Insights
19/08/2026

European Accessibility Act: pharma website compliance

What the European Accessibility Act actually requires, what it does not, and a practical sequence for addressing it rather than reacting under pressure.

In this article

What this covers

The European Accessibility Act has been in force since June 2025, and for pharma companies with any consumer-facing web presence — e-commerce, booking flows, patient portals, downloadable leaflets — it changes accessibility from a UX nice-to-have into a legal compliance question with a deadline attached. This article sets out what the EAA actually requires, who genuinely falls in scope and why that determination is not ours to make, and the practical sequence of audit, prioritisation and remediation that holds up under real scrutiny — including the gap, untagged PDFs, that most automated checks miss entirely.

What the EAA actually is

As set out in the European Accessibility Act (EAA), formally Directive (EU) 2019/882, the legislation has applied since 28 June 2025 to companies above defined size and turnover thresholds that sell products or services to consumers within the EU. For anything published on the web — marketing sites, patient portals, e-commerce or booking flows — the reference technical standard is EN 301 549, which in practice points back to WCAG 2.1 AA as the conformance level regulators and courts will actually check against. See what is EN 301 549 for how that standard is structured and what it covers beyond the web, including documents, software and hardware interfaces.

What makes the EAA different from most accessibility guidance pharma companies have seen before is that it is now law with ongoing compliance considerations, not a best-practice recommendation. That shift changes how the topic should be handled internally: from something UX might look into eventually, to a compliance item with an owner, defined remediation priorities and a real cost of inaction.

What "in scope" actually means for a pharma company specifically

The EAA applies based on company size thresholds and whether you sell to EU consumers — not based on being a pharmaceutical company specifically. That single distinction matters more than it sounds: a mid-size pharma with a patient-facing e-commerce function, an appointment or sample-request booking flow, or a direct-to-consumer portal is more likely to fall in scope than a B2B-only CDMO of similar size that only ever deals with other businesses. Two companies of near-identical headcount and revenue can land on opposite sides of the line purely because of who their end customer is.

Determining actual scope is a legal question your compliance function needs to answer directly, using the size and turnover thresholds together with the nature of your consumer-facing activity. What we can tell you, and what the rest of this article covers, is what WCAG 2.1 AA conformance actually requires in practice once you are in scope — because that work is the same regardless of which side of the legal line you end up on.

Why we will not tell you if it applies to you

Whether your specific company and properties fall within scope depends on facts about your business — size, turnover, which markets you serve consumers in, how your web presence is structured — that only your legal counsel can properly assess with the full picture in front of them. We build to the standard; the scope determination itself is not ours to make.

A red flag worth remembering

Be wary of any agency, including one you are talking to about this, that claims confidently to know whether the EAA applies to you without having reviewed your actual corporate structure and revenue. That confidence is not something a web vendor is in a position to have.

Why building to it makes sense regardless

Independent of the formal legal trigger, EN 301 549 and WCAG 2.1 AA represent genuine good practice, not regulatory box-ticking. Sufficient colour contrast, full keyboard operability, a logical heading and landmark structure, and accessible documents all benefit every visitor who interacts with the site — older users, people on a phone in bright sunlight, anyone using a screen reader for any reason, not only the specific population the regulation was written to protect.

That is also why building to the standard is defensible even before a formal scope determination is made: if legal counsel later concludes you are in scope, the work is already done; if they conclude you are not, you still end up with a more usable site for every visitor. There is no version of this where doing the work turns out to have been wasted effort.

A practical sequence, not a panic response

Once a decision has been made to act, the sequence matters as much as the intent. Treating every finding as equally urgent, or starting remediation before you actually know what is broken, wastes budget and rarely produces a site that would hold up under real scrutiny. A defensible approach follows a fixed order:

  1. Audit first — automated scanning combined with manual keyboard and screen-reader testing, since automated tools alone catch only a fraction of real WCAG failures.
  2. Prioritise by real impact — rank findings by how much they actually block a user from completing a task, not simply by how many instances a scanner reports.
  3. Remediate at design and code level — fix the underlying markup, components and design decisions rather than layering on superficial patches that happen to satisfy one specific automated check.

See accessibility compliance for the full process we run through with clients, including how each stage is scoped and validated.

