Smarter sites, safer businesses — no strings attached.
Short answer: WCAG Level AA is the accessibility benchmark most laws, lawsuits, and settlements point to (usually version 2.0 or 2.1; 2.2 is current). For a US small business, the real exposure is demand letters over common, fixable failures like missing alt text, low contrast, and unlabeled form fields.
A blind visitor uses a screen reader that reads a page out loud. Someone with limited hand mobility navigates a site entirely with a keyboard, tabbing from link to link instead of clicking. Someone with low vision needs text and background colors that don't blur together. None of that is an edge case — it's a normal way a meaningful share of visitors use the internet every day. A website that only works for a mouse-and-perfect-vision user isn't neutral; it's a site with a door some customers can't open.
That's the accessibility half of the picture. The GRC half is what makes it relevant to a business owner who isn't especially concerned with web standards for their own sake: an inaccessible website is also, increasingly, a legal-exposure problem — one that shows up as a demand letter, not a warning.
The Web Content Accessibility Guidelines (WCAG) are the technical standard most accessibility rules and lawsuits point back to. They're maintained by the World Wide Web Consortium (W3C) through its Web Accessibility Initiative. The current version is WCAG 2.2, which became an official W3C Recommendation in October 2023. It builds on and is backwards compatible with WCAG 2.1, adding nine new success criteria and removing one obsolete one (4.1.1 Parsing), so a site that meets 2.2 Level AA also meets the earlier versions' AA requirements.
WCAG is organized around four principles, often shortened to POUR:
Underneath those four principles sit specific, testable success criteria — 86 of them in WCAG 2.2 — each assigned a conformance level:
For a small business, the useful takeaway isn't "read all 86 criteria." It's that WCAG Level AA is the standard everything else in this post points back to — most laws and court cases today cite version 2.0 or 2.1, and 2.2 is the current version and the sensible target, since meeting it covers the earlier ones.
This is where accessibility stops being a UX topic and becomes a compliance one — and where it's important to be precise about what actually is and isn't required, because a lot of what circulates online overstates it.
In the United States, there is no single federal law that names WCAG and says "every business website must meet this." The Americans with Disabilities Act (ADA) doesn't mention websites at all — it was written in 1990. What exists instead is Department of Justice guidance interpreting Title III of the ADA (which covers "public accommodations" — businesses open to the public) as requiring that the goods and services a business offers online be accessible, under the ADA's general nondiscrimination and effective-communication requirements. The DOJ has been explicit that it "does not have a regulation setting out detailed standards" for private business websites — it's longstanding interpretation and enforcement practice, not a codified checklist, and courts have not agreed on every question (for example, how far Title III reaches for websites with no physical storefront). In practice, though, settlements, DOJ enforcement actions, and many court decisions frequently reference WCAG (usually 2.0 or 2.1 Level AA) as the benchmark for what "accessible" means, even without a formal rule requiring it. There is no small-business exemption from Title III based on size, and there's a well-documented pattern of law firms sending demand letters or filing lawsuits over inaccessible small-business websites — the scenario below is exactly that pattern.
(For contrast: in April 2024 the DOJ did finalize an actual regulation — but it applies to state and local government websites and apps under Title II and requires WCAG 2.1 Level AA specifically. Its compliance deadlines depend on the population a government serves, and in April 2026 the DOJ extended them to April 26, 2027 for governments serving 50,000 or more people and April 26, 2028 for smaller ones and special districts. That rule does not apply to a private business.)
In Ontario, Canada, the picture is more concrete. The Accessibility for Ontarians with Disabilities Act (AODA) has an actual, codified website requirement under its Integrated Accessibility Standards: as of January 1, 2021, designated public sector organizations of any size, and private-sector or non-profit organizations with 50 or more employees in Ontario, must make their public-facing websites and web content conform to WCAG 2.0 Level AA (with two narrow exceptions, around live captions and pre-recorded audio description). It only applies to web content posted after January 1, 2012. A business under 50 employees in Ontario is not currently subject to this specific requirement — worth knowing precisely, since "AODA applies to every Ontario business" is a common overstatement.
