Skip to content
German Accessibility Act

Keeping Accessibility: Review Cadence After Go-live

The duty does not end at acceptance. Which events trigger a re-test, which sample size holds up and how long the evidence has to stay on file.

14 min read BFSGMonitoringNachprüfungMarktüberwachungWCAG 2.2

Acceptance is the day a website reaches a tested state. It is not the day the duty ends. Between acceptance and the next review there are releases, new landing pages, a replaced payment form, an updated theme and a standard that keeps moving. Every one of those changes can shift the state that an audit report and remediation plan once recorded. German law knows the difference and phrases the requirement as a continuous state rather than a cut-off date: the service provider must ensure that the requirements are met at all times while the service is offered or provided (Section 14(3) BFSG). This article turns that single sentence into something you can operate: a calendar with triggers, a sample of a defined size, an evidence file with a retention rule and a named role that sets off the notification when it matters.

Key takeaways

  • Section 14(3) BFSG frames accessibility as a continuous state: the requirements have to be met at all times while the service is offered or provided (BFSG). In day-to-day operation that becomes ongoing monitoring rather than a single pass.
  • The act names three kinds of change explicitly that the provider has to take into account: in the way the service is provided, in the applicable requirements and in the harmonised standards referred to (BFSG).
  • A live site drifts even without releases of your own. The number of automatically detected errors per home page rose by 10.1 percent within a single year (WebAIM Million).
  • A cadence that holds combines two kinds of trigger: the calendar and the event. For the state monitoring of public sector bodies the European methodology sets the calendar at annual intervals (Commission Implementing Decision (EU) 2018/1524).
  • The sample needs a fixed core plus a random share of at least 10 percent, otherwise every cycle tests the same pages and the rest of the site is never seen (Commission Implementing Decision (EU) 2018/1524).
  • Where non-conformity is established, corrective measures are required and the market surveillance authority has to be informed without undue delay (Section 14(4) BFSG). That duty needs a name inside the company, not a department.

Acceptance is a date, not a terminus

The starting picture is sobering, and it is getting worse. The annual analysis of one million home pages found automatically detectable WCAG failures on 95.9 percent of pages in February 2026 (WebAIM Million). A year earlier the share was lower: the study cites 94.8 percent for 2025 and notes that this reverses a run of small improvements over six years (WebAIM Million). This is not a finding about bad intentions but about movement. Sites grow, components are added, templates get copied, and every copy carries a defect a little further.

How strong that movement is shows in two further figures from the same study. The number of detected errors per home page rose by 10.1 percent against the 2025 analysis, starting from 51 errors per page (WebAIM Million). At the same time the pages themselves grew: the average number of elements per home page rose by 14.3 percent to 1437 in a single year (WebAIM Million). More elements mean more places where something can slip. A report describing a state from twelve months ago therefore describes a different website from the one being served today.

Many relapses arrive without a release

New barriers do not only appear in a deployment but also in everyday editing: an image without alternative text, bold type used as a heading, an embedded form from an external system, a campaign banner with text that is too light. Anyone who ties the cadence exclusively to releases does not measure precisely these ongoing changes.

What the act requires permanently

The legal basis is short and unambiguous. Section 14(3) sentence 1 BFSG requires the service provider to ensure that the accessibility requirements of the ordinance to be issued under Section 3(2) are met at all times while a service is offered or provided (BFSG). The words at all times carry the whole weight: they turn a test into a state. Which technical yardstick applies follows from that ordinance and from EN 301 549, which describes the requirements for Europe.

Sentence 2 names the triggers without calling them that. It requires the provider to take due account of changes in the way the service is provided, changes in the applicable accessibility requirements and changes in the harmonised standards or technical specifications referred to in the declaration of conformity (BFSG). That puts three kinds of change into the statutory text, and they cover exactly the cases that tip a tested state over: the service changes, the requirement changes, the yardstick changes.

