What It Costs

Rapid Audit: $499, up to 10 pages you pick, report in 5 business days. Standard Audit: $1,499, up to 25 pages in 10 business days. Flat rates, no discovery calls, and a real blind screen-reader user on every engagement. Pick your pages. We bring the humans.

Worth Reading Next

Related on this site

Guides, checklists, tools, and terms that go with this service.

More in Focused audits

Go somewhere useful

Find tools, resources and your workspace.

29 destinations