Accessibility auditing is a freelance service with something most freelance services lack: a calendar. Two separate bodies of law have set dates by which specific organisations must meet a specific technical standard, and the standard is published, testable and almost universally failed right now. That combination is what makes this work sellable. You are not persuading a prospect that they might want a nicer website. You are telling them a deadline exists, showing them where they currently fail, and quoting to close the gap.
The service itself is straightforward to describe. A client gives you a website, a web application or a mobile app. You test it against the Web Content Accessibility Guidelines at the conformance level their obligation requires, then hand back a report that says which success criteria fail, on which screens, what a user relying on assistive technology experiences as a result, and what the developer should change. Some auditors stop at the report. Others stay on to verify the fixes, which is where the recurring revenue lives.
Almost every accessibility engagement traces back to one of three obligations. Knowing which one applies to a prospect tells you what standard to test against, what their deadline is, and how urgently they will move.
Check these dates rather than trusting a blog post, including this one. An interim final rule published on 20 April 2026 moved the deadlines out from the schedule set in the original 2024 rule, so a great deal of the advice written between 2024 and early 2026 now cites dates that no longer apply. The DOJ page is the authority and it is a single link away.
There is one nuance worth holding onto, because it is a live sales objection. Article 32(1) provides a transitional period ending 28 June 2030 during which service providers may continue providing services using products that were already lawfully in use before the application date. A prospect will sometimes read that as a blanket extension to 2030. It is narrower than that, and the distinction between a legacy product still in service and a new service being offered today is exactly the kind of question that sends organisations looking for someone who has read the directive.
The practical upshot is that you should ask one question on every first call. Which of those three applies to you, and if none of them do, what is making you look at this now? The answer sorts a serious buyer from a curious one in about fifteen seconds.
WCAG has three conformance levels, A, AA and AAA, from lowest to highest. Regulation almost always lands on AA. Nobody sensible sells AAA as a target, because some AAA criteria are impossible to satisfy for whole categories of content.
Version matters more than newcomers expect. WCAG 2.1 was published in June 2018 and is the version the DOJ Title II rule names. WCAG 2.2 reached W3C Recommendation status in a revision dated 12 December 2024 and adds nine success criteria over 2.1:
Read that list as a commercial signal rather than a technical one. Every criterion on it describes a pattern that shipped everywhere in the last decade. Drag-and-drop reordering with no keyboard alternative. A sticky header that swallows the focus ring as you tab down a page. Tap targets sized for a mouse. A checkout that makes you retype an address you entered two steps earlier. A login that demands you transcribe a code from an image. Those are not exotic edge cases. They are the default behaviour of most modern interfaces, which is why an audit against 2.2 finds more than an audit against 2.1 and why you should be explicit in the contract about which version you are testing.
The WebAIM Million report is the single most useful number in your sales deck. In its February 2026 edition, automated testing of one million home pages found that 95.9% had detected WCAG 2 failures, up from 94.8% the year before. The average page carried 56.1 detected errors.
Those six categories account for 96% of all detected errors, and WebAIM notes the pattern has held steady across seven years of reports. Two conclusions follow, and they pull in opposite directions.
The encouraging one is that most of what you will find is boring and fixable. A contrast ratio is arithmetic. An empty button needs an accessible name. A missing \`lang\` attribute is one line in the document head. You do not need deep expertise to find these, and a client who fixes only these six categories removes the overwhelming majority of their detected errors.
The sobering one is that "detected" is doing a lot of work in that sentence. Automated tools find a minority of actual WCAG failures, because most criteria require judgment. Does this alternative text convey the same information as the image, or does it say "image123.png"? Is the reading order of this page logical? Does the error message tell the user how to fix the problem? Can you complete the whole checkout with a keyboard alone? Nothing detects those. A human does. That gap is your entire business, and it is also why the work resists automation: the value you add starts precisely where the free scanner stops.
Selling this service gets much easier once you can describe the artefact concretely. An audit report that earns repeat work has these parts.
What This Work Actually Pays
Unusually for a freelance service, several established accessibility vendors publish their rate cards in full, so you can anchor your pricing to public numbers instead of guessing.