Kind of changeTypical case in operationWhat the cadence makes of it
Way the service is providedrelease, theme change, new payment method, new booking flowevent-driven re-test at a scope defined in advance
Applicable accessibility requirementsamended ordinance, new reading by the authorityreconcile the test list, then test the criteria affected
Harmonised standards and specificationsnew edition of EN 301 549, new WCAG version referencedstandards reconciliation, then testing of the added criteria
Not in the wording, but in the effecteditorial work without any deploymentcalendar-driven sample independent of the release plan

The fourth row deliberately sits below the line. It does not follow from the wording but from its effect: if the requirements have to be met at all times, the duty also covers the period between two releases. A cadence that only reacts to deployments leaves precisely that period untested, and it is where most of the content work happens.

Six events that start a re-test

A trigger is a condition that starts a test on occurrence, without further discussion. Its value lies in moving the decision forward in time: it is taken once and applied from then on. The following six cover typical cases that can shift a tested state.

Release touching the interface

Any change to markup, components or interaction. Not every release touches the interface; tying the trigger to every deploy means testing too often at first and then not at all. The condition therefore reads: component changed or template changed.

Theme or design system change

A new theme replaces colours, spacing, focus styling and often the entire component library. Contrast values from the old report are no longer meaningful afterwards. A theme change therefore usually warrants a full re-test rather than a sample.

New third-party system in the path

An embedded booking window, a review component, a map service. Responsibility usually stays with whoever embeds the service. Embedded third-party components therefore belong in scope as soon as they sit in the user's path.

New version of the standard

WCAG 2.2 carries the date 12 December 2024 as a W3C Recommendation (W3C). When the referenced version changes, the difference list is tested rather than the whole catalogue. The added criteria can be settled in one pass.

Editorial growth

New pages, campaign routes, uploaded documents. Here the condition is a quantity rather than an event: once a defined number of new pages or documents is reached, the next sample runs. A content management system with guardrails lowers the error rate but does not replace testing.

Feedback from outside

A message through the feedback channel, a complaint, an enquiry from market surveillance. Every barrier reported from outside starts a test that goes beyond the reported place, because the same component usually sits in several places across the site.

These six triggers belong in a document with two columns: condition and scope. Anyone who determines the scope only when the event occurs negotiates it under time pressure, and time pressure usually cuts in the same place, namely manual testing. If the scope is fixed beforehand, the discussion has already been held when the event arrives.

The trigger belongs in the process, not in someone's memory

A trigger that only exists in a document is easily forgotten after a few releases. It becomes effective where the change is created: as an item in the definition of done, as a mandatory field in the change request, as a task that is attached automatically when a release ticket is opened.

The calendar: interval, scope, depth

Besides the events, the cadence needs an interval that runs even when nothing happens. For the monitoring of public sector bodies by the member states that interval is prescribed: after the first monitoring period, monitoring is carried out annually according to Commission Implementing Decision (EU) 2018/1524. The BFSG sets no such deadline for companies. The European methodology remains the most usable yardstick available, because it names the three quantities that decide any cadence: interval, sample size and depth of testing.

In practice a staggered set of passes works better than a single deadline. A short, narrow pass keeps the core paths clean; a long, broad pass catches what narrow passes miss. Automated testing tools carry the frequency, not the verdict: they reliably find contrast values, missing alternative texts and unlabelled form fields, but they make no decision about clarity, order or the sense of a text.

PassIntervalScopeDepth
Quick checkweekly to monthlyhome page, two core paths, newly published pagesautomated, followed by review of the hits
Samplequarterlyfixed core plus random shareautomated plus manual keyboard and screen reader testing
Full auditannuallyall page types and all user pathsmanual testing against WCAG 2.2 AA, with a report
Event teston occurrence of a triggerthe component affected and everywhere it appearsdepends on the trigger, from quick check to full audit

The annual audit is the anchor of this structure. It produces the report the accessibility statement can rest on, and it is the pass for which a full WCAG audit provides the right frame. The other three passes have a different job: they keep the distance between two annual audits short enough that a finding can still be traced back to whatever caused it. An error that is eleven months old can often no longer be attributed to a release.

