Skip to content
Accessibility Web Development Guides

WCAG 2.2 AA for Australian Organisations: What Changed, What Applies and How to Audit

Shakewell ·

WCAG 2.2 is the current version of the Web Content Accessibility Guidelines. The W3C published it on 5 October 2023 and republished it with errata fixes on 12 December 2024.

If you were building to WCAG 2.1 AA, the change is smaller than the version number suggests. There are nine new success criteria, six of which apply at Level AA, and one old criterion is gone.

The harder question is which version Australian organisations have to meet. We checked the primary sources on 3 October 2026.

What WCAG 2.2 added

The W3C says WCAG 2.2 “builds on and is backwards compatible with WCAG 2.1, meaning web pages that conform to WCAG 2.2 are at least as accessible as pages that conform to WCAG 2.1.” It adds nine success criteria:

Criterion Level What it asks for
2.4.11 Focus Not Obscured (Minimum) AA A focused control is not entirely hidden by content the site added
2.4.12 Focus Not Obscured (Enhanced) AAA No part of a focused control is hidden
2.4.13 Focus Appearance AAA Focus indicators meet a minimum area and 3:1 contrast
2.5.7 Dragging Movements AA Anything done by dragging can also be done with a single pointer, without dragging
2.5.8 Target Size (Minimum) AA Pointer targets are at least 24 by 24 CSS pixels, with exceptions
3.2.6 Consistent Help A Help repeated across pages appears in the same relative order
3.3.7 Redundant Entry A Information already given in a process is filled in or selectable, not typed again
3.3.8 Accessible Authentication (Minimum) AA Logging in does not rely on a cognitive function test, such as remembering a password, unless there is an alternative or help
3.3.9 Accessible Authentication (Enhanced) AAA As above, without the object recognition and personal content exceptions

Six of these count towards Level AA: the two Level A criteria (3.2.6 and 3.3.7) and the four Level AA criteria (2.4.11, 2.5.7, 2.5.8 and 3.3.8). The three AAA criteria are not part of AA conformance.

What WCAG 2.2 removed

One criterion: 4.1.1 Parsing. The W3C’s note says it “was originally adopted to address problems that assistive technology had directly parsing HTML. Assistive technology no longer has any need to directly parse HTML. Consequently, these problems either no longer exist or are addressed by other criteria.”

The W3C has also updated WCAG 2.1, which now says 4.1.1 “should be considered as always satisfied for any content using HTML or XML.”

There is a catch for contracts. The W3C says authors “required by policy to conform with WCAG 2.0 or 2.1 will be able to update content to WCAG 2.2, but may need to continue to test and report 4.1.1.” If your contract names 2.1, check what it expects before you drop parsing from the report.

Nothing else moved. 2.4.7 Focus Visible is still Level AA.

What Level AA means

For Level AA, the spec says a page “satisfies all the Level A and Level AA success criteria.” In WCAG 2.2, that is 55 criteria: 31 at Level A and 24 at Level AA.

Three rules catch people out:

  • It is for full pages. Conformance “cannot be achieved if part of a web page is excluded.”
  • It is for complete processes. If one page in a checkout or application form fails, the whole process fails.
  • AAA is not a sensible blanket target. The W3C does not recommend requiring it “as a general policy for entire sites because it is not possible to satisfy all Level AAA success criteria for some content.”

The W3C’s evaluation methodology calls Level AA “the generally accepted and recommended target.”

What Australian governments require

Commonwealth. The Digital Transformation Agency’s Digital Experience Policy sets four standards, and two of them cover accessibility in the same words. Criterion 3 of the Digital Service Standard (“Leave no one behind”) and criterion 4 of the Digital Inclusion Standard (“Make it accessible”) require agencies to comply with the Disability Discrimination Act 1992, the “latest version of the Web Content Accessibility Guidelines (WCAG)” and the Australian Government Style Manual.

Neither names a version number, so the target moves with WCAG. The Style Manual says “WCAG 2.2 is the current version”, and its advice is headed “Meet WCAG level AA, but aim higher”. For services in scope, that reads as WCAG 2.2 AA.

The DTA’s dates:

  • Digital Service Standard: 1 July 2024 for new and replacement public-facing and staff-facing services, and 1 July 2025 for existing public-facing services.
  • Digital Inclusion Standard: 1 January 2025 for new and replacement services, and 1 January 2026 for existing public-facing services.

The DTA says the policy “does not apply to state or territory services.”

NSW. The Digital NSW Design Standards tell agencies to “Comply with WCAG 2.2 at level AA (AAA where achievable)”.

Victoria. The Victorian Government says “all digital content and websites must, at a minimum, meet the current WCAG version Level AA. As of January 2025, this is WCAG 2.2.”

Other states and territories have their own policies. If you supply government, build to the version and level your contract names. Where it names none, we build to 2.2.

Where the Disability Discrimination Act fits

The DDA applies well beyond government. Section 24 makes it unlawful for a person who provides goods or services, or makes facilities available, “whether for payment or not”, to discriminate on the ground of disability. That includes discrimination in “the manner in which” the goods or services are provided.

The Act defines services to include banking, insurance, entertainment, transport, telecommunications, professional services and government services. Section 29A sets out an unjustifiable hardship exception.

The Act does not mention websites or WCAG. The Australian Human Rights Commission’s advisory notes on web access say “the provision of information and online services through the web is a service covered by the DDA.” The notes “do not have direct legal force,” but the Commission and other anti-discrimination agencies “can consider them in dealing with complaints lodged under the DDA.”

Those notes are version 4.1, from 2014, and they recommend WCAG 2.0 AA. In February 2024 the Commission added a notice saying they are “no longer current” and that an update was underway. We could not find a published replacement.

