CONTACT
CONTACT

ADA & EAA compliance for SaaS

The EAA is enforced.
ADA lawsuits are rising.
Your product needs
to be compliant.

We assess your SaaS platform against
ADA Title III, EAA, and WCAG 2.2 AA —
then build the remediation roadmap
and VPAT documentation you need.

REGULATORY LANDSCAPE

I.

What your SaaS product
is exposed
to today

Enterprise buyers increasingly require

VPAT/ACR

documentation before signing

a contract —

a standardized report that

documents how

a product conforms
to WCAG,
Section 508,

and EN 301 549.
If you can’t
produce one, you’re

excluded
from the RFP.

Buyers ask for it because adopting


an inaccessible product creates legal
exposure

for them, under two regulatory
frameworks

that now apply to most
SaaS products:

European Accessibility Act (EAA)

Enforcement began June 2025. The EAA’s

technical benchmark
is the harmonized
standard

EN 301 549 — currently v3.2.1,
which incorporates

WCAG 2.1 Level AA and adds
requirements


for mobile apps, software, and documents beyond

the web.

Conforming to it gives a “presumption

of conformity” with the EAA.
We audit


to WCAG 2.2 AA — the superset of 2.1 — so you

meet
today’s legal floor and stay ahead


of EN 301 549 v4.1.1, the update
expected in 2026

that folds in WCAG 2.2.
Non-compliance means


market access restrictions (you can’t sell to
EU
enterprises),

fines that vary by member state

(from roughly €5,000
to €500,000+ depending


on country and severity), and exclusion
from

public-sector procurement. If your product
serves

European
customers, the EAA applies — regardless

of where your company

is incorporated.

ADA Title III

US courts have consistently treated digital

products as “places
of public
accommodation”

under the Americans with Disabilities Act.


There’s no WCAG version
written into the statute,

but courts apply
WCAG as the de facto standard

through
precedent —
and accessibility lawsuits

against SaaS companies are rising



(over 8,000 ADA digital cases filed in 2025).

“ADA compliance audit”
is one

of the
fastest-growing queries in our dataset —

the market
is waking up.

THE ENGAGEMENT

II.

From assessment
to remediation

We evaluate your platform against
WCAG 2.2 AA

criteria
and map every
finding to the relevant

ADA/EAA
requirement.
Deliverable: a compliance

gap
report with every issue tied
to a specific


regulatory clause.

FROM [2-3] WEEKS

Every issue severity-rated (critical, major,
minor —

the same model
as the audit,
mapped to regulatory

exposure) with
estimated
engineering effort.

Critical issues
first — the ones that could trigger

legal

action or block enterprise deals.

We design the compliant alternatives —

updated
components,
interaction patterns,
color
systems,
and form behaviors.
Your
engineers
implement,
or we handle
both through
a design retainer.

We prepare the accessibility conformance
report

(VPAT/ACR)
that enterprise
procurement teams

increasingly require
from
SaaS vendors before

signing —
often the difference between
clearing


a security-and-compliance review
and stalling in it.

Accessibility isn’t a one-time project.
Every feature

release can
introduce
regressions. We offer ongoing

compliance
monitoring
through a design retainer —


quarterly audits after each major
release,

regression
checks, and VPAT/ACR updates

as standards
evolve.
Most compliance
clients
transition to a monitoring
retainer

within 4–6
months
of the initial assessment.

Find your gaps before the deadline does

GET A COMPLIANCE ASSESSMENT

WHO DOES YOUR COMPLIANCE WORK

III.

Assessed by designers who


test
the way your users do

Compliance is only as good as the testing
behind
it,

and only useful if someone can act
on it. Most


vendors give you one half:
dedicated accessibility


firms produce
a findings report and hand


the redesign
back to you; generalist agencies run



an automated scan and miss most
of what fails.


We do both halves in one
engagement —
manual

assistive-technology
testing to find what’s
actually

broken,
then product design to fix it.

