WCAG 2.2 is the current version of the Web Content Accessibility Guidelines, the W3C standard that accessibility laws, policies and contracts usually point to.
If you’ve been asked to make a website meet “WCAG 2.2 AA”, most of the work isn’t new. The changes from 2.1 turn up in a handful of places: sticky headers, cookie banners, sliders, small icons, multi-step forms and logins.
The short answer
- WCAG 2.2 is W3C’s current web accessibility standard, a Recommendation since 5 October 2023.
- It adds nine success criteria to WCAG 2.1 and removes one, 4.1.1 Parsing, as obsolete.
- Six of the new criteria are level A or AA: Focus Not Obscured (Minimum), Dragging Movements, Target Size (Minimum), Consistent Help, Redundant Entry and Accessible Authentication (Minimum). The other three are AAA.
- WCAG 2.2 AA means every page meets all level A and AA success criteria: 55 in total.
- It’s backwards compatible: content that meets 2.2 AA also meets 2.1 AA and 2.0 AA.
How WCAG conformance levels work
WCAG’s success criteria are testable statements a page either meets or doesn’t. Each has one of three levels, and the levels are cumulative: AA means meeting every A and every AA criterion.
| Level | What it covers | Examples |
|---|---|---|
| A | The most basic barriers, which stop some people using a page at all | Text alternatives for images (1.1.1), full keyboard access (2.1.1) |
| AA | Significant barriers affecting many more people | Text contrast of 4.5:1 (1.4.3), visible focus (2.4.7), reflow at 320 CSS pixels wide (1.4.10) |
| AAA | The highest level, not achievable for every kind of content | Text contrast of 7:1 (1.4.6), targets of 44 by 44 CSS pixels (2.5.5) |
What conformance actually means
- The whole page counts, cookie banner, chat widget, embedded map and booking tool included. If third-party parts fail, the most you can publish is a statement of partial conformance.
- Processes count as a whole. If a quote request or checkout runs across several steps, every step must conform, or none of them can.
- There’s no partial credit. One failing criterion means that page doesn’t conform. “Mostly AA” is a progress report, not a claim.
Why AA is the level contracts ask for
Level A alone leaves obvious barriers in place; minimum text contrast, for example, is AA. At the other end, WCAG itself advises against requiring AAA as a general policy for entire sites, because some content can’t meet every AAA criterion. AA is the demanding but achievable middle, which is why laws and procurement standards so often name it.
WCAG 2.1 vs 2.2: what changed
W3C aimed the changes at people with cognitive or learning disabilities, people with low vision and people with disabilities on mobile devices. These are the nine new success criteria in WCAG 2.2:
| Success criterion | Level | In one line |
|---|---|---|
| 2.4.11 Focus Not Obscured (Minimum) | AA | A focused element isn’t completely hidden |
| 2.4.12 Focus Not Obscured (Enhanced) | AAA | No part of a focused element is hidden |
| 2.4.13 Focus Appearance | AAA | The focus indicator is big and contrasting enough |
| 2.5.7 Dragging Movements | AA | Dragging always has a click or tap alternative |
| 2.5.8 Target Size (Minimum) | AA | Targets are at least 24 by 24 CSS pixels, or well spaced |
| 3.2.6 Consistent Help | A | Help options stay in the same place across pages |
| 3.3.7 Redundant Entry | A | No typing the same information twice in one process |
| 3.3.8 Accessible Authentication (Minimum) | AA | Logging in doesn’t rely on memory, retyping or puzzles |
| 3.3.9 Accessible Authentication (Enhanced) | AAA | The same, with fewer exceptions |
Why 4.1.1 Parsing was removed
4.1.1 asked for well-formed markup, because assistive technologies once parsed HTML themselves. They now rely on the browser, and the HTML standard defines how browsers handle markup errors. Problems that still affect people, like a duplicate ID that breaks a form label, fail 1.3.1 Info and Relationships or 4.1.2 Name, Role, Value instead. W3C has also published notes for WCAG 2.0 and 2.1 saying 4.1.1 should be treated as always satisfied for HTML and XML.
The six new A and AA criteria, with everyday examples
2.4.11 Focus Not Obscured (Minimum)
Level AA. When a link, button or field receives keyboard focus, it mustn’t be completely hidden by content the site itself added.
On a real website. Someone tabbing down a service page reaches a link hidden under the sticky header, or behind a cookie banner pinned to the bottom of the screen, so focus lands on something they can’t see.
The fix. Set scroll-padding-top (and scroll-padding-bottom) to the height of fixed bars so the browser scrolls focused items clear of them (W3C technique C43). Either make the cookie banner modal, so it’s dealt with first, or pad for it the same way. Our guide to accessible navigation and visible focus goes further.
2.5.7 Dragging Movements
Level AA. Anything that works by dragging must also work with a single click or tap, unless dragging is essential or the behaviour comes from the browser and the site hasn’t changed it.
On a real website. A price-range slider, a before-and-after image comparison, drag-to-reorder lists, a map you pan by dragging. For people with tremors, or using a head pointer, pressing, holding and moving at once can be impossible.
The fix. Let a click on the slider’s track move the handle, or add minimum and maximum fields beside it; add arrow buttons to the map and up and down buttons for reordering. Keyboard support alone doesn’t satisfy this one, because touchscreen users may have no keyboard. A native HTML range input usually falls under the browser exception; custom sliders are where problems start.
