On June 28, 2025 the European Accessibility Act became enforceable across the EU, and the Netherlands became the most interesting place in Europe to have a broken checkout.
Within weeks of the launch date, the Autoriteit Consument & Markt (ACM) – the Dutch consumer and markets authority – published reporting rules nobody else in Europe has matched, mandatory since October 15, 2025. If your e-commerce or communications service has a serious accessibility barrier you can’t fix within a week, you report yourself to the regulator, with a remediation plan and a completion date you’ll be held to.
Yes, you report yourself. And no, “we didn’t know” doesn’t help – the obligation attaches to the barrier itself, not your awareness of it.
If that sounds less like accessibility law and more like the way your security team handles a vulnerability, you’ve spotted the story. A year into the EAA, most of the conversation is still about WCAG checklists and whether anyone’s been fined yet. Meanwhile the Dutch built something different, and I think it’s the model everyone else will drift toward. Here’s why.
The elegance of what the Dutch built
The ACM’s regime has four pieces, and each is more radical than it looks.
Severity is measured by workarounds, not WCAG
The ACM classifies accessibility problems into four impact levels – critical, serious, moderate, minor – defined entirely by whether a user with disabilities can get around them. “Critical” means users with disabilities cannot use the service at all and cannot circumvent the problem; in the ACM’s own deadpan phrasing, “the only option is to close the website completely.”
Deadlines are tiered by severity
Critical and serious problems: fix within a week or report to the ACM. Moderate and minor: a month. Your report includes what’s broken, the impact level, and a plan with a committed “fully accessible by” date. If you miss that date, you file again.
Two regulators, one playbook
The AFM – the Dutch financial-markets authority – runs the identical taxonomy and clocks for banking and financial services, and opened its own investigation of financial firms’ websites in April 2026. The Netherlands built a coordinated system.
No audit required. Good luck without one
The ACM is explicit that no certificate, inspection, or audit is mandatory. But you can’t classify a problem’s severity or discharge a reporting duty for issues you haven’t found. The audit isn’t legally required; it’s epistemically required. That’s either clever regulatory design or a trap, depending on your mood.
Wouldn’t everyone just… not report?
The obvious objection to self-reporting is that nobody volunteers for regulatory attention. The ACM answered it before the law even took effect. At a Dutch accessibility conference on June 5, 2025, the ACM’s own slide put it in a big magenta box: “Melden is een pre!” – “een pré” is Dutch job-ad language for “a plus,” so: reporting counts in your favor.
There’s one condition, in the box right next to it: there must be a solid plan behind it. Their enforcement posture says the same thing: what happens to you depends on the severity of your problems and on what you’re doing about them. Report with a credible plan and you’re in the cooperative lane. It’s the same logic that makes companies report data breaches. Disclosure with a plan beats getting caught hiding.
Organizations will use a lane like that when it’s offered. Austria (whose entire reporting machinery is a designated email address) received 53 company self-notifications in year one, mostly from banks and insurers, and its regulator published the numbers.
So how did the Dutch market respond to the most sophisticated version of that offer in Europe?
Mostly by ignoring it.
In March 2026 the ACM published the results of testing roughly 100 of the largest Dutch online stores plus the biggest telecom and energy providers. On 61% of the sites, placing an order with assistive technology was impossible – order buttons that can’t be operated by keyboard, CAPTCHAs that lock the door entirely. Another 33% had serious problems. By the ACM’s own scale, roughly nine in ten of the country’s biggest online stores were sitting at report-within-a-week severity. The ACM has published nothing about how many reported, and its 2025 annual report notes: after call-to-action letters went to the CEOs of the largest e-commerce companies, awareness went up – but a substantial share of those companies never responded at all. The ACM has since sent information requests to e-commerce operators worldwide, including companies headquartered outside the EU that sell to Dutch consumers. Non-responders are under active monitoring. Formal enforcement is expected in the second half of 2026, where we are now.
I checked all 27 countries
I wanted to know whether the Netherlands is an outlier or just early, so I checked how every member state handled the same legal duty – Article 13(3) of the EAA, which requires service providers to inform their national authority when their service doesn’t conform.