In the European Union, the European Accessibility Act (EAA) sets accessibility requirements for certain products and services, including e-commerce, with a compliance deadline of June 28, 2025. It's aimed at businesses selling into the EU market, not a general rule for any website anywhere — and it carries a microenterprise exemption: businesses with fewer than 10 employees and no more than €2 million in annual turnover or balance-sheet total are exempt from the EAA's service-related accessibility requirements. This mostly matters for a small business if it sells products or services to customers in the EU; it's not a first-order concern for a purely local shop with no EU customers.
The pattern across all three: the legal exposure is real, but it varies a lot by where the business is and who it serves — which is exactly why "am I definitely covered by a specific law" is the wrong first question for a small business to spend time on. The more useful question is the one below.
(This is a composite, illustrative scenario built from a pattern that shows up repeatedly in real ADA website-accessibility demand letters and lawsuits — not a specific business's story.)
A local home-services company — the kind with a marketing site, a services page, and a contact form for quote requests — had never thought about accessibility once in the life of the site. It looked clean, loaded fast, and converted visitors into calls. Then, out of nowhere, the owner received a letter from a law firm on behalf of a visually impaired visitor, alleging the site violated the ADA: images with no alt text a screen reader could announce, a contact form where none of the fields had labels a screen reader could read aloud (just placeholder text that disappears once you start typing), and text-over-background color combinations that didn't meet minimum contrast. The letter proposed a "settlement" — a payment plus a commitment to fix the site — instead of a lawsuit.
Nothing on the site had ever been reported as broken by an actual customer. The business had no idea any of this counted as a legal issue at all; the contact form worked fine for the owner, testing it with a mouse and normal vision. That's exactly the blind spot: none of the failures were visible to anyone who wasn't specifically testing with a screen reader or a keyboard-only navigation, which nobody at the business had ever done.
What closing this gap actually looked like: the business brought in a developer to run the site through both automated accessibility scanning tools and a manual keyboard-and-screen-reader check, fixed the concrete issues (added real alt text to meaningful images, added visible form labels instead of placeholder-only fields, adjusted a handful of low-contrast color pairings, made sure every interactive element could be reached by tabbing through the keyboard alone), and published a short accessibility statement on the site describing the standard it aims for (WCAG 2.2 Level AA) and how to report a barrier. None of that made the legal claim disappear on its own — that got resolved separately, with legal counsel — but it turned "we have no idea what's wrong or whether it's still wrong" into a documented, defensible position, and it meant the next visitor using a screen reader could actually use the site.
The same handful of issues account for most of what shows up in demand letters and automated scans. None of them require a redesign:
alt="Golden retriever puppy at a grooming appointment", not alt="image1.jpg" or nothing at
all). Purely decorative images can have empty alt text on purpose — that's
correct, not an oversight.<label> element tied to the field.Checking for these five doesn't require hiring an accessibility firm. It requires deliberately testing the site the way someone other than its usual visitor would use it — which is also, not coincidentally, the same instinct behind the free Compliance & Accessibility Self-Check, which walks through website accessibility alongside the other areas covered on this blog, in plain English, with nothing entered leaving your browser.
A note on what this is and isn't: this post is educational — general patterns and plain-English explanations, written as I work through this material myself. It isn't legal advice, and passing an automated scan or a self-check isn't the same as a full WCAG conformance audit or a legal opinion on your specific site and jurisdiction. If any part of the scenario above sounds familiar, or your business serves customers in Ontario or the EU, that's worth a conversation with a qualified accessibility professional or attorney, not just a blog post.
Governance, Risk, and Compliance sounds like a Fortune 500 problem. Two real-world scenarios showing why it isn’t.
GRC fundamentalsAll sectorsAlmost every local business that takes a card is already in scope for PCI DSS. What that actually means, and a scenario of how a small shop got it wrong.
PCI DSS fundamentalsAll sectorsCanada has a federal privacy law plus three provinces with their own private-sector laws — and Quebec’s Law 25 is the strictest in the country. What actually applies, and a scenario of a Quebec business closing the gap.
Canadian privacy fundamentals