The gap almost everyone misses

Untagged PDFs are consistently the largest, least visible gap we find during audits. A site can pass an automated scan with a clean bill of health while every patient information leaflet, safety data sheet or downloadable form remains completely unusable with a screen reader, because the scan checked the web page that links to the PDF and never looked inside the document itself. For a pharma company, that gap is not a minor technicality — leaflets and safety documents are often exactly the content a patient with a disability most needs to read unassisted.

Compliance and enforcement considerations

Enforcement varies by EU member state, since the EAA is transposed into national law rather than applied uniformly — Germany’s own transposition, the Barrierefreiheitsstärkungsgesetz (BFSG), is one example of how a member state has set its own thresholds and enforcement route — but the realistic exposure across jurisdictions is a combination of regulatory penalties and reputational risk. In a sector where trust is already a core part of the brand, an accessibility failure that becomes public reads as a company that does not take its patients seriously — a harder reputation to repair than the underlying technical fix would have cost to prevent.

The practical cost of remediation after a complaint or an enforcement action is also typically higher than proactive conformance work would have been: fixes completed reactively after a complaint or enforcement action can cost more than planned remediation work.

What to do if the deadline has already passed for you

Address it now, in the order set out above, rather than not at all. There is no version of “it is too late to start” that makes sense here — every week without proper accessibility work is ongoing exposure, and starting late is still measurably better than continuing not to start.

EAA deadline FAQ

Does the EAA apply to our company?

That is a legal determination for your compliance counsel, based on company size and turnover thresholds together with whether you sell to EU consumers, not on being a pharmaceutical company specifically. Two companies of similar size can land on opposite sides of that line depending on their end customer, which is why scope is not something a web vendor should confidently claim to know. See does the EAA apply to pharma websites for what is publicly known about the thresholds.

What is the actual technical standard?

EN 301 549 is the reference technical standard, which points to WCAG 2.1 AA as the conformance level regulators and courts check against in practice. It covers more than the website itself, including documents like patient leaflets and any downloadable forms, which is where most sites carry hidden gaps. See what is EN 301 549 and WCAG 2.1 vs 2.2 for how the standard is structured.

What is the single biggest gap you find during audits?

Untagged PDFs — a site can pass an automated accessibility scan with a clean result while every patient leaflet, safety data sheet or downloadable form stays unusable with a screen reader, because the scan checks the web page linking to the PDF and never looks inside the document. For a pharma company, that gap sits exactly on the content a patient with a disability most needs to read unassisted.

Does this apply to a company outside the EU?

Yes, if you serve EU consumers above the relevant size and turnover thresholds, since the EAA applies based on who you serve rather than where your company is headquartered. A non-EU company selling consumer-facing products or services into the EU falls under the same obligation as an EU-based one at equivalent scale, which is a distinction worth confirming with counsel rather than assuming away by geography.

CODE GxP

Get audited against
EN 301 549 now

Tell us what you have and we will check it properly, regardless of your formal scope determination.

contact us
Contact Form

Tell us
about your project

Tell us about your organization’s context and the planned scope of the project.
CODE GxP, as the data controller, will process your data in order to respond to the query and/or request you submit through this contact form. Privacy Policy.
Our site uses cookies to collect information about your device and browsing activity. We use this data to improve the site, ensure security and deliver personalized content. You can manage your cookie preferences by clicking here.
Accept cookies Configure Decline cookies
Basic cookie information
This website uses cookies and/or similar technologies that store and retrieve information when you browse. In general, these technologies can serve very different purposes, such as, for example, recognizing you as a user, obtaining information about your browsing habits or personalizing the way in which the content is displayed. The specific uses we make of these technologies are described below. By default, all cookies are disabled, except for technical ones, which are necessary for the website to function. If you wish to obtain more information or exercise your data protection rights, you can consult our Cookie Policy".
Accept cookies Configure
Technical cookies needed Always active
Technical cookies are strictly necessary for our website to work and for you to navigate through it. These types of cookies are those that, for example, allow us to identify you, give you access to certain restricted parts of the page if necessary, or remember different options or services already selected by you, such as your privacy preferences. Therefore, they are activated by default, your authorization is not necessary.Through the configuration of your browser, you can block or alert the presence of this type of cookies, although such blocking will affect the proper functioning of the different functionalities of our website.
Analytics cookies
Analytics cookies are used to analyse website behaviour anonymously. They help us measure activity and improve the website.
Confirm preferences
Title
Popupcontent
Contact us
CODE GxP, as the data controller, will process your data in order to respond to the query and/or request you submit through this contact form. Privacy Policy.
Aceptar