The short version: as of the writing of this article, no other country has a severity taxonomy, and no other country has deadlines tiered by severity. A second tier of legislation has built real machinery without the clocks:
- Sweden’s PTS runs a dedicated reporting e-service and is the only other regulator to publish a concrete deadline (14 days counts as “immediately”);
- France launched a mandatory declaration form in November 2025 that demands a committed conformity date;
- Luxembourg requires declarations through its government portal, complete with a corrective-action plan;
- Finland’s combined notification form requires a remediation schedule.
A third tier has an email address and a content list. And roughly fifteen member states transposed the directive’s sentence – “inform the authority immediately” – but built nothing at all. Germany, with its famously harsh penalties, offers a generic contact form.
The ugly side is that if you operate across the EU, you owe a non-conformity report to each country’s regulator. Right now that means one stopwatch regime, four structured forms with different fields, a few mailboxes, and fifteen shrugs. It’s one obligation with 27 procedural realities. The EAA harmonized the obligation, but left the mechanics to the member states, and they’re all over the place.
When this same file-in-every-member-state problem hit e-commerce VAT, the EU built the One Stop Shop. There is no accessibility OSS, no coordination body to build one, and the Commission’s first formal review of the EAA isn’t due until 2030.
This is where EU regulation has been heading
The Dutch design looks less surprising when you notice it’s written in the EU’s current regulatory house style. Report-your-own-failure-on-a-clock has been the direction of travel for a decade:
| Regime | Domain | Clocks |
| GDPR, Art. 33 (2016) | Personal data breaches | 72 hours to the regulator |
| NIS2, Art. 23 (2022) | Cybersecurity incidents | 24h warning → 72h notification → 1-month report |
| DORA (2022) | Financial-sector ICT incidents | 4h from classification → 72h → 1-month report |
| Netherlands, EAA (2025) | Accessibility non-conformity | 1 week (critical/serious) → 1 month (moderate/minor) |
The security laws report incidents – something broke on a Tuesday. The Dutch regime covers standing states of non-conformity, which is if anything the harder version: there’s no bad-day framing, just “your service doesn’t comply and the clock is running.” And where a security regulator’s final report describes what you did, the ACM makes you commit to a future date and answer for it.
The structural convergence is real, but we’re left with a glaring omission: unlike GDPR (which has the European Data Protection Board) or NIS2 (which has a network of national response teams), EAA enforcement has no EU coordination body. The national layer is the whole game, and it will converge only by imitation.
Three further Dutch details
I think there are three scope details from the Dutch guidance that deserve more attention than they’ve gotten.
- “Free” doesn’t mean out of scope. The ACM says explicitly that services where consumers pay with personal data instead of money count as e-commerce. If your “free” service takes sign-ups, read that again. The legal reasoning is EU-wide, even though the Dutch are the first regulator to write it down. The ACM’s scope examples for communications services name WhatsApp, Signal, Zoom, and Webex.
- Your accessibility statement needs an audio version. Under the ACM’s reading of the EAA’s “more than one sensory channel” requirement, the statement must also be offered verbally – for example, as an audio recording. I have questions about this one (translation? updates?), but it’s in the guidance, and it’s been there from the start.
- WCAG 2.2 is coming on a schedule now. The ACM has said all along that WCAG 2.2 AA becomes the standard “in the course of 2026,” and the European standards process has nearly caught up: expect the Official Journal citation around November 30. If your roadmap still says WCAG 2.1, it’s time. (There are only six new criteria to meet AA and they’re not that onerous – we made a video for each one.)
What this means for how you run accessibility
If the Dutch model spreads – and courts are already reasoning the same way; when Carrefour argued in a French courtroom this June that its site was “71% accessible,” the court replied, in effect, that a site cannot be partly accessible – then accessibility stops being a document you produce and becomes a process you run. The annual audit becomes the annual pentest: still worth doing, nowhere near enough. Findings become tickets – objects with a severity, an owner, a due date, and an “is this still open?” flag – because that is what a Dutch report is. And the ACM’s stated minimum expectation for companies isn’t “your site passes.” It’s that responsibility for accessibility is durably embedded in the organization. That’s how security teams already run vulnerabilities – except here, the regulator sets the deadlines.
“We audited our accessibility in March” is a photograph, already aging the day it was taken. “We know what our serious outstanding accessibility defects are today, and each one has an owner and a date” is very different, and the Dutch model rewards only the second.
It doesn’t reward not looking. The obligation attaches to the barrier whether you’ve seen it or not, and the ACM has already shown it will find your defects without your help – that’s what the sweep was. What the regime punishes is the old industry standard of audit, file the report, do nothing.