Manual testing,
not automated-only

Every assessment includes hands-on testing
with NVDA, VoiceOver,
and JAWS,

keyboard-
only navigation, and 200% / 400% zoom.

Automated scanners catch

roughly a third
of WCAG issues;
the regulated-exposure
failures usually sit

in the two-thirds
they miss.

Every finding tied to a regulatory clause

Not just “this fails WCAG 1.4.3” — we map
each issue to the specific
EAA /
EN 301
549
or ADA exposure it creates, severity-rated,
so your legal

and engineering teams
see
what’s legally urgent versus cosmetic.

Assessed at depth

[N]+ SaaS platforms taken through WCAG 2.2 AA assessment and remediation planning.

We design the remediation

Because we’re a product team, the work continues past the gap report
into the compliant components, patterns, and flows. The half dedicated audit
shops don’t do.

Because we’re a product team, the deliverable doesn’t stop at a list of failures —
we design the compliant alternative for every critical and high-severity finding.
That’s the half dedicated audit shops don’t do.

Because we’re a product team, the deliverable doesn’t stop at a list
of failures — we design the compliant alternative for every critical
and high-severity finding. That’s the half dedicated audit shops don’t do.

Because we’re a product team,
the deliverable doesn’t stop at a list
of failures — we design the compliant
alternative for every critical and high-
severity finding. That’s the half dedicated
audit shops don’t do.

Named lead on every audit

Placeholder

FAQ

IV.

Common questions

An accessibility audit (/accessibility) evaluates your product against WCAG criteria
and tells you what's broken. A compliance assessment maps those findings
to specific regulations (EAA, ADA) and tells you what's legally required to fix
and by when. Most clients need both.

An accessibility audit (/accessibility) evaluates your product
against WCAG criteria and tells you what's broken.
A compliance assessment maps those findings to specific
regulations (EAA, ADA) and tells you what's legally required
to fix and by when. Most clients need both.

An accessibility audit (/accessibility) evaluates your product against WCAG criteria and tells you
what's broken. A compliance assessment maps those findings to specific regulations (EAA, ADA)
and tells you what's legally required to fix and by when. Most clients need both.

An accessibility audit (/accessibility) evaluates
your product against WCAG criteria and tells
you what's broken. A compliance assessment
maps those findings to specific regulations
(EAA, ADA) and tells you what's legally required
to fix and by when. Most clients need both.

Yes. We prepare VPAT/ACR documentation based on our assessment findings —
the accessibility conformance report enterprise procurement teams increasingly
require from SaaS vendors during security-and-compliance review.

Yes. We prepare VPAT/ACR documentation based on our
assessment findings — the accessibility conformance report
enterprise procurement teams increasingly require from SaaS
vendors during security-and-compliance review.

Yes. We prepare VPAT/ACR documentation based on our assessment findings — the accessibility
conformance report enterprise procurement teams increasingly require from SaaS vendors during
security-and-compliance review.

Yes. We prepare VPAT/ACR documentation
based on our assessment findings —
the accessibility conformance report
enterprise procurement teams increasingly
require from SaaS vendors during security-
and-compliance review.

Compliance work is scoped per platform, not sold off a price list. A focused
assessment of a single product surface typically runs from 2–3 weeks;
a comprehensive assessment with remediation planning and VPAT/ACR
documentation runs longer. Remediation cost depends on the severity and volume
of findings. We scope precisely after a short discovery call, once we understand
your platform's component count, framework, and regulatory exposure (EAA, ADA,
enterprise procurement).

Compliance work is scoped per platform, not sold off a price
list. A focused assessment of a single product surface typically
runs from 2–3 weeks; a comprehensive assessment
with remediation planning and VPAT/ACR documentation runs
longer. Remediation cost depends on the severity and volume
of findings. We scope precisely after a short discovery call,
once we understand your platform's component count,
framework, and regulatory exposure (EAA, ADA, enterprise
procurement).

