You are on a client's checkout page with your hands off the mouse, tabbing through the form one field at a time. The focus ring slides under a sticky header and vanishes. Suddenly you have no idea where you are.
Now picture someone who cannot use a mouse meeting that page every single day. They give up and leave. The company loses the sale and never learns why.
That failure has a name, 2.4.11 Focus Not Obscured (Minimum), and you can capture it, write it up and hand it to whoever owns that site.
Maybe you are a tester or developer watching AI write code faster than you, wondering where your seat is in two years. Maybe you are tired of a role that never lets you see who your work helps. Accessibility auditing pays for careful human judgment, and laws keep widening the list of organisations that need it.
Here is the urgency. Each new rule sends organisations looking for auditors they can trust, and they keep the first one who does good work. The people who publish credible audits now get the referrals. Those who wait compete with them.
Getting started costs anything from nothing to $1,200, so you can begin this week without buying a thing. Early income sits near $1,250 a month, the floor of this guide's range, and getting there usually takes 2 to 6 months.
Today, open a page you use often, put the mouse away, and tab from top to bottom, noting every point where you lose sight of the focus.
The service itself is simple to describe. A client gives you a website, a web application or a mobile app. You test it against the Web Content Accessibility Guidelines at the conformance level their obligation requires, then hand back a report that says which success criteria fail, on which screens, what a user relying on assistive technology experiences as a result, and what the developer should change. Some auditors stop at the report. Others stay on to verify the fixes, and that is where your recurring revenue lives.
Almost every accessibility engagement you take will trace back to one of three obligations. Once you know which one applies to a prospect, you know what standard to test against, what their deadline is, and how fast they will move.
Check these dates yourself rather than trusting a blog post, including this one. An interim final rule published on 20 April 2026 pushed the deadlines out from the schedule in the original 2024 rule, so a lot of the advice written between 2024 and early 2026 now cites dates that no longer apply. The DOJ page is the authority, and it is a single link away.
Hold on to one nuance here, because you will hear it as a sales objection. Article 32(1) provides a transitional period ending 28 June 2030 during which service providers may keep providing services using products that were already lawfully in use before the application date. A prospect will sometimes read that as a blanket extension to 2030. Its scope is much narrower, and the line between a legacy product still in service and a new service being offered today is exactly the kind of question that sends organisations looking for someone who has actually read the directive. That someone can be you.
So ask one question on every first call: which of those three applies to you, and if none does, what is making you look at this now? The answer sorts a serious buyer from a curious one in about fifteen seconds.
WCAG has three conformance levels, A, AA and AAA, from lowest to highest. Regulation almost always lands on AA. Nobody sensible sells you AAA as a target, because some AAA criteria are impossible to meet for whole categories of content.
The version matters more than newcomers expect. WCAG 2.1 was published in June 2018 and is the version the DOJ Title II rule names. WCAG 2.2 reached W3C Recommendation status in a revision dated 12 December 2024 and adds nine success criteria over 2.1:
Read that list as a commercial signal. Every criterion on it describes a pattern that shipped everywhere in the last decade. Drag-and-drop reordering with no keyboard alternative. A sticky header that swallows the focus ring as you tab down a page. Tap targets sized for a mouse. A checkout that makes you retype an address you entered two steps earlier. A login that makes you copy a code out of an image. Think about the last time a site made you do one of those. They are the default behaviour of most modern interfaces, which is why an audit against 2.2 finds more than an audit against 2.1, and why you should say clearly in the contract which version you are testing.
The WebAIM Million report is the single most useful number in your sales deck. In its February 2026 edition, automated testing of one million home pages found that 95.9% had detected WCAG 2 failures, up from 94.8% the year before. The average page carried 56.1 detected errors.
Those six categories account for 96% of all detected errors, and WebAIM notes the pattern has held steady across seven years of reports. Two conclusions follow, and they pull in opposite directions.
The encouraging one: most of what you will find is boring and fixable. A contrast ratio is arithmetic. An empty button needs an accessible name. A missing `lang` attribute is one line in the document head. You do not need deep expertise to find these, and a client who fixes only these six categories clears the overwhelming majority of their detected errors.