The sample: which scope holds up

A sample is usable when it has two properties: it contains a fixed core that every cycle tests in the same way, and a share that nobody knows in advance. The European monitoring methodology solves this with a fixed list of page types and a random share of at least 10 percent of the defined sample (Commission Implementing Decision (EU) 2018/1524). The fixed part makes cycles comparable; the random part keeps the site from getting used to the test.

Translated to a company website, this yields a list that can be fixed once and applied every quarter from then on:

  • home page, login, search or sitemap, contact page, help page and the legal texts, meaning the pages every visitor reaches at some point
  • for each type of service offered, one page that actually delivers that service rather than merely announcing it
  • the accessibility statement together with the route for feedback, because it is itself an object of testing
  • pages with a different appearance or a different structure, such as campaign routes, landing pages and form pages
  • at least one downloadable document per document type, from the price sheet through the form to the instructions
  • one complete user path from the first page through to the confirmation page, not just individual pages from it
  • the random share, drawn from the remaining site by a recorded procedure rather than by feel

The second building block is the overlap between cycles. From the second monitoring period onwards, the European methodology requires at least 10 percent of previously monitored objects in the sample and at least 50 percent that were not monitored in the previous reporting period (Commission Implementing Decision (EU) 2018/1524). Transferred to a single website this means: part of the pages is tested again so that it becomes visible whether a fixed barrier has stayed fixed. The larger part rotates so that the site is covered step by step across the cycles.

What a sample does not deliver

A sample measures the state of the site, not the experience of a person. Whether a path without a mouse actually reaches the goal, and whether an error message arrives in an understandable form, shows up in usability testing with disabled participants. An annual cadence should contain at least one such test, otherwise the entire body of evidence stays automated.

Not every piece of content belongs in the sample. For certain holdings the act provides exemptions, for example for old recordings and archived material; which ones these are and where the exemption ends is set out in the article on content the BFSG leaves out. That boundary deserves a review once a year, because an update can end the exemption for the document concerned.

Evidence: what stays and for how long

A cadence without a file is an assertion. Section 14(2) BFSG ties retention not to a number of years but to the duration of the offer: the service provider keeps the information referred to in subsection 1 number 2 for as long as the service is offered or provided (BFSG). For this part there is therefore no deadline in the usual sense but a condition. As long as the service exists, the documents about it exist too.

At a second point the act does name a real deadline. Anyone relying on a disproportionate burden carries out that assessment for each service category or type at least every five years (Section 17(3) BFSG) and keeps the documented assessment for a period of five years after the service was last provided (Section 17(2) BFSG). Using that exemption therefore adds a second calendar entry, and it sits outside the ordinary testing cadence.

What belongs in the file follows from the question an authority will ask later: what was tested, when, by whom and at what scope, with what result, and what became of that result?

  • a test report per pass with date, test method, scope covered and the version of the standard applied
  • a list of the addresses tested, stating which belonged to the fixed core and which to the random share
  • the tools used with their version, plus the environment of the manual test, meaning browser and assistive technology
  • a remediation plan with priority, responsible role and due date per finding, carried forward rather than rewritten each time
  • proof of the fix: date, release or change, and the repeat test of the same place
  • items received through the feedback channel with date, reply and outcome, including those that turned out not to be confirmed
  • the version history of the accessibility statement, so that every published state stays tied to a test report

The accessibility statement is the only part of this file that is public. It connects the internal cadence with the outside view by naming the current state, the known limitations and the route for feedback. A maintained feedback mechanism is an inexpensive early warning system: it reports barriers before an authority does, and it produces exactly the records that are asked for later.

Notification: who flips the switch in house

The least comfortable part of the continuous duty sits in Section 14(4) BFSG and consists of two sentences with two different addressees. Sentence 1 points inwards: where there is non-conformity, the service provider takes the corrective measures necessary to bring the service into conformity with the accessibility requirements (BFSG). That is the duty a remediation plan covers anyway, and it rarely surprises anyone.

