A company orders a new website. Six months later the market surveillance authority finds that the checkout cannot be completed without a mouse. The operator turns to the agency that built it and receives a quote for the fix. The case has a simple cause: the contract said nothing about accessibility. What was not agreed is not a defect but a change order. This article shows which wording turns an expectation into an owed quality, how an acceptance procedure worthy of the name runs, and which rights remain open once acceptance has taken place.
Key takeaways
- Accessibility is a defect only if it was agreed. Section 633(2) sentence 1 BGB puts the agreed quality first; without an agreement, customary use decides, and that is hard to prove in a dispute.
- The duty stays with the operator. Section 14(1) BFSG addresses the service provider, not its suppliers: a contract does not shift responsibility towards the authority.
- Acceptance tips three things at once: the burden of proof, the payment becoming due, and the start of the limitation period. Testing before costs days; testing after costs rights.
- Anyone who accepts a known defect without reserving their rights loses subsequent performance, self-remedy, rescission and price reduction (Section 640(3) BGB).
- An automated scan cannot carry an acceptance. The WebAIM Million states that an absence of detected errors proves nothing; the five conformance requirements in EN 301 549 call for manual testing.
- While defects remain open, part of the payment may be withheld. Under Section 641(3) BGB, twice the cost required for removing the defect is usually deemed appropriate.
Who carries the duty and who implements it
The German Accessibility Strengthening Act addresses economic operators, not tools. Section 3(1) BFSG requires services offered or provided by an economic operator to be accessible (BFSG). Anyone running an online shop or a booking portal is therefore a service provider within the meaning of the act, regardless of who built the software. Section 14(1) BFSG frames this as a prohibition with a reservation of permission: the service may only be offered if it meets the requirements of the implementing regulation and the information under Annex 3 is made available in an accessible form (BFSG).
Implementation, by contrast, rarely happens in house. Between the duty and the source code sits a contract with an agency, a system integrator, a shop vendor or a freelance development team. That separation is the heart of the problem: the authority talks to the operator, the operator talks to the supplier, and between those two conversations lies a contract document that often does not mention accessibility at all. Section 14(3) BFSG additionally calls for continuous compliance for as long as the service is offered or provided (BFSG), and Section 14(4) BFSG requires corrective measures in case of non-conformity (BFSG). How an official audit runs in practice is described in BFSG market surveillance: how an audit unfolds.
A contract does not shift the responsibility
Contract for work or for services: the difference in a dispute
Section 631(1) BGB defines the contract for work: the contractor owes the production of the promised work, the customer owes the agreed remuneration (BGB). What is owed is a result. Section 611(1) BGB describes the service contract differently: whoever promises services owes the performance of those services (BGB). What is owed is an activity. The entire difference in enforceability sits between those two sentences.
For accessibility, the classification is decisive. Under a contract for work, a checkout that cannot be operated is a defect, and the catalogue in Section 634 BGB is open. Under a service contract, typical for maintenance and support billed by effort, that remedy does not exist; anyone unhappy with the hours delivered may terminate, but cannot demand a fix. Section 631(2) BGB explicitly states that a result to be brought about by work or a service may also be the subject of a contract for work (BGB). So the heading on the letterhead does not decide; the agreed content does.
| Provision | What it says | What follows for the contract |
|---|---|---|
| Section 631(1) BGB | The contractor owes the production of the promised work. | A result is owed. The target description has to be phrased so that it can be tested. |
| Section 633(2) sentence 1 BGB | The work is free of material defects if it has the agreed quality. | The quality agreement is the first yardstick and takes precedence over expectation. |
| Section 640(1) sentence 1 BGB | The customer is obliged to accept the work produced in conformity with the contract. | Without a defect there is a duty to accept. A refusal needs a named test result. |
| Section 640(3) BGB | With knowledge of the defect, rights survive only with a reservation. | Known findings belong in the acceptance record, not in a later message. |
| Section 634a(2) BGB | The limitation period begins upon acceptance. | The acceptance date also starts the clock for defect claims. |
| Section 3(1) BFSGV | The state of the art is to be observed when meeting the requirements. | A rigid reference to one edition ages. The clause needs a date and a route for updates. |
Two points are regularly overlooked. First, the catalogue of defect rights does not apply without limits: Section 650(2) BGB exempts consumer contracts on the production of digital products from Sections 633 to 639 and from Section 640 BGB (BGB). Between businesses that plays no role; for commissions from private individuals it very much does. Second, a subsequent maintenance contract does not automatically shift responsibility for the result back; what is owed there must be described there just as clearly. Anyone procuring publicly already knows this diligence from the statement of work, as accessibility in public tenders shows.