The sobering one: "detected" is carrying a lot of weight in that sentence. Automated tools find a minority of actual WCAG failures, because most criteria need judgment. Does this alternative text carry the same information as the image, or does it say "image123.png"? Is the reading order of this page logical? Does the error message tell the user how to fix the problem? Can you finish the whole checkout with a keyboard alone? No tool detects those. You do. That gap is your entire business, and it is also why the work resists automation: the value you add starts exactly where the free scanner stops.
So there is a standard, and there are sites breaking it in ways that cost their owners money. Between those two facts sits the one thing a client actually pays you for.
Selling this service gets much easier once you can describe the thing you deliver in concrete terms. An audit report that earns repeat work has these parts.
A conformance statement, carefully worded. You report what you tested and what you found. You never certify a site as compliant, because no such certificate exists, and issuing one moves legal risk onto you for a claim you cannot support. Say what you tested, when, against what, and what remained open.
A verification pass. Price this separately and offer it from the start. The client fixes, you retest the closed items, you issue a delta report. This is your natural door into a retainer, because a site that changes weekly needs retesting more than once.
What This Work Actually Pays
You now know what lands in the client's inbox at the end of the job. Before you can put a figure on it, you need to see what buyers are already used to paying.
Unusually for a freelance service, several established accessibility vendors publish their rate cards in full, so you can anchor your pricing to public numbers and skip the guessing.
Accessible.org publishes a per-page model. Audits are $100 to $250 per primary page or screen, and $25 to $100 for light pages or screens, where a primary page is content rich or interactive and a light page has minimal content or repeated patterns. They state that most audits land between $1,250 and $2,750 in total. Their audits are fully manual, evaluated against WCAG 2.1 AA or 2.2 AA, and conducted by Certified DHS Trusted Testers. DigitalA11Y publishes a different shape for the same service, quoting $1,500 to $5,000 per audit.
The rest of the same rate card teaches you more than the audit line, because it shows where the margin really sits:
| Service | Published price |
|---|
| Audit, primary page or screen | $100 to $250 each |
| Audit, light page or screen | $25 to $100 each |
| Technical support and fix validation | $195 per hour, two hour minimum |
| Senior consultation | $495 per hour |
| VPAT, WCAG edition, plus audit cost | $350 |
| VPAT, Section 508 edition | $550 |
| VPAT, EN 301 549 edition | $650 |
| User testing by a professional with a disability | $550 per session, $450 with an audit |
| Expedited or overnight turnaround | $250 to $750 |
| Remediation, per page or screen | $250 to $550 |
| PDF remediation | from $7.50 per page |
| Word and PowerPoint remediation | from $7.00 per page |
| Alt text writing | $2.25 per image |
| Closed captions | $2.25 per minute |
| Audio description | $17.50 per minute |
| Transcripts | $1.50 per minute |
Read that table as a map of the business; copying it line by line as your price list would miss the point. Four things stand out.
The audit is the cheapest thing on it. Remediation is priced at $250 to $550 per page, two to five times the audit price for the same page. The audit opens the door; the fixing is the room behind it.
Hourly validation work at $195 per hour with a two hour minimum is the most repeatable line item, because every audit leaves you with a client who has made fixes and wants to know whether they worked.
The conformance report is nearly pure margin. A $350 WCAG VPAT is compiled from an audit you already ran, and the Section 508 and EN 301 549 editions are priced higher at $550 and $650 because the buyer needs them to satisfy a procurement requirement.
Documents are a volume business hiding inside a service business. At $7.00 to $7.50 per page, a single untagged 400 page policy library is a meaningful engagement on its own, and it needs no design opinion or developer coordination. Do you know an organisation sitting on a shelf of PDFs like that? That could be your first invoice before you ever audit a website.
