A checklist building a website accessibility cost from seven items taken off a reader's own site: unique templates, interactive components, states per component, critical journeys, document formats in scope and the assistive technology and browser matrix, each checked off as a count, with a seventh item marked apart as a question to ask a vendor rather than a count to take

What a website accessibility cost is actually built from

A website accessibility cost is built from counted scope, not company size. These are the seven counts you can take off your own site before you contact anybody.

The seven counts a quote is built from#

There are seven, and every one of them comes off your own site. The seventh is not a count at all. It is a question you put to every firm you speak to.

The seven inputs a quote is built from, each with the unit it is counted in and where on your own site it comes from. The seventh is a question put to the firm rather than a number taken off the site. The units are ours; the scope vocabulary of pages, complete processes and technologies relied upon is WCAG 2.2.
InputCounted inWhere you get it
Unique templatesTemplates, not URLsOpen your site and group pages that share a layout.
Interactive componentsComponentsMenus, modals, carousels, date pickers, tabs, accordions, custom selects, data tables.
States per componentStatesEvery state a component can reach: opened, focus-trapped, validated, errored.
Critical journeysWhole processes, first click to confirmationWalk each journey end to end. One that crosses a subdomain is still one journey.
Document formats in scopeFormatsPDFs, spreadsheets and anything else you publish as a file.
Assistive technology and browser matrixPairs you will test againstWrite down what you expect the work to be tested on.
Re-test after the fixesA question to ask, not a count to takeAsk every firm: does re-test sit inside this number, and what is a re-test here?

A band would be unverifiable against your own site, so it would only look like an answer. Those seven counts are checkable, which is the whole difference.

Two of them surprise people. States per component matters because you check a component in each state it can reach, not once. Document formats matter because a PDF application form is often the least accessible thing an organisation publishes. Yet it rarely appears on anybody's page count.

Why company size is the wrong proxy for a website accessibility cost#

Company size does not appear anywhere in the standard that measures the work. WCAG 2.2, published by W3C as a Recommendation, names pages, complete processes and the technologies relied upon. Those are the units conformance is scoped against. Headcount is not one of them.

That matters practically rather than philosophically. If you are trying to locate yourself in someone else's bracket, you are answering a question the standard cannot settle. A twelve-person company running a multi-tenant product with forty interactive components has more to check than a two-hundred-person firm with a brochure site.

Therefore the bracket question has no answer as posed. Two firms of identical size can differ by an order of magnitude in what you have to check. Moreover, nothing about their headcount predicts which is which. The question that does have one is about your site.

What WCAG says the unit of work actually is#

The unit is a full page checked against five requirements, at every width it renders. WCAG 2.2 states it directly: "In order for a web page to conform to WCAG 2.2, all of the following conformance requirements must be satisfied". All five. Not the three that a tool happens to reach.

One full page multiplied by each width it automatically presents and by all five conformance requirements, and then the same again for every step of a complete process, with one failing step voiding the claim for the whole process.The unit of checking, drawn from the WCAG 2.2 conformance requirements. A responsive page is several pages of checking, and a process conforms only if every page in it does.

Two of those requirements do most of the work on scope. W3C writes that "Conformance (and conformance level) is for full web page(s) only, and cannot be achieved if part of a web page is excluded." It also writes that "A full page includes each variation of the page that is automatically presented by the page for various screen sizes". In practice, a responsive page is several pages of checking.

The third scope multiplier is processes. W3C requires that when a page is one of a series presenting a process, "all web pages in the process conform at the specified level or better". As a result, a checkout that fails at step four fails as a whole.

For instance, two sites with two hundred pages each are not the same job. One has three breakpoints and no forms; the other has five breakpoints and a four-step application.

The count that moves an estimate is variety, not volume#

A sound evaluation samples by variety. WCAG-EM 2.0, W3C's evaluation methodology and a Group Note dated 23 July 2026, builds a structured sample. That sample covers common views, essential functionality, distinct sample types and the technologies relied upon. A random set is then added on top of it.