Compliance work is scoped per platform, not sold off a price list. A focused assessment of a single
product surface typically runs from 2–3 weeks; a comprehensive assessment with remediation
planning and VPAT/ACR documentation runs longer. Remediation cost depends on the severity
and volume of findings. We scope precisely after a short discovery call, once we understand your
platform's component count, framework, and regulatory exposure (EAA, ADA, enterprise
procurement).

Compliance work is scoped per platform, not
sold off a price list. A focused assessment
of a single product surface typically runs from
2–3 weeks; a comprehensive assessment
with remediation planning and VPAT/ACR
documentation runs longer. Remediation cost
depends on the severity and volume
of findings. We scope precisely after a short
discovery call, once we understand your
platform's component count, framework,
and regulatory exposure (EAA, ADA, enterprise
procurement).

Yes. We audit against your existing VPAT or internal audit results and focus
on the gaps — faster and more cost-effective than a full assessment.

Yes. We audit against your existing VPAT or internal audit results
and focus on the gaps — faster and more cost-effective than
a full assessment.

Yes. We audit against your existing VPAT or internal audit results and focus on the gaps — faster
and more cost-effective than a full assessment.

Yes. We audit against your existing VPAT
or internal audit results and focus on the gaps
— faster and more cost-effective than a full
assessment.

We offer accelerated timelines for compliance-critical projects. We'll scope
the engagement to prioritize the most legally exposed issues first.

We offer accelerated timelines for compliance-critical projects.
We'll scope the engagement to prioritize the most legally
exposed issues first.

We offer accelerated timelines for compliance-critical projects. We'll scope the engagement
to prioritize the most legally exposed issues first.

We offer accelerated timelines for
compliance-critical projects. We'll scope
the engagement to prioritize the most legally
exposed issues first.

That's more common than not having one. A design system that isn't working
is usually a governance problem, not a component problem — unclear ownership,
no contribution model, drift between code and design. We audit how the system
is actually used, then fix the operating model around it: decision rights, contribution
workflow, release cadence, documentation engineers accept. Sometimes
the answer is consolidating what you have rather than rebuilding — that's a cheaper
answer, and we give it when it's true. For teams preparing for AI tooling (Code
Connect, MCP, DTCG tokens), we assess AI-readiness specifically.

That's more common than not having one. A design system that
isn't working is usually a governance problem, not a component
problem — unclear ownership, no contribution model, drift
between code and design. We audit how the system is actually
used, then fix the operating model around it: decision rights,
contribution workflow, release cadence, documentation
engineers accept. Sometimes the answer is consolidating what
you have rather than rebuilding — that's a cheaper answer, and
we give it when it's true. For teams preparing for AI tooling
(Code Connect, MCP, DTCG tokens), we assess AI-readiness
specifically.

That's more common than not having one. A design system that isn't working is usually
a governance problem, not a component problem — unclear ownership, no contribution model,
drift between code and design. We audit how the system is actually used, then fix the operating
model around it: decision rights, contribution workflow, release cadence, documentation engineers
accept. Sometimes the answer is consolidating what you have rather than rebuilding — that's
a cheaper answer, and we give it when it's true. For teams preparing for AI tooling (Code Connect,
MCP, DTCG tokens), we assess AI-readiness specifically.

That's more common than not having one.
A design system that isn't working is usually
a governance problem, not a component
problem — unclear ownership, no contribution
model, drift between code and design. We
audit how the system is actually used, then fix
the operating model around it: decision rights,
contribution workflow, release cadence,
documentation engineers accept. Sometimes
the answer is consolidating what you have
rather than rebuilding — that's a cheaper
answer, and we give it when it's true.
For teams preparing for AI tooling (Code
Connect, MCP, DTCG tokens), we assess
AI-readiness specifically.

Need the technical audit first?

SEE ACCESSIBILITY

Compliance deadlines
don't move.
Neither should
your roadmap.

GET A COMPLIANCE ASSESSMENT