How that becomes a monthly number. Treat the per-unit rates above as the sourced part and the assembly as the estimate. One 12 primary page audit at the middle of the published range, plus its VPAT, plus four hours of fix validation, is one engagement of a few thousand dollars. Do one of those a month while carrying a small document remediation queue and you have a part-time income; do three, with two retainer clients on quarterly regression passes, and you have a full-time one. The rate stays fairly fixed. What changes is how many engagements you can find, which is why the sections below spend more time on credibility than on pricing.
The three revenue shapes, roughly in the order people grow into them:
- Fixed-scope audit. One report, defined page or template count, defined journeys. Predictable, and the easiest thing for a buyer with a procurement process to approve.
- Audit plus validation. The audit, then hourly work retesting fixed items after the client's development cycle. Better margin, because your second pass reuses your test plan.
- Retainer. A monthly or quarterly regression pass, plus review of new features before release, plus keeping the published accessibility statement current. This is the grown-up version of the business, and where your income stops depending on winning new logos every month.
You scope an audit from three inputs: the number of distinct templates (pages matter less), the number of critical user journeys to walk end to end, and how many assistive technology combinations the client wants covered. Templates matter because a 4,000 page site built from 11 templates is an 11 template audit plus spot checks. Journeys matter because that is where the expensive findings hide: registration, search, checkout, payment, form validation, error recovery. Assistive technology combinations matter because each one is a full re-walk of the same ground.
Early on, credibility limits your income far more than your rate does. Your first two or three engagements will be priced on trust more than on any rate card, and the fastest way through that is a public piece of work: an audit of something in your prospects' own sector, published, with the findings mapped to criteria and the user impact spelled out.
Price a first audit at $100 to $250 a primary page and even a modest site becomes a proper invoice. If audits bring in around 1,250 a month, the low end here, your car insurance, your phone and the weekly shop could be covered by checking keyboard focus and colour contrast on somebody else's website. Build the public audit that gives a client a reason to hire you.
Think of what the first few invoices replace. The stress of a renewal letter for the flat. The guilt of saying no when your parents need help with a bill. Every audit you deliver well becomes a reference, and every reference makes the next invoice easier to send.
The Conformance Report Nobody Talks About
The VPAT gets its own section because it is the most misunderstood high-margin deliverable in this field.
A Voluntary Product Accessibility Template is a standard form. Filled in, it becomes an Accessibility Conformance Report, which states, criterion by criterion, whether a product supports, partially supports or does not support each requirement. There are separate editions for WCAG, for Section 508 and for EN 301 549, which is why the published prices differ: $350, $550 and $650 respectively on top of the audit cost.
It matters commercially because the buyer is usually someone other than the person who cares about accessibility. A software vendor selling to a federal agency, a university or a European bank gets asked for an ACR during procurement. Without one, the deal stalls. That vendor is shopping for the document that unblocks a contract, and their urgency is completely different from a public body working towards a 2027 deadline. Which software companies near you sell to universities or government? They are your shortest route to a first paid VPAT.
Two cautions. First, an honest ACR often says "partially supports", and a vendor who wanted a clean sheet may push back. Filling it in optimistically is a misrepresentation their customer's procurement team may test. Second, the ACR is only as good as the audit underneath it, so refusing to produce one without doing the testing is both the ethical position and the commercially sound one.
Beyond the US and EU: the UK Regime
The UK has its own public sector rule, and it is worth knowing because the obligations have been live for years, so the market there is mature and already buying.
The Public Sector Bodies (Websites and Mobile Applications) (No. 2) Accessibility Regulations 2018 define the "accessibility requirement" as making a website or mobile application "perceivable, operable, understandable and robust", the four WCAG principles. The application dates have all passed:
| Asset | Requirement applies from |
|---|
| Website published on or after 23 September 2018 | after 22 September 2019 |
| Any other public sector website | after 22 September 2020 |
| Public sector mobile application | after 22 June 2021 |
Three features of the UK regulations create billable work for you that the US and EU rules do not.
The accessibility statement is mandatory and must be maintained. Regulation 8 requires a public sector body to publish a detailed, comprehensive and clear statement, following the model statement, and to "keep that statement under regular review". A statement that must stay current is a recurring engagement by design, and most published statements go stale within a year of being written.