I think that’s good news, honestly. Nobody in a boardroom asks whether the security team is worth funding. Putting accessibility in the same operational-risk grammar is how it stops being the thing that slips.
The scoreboard, and what to watch
The EAA’s first-year enforcement record fits in one sentence: zero companies fined anywhere in the EU; one company under a binding court order (Carrefour – full accessibility by early December, €500 per day after that); and exactly one fine on the books – €1.5 million, paid by Bulgaria to the European Commission for failing to transpose the law on time, in the first-ever Court of Justice ruling on the EAA.
A fair objection at this point: How can the benchmark be a country where 61% of the biggest online stores can’t take an order from a customer with a disability?
Because the benchmark is the machinery, not the outcomes. The machinery doesn’t fix websites. It puts every failure on a list, with a rating and a deadline, and makes ignoring the list expensive. The sweep certainly doesn’t suggest the Netherlands is unusually accessible – but that was never the claim.
Researchers count all the time – the WebAIM Million found detectable failures on 95.9% of the web’s top million homepages this year, a number that went up – but nobody has to answer for those numbers. The Netherlands is the only country whose regulator counted its own market and put deadlines on what it found.
What happens next is more interesting than what has happened so far. Watch four dates:
- the ACM’s formal enforcement window, open now;
- Carrefour’s compliance deadline in early December;
- the revised European standard (EN 301 549, carrying WCAG 2.2 AA) expected in the EU’s Official Journal around the end of November; and
- the European Disability Forum’s anniversary event on September 22–23, the field’s first big gathering since enforcement began.
Expect notes to be compared. I’ll be watching all four.
Because one year in, the only party fined under the European Accessibility Act was a government. That changes this fall, or it doesn’t.
Either way, the move is the same: know what your serious defects are today, give each one an owner and a date, and don’t let the report sit. Wherever enforcement lands, that work makes for an accessible site.
Which was the point all along.
Sources
The Dutch regime
• ACM: Accessibility of e-commerce services and electronic communications services – the guidance page: severity levels, deadlines, scope, exceptions
• ACM: Reporting obligation for non-accessible services (Dutch) – the report form
• AFM: EAA notifications for financial services – the parallel regime, same taxonomy and clocks
• ACM presentation, Nationaal Congres Digitale Toegankelijkheid, June 5, 2025 (PDF, Dutch) – the “Melden is een pre!” slide
• ACM: majority of large online stores are not accessible (March 24, 2026) – the sweep: 61% / 33%
• ACM Jaarverslag 2025 (PDF, Dutch) – p. 58: CEO letters, non-response, “additional interventions”
Other member states
• Austria: one year of the Barrierefreiheitsgesetz (Behindertenrat, German) – 53 self-notifications, 84 proceedings, 0 fines
• Sweden: PTS deficiency-reporting e-service (Swedish) and PTS supervisory cases against e-commerce services (Swedish)
• France: DGCCRF non-conformity / exemption declaration
• Luxembourg: OSAPS non-conformity declaration (French)
• Finland: Traficom notification obligation (Finnish)
• Ireland: CCPC accessibility notification form
• Austria: Sozialministeriumservice, reporting non-conformity (German)
• Germany: MLBF market surveillance authority (German)
Courts and the EU level
• CJEU, Commission v Bulgaria, C-646/24, judgment of March 19, 2026 (ECLI:EU:C:2026:221, French) – the €1.5M lump sum
• Silktide: The second EAA ruling – “71% accessible” is not a defense (June 4, 2026) – the Carrefour order
• Directive (EU) 2019/882 (the EAA), Article 13
• Level Access: EAA compliance in 2026 – how enforcement has evolved – worldwide information requests, H2 2026 enforcement
• EDF: Web Accessibility Directive anniversary event, September 22–23, 2026
The regulatory-grammar comparison
• GDPR Article 33 – breach notification
• NIS2 Article 23 – reporting obligations
• DORA RTS Article 5 – incident-reporting time limits
Context
• The WebAIM Million – annual automated survey of the top million homepages; verify the current year’s failure percentage before publication
Standards
• ETSI: final draft EN 301 549 V4.1.0 (PDF)
• EN 301 549 v4.1.1: what changes and when it applies (AxAll, Aug 18, 2026) – the ~Nov 30 Official Journal timing