The anchored arithmetic is one line. W3C states that "The number of samples to randomly select is 10% of the structured sample set selected through the previous steps." That random set exists to test whether the structured one was representative at all.

Also worth knowing: W3C says that "If feasible, it is recommended to evaluate the entire digital product. The sampling procedure may then be skipped." Sampling is a compromise made when evaluating everything is not feasible.

Our reading of what that methodology asks an evaluator to weigh, when deciding how large a sample set must be, is eight things. They are size, age, complexity, how content is generated, consistency of coding style, number of authors, how formalised the development process is, and the confidence required. Those are our words, not W3C's.

Our illustration. Modelled, not measured. Two sites matched on nothing but page count, sampling in opposite directions. Page count says the opposite of what the sample set does.
What is countedThe five-hundred-page siteThe sixty-page site
Pages50060
Templates the pages are built from4Assembled rather than templated
Authors212
Systems the content comes from13
Development processFormal, with QAInformal
Which one produces the larger sample setNot this oneThis one, on every factor that decides a sample

By our own illustration, a five-hundred-page site can sample smaller than a sixty-page site. The five-hundred-page site is built from four templates by two people with a formal QA process; the sixty-page site is assembled by twelve authors from three systems. Page count says the opposite. Sizing by page count gets that backwards.

The worksheet: seven counts you can take this afternoon#

Here is how to produce each number without a specialist. None of this requires a tool licence.

Count unique templates by opening your site and grouping pages that share a layout. A blog index, a blog post, a product page, a checkout step. Most large estates collapse hard here.

Count interactive components: menus, modals, carousels, date pickers, tabs, accordions, custom selects, data tables. Then count states per component. For example, a modal that opens, traps focus, validates and errors is four things to check, not one.

Count critical journeys from first click to confirmation, and count them as whole processes. A journey that crosses a subdomain is still one journey. Next, count document formats in scope. Finally, write down the assistive technology and browser matrix you expect to test against. Put the re-test question to every firm.

Page count against template count400 down to 11

400

URLs in the estate

The number that matters

11

Unique templates the URLs resolve to

A firm quoting from your sitemap alone has priced the wrong number, because it has not looked at your site.

Page count against template count (A hypothetical estate. Invented illustration, not a project we ran. Counts are URLs and templates, not hours and not money.)
OptionA hypothetical estate. Invented illustration, not a project we ran. Counts are URLs and templates, not hours and not money.
URLs in the estate400
Unique templates the URLs resolve to11

For example, a hypothetical four-hundred-page estate is an invented illustration rather than a project we ran. It might resolve to eleven templates, nine interactive components and three critical journeys. The number that changed was four hundred to eleven. It is also why a firm quoting from your sitemap alone has not looked at your site.

A scan and an audit are different purchases#

An automated scan reports what a tool can detect. Therefore it cannot settle conformance. That is why a free report and an audit are two different things rather than the same thing at two prices.

W3C is plain about this in WCAG-EM 2.0: "While most accessibility checks are not fully automatable, evaluation tools can significantly assist evaluators during the evaluation process and contribute to more effective evaluation." It can assist. Still, it cannot settle the question.

The strongest statement comes from a source whose entire dataset is automated. WebAIM, at the Institute for Disability Research, Policy, and Practice at Utah State University, writes in its 2026 Million report that "Because only automatically detectable WCAG failures were considered, this suggests that the rate of full WCAG 2 A/AA conformance was certainly lower than 4.1%." That 4.1% is an upper bound WebAIM places on conformance, not a measured rate.

A scan finds the repeated, machine-visible failures. It is silent on whether a keyboard user can finish your checkout. If you want the detail on why two scanners disagree with each other, our note on why two accessibility scanners return different results covers the mechanics. Our note on why automated scanners settle only part of WCAG covers the boundary.

What automated detection keeps finding, and what that tells you#

Across the top one million home pages, most have at least one automatically detectable instance of a short list of named failure types. Of the top one million home pages analysed in February 2026, WebAIM found that 95.9% had automatically detectable WCAG 2 failures.

The type breakdown carries the same population and the same predicate. It is the share of home pages carrying at least one instance of each type.