Failure is routed into discrimination law. A failure to comply with the accessibility requirement "is to be treated as a failure to make a reasonable adjustment", which ties the regulations to the Equality Act and keeps them from being a standalone technical duty. That framing is why UK public sector buyers treat your findings as legal risk, well beyond a quality backlog.
There is a disproportionate burden exemption, and it has to be argued. Regulation 7 removes the requirement where compliance "would impose a disproportionate burden", and the regulations exempt specific categories including live time-based media, pre-recorded media published before 23 September 2020, online maps where essential information is available another way, heritage collection items, and intranet or extranet content published before 23 September 2019 until it undergoes substantial revision. Documenting a disproportionate burden assessment properly is skilled work, and a body that claims the exemption without an assessment is more exposed than one that never claimed it.
You have the standard, the regimes that enforce it and the report format buyers expect. What decides whether you can actually produce that report is what you test with.
The tooling floor is genuinely zero, which is rare for a technical service.
Automated scanners. The axe DevTools browser extension has a free tier that runs basic automated testing page by page. Deque's paid tiers add AI-assisted automation, guided testing, user flow analysis, deduplication, CI integration and API access, and their sales team quotes them on request with no public list price. WAVE and the accessibility audit built into Chrome's Lighthouse cost nothing. Every one of these finds the same narrow band of machine-detectable issues, so running three of them is mostly redundant. Pick one and learn its false positives.
Screen readers. This part is non-negotiable, and it is where your real skill sits. NVDA on Windows is free and is what a large share of screen reader users actually use. VoiceOver ships with macOS and iOS at no cost. JAWS is the commercial Windows incumbent and matters because enterprise and government users are often standardised on it. TalkBack ships with Android. You need to be fluent in at least one and competent in a second, because a bug that reproduces in NVDA and not VoiceOver is a common and telling result. Have you ever listened to a website you use with your eyes closed? Try it tonight with VoiceOver or NVDA, and you will hear why this skill pays.
Keyboard only. Unplug the mouse. A large share of the findings clients care about most come from simply tabbing through a page: focus that disappears, focus that gets trapped in a modal, focus order that jumps around, controls you cannot reach at all.
Contrast and zoom. A contrast checker for the 83.9% problem. Then set browser zoom to 400% and reflow the page at a 320 pixel viewport width, which is what criterion 1.4.10 requires and which breaks a surprising number of otherwise tidy layouts.
Colour vision simulation and reduced motion. Both are built into modern browser dev tools. Both take seconds, and both catch issues automated scanners never report.
The pattern across all of it: automated tools narrow the search, then you walk the journeys yourself. Anyone selling you a subscription that replaces that second half is selling the overlay problem described below.
Getting Credible Before You Have Credentials
Knowing how to test is one half of it. Getting a stranger to trust your findings is the half that decides whether those first 2 to 6 months turn into income.
The International Association of Accessibility Professionals runs the best known certifications: CPACC for core competencies, WAS for the technical web specialist track, and CPWA for holding both. They carry real weight in public sector procurement, where a named certification sometimes appears in the tender criteria. They also cost money and take study time you may not have at the start.
There is a second credential that fewer newcomers know about, and it matters more than its obscurity suggests. The Department of Homeland Security runs the Section 508 Trusted Tester Conformance Test Process, a prescribed manual testing method with its own certification. Its test process follows the ICT Testing Baseline, which meets the minimum requirements for the Revised 508 Standards including WCAG 2.0 Levels A and AA. DHS provides training and formal testing certification through a self-enrolment portal, currently for Trusted Tester v5; training and certification on v4.0 was retired, so check which version you are enrolling in. The Section 508 programme page does not publish a price and directs questions to the DHS accessibility helpdesk, so confirm the cost before you assume either way.
Two reasons to care. It gives you a repeatable, defensible test procedure, which is exactly what you lack as a beginner when all you have is principles. And it is a named qualification that shows up in the marketing of established vendors: Accessible.org states that its audits are conducted by Certified DHS Trusted Testers. A credential your competitor advertises is a credential your buyers recognise.