The quality agreement: what belongs in the contract
Section 633(1) BGB obliges the contractor to procure the work for the customer free of material and legal defects (BGB). Subsection 2 sentence 1 names the yardstick: the work is free of material defects if it has the agreed quality (BGB). Only where nothing is agreed does the fallback in Section 633(2) sentence 2 BGB apply, under which the use presupposed by the contract, otherwise customary use and customary quality, count (BGB). That order is the whole message of this section: the agreement takes precedence over expectation.
A robust agreement names three things: the yardstick, the scope and the procedure. A sentence such as "the website is accessible" does not work as a yardstick; it cannot be tested and is worth little in a dispute. The standard makes it testable. Clause 9.6 of EN 301 549 requires a web page to satisfy all five WCAG conformance requirements at Level AA (EN 301 549), among them full pages and complete processes rather than individual building blocks. What the standard means in relation to the BFSG is set out in EN 301 549: the EU standard behind the BFSG.
Name the yardstick
Spell out standard, edition and level: EN 301 549 in the edition in force at contract conclusion, WCAG Level AA, plus the reference to the state of the art under Section 3 BFSGV.
Delimit the scope
Which page types, which templates, which processes? A basket without a checkout is not a complete process and does not satisfy the requirement in clause 9.6.
Settle third-party content
Embedded maps, payment dialogues and chat windows belong explicitly inside the scope or explicitly outside it, as third-party widgets and BFSG duties shows.
Define the evidence
Who tests, with which method, in which form? A report with success criterion, location and evidence per finding is something other than a tool printout.
Reflect the ongoing duty
Section 14(3) BFSG calls for continuous compliance. Editorial training, component maintenance and retests need their own lines and their own budget.
Describe the consequences
Deadline for subsequent performance, withholding, substitute performance: what follows from the statute anyway should be written out and dated in the contract.
A sentence that carries no weight in a dispute
Acceptance is the tipping point
Section 640(1) sentence 1 BGB obliges the customer to accept the work produced in conformity with the contract (BGB). Sentence 2 limits this: acceptance may not be refused on account of insignificant defects (BGB). That settles the first question of every acceptance. It is not "are there findings?" but "are the findings significant?". A checkout that cannot be completed without a mouse is significant; a missing language attribute on a peripheral page usually is not. That assessment belongs in the record with reasons.
Acceptance changes three things at the same time. The remuneration falls due (Section 641(1) BGB). The limitation period for defect claims begins (Section 634a(2) BGB). And the burden of proof switches: before acceptance the contractor shows that the agreed quality has been reached, afterwards the customer has to make out the defect. Section 640(3) BGB is particularly consequential: anyone who accepts a defective work despite knowing the defect keeps the rights under Section 634 numbers 1 to 3 BGB only if they reserve them upon acceptance (BGB). A test report that arrives two weeks before the date turns every finding named in it into a known defect. And anyone who lets a set acceptance deadline pass without naming at least one defect has accepted without saying so.
- Announce date and scope in writing, with the list of page types and processes to be tested.
- Finish the test before the acceptance date, not during it: otherwise there is no time to assess significance.
- Map every finding to a success criterion and a location; without that mapping the notice of defect is open to challenge.
- List significant and insignificant findings separately and give reasons for the classification.
- Expressly reserve known but tolerated findings; the reservation belongs in the record and is signed by both sides.
- Record the moment of acceptance; it starts the limitation period and makes payment due.
- Withhold an appropriate part of the remuneration while notified defects remain open (Section 641(3) BGB).
A work is also deemed to have been accepted if the contractor has set the customer an appropriate deadline for acceptance after completion of the work and the customer has not refused acceptance within that deadline stating at least one defect.
Defect claims: what remains available after acceptance
Section 634 BGB lists the customer's rights where the work is defective: subsequent performance under Section 635, self-remedy with reimbursement of expenses under Section 637, rescission or price reduction under Sections 636, 323, 326(5) and 638, and damages or reimbursement of futile expenses (BGB). The list is not a free choice. Subsequent performance comes first, and anyone skipping it often loses the remaining rights at that very point.
With subsequent performance the contractor chooses whether to remove the defect or produce a new work (Section 635(1) BGB). Only after an appropriate deadline has passed without success may the customer remove the defect themselves and demand reimbursement of the necessary expenses (Section 637(1) BGB), and under Section 637(3) BGB they may demand an advance for it (BGB). That is a practically important lever when a supplier stops delivering: remediation by another team becomes possible without fronting the cost. Instead of rescinding, the customer may also reduce the remuneration by declaration to the contractor (Section 638(1) BGB). Where such a substitute performance is due, an enquiry about defect remediation is the direct way in.
- Name the defect: success criterion, location, effect on use, evidence as an image or a recording.
- Demand subsequent performance and set an appropriate deadline, with a date rather than the word "soon".
- Withhold an appropriate part of the remuneration; twice the removal cost is usually deemed appropriate (Section 641(3) BGB).