Accessible.org publishes a per-page model. Audits are $100 to $250 per primary page or screen, and $25 to $100 for light pages or screens, where a primary page is content rich or interactive and a light page has minimal content or repeated patterns. They state that most audits land between $1,250 and $2,750 in total. Their audits are fully manual, evaluated against WCAG 2.1 AA or 2.2 AA, and conducted by Certified DHS Trusted Testers. DigitalA11Y publishes a different shape for the same service, quoting $1,500 to $5,000 per audit.
The rest of the same rate card is more instructive than the audit line, because it shows where the margin actually sits:
| Service | Published price |
|---|
| Audit, primary page or screen | $100 to $250 each |
| Audit, light page or screen | $25 to $100 each |
| Technical support and fix validation | $195 per hour, two hour minimum |
| Senior consultation | $495 per hour |
| VPAT, WCAG edition, plus audit cost | $350 |
| VPAT, Section 508 edition | $550 |
| VPAT, EN 301 549 edition | $650 |
| User testing by a professional with a disability | $550 per session, $450 with an audit |
| Expedited or overnight turnaround | $250 to $750 |
| Remediation, per page or screen | $250 to $550 |
| PDF remediation | from $7.50 per page |
| Word and PowerPoint remediation | from $7.00 per page |
| Alt text writing | $2.25 per image |
| Closed captions | $2.25 per minute |
| Audio description | $17.50 per minute |
| Transcripts | $1.50 per minute |
Read that table as a map of the business rather than a price list to copy. Four things stand out.
The audit is the cheapest thing on it. Remediation is priced at $250 to $550 per page, which is two to five times the audit price for the same page. The audit is the door; the fixing is the room.
Hourly validation work at $195 per hour with a two hour minimum is the most repeatable line item, because every audit produces a client who has made fixes and wants to know whether they worked.
The conformance report is nearly pure margin. A $350 WCAG VPAT is compiled from an audit you already ran, and the Section 508 and EN 301 549 editions are priced higher at $550 and $650 because the buyer needs them to satisfy a procurement requirement.
Documents are a volume business hiding inside a service business. At $7.00 to $7.50 per page, a single untagged 400 page policy library is a meaningful engagement on its own, and it needs no design opinion or developer coordination.
How that becomes a monthly number. Take the per-unit rates above as the sourced part and the assembly as the estimate. One 12 primary page audit at the middle of the published range, plus its VPAT, plus four hours of fix validation, is one engagement of a few thousand dollars. Doing one of those a month while carrying a small document remediation queue is a part-time income; doing three, with two retainer clients on quarterly regression passes, is a full-time one. What varies is not the rate, it is how many engagements you can source, which is why the sections below spend more time on credibility than on pricing.
The three revenue shapes, roughly in the order people grow into them:
1. Fixed-scope audit. One report, defined page or template count, defined journeys. Predictable, and the easiest thing for a buyer with a procurement process to approve. 2. Audit plus validation. The audit, then hourly work retesting remediated items after the client's development cycle. Better margin because the second pass reuses your test plan. 3. Retainer. A monthly or quarterly regression pass, plus review of new features before release, plus keeping the published accessibility statement current. This is the mature version of the business and where income stops depending on winning new logos every month.
An audit is scoped from three inputs: the number of distinct templates rather than pages, the number of critical user journeys to walk end to end, and how many assistive technology combinations the client wants covered. Templates matter because a 4,000 page site built from 11 templates is an 11 template audit plus spot checks. Journeys matter because that is where the expensive findings hide: registration, search, checkout, payment, form validation, error recovery. Assistive technology combinations matter because each one is a full re-walk of the same ground.
The honest constraint on early income is not rate, it is credibility. Your first two or three engagements will be priced on trust rather than on a rate card, and the fastest route through that is a public artefact: an audit of something in your prospects' own sector, published, with the findings mapped to criteria and the user impact spelled out.
The Conformance Report Nobody Talks About
The VPAT deserves its own section because it is the most misunderstood high-margin deliverable in this field.
A Voluntary Product Accessibility Template is a standard form. Filled in, it becomes an Accessibility Conformance Report, which states, criterion by criterion, whether a product supports, partially supports or does not support each requirement. There are separate editions for WCAG, for Section 508 and for EN 301 549, which is why the published prices differ: $350, $550 and $650 respectively on top of the audit cost.