You can build a track record people can see before you sit any exam, and the order matters less than most people think.
Read the actual criteria. The WCAG 2.2 specification and the Understanding documents that go with each success criterion are the primary text, they are free, and they are more precise than any course built on top of them. Working through the AA criteria one at a time, testing each against a real page, is the single best use of your first month.
Then publish. Audit three sites in a sector you want to work in. Write them up properly, with criterion numbers, reproduction steps and user impact. Publishing an audit of an organisation you have no relationship with is a judgment call, so keep it factual, keep it about the interface and away from the organisation, and send it to them before you post it. Handled that way it becomes a portfolio piece, and now and then a first client. Which three sites in your chosen sector frustrate you most? Start with those, because your irritation already found the first findings.
Then get one paid engagement at a price you are slightly embarrassed by, in exchange for a reference and permission to describe the work. Your second engagement prices from the first.
That slightly embarrassing first price buys you a named reference from a real organisation. Months later, when a friend in web development asks how you started selling WCAG audits, you can turn the laptop around and show them the published audit, with the client's permission to name the work. Give that conversation something to rest on by publishing an audit a prospect can use.
Rookie Mistakes
Shipping the scanner output as the report. A client can run axe themselves for free. Exporting 300 automated violations to PDF, sorting by severity and invoicing for it is the fastest way to end an engagement badly, because the client will work out in about ten minutes that they could have made it themselves. Your findings should be mostly things no tool reported.
Testing pages instead of journeys. A page-by-page sweep of 40 URLs will miss the fact that the multi-step booking form loses keyboard focus between steps and strands the user. The findings that get budget approved almost always come from walking a task end to end.
Reporting by symptom rather than by cause. Two hundred findings that come down to nine root causes should be presented as nine root causes with instance counts. Presented as 200 line items, your report reads as unmanageable and gets put off.
Ignoring documents. Government and university sites are full of PDFs, and an untagged PDF is inaccessible however clean the HTML around it is. Scope documents explicitly, in or out, in writing. Discovering 4,000 untagged PDFs after agreeing a fixed price is a painful conversation.
Promising compliance. You test and report. Writing "this site is now ADA compliant" into a deliverable is a claim about legal exposure that you are in no position to make, and one a plaintiff's lawyer would enjoy reading.
Testing only the happy path. Submit the form empty. Enter a bad card number. Let the session time out. Error states are often the least accessible part of an interface and the most consequential, because that is the moment a user most needs to understand what went wrong.
Skipping the retest. Fixes introduce regressions fairly regularly. A fix that adds an `aria-label` while removing the visible text label makes things worse for some users. If you never look again, you never learn which of your recommendations were implemented badly.
Gotchas to Know Before Your First Call
The overlay problem. One category of product promises compliance through a single line of JavaScript that adds a widget to the page. These are widely criticised within the accessibility community, and organisations that installed one and considered the matter closed have still faced complaints. You will meet prospects who have already bought one. The useful response is to test the site with the widget switched on and show them what still fails, and to leave the argument about the vendor's marketing alone.
An automated score falls short of conformance. A client who reports a Lighthouse accessibility score of 98 believes they are nearly done. That score reflects a subset of machine-checkable criteria on one page. Explaining the gap gently, with a concrete failure their scanner missed, is often the moment the engagement becomes real. How would you show them that gap in under two minutes on a call? Keep one keyboard trap ready to demonstrate.
Deadlines move. The DOJ dates shifted in April 2026. Make a habit of checking the primary regulatory page before every proposal, and cite the date you checked it in the proposal itself. Clients notice, and it protects you when a date changes mid-engagement.
You are often auditing someone else's mistake. The person who hired you may have signed off the design that fails. Your findings land better when written about the interface than about anyone's decisions, and the auditor who makes the client's team look incompetent does not get the retainer.