2.5.8 Target Size (Minimum)
Level AA. Click and tap targets must be at least 24 by 24 CSS pixels, or spaced so that a 24 CSS pixel diameter circle centred on each smaller target doesn’t overlap another target or another small target’s circle.
On a real website. 16-pixel footer icons packed side by side, the “×” that closes a pop-up, carousel dots: the controls people miss on a phone. Exceptions include links within a sentence, browser-default controls you haven’t resized, and targets with a full-size equivalent on the same page.
Keep it in proportion. 24 pixels is a floor: AAA (2.5.5) asks for 44 by 44 CSS pixels, and Apple’s Human Interface Guidelines ask for at least 44 by 44 points on buttons. Our guide to mobile-first and responsive design covers designing for touch from the start.
3.2.6 Consistent Help
Level A. If help options repeat across pages (phone number, email, contact form link, chat or chatbot, FAQ), they must sit in the same order relative to the rest of the page each time.
On a real website. The phone number sits in the header on most pages but drops to the footer on landing pages built from a different template, so people who found it once lose it. The criterion doesn’t oblige you to offer help, only to keep what you offer in place.
3.3.7 Redundant Entry
Level A. Within one process, information someone has already entered or been given must be filled in or offered to select, not typed again.
On a real website. A three-step quote form asks for an email address on step one and again on step three. A checkout has no “billing address same as delivery” option.
Exceptions. Re-entry is allowed when it’s essential, needed for security, or the earlier information is no longer valid. Our guide to accessible web forms covers this alongside labels, errors and autocomplete.
3.3.8 Accessible Authentication (Minimum)
Level AA. No step of logging in may rely on a cognitive function test, such as remembering a password, transcribing a code or solving a puzzle, unless there’s an alternative method or help such as password manager support or copy and paste. Recognising objects, or content you supplied, is still allowed at AA.
On a real website. Client portals and shop accounts where code fields block paste, password managers can’t fill in, or a distorted-letters CAPTCHA has no alternative.
The fix. Allow paste, mark up fields with autocomplete="username", autocomplete="current-password" and autocomplete="one-time-code" so browsers and password managers can fill them, and consider email sign-in links or passkeys. A CAPTCHA on an enquiry form isn’t authentication, but 1.1.1 already requires CAPTCHAs to have a text description and a version for another sense, such as audio.
The three AAA additions
A “WCAG 2.2 AA” requirement doesn’t include these, but one is cheap enough to adopt anyway.
- 2.4.12 Focus Not Obscured (Enhanced). No part of the focused element may be hidden.
- 2.4.13 Focus Appearance. The indicator must be at least as large as a 2 CSS pixel thick outline around the unfocused element, with at least 3:1 contrast between focused and unfocused states. A solid outline of 2 CSS pixels or more, at 3:1 against its surroundings, generally passes: a sensible default even at AA.
- 3.3.9 Accessible Authentication (Enhanced). Drops the object-recognition and personal-content exceptions, so “select every image with a bus” no longer passes on its own.
A WCAG 2.2 AA checklist for the new criteria
Run these on each key template and on every form, checkout and login.
Most of these need a person: an automated checker can’t tell whether a slider has a tap alternative, and an overlay widget can’t add one. Our guide to accessibility audits, automated checkers and overlays compares what each can tell you.
And keep the six in perspective. If your site was never built to 2.1 AA, the bigger wins are colour contrast, alt text, form labels, keyboard access and headings, which is where our practical guide to web accessibility starts.
What about WCAG 3?
WCAG 3, formally the W3C Accessibility Guidelines 3.0, is the planned successor. At the time of writing (September 2026) it’s still a Working Draft with its conformance model in development, so there’s nothing to conform to yet.
Don’t wait for it: seeing where focus is, reaching controls and logging in without memory tests are needs that won’t change with a version number. If you need to win internal support first, the business case for accessibility makes the argument.
Frequently asked questions
Is WCAG 2.2 a legal requirement?
Not in itself: WCAG is a technical standard. It becomes a requirement when a law, regulation, policy or contract references it, usually naming a version and level. Check the wording that applies to you, and take legal advice where it matters.
Does WCAG 2.2 replace WCAG 2.1?
Not formally: 2.0 and 2.1 remain W3C Recommendations, and many laws and contracts still name 2.1 AA. But W3C recommends 2.2 as the target even then, and meeting 2.2 AA also meets 2.1 AA.
How many success criteria are in WCAG 2.2 AA?
55: 31 at level A and 24 at level AA. With the 31 AAA criteria, WCAG 2.2 has 86 in total, not counting the removed 4.1.1 Parsing.
Do we need a new accessibility audit for WCAG 2.2?
Not necessarily. If a recent audit tested against 2.1 AA, check the six new A and AA criteria, plus anything added since: new templates, plugins, banners or widgets.
What to do next
WCAG 2.2 AA is 2.1 AA with one obsolete criterion retired and six specific, testable additions, most of them in a handful of components. The cheapest time to meet them is before anything is built, with target sizes, focus styles and form flows settled in the design, not patched later.
Planning a new site? Our website design and development process builds accessibility in from the first layouts. If your current site has deeper problems, a website redesign fixes them at the source. And if a contract has handed you a WCAG 2.2 requirement to talk through, get in touch.