The reason this matters commercially is that the buyer is usually not the person who cares about accessibility. A software vendor selling to a federal agency, a university or a European bank gets asked for an ACR during procurement. Without one, the deal stalls. That vendor is not shopping for an audit, they are shopping for the document that unblocks a contract, and their urgency is entirely different from a public body working towards a 2027 deadline.
Two cautions. First, an honest ACR frequently says "partially supports", and a vendor who wanted a clean sheet may push back. Filling it in optimistically is a misrepresentation that their customer's procurement team may test. Second, the ACR is only as good as the audit underneath it, so refusing to produce one without doing the testing is both the ethical and the commercially sound position.
Beyond the US and EU: the UK Regime
The UK has its own public sector rule and it is worth knowing because the obligations have been live for years, which makes the market mature rather than anticipatory.
The Public Sector Bodies (Websites and Mobile Applications) (No. 2) Accessibility Regulations 2018 define the "accessibility requirement" as making a website or mobile application "perceivable, operable, understandable and robust", the four WCAG principles. The application dates have all passed:
| Asset | Requirement applies from |
|---|
| Website published on or after 23 September 2018 | after 22 September 2019 |
| Any other public sector website | after 22 September 2020 |
| Public sector mobile application | after 22 June 2021 |
Three features of the UK regulations create billable work that the US and EU rules do not.
The accessibility statement is mandatory and must be maintained. Regulation 8 requires a public sector body to publish a detailed, comprehensive and clear statement, following the model statement, and to "keep that statement under regular review". A statement that must stay current is a recurring engagement by design, and most published statements go stale within a year of being written.
Failure is routed into discrimination law. A failure to comply with the accessibility requirement "is to be treated as a failure to make a reasonable adjustment", which connects the regulations to the Equality Act rather than leaving them as a standalone technical duty. That framing is why UK public sector buyers treat findings as legal risk rather than as a quality backlog.
There is a disproportionate burden exemption, and it has to be argued. Regulation 7 removes the requirement where compliance "would impose a disproportionate burden", and the regulations exempt specific categories including live time-based media, pre-recorded media published before 23 September 2020, online maps where essential information is available another way, heritage collection items, and intranet or extranet content published before 23 September 2019 until it undergoes substantial revision. Documenting a disproportionate burden assessment properly is skilled work, and a body that claims the exemption without an assessment is more exposed than one that never claimed it.
The tooling floor is genuinely zero, which is unusual for a technical service.
Automated scanners. The axe DevTools browser extension has a free tier that runs basic automated testing on a page-by-page basis. Deque's paid tiers add AI-assisted automation, guided testing, user flow analysis, deduplication, CI integration and API access, and are quoted by their sales team rather than listed publicly. WAVE and the accessibility audit built into Chrome's Lighthouse cost nothing. Every one of these finds the same narrow band of machine-detectable issues, so running three of them is mostly redundant. Pick one, learn its false positives.
Screen readers. This is non-negotiable and it is where the real skill sits. NVDA on Windows is free and is what a large share of screen reader users actually use. VoiceOver ships with macOS and iOS at no cost. JAWS is the commercial Windows incumbent and matters because enterprise and government users are often standardised on it. TalkBack ships with Android. You need to be fluent in at least one and competent in a second, because a bug that reproduces in NVDA and not VoiceOver is a common and diagnostic result.
Keyboard only. Unplug the mouse. A large fraction of the findings that clients pay most attention to come from simply tabbing through a page: focus that disappears, focus that gets trapped in a modal, focus order that jumps around, controls you cannot reach at all.
Contrast and zoom. A contrast checker for the 83.9% problem. Then set browser zoom to 400% and reflow the page at a 320 pixel viewport width, which is what criterion 1.4.10 requires and which breaks a remarkable number of otherwise tidy layouts.
Colour vision simulation and reduced motion. Both are built into modern browser dev tools. Both take seconds and both catch issues that automated scanners never report.
The pattern across all of it: automated tools narrow the search space, then a human walks the journeys. Anyone selling you a subscription that replaces the second half is selling the overlay problem described below.