Legal risk runs both ways. Be careful with certainty in writing. Report what you tested, when, and what you found. Turn down requests to sign statements asserting compliance, and price legal support work, such as responding to a complaint, as its own separate engagement.
Scope creep is the default. "While you're in there, can you check the intranet?" is the shape it takes. List templates, journeys, assistive technology combinations and documents in the statement of work, with a stated rate for additions.
Behind the Scenes: What the Work Feels Like
Your first audit of a mid-sized site will be less glamorous than the deadline-driven story suggests.
You start by counting templates, and this alone often surprises the client, who has never counted. You pick representative pages per template and list the journeys.
Then you do the automated sweep, which takes an afternoon and produces a long, mostly repetitive list. You triage it, throw out the false positives, and collapse the rest by cause.
Then comes the slow part, and it is most of the engagement. A keyboard walk of every journey. A screen reader walk of every journey, in at least two combinations, saying aloud what you hear so you notice when the announcement makes no sense. Zoom to 400% and reflow at 320 pixels. Colour vision simulation. Reduced motion. Form validation with deliberately bad input. Each pass is slow and repetitive, and each one turns up findings the tools never saw.
Then the writing, which takes longer than people budget for. Each finding needs a reproduction path a developer can follow, and a user impact sentence that makes sense to someone who has never used a screen reader.
Then the presentation, which is the part that decides whether you get more work. A 40-page PDF emailed without a walkthrough tends to get skimmed. Ninety minutes on a call demonstrating three findings live, with a screen reader audible, changes how a team thinks about the whole document.
The feelings deserve a name too. Your first audit will feel like you are missing things, because you are. Fluency arrives somewhere around the fifth or sixth engagement, when the common patterns start announcing themselves before you finish tabbing to them. Could you sit with that unsure feeling for five jobs? Most people who can, end up good at this.
By the fifth or sixth engagement the patterns announce themselves and each audit goes faster. If your audit work reaches the upper end, around 2,750 a month, that speed could pay for swimming lessons for your kids and the school trip deposit, signed the same night the form comes home. Keep practising the keyboard checks until you can price the work with a clear sense of the hours.
Every month you wait, someone else publishes the sample audit in your prospects' sector, and their name comes up first when a buyer goes looking. The skill only grows by doing it. Pick one public site tonight, run the keyboard checks, and write up three findings before you go to bed.
Where This Goes Next
Some predictions, offered as reasoning, with the uncertainty left in.
The 2027 and 2028 US deadlines will bring a procurement wave, then a support market. Public bodies rarely act early. Expect demand to bunch up in the twelve months before each date, followed by a quieter, steadier market for regression testing, because a site that reached conformance in April drifts out of it by September.
The vendor pass-through becomes the bigger market. Public bodies rarely build their own systems. Once an agency is obligated, it pushes the obligation into contracts with its content management vendor, its payments provider and its bookings platform. Those vendors then need audits for reasons unrelated to their own legal exposure, which makes them a larger and less deadline-bound buyer than the agencies themselves.
Automated coverage improves at the edges and the gap stays open. Machine detection will keep getting better at pattern-shaped criteria. It will not tell you whether alternative text carries the right meaning, whether an error message actually helps, or whether a journey can be completed. The human share of the work shrinks slightly and moves upmarket.
Design systems move the work earlier. The efficient fix for an organisation running 30 products on one component library is to audit the library. That is a different, more technical and better-paid engagement than auditing a website, and it is where the specialists are heading.
WCAG 2.2 adoption in regulation lags the specification by years. The DOJ rule names 2.1. Regulation moves slowly, so expect to test against 2.1 for legal purposes while advising against 2.2 for practical ones for some time yet, and expect to explain the difference on most calls.
Documents remain the neglected half. PDFs, spreadsheets and slide decks are inaccessible at scale across the public sector, remediation is tedious, and few people want the work. Tedious and unwanted is often where your margin is.
Regulation is slow, and that slowness is your opening. Organisations that realise they are behind start looking for help all at once, and they hire the auditors whose names they have already seen. Publish now and your work is sitting there when that search begins.