Show data table
Each bar is the share of home pages carrying at least one instance of that failure type. It is not a share of error volume, and it says nothing about how many instances any one page carries.
Item share of home pages carrying at least one instance
Low contrast text 83.9%
Missing alternative text for images 53.1%
Missing form input labels 51%
Empty links 46.3%
Empty buttons 30.6%
Missing document language 13.5%

Six named types, each produced by a different part of a build, which is what makes them countable rather than mysterious.

Share of the top one million home pages carrying at least one automatically detectable instance of each failure type, February 2026 Each bar is the share of home pages carrying at least one instance of that failure type. It is not a share of error volume, and it says nothing about how many instances any one page carries. WebAIM Million 2026, Institute for Disability Research, Policy, and Practice, Utah State University. The top one million home pages, analysed February 2026, automated detection only.

The useful part for sizing is knowing which parts of your build produce those types. Low contrast comes from a colour palette. Missing labels come from a form component. Empty links and empty buttons come from icon-only controls. Consequently the remediation question is which of those your build produces, and where.

What this measurement cannot tell you is what proportion of your own error count those types will be. Because it measured one home page per domain, it speaks to prevalence across sites and to nothing else. A findings report on your site will contain one or more of the named types. However, this data does not say how many of each.

Show data table
The 2026 edition stands above 2025 on four of the six types: low contrast text, missing form input labels, empty links and empty buttons. WebAIM attributes the reversal to rising page complexity, more ARIA and third-party frameworks. Each bar is a share of home pages, not a share of error volume.
Dimension 2019 edition 2022 edition 2025 edition 2026 edition
Low contrast text 85.3% 83.9% 79.1% 83.9%
Missing alternative text for images 68% 55.4% 55.5% 53.1%
Missing form input labels 52.8% 46.1% 48.2% 51%
Empty links 58.1% 49.7% 45.4% 46.3%
Empty buttons 25% 27.2% 29.6% 30.6%
Missing document language 33.1% 22.3% 15.8% 13.5%

Automated detection is finding more of most of these types than it did a year earlier, not fewer.

Share of the top one million home pages carrying at least one instance of each failure type, across four WebAIM Million editions The 2026 edition stands above 2025 on four of the six types: low contrast text, missing form input labels, empty links and empty buttons. WebAIM attributes the reversal to rising page complexity, more ARIA and third-party frameworks. Each bar is a share of home pages, not a share of error volume. WebAIM Million, 2019, 2022, 2025 and 2026 editions, Institute for Disability Research, Policy, and Practice, Utah State University. The top one million home pages in each edition, automated detection only. The source publishes every year between; four editions are drawn for legibility.

Turn the counts into hours you own#

Split the work into three classes, then price each class against your own team's hours for comparable past work. You are substituting your last comparable ticket, not an industry rate. We publish no hours figure, and neither should anyone who has not seen your code.

The first class is defects of a named failure type, fixed at their source. A contrast token changed once. The second is sweeps that recur across every template, such as a heading structure corrected in every template. The third is interactive components that you have to rebuild and re-test per state. That is where the states count from the worksheet earns its place.

Effort hours worksheet
Count times your own hours per unit, summed down the column.
Class of effortYour countYour hours per unitHours for this class
Defects of a named failure type, fixed at their source
Sweeps that recur across every template
Interactive components rebuilt and re-tested per state
Total hours

No rows completed yet.

Type your own counts and your own hours per unit, and the row products and the total compute as you type. Every hours cell ships empty on purpose: we publish no hours figure, no default, no typical and no ratio between the three classes. Hours only, no currency. Nothing is stored and nothing is sent. With scripting off the same three-row table renders with empty printable cells.

Fill your counts into the first column and your own hours into the second. The arithmetic is yours, and you can check every input in it. The output is a number you can defend internally and hold against whatever a firm returns. It will be an estimate, in hours your own team recognises.

Six questions that make two quotes comparable#

Two quotes become comparable once you know six things. Send these as they stand.