Sentence 2 points outwards and is easily overlooked. Where the service does not meet the requirements, the service provider informs the market surveillance authority and the market surveillance authorities of the Member States in which the service is offered or provided without undue delay (BFSG). Without undue delay means without culpable hesitation, so not necessarily the same day, but also not after the next sprint. The trigger is the finding, not the fix.

This raises a question no tool answers: who in the company establishes the non-conformity, and who reports it? If that stays open, the case travels between project management, legal and the service provider while the clock on undue delay keeps running. How a market surveillance procedure runs once it has started is described in the article on the market surveillance audit process.

StepWho decidesWhat is recorded
Record the findingtest team or the contracted providercriterion, location, severity, steps to reproduce
Classify as non-conformityrole named in advance inside the companyreasons for the classification with date and name
Define the corrective measureproduct ownership together with engineeringmeasure, estimated effort, due date
Notify market surveillancemanagement or an expressly authorised roletime, content, recipients, later responses
Prove the fixtest teamrepeat test of the same place with date and result
Update the statementeditorial team together with legalnew status, changed limitations, date

The second row is the important one. Not every finding is a non-conformity in the sense of the act, and not every non-conformity is a minor matter. Tying that classification to a role and recording its reasoning turns a judgement call into a traceable process. What belongs in the contract when a provider delivers these tests is set out in the article on acceptance and defect rights.

The frame this all sits in is set by Section 37 BFSG: in certain cases the administrative offence can be punished with a fine of up to one hundred thousand euro, and in the remaining cases with a fine of up to ten thousand euro (BFSG). That figure is no argument for panic but a piece of context: the legislator does not treat a breach of the continuous duty as a formality at the margin.

From calendar to habit

A cadence rarely fails on the plan and mostly on how well it connects. Three things decide whether it survives into the second year. It hangs on events that occur anyway rather than on a date of its own. It creates tasks in the system where the work already lives rather than in a spreadsheet beside it. And it has a role that owns the rhythm, not just the testing.

That a cadence also catches simple things again shows in the most common finding of all. Text with insufficient contrast was found on 83.9 percent of the home pages analysed, up from 79.1 percent the year before (WebAIM Million). Contrast is machine measurable, usually fixable with little effort and still the finding that returns most reliably, because it is created afresh with every new element. That is exactly what the short, frequent pass is for, and exactly why it does not replace the annual manual test.

Accessibility is not a state a project reaches, but a property an operation maintains.

Working principle for operation after go-live

Getting started is smaller than it looks from outside. A cadence comes out of four decisions: a list of triggers, a sample with a fixed core, a place to file evidence with a retention rule, and a named role for the classification. Take those four decisions once and the rest is repetition. Whether the ongoing testing stays in house or is placed under an ongoing maintenance contract is a question of capacity; the duty itself stays with the provider of the service either way. How to set up accessibility monitoring that brings calendar, sample and evidence file together is what we work out in a first conversation.

Sources and studies

This article draws on the German Accessibility Strengthening Act (Sections 14, 17 and 37 BFSG), on Commission Implementing Decision (EU) 2018/1524, on the WebAIM Million 2026 and on the Web Content Accessibility Guidelines 2.2 published by the W3C. The figures quoted refer to the state of the respective publication.

Related Articles

German Accessibility Act

Accessible E-Learning: Platforms, Courses and Quizzes

Paid online courses fall under the BFSG, universities under BITV 2.0. How to make the learning journey from booking to certificate genuinely accessible.

13 min read
Recht & Compliance

BFSG Market Surveillance 2026: How an Audit Works

Market surveillance authorities, information requests, deadlines and fines up to EUR 100,000: how a BFSG audit unfolds and how to prepare for it.

13 min read
German Accessibility Act

Third-Party Widgets: BFSG Duties for Embedded Tools

Booking calendars, chat widgets and payment iframes are third-party code, yet BFSG duties stay with the operator. Evidence, testing and fallback routes.

13 min read