What the law actually asks of your website
The duties are simpler than most summaries make them — and the monitoring data shows exactly where bodies fall short. Knowing both is the difference between a compliance programme and a panic.
The two duties
The Public Sector Bodies (Websites and Mobile Applications) (No. 2) Accessibility Regulations 2018 place two obligations on councils, universities, NHS bodies and most other public organisations:
- Meet the standard. Websites and mobile apps must satisfy WCAG 2.2 level AA — the current version of the international accessibility standard, which the UK monitoring body adopted in its audits from 2024 onwards.
- Publish an accessibility statement. Every in-scope body must publish, in a prescribed format, a statement saying how accessible the site is — including a list of known non-compliances and any claim of disproportionate burden. The statement must be reviewed and kept current: an accurate list of failures is compliant; a stale statement is itself a breach.
The second duty is widely misunderstood. Admitting failures in your statement is not an admission of unlawfulness — it is the mechanism the regulations expect. What the regime penalises is silence, staleness and inaction.
How monitoring and enforcement work
The Government Digital Service monitors compliance on behalf of the Cabinet Office, sampling public-sector websites each year — a mix of simplified and detailed audits, followed up until issues are fixed. In its last published reporting period GDS monitored 1,203 websites and 21 mobile apps.
Enforcement of the underlying equality duty sits with the Equality and Human Rights Commission in England, Scotland and Wales, and the Equality Commission for Northern Ireland. An inaccessible public-sector website can amount to a failure to make reasonable adjustments under the Equality Act 2010 — which is where complaints, letters and reputational exposure arise.
The number that should focus attention: at first test, only 8% of sampled bodies had a fully compliant accessibility statement — and GDS specifically flagged that many statements had not been reviewed within the previous twelve months.
The most common technical failures across the sample were insufficient colour contrast, missing visible focus indicators, keyboard navigation problems and reflow at high zoom — the same four criteria that recur in individual bodies' own statements.
Why the gap persists
Very few public bodies are ignoring accessibility. The pattern we see in published statements is different: the failures were identified — often years ago — and listed honestly, and then remediation never reached the top of a stretched digital team's queue. Scanners keep reporting; statements keep ageing; the list never gets shorter.
There are structural reasons too. Many public-sector websites run on supplier platforms where the in-house team cannot change code at all. Document backlogs (PDFs, spreadsheets, committee papers) sit outside normal web workflows. And accessibility work competes with launches and statutory deadlines that always feel more urgent — until a monitoring email or a complaint arrives.
This is precisely the gap a remediation engagement closes: not discovering the problem, which your statement already records, but clearing it — and leaving evidence that it was cleared. How we do that.