Skip to main content
Dark green background, "Weak Application Security Can Cost You Millions," 3 slanted images of fingers pointing to digital locks, and a "Learn the Basics" button
Is EAA Compliance a Project or a Program?Laws and Regulations
5 min readFor GRC Leaders

Is EAA Compliance a Project or a Program?

The Question Assistive Technology Hand

You launched your European Accessibility Act (EAA) conformance initiative in early 2025. Your team audited the e-commerce platform, fixed critical violations, published an accessibility statement, and met the June deadline. The project closed, and the budget Web Accessibility Specialist reallocated.

Six months later, your legal team forwards a formal information request from a national market surveillance authority. Your product team just deployed a new checkout flow that reintroduces violations your original audit caught. A civil society organization sends a pre-litigation notice citing non-conformance on your mobile app.

The core question facing compliance leaders: Should you treat EAA conformance as a bounded project with a defined end state, or as a continuous program that requires permanent infrastructure, budget, and governance?

The first year of enforcement since the June 2025 deadline makes this question urgent. France has seen civil society lawsuits against Auchan, Carrefour, E. Leclerc, and Picard. Germany's private warning letters began arriving within weeks of the BFSG taking effect. The Dutch Consumer and Market Authority sent information requests to e-commerce operators worldwide, including companies outside the EU. Sweden's PTS received 124 public complaints in the first months and opened regulatory cases against larger retailers.

The Case for Treating EAA as a Project

Organizations with finite compliance budgets have reasons to structure EAA work as a scoped project rather than an ongoing program.

Define Clear Deliverables: Audit against EN 301 549. Remediate identified violations. Publish the accessibility statement. Establish the complaint mechanism. These are discrete outputs with measurable completion criteria. You can assign them to a project team, track progress, and declare success when the work is done.

Avoid Permanent Overhead: A compliance program requires dedicated headcount, recurring audit cycles, and continuous monitoring. For mid-market organizations with 10 to 50 employees, that overhead can represent a significant percentage of operational capacity. If you're confident your digital properties won't change significantly post-launch, a project model keeps costs contained.

Engage External Expertise Efficiently: Accessibility conformance testing requires specialized knowledge most organizations don't maintain in-house. A project structure lets you engage consultants or agencies for a defined engagement, implement their recommendations, and release them when the work concludes.

No Explicit Mandate for Ongoing Monitoring: The EAA requires that products and services meet accessibility requirements. It doesn't prescribe the internal governance model you use to maintain conformance. If your digital properties are relatively static and you're prepared to commission spot audits when changes occur, a project approach technically satisfies the legal obligation.

The Case for Treating EAA as a Program

The enforcement pattern emerging across EU Member States suggests the project model creates substantial risk.

Constantly Changing Digital Properties: Unless you've frozen all development, your website and mobile applications are evolving. New features ship, third-party integrations update, and marketing campaigns launch landing pages. Each change introduces conformance risk. The Carrefour case illustrates the problem: The company reported 71% conformance against France's RGAA standard, but the court Web Accessibility Specialist direct that partial conformance doesn't satisfy accessibility obligations. If you audited once in 2025 and haven't tested since, you don't know your current conformance state.

Enforcement Looks for Demonstrated Progress: When the Dutch ACM sends an information request or the Swedish PTS opens a regulatory case, they're not asking whether you met the June 2025 deadline. They're asking what you've done since. Organizations that can produce audit reports, remediation logs, and governance documentation showing continuous attention are in a stronger position than those presenting a single 2025 audit and nothing after.

Evolving Technical Standards: EN 301 549 is due for a new version in 2026. Emergency communications services come into scope in June 2027. Legacy products must comply by 2030. If your governance model treats each of these as a new project requiring new budget approval and vendor selection, you'll spend more time ramping up than maintaining conformance.

Civil Society and Private Enforcement: The French NGO lawsuits and German warning letters demonstrate that enforcement exposure doesn't come only from national authorities. Your organization can face legal action from disability advocacy groups or competitors using accessibility non-conformance as grounds for unfair competition claims. These actors don't send advance notice or grace periods.

Where Practitioners Actually Land

Most organizations aren't choosing purely between project and program models. They're running hybrids that reflect their risk tolerance and resource constraints.

Minimum Viable Program: Includes quarterly automated scans, an annual manual audit, a defined escalation path when violations are detected, and a single point of accountability who owns the conformance record. This doesn't require a full-time accessibility team, but it does require treating conformance as a recurring line item rather than a one-time expense.

Mature Program: Adds pre-deployment conformance gates, component library governance, procurement requirements for third-party tools, and training for product and engineering teams. Organizations in high-enforcement jurisdictions or those already subject to the Corporate Sustainability Reporting Directive are moving toward this model because accessibility conformance intersects with ESG reporting obligations.

Project-Until-Enforcement Approach: Treats EAA as a project until the organization receives a regulatory notice, then converts to a program under pressure. This is the highest-risk path. Germany's penalty framework allows up to €100,000 per violation. Spain's tiered structure reaches €1 million for very serious violations. The Netherlands can impose €900,000 or 10% of annual revenue. Building a compliance program while defending against enforcement action is expensive and chaotic.

Our Take

If your digital properties are static, your development has frozen, and you're prepared to commission a new audit before every product change, a project model might work. That describes almost no one.

For everyone else, treating EAA conformance as a program isn't perfectionism or over-engineering. It's the only structure that aligns with how enforcement actually operates. Regulators and courts are looking for evidence of ongoing attention. Your digital properties are changing too frequently for point-in-time audits to remain valid. The technical standards and in-scope services are expanding through 2030.

The organizations that will defend their conformance position confidently when the Dutch ACM sends an information request or a French NGO files an emergency injunction are the ones building compliance records now. That requires permanent infrastructure, recurring budget, and a governance model that treats accessibility as a continuous obligation rather than a deadline you met once.

If you're still operating on the project model, the question isn't whether you'll eventually need a program. It's whether you'll build one proactively or under enforcement pressure.

European Accessibility Act Overview

a promotional banner asking how ready are you for PCI DSS 4.0? With a call-to-action to get the checklist now.

You Might Also Like