- Once the deadline has passed without success, decide: self-remedy with an advance, price reduction or rescission.
- Retest and document the result; remediation counts as done only once a retest has passed.
- Keep an eye on the limitation period; under Section 634a(2) BGB it begins upon acceptance.
How long defect claims run
The test report as a notice of defect
A notice of defect without evidence is an opinion. The test report turns it into a verifiable assertion, provided it is built so that each finding can be accepted or disputed on its own. That calls for the success criterion, the precise location, the observed and the expected state, the test environment and a piece of evidence. How such a report becomes an order of remediation is shown in from test report to remediation plan.
An automated scan is not enough for that. The evaluation of one million home pages found an average of 56.1 errors per page in February 2026 and detectable WCAG failures on 95.9 percent of home pages (WebAIM Million, 2026). The same report contains the sentence that matters for every acceptance: an absence of detected errors indicates neither accessibility nor conformance (WebAIM Million, 2026). For acceptance that means the scan narrows things down and the manual test decides. Why purchased script solutions do not close that gap is set out in accessibility overlays and BFSG conformance.
- Test subject with address, date, version and test environment made up of browser, assistive technology and resolution.
- Per finding: success criterion, level, location in the page tree, observed and expected behaviour.
- Separation between failure, advisory note and item that cannot be tested; an untestable item is not a passed item.
- Assessment of significance in the sense of Section 640(1) sentence 2 BGB, so that the acceptance decision is reasoned.
- Mapping of each finding to a template or component, so that one fix reaches several pages at once.
- A verifiable statement on complete processes and not merely on individual pages (EN 301 549, clause 9.6).
Making clauses testable
The building blocks below are not legal advice and do not replace review by a lawyer. They show which details make a clause testable: named standard, named scope, named procedure, named consequence. The deadlines in them are placeholders and should be sized to the project. The requirements behind all of this are summarised in the overview of BFSG requirements.
Sec. 4 Agreed quality: accessibility
(1) The contractor owes the production of the page types and
processes listed in Annex 2 in an implementation that meets
the requirements of EN 301 549 in the edition in force at
the conclusion of this contract, including the five
conformance requirements under clause 9.6 at Level AA.
(2) The scope covers the complete processes registration, sign
in, basket, checkout and contact, in each case from the
entry page through to the confirmation page.
(3) For embedded third-party content under Annex 3 the
contractor owes an equivalent alternative operable without a
mouse, together with its documentation.
(4) Where the state of the art within the meaning of Sec. 3
BFSGV changes, the contractor notifies the resulting need
for adjustment within the period set out in Annex 4.The second building block governs what happens at acceptance. It picks up Section 640 BGB and turns the statutory rule into a procedure with dates and responsibilities. For heavily regulated sectors, the sector-specific examples are worth a look: for accommodation and hospitality in accessible hotel booking in hospitality, for health applications in digital health apps and accessibility under SGB V.
Sec. 9 Acceptance and defect claims
(1) The basis for acceptance is a test report under Sec. 4 that
states, for each finding, the success criterion, the
location, the observed and the expected behaviour and a
piece of evidence.
(2) The customer tests within the period set out in Annex 4
after notice of completion. If it passes without at least
one defect being stated, Sec. 640(2) BGB applies.
(3) Findings that render a complete process under Sec. 4(2)
unusable without a mouse or without a visual display count
as a significant defect within the meaning of Sec. 640(1)
sentence 2 BGB.
(4) Where known defects are tolerated at acceptance, the rights
under Sec. 634 numbers 1 to 3 BGB are expressly reserved in
the acceptance record (Sec. 640(3) BGB).
(5) Until notified defects are removed, the customer withholds
an appropriate part of the remuneration under Sec. 641(3)
BGB.Anyone discovering these building blocks only after the contract is signed is not empty handed. A supplementary agreement can fix the quality later on; it costs negotiation, but less than a dispute about customary quality. In running projects, taking it into the next statement of work is a workable route, especially where a new template or component is due anyway. For building a tested stock of components, accessible design system is the right way in, and how to lower the testing effort early in a project is described in accessibility by design. An independent WCAG audit serves as the acceptance basis, and its findings can serve as the basis of a notice of defect.
Sources
Related Articles
Which Website Content the BFSG Leaves Out
Section 1(4) BFSG exempts five types of content. How to split a grown document stock - and how the exemption quietly comes to an end.
Keeping Accessibility: Review Cadence After Go-live
The duty does not end at acceptance. Which events trigger a re-test, which sample size holds up and how long the evidence has to stay on file.
Usability Testing With Disabled Users: What Tools Miss
How a test round with blind, low-vision and motor-impaired participants is organised: recruitment, consent, task script, logging and the route into the remediation plan.