Each question beside the thing that makes it answerable rather than a matter of taste. Sources: W3C, WCAG 2.2 sections 5.2 and 5.3.1, and WCAG-EM 2.0. The sixth question is ours.
Ask thisWhat makes it answerable
Which WCAG version and level is this claiming?WCAG 2.2 section 5.3.1 lists what a conformance claim must carry.
How was the sample chosen?WCAG-EM 2.0 sets out a structured sample plus a random set of 10% of it.
Which assistive technologies and browsers are in the matrix?It is a list the firm either holds or does not.
Does the plan cover complete processes as whole journeys?WCAG 2.2 requires every page in a process to conform, or the process does not.
Is a conformance claim or a report the deliverable?W3C notes that "Conformance claims are not required", so a firm can say plainly which you are getting.
Does re-test after the fixes sit inside the number?Ours is the question; the answer is a scope line the firm either writes down or does not.

Note that W3C itself writes "It is not recommended that Level AAA conformance be required as a general policy for entire sites". That is how you recognise an over-specified scope.

Our comparison of which WCAG version and level actually binds you is the companion to the first question.

When the level is not yours to choose#

Sometimes a regulation names the standard, and the level stops being a budget line. The U.S. Department of Justice, Civil Rights Division, published a final rule in the Federal Register on 24 April 2024 covering web content and mobile apps provided by state and local governments. It names a technical standard, and the compliance deadline is a function of population size.

That is what the rule says and who it names. Whether any rule reaches your organisation is a question for your own counsel, and this page is general information rather than legal advice.

The cost consequence is narrow and worth stating. A named standard removes the level from the negotiation. However, it removes nothing from the scope, which you still have to count exactly as above. A named deadline changes when the counting work happens. It does not change how much of it there is.

When not to buy an audit at all#

Three situations make an audit the wrong purchase.

Three situations in which an audit is the wrong purchase, and where each one routes instead: a rebuild next quarter routes the requirements into the build, a small brochure site routes to a scan plus a developer day, and no capacity with no intent to have the work delivered routes nowhere, while no capacity but a clear intent routes to the delivery conversation.The routing only. Every branch and destination is stated earlier and in the routes below.

A site being rebuilt next quarter is the first case: the findings expire before the fixes ship. Instead, the requirements belong in the build. That is the wrong purchase rather than the wrong service, and the routes below carry it.

If you run a small brochure site with no interactive components, a scan plus a developer day is the honest answer. Take the scan, fix the contrast and the alt text, and spend the rest elsewhere.

Say you have no capacity to act on a report, and no intention of having the work delivered by anyone. Then that report becomes a document nobody implements. Split that case carefully, though. No capacity but a clear intent to have the work delivered is a routing question, not a disqualification.

The worksheet has its own limit too. It sizes scope, and it does not tell anybody what an hour is worth. Where it breaks is for a reader with no team and therefore no rate to multiply by.

Where to go once you hold your own counts#

Your counts point at one of three next steps, and they are different work.

A template estate that needs remediating points to a WCAG audit, the fixes, and the re-test, which is the shape that matches. That page sets out the scope, the loop and what its re-test is not. A build already under way is a different case: building products everyone can actually use covers what forces the accessibility question and what happens on an accessible build. And when the rebuild is next quarter, the requirements belong in the design and the build, with how to get started with accessible websites as the starting point.

If you leave without talking to anybody, you leave holding seven counts, an hours model and six questions. That is enough to read any website accessibility cost estimate you are handed.

A final word on why a website accessibility cost resists a published band. You measure accessibility work in templates, components, states and journeys. No two sites of the same page count carry the same ones. Take the seven counts off your own site before you ask anyone for a number. Then the conversation is about your site rather than about a bracket.

Ishan Chavda

Software Engineer, Atyantik Technologies

Ishan Chavda is a Software Engineer at Atyantik Technologies, a software product studio building web platforms and integrated systems since 2015. He works on the front of the stack, where interaction patterns and interface state decide whether a page holds up under real use.

More from Ishan ChavdaAccessibility testing at AtyantikTalk to Atyantik

Keep reading