We are developers rather than lawyers, so treat this as background and take advice on your own obligations. In practice, the requirement usually arrives through procurement, as a WCAG level in a contract.

What automated tools catch and what they miss

Automated checkers are worth running first. They are cheap and catch mechanical faults such as missing labels, broken heading order and low contrast.

They do not decide conformance. The W3C says “Web accessibility evaluation tools can not determine accessibility, they can only assist in doing so”, and its evaluation methodology notes that “most accessibility checks are not fully automatable.”

A tool can tell that an image has alt text. It cannot tell you whether the alt text is right, whether the focus order makes sense or whether an error message helps.

Most of the new 2.2 criteria are about interaction. You find out whether a sticky header hides focus by tabbing through the page, and whether a drag has an alternative by trying it.

Tools also report failures that are not real. When we built a contrast checker for this site, 14 of its first 21 findings were artefacts of the checker. More in the contrast failures automated tools miss.

How an accessibility audit works

The W3C’s WCAG Evaluation Methodology (WCAG-EM), updated to version 2.0 on 23 July 2026, sets out five steps. They are a good test of whether an audit is thorough.

1. Define the scope. Agree what is in and out, the conformance target (for example WCAG 2.2 Level AA), and the accessibility support baseline: the browsers and assistive technologies the site has to work with.

2. Explore the site. Identify the common views such as header, footer and navigation, the essential functionality, the types of page and the technologies they rely on.

3. Select a sample. Take a structured sample that covers everything found in step 2, plus a random sample on top, which WCAG-EM sizes at 10% of the structured set. Every page in a complete process, such as checkout or sign-up, goes in.

4. Evaluate. Run automated scans, then test by hand: keyboard-only navigation, screen reader testing, focus management, forms and error states. That manual pass is where most sites genuinely fail. WCAG-EM also strongly recommends involving real people with a wide range of abilities.

5. Report. Record the findings against each success criterion, with what was tested and how.

Our accessibility audits follow that shape. You get a prioritised list of issues with the effort each one needs, so you can fix the barriers that block people first and schedule the rest. You also get a written conformance statement covering what was tested, how, and what remains outstanding.

Remediation is where the cost sits. Colour and copy fixes are quick. A component library with no keyboard support means rebuilding components rather than adjusting them. Re-test after each round of fixes.

It is cheaper to decide contrast, focus states, target sizes and keyboard paths during UX and UI design, and to build them into the component layer during website development. We do not install overlay widgets. They cannot fix the underlying markup.

If you meet WCAG 2.1 AA today

Six checks cover most of the gap to 2.2 AA:

  • Tab through every template with the sticky header, footer and cookie banner showing. The W3C says a cookie banner fails if it entirely hides the focused control.
  • Measure icon buttons, close buttons and pagination. Anything under 24 by 24 CSS pixels needs spacing (a 24 pixel circle centred on it touches no other target or circle) or another exception.
  • Find every drag: sliders, carousels, maps, sortable lists. Each needs a single-pointer alternative, such as clicking along a slider track.
  • Log in with a password manager, then by pasting. The W3C gives both as examples of what satisfies 3.3.8, so neither should be blocked.
  • Keep help in the same place. Contact details, help links and chat should sit in the same order on every page.
  • Walk every multi-step form. Do not ask for the same information twice.

Sources: WCAG 2.2, What’s New in WCAG 2.2, Understanding Parsing, Understanding Focus Not Obscured (Minimum), Understanding Dragging Movements, WCAG 2.1, WCAG-EM 2.0 and Selecting Web Accessibility Evaluation Tools (W3C), Digital Service Standard criterion 3, Services covered by the Digital Service Standard, Digital Inclusion Standard criterion 4, Services covered by the Digital Inclusion Standard and Digital Experience Policy (DTA), Agency responsibilities and commitments (Australian Government Style Manual), Design Standards (Digital NSW), How to make content accessible (Victorian Government), Disability Discrimination Act 1992 (Federal Register of Legislation), World Wide Web Access: Disability Discrimination Act Advisory Notes ver 4.1 (Australian Human Rights Commission).

Common questions

What is new in WCAG 2.2 at Level AA?

Six of the nine new success criteria count towards Level AA. Two are Level A: 3.2.6 Consistent Help and 3.3.7 Redundant Entry. Four are Level AA: 2.4.11 Focus Not Obscured (Minimum), 2.5.7 Dragging Movements, 2.5.8 Target Size (Minimum) and 3.3.8 Accessible Authentication (Minimum). The other three are Level AAA and are not needed for AA conformance.

Is 4.1.1 Parsing still required?

Not in WCAG 2.2, where it is obsolete and removed. The W3C has also updated WCAG 2.1 to say it should be considered always satisfied for content using HTML or XML. The W3C does note that anyone required by policy to conform with WCAG 2.0 or 2.1 may need to keep testing and reporting 4.1.1, so check what your contract expects.

Do Australian government websites have to meet WCAG 2.2 AA?

For Commonwealth services in scope, the Digital Service Standard and the Digital Inclusion Standard require the latest version of WCAG, and the Australian Government Style Manual names 2.2 as current and says to meet Level AA. The Digital NSW Design Standards say WCAG 2.2 AA. Victoria says the current version at Level AA, which it states has been 2.2 since January 2025.

Does WCAG apply to private businesses in Australia?

WCAG itself is a W3C standard, not a law. The Disability Discrimination Act 1992 applies to anyone providing goods or services, and the Australian Human Rights Commission's advisory notes say information and online services through the web are a service covered by the DDA. The Act does not name WCAG. We are developers rather than lawyers, so take advice on your own obligations.

Start a conversation

Start a conversation

Tell us what you want to build, fix or scale, we’ll come back with a clear way forward.