Guide · Website Compliance

AODA website compliance: what Ontario law actually requires

Guide · Updated 2026-07-13 · 10 min read

If your organization has 50 or more employees in Ontario, your public website and web content must meet WCAG 2.0 Level AA — and that has been the law since January 1, 2021, not something arriving in 2026. Businesses under 50 employees have no WCAG mandate. What changes this year is visibility: the accessibility compliance report due December 31, 2026 asks 50+ organizations to certify, yes or no, whether their website complies.

The rule, precisely

What the requirement covers — and what it doesn't

The rule (section 14 of O. Reg. 191/11) applies to businesses and non-profits with 50+ employees and to designated public-sector organizations, for websites they control directly or through a contractual relationship — "our agency runs the site" is not an exemption. It covers content published since January 1, 2012: pages, images, forms, documents like PDFs, and web applications.

Getting the boundaries right matters, because over-claiming is how vendors scare businesses into overlays. The real rule:

Scope — WCAG 2.0 AA under the AODA

  • Public websites and web content published since January 1, 2012 — must meet WCAG 2.0 Level AA
  • Except success criteria 1.2.4 (live captions) and 1.2.5 (pre-recorded audio description) — explicitly carved out
  • Internal sites (intranets, extranets) are exempt — though accessible formats on request still apply
  • Where meeting a criterion is not practicable, the regulation allows posting non-conforming content with an explanation and an accessible summary

In practice

What failing actually looks like

WCAG 2.0 AA is a technical standard, but the failures we find are mundane: product photos with no text description, links a screen reader announces as "link," grey-on-grey text, forms whose fields have no labels, pages that block zooming on a phone. When we scan established Ontario businesses in the 50–100 employee range, a typical site fails 95 to 274 automated checks across just six pages — including issues classed as critical. An excerpt from a real (anonymized) scan:

Website Scan — Findings

Ontario manufacturer · 50–100 employees · 6 pages scanned

Real scan — anonymized axe-core automated review
Critical

Product images missing text descriptionsScreen-reader users cannot tell what they show

WCAG 1.1.1
Critical

Dozens of links with no accessible nameAnnounced only as “link” by assistive technology

WCAG 4.1.2
Serious

74 colour-contrast failuresText illegible for low-vision users — common even on newly redesigned sites

WCAG 1.4.3
Serious

Zoom disabled on mobileUsers cannot magnify text — a one-line fix in the page header

WCAG 1.4.4

Prepared by AODAPrep · Human-reviewed4 of 140 instances shown✓ Each maps to report Q2

Two honest caveats. Automated scanners catch only roughly a third of WCAG criteria — a clean scan is necessary, not sufficient. And a recent redesign is no guarantee: some of the worst contrast and ARIA failures we've found were on professionally rebuilt sites.

Check it yourself — free

Free ways to test your own site today

You don't need a vendor to get a first read. Any of these free tools will surface the automated failures in minutes:

DIY toolbox — all free

  • WAVE — paste your URL, see issues overlaid on your page
  • Lighthouse — built into Chrome (DevTools → Lighthouse → Accessibility)
  • axe DevTools — the same engine our scanner uses, as a browser extension
  • The five-minute manual test: unplug your mouse and try to navigate by keyboard alone; then try zooming to 200%

The catch: these tools produce developer output — hundreds of findings with no prioritization, no sense of what the law actually requires, and nothing about the policy, feedback-process, and accessible-formats obligations that sit next to WCAG in the same report question.

Fixing it

How we take a failing site to a defensible "Yes"

  1. Free scan

    Send us your address; we scan your key pages and top public PDFs and tell you plainly where you stand — free, whether or not we ever speak again.

  2. Two reports, two audiences

    A plain-English report for the owner (what's wrong, what it means for the December certification) and a precise, prioritized fix list your developer or agency can work through ticket by ticket.

  3. Rescan and document

    After fixes, we rescan, record the result, and draft the accessibility-statement and feedback-process pages the same report question expects.

  4. Answer, supported

    Question 2 gets answered with evidence behind it — or, where something genuinely can't be finished in time, an honest answer with a documented remediation plan, which the regulation itself anticipates.

Find out what your website fails — free.

Send us your website address. We’ll run the scan and reply in plain English with your top findings and what they mean for the December report. No obligation.

Sources — Official

Report question and checkbox wording captured from the Accessibility Compliance Reporting Portal, July 2026. This guide is general information, not legal advice.