Getting Credible Before You Have Credentials
The International Association of Accessibility Professionals runs the best known certifications, CPACC for core competencies, WAS for the technical web specialist track, and CPWA for holding both. They carry real weight in public sector procurement, where a named certification sometimes appears in the tender criteria. They also cost money and take study time you may not have at the start.
There is a second credential that fewer newcomers know about and that matters more than its obscurity suggests. The Department of Homeland Security runs the Section 508 Trusted Tester Conformance Test Process, a prescribed manual testing methodology with its own certification. Its test process follows the ICT Testing Baseline, which meets the minimum requirements for the Revised 508 Standards including WCAG 2.0 Levels A and AA. DHS provides training and formal testing certification through a self-enrolment portal, currently for Trusted Tester v5; training and certification on v4.0 was retired, so check which version you are enrolling in. The Section 508 programme page does not publish a price and directs questions to the DHS accessibility helpdesk, so confirm the cost before assuming either way.
Two reasons to care. It teaches you a repeatable, defensible test procedure rather than a set of principles, which is exactly what a beginner lacks. And it is a named qualification that appears in the marketing of established vendors: Accessible.org states that its audits are conducted by Certified DHS Trusted Testers. A credential that a competitor advertises is a credential your buyers recognise.
You can build a demonstrable track record before you sit any exam, and the order matters less than most people assume.
Read the actual criteria. The WCAG 2.2 specification and the Understanding documents that accompany each success criterion are the primary text, they are free, and they are more precise than any course built on top of them. Working through the AA criteria one at a time, testing each against a real page, is the single highest-yield thing you can do in your first month.
Then publish. Audit three sites in a sector you want to work in. Write them up properly, with criterion numbers, reproduction steps and user impact. Publishing an audit of an organisation you have no relationship with is a judgment call, so keep it factual, keep it about the interface rather than the organisation, and send it to them before you post it. Handled that way it is a portfolio piece and occasionally a first client.
Then get one paid engagement at a price you are slightly embarrassed by, in exchange for a reference and permission to describe the work. The second engagement prices from the first.
Rookie Mistakes
Shipping the scanner output as the report. A client can run axe themselves for free. Exporting 300 automated violations to PDF, sorting by severity and invoicing for it is the fastest way to end an engagement badly, because the client will discover in about ten minutes that they could have generated it. Your findings should be dominated by things no tool reported.
Testing pages instead of journeys. A page-by-page sweep of 40 URLs will miss the fact that the multi-step booking form loses keyboard focus between steps and strands the user. The findings that get budget approved almost always come from walking a task end to end.
Reporting by symptom rather than by cause. Two hundred findings that reduce to nine root causes should be presented as nine root causes with instance counts. Presented as 200 line items, the report reads as unmanageable and gets deferred.
Ignoring documents. Government and university sites are full of PDFs, and an untagged PDF is inaccessible regardless of how clean the HTML around it is. Scope documents explicitly, in or out, in writing. Discovering 4,000 untagged PDFs after agreeing a fixed price is a painful conversation.
Promising compliance. You test and report. Writing "this site is now ADA compliant" into a deliverable is an assertion about legal exposure that you are not positioned to make and that a plaintiff's lawyer would enjoy reading.
Testing only the happy path. Submit the form empty. Enter a bad card number. Let the session time out. Error states are frequently the least accessible part of an interface and the most consequential, because that is the moment a user most needs to understand what went wrong.
Skipping the retest. Fixes introduce regressions with some regularity. A fix that adds an \`aria-label\` while removing the visible text label makes things worse for some users. If you never look again, you never learn which of your recommendations were implemented badly.
Gotchas Worth Knowing Before Your First Call
The overlay problem. A category of product promises compliance through a single line of JavaScript that adds a widget to the page. These are widely criticised within the accessibility community, and organisations that installed one and considered the matter closed have still faced complaints. You will meet prospects who have already bought one. The productive response is to test the site with the widget active and show them what still fails, rather than to argue about the vendor's marketing.
Automated scores are not conformance. A client who reports a Lighthouse accessibility score of 98 believes they are nearly done. That score reflects a subset of machine-checkable criteria on one page. Explaining the gap gently, with a concrete failure their scanner missed, is often the moment the engagement becomes real.
Deadlines move. The DOJ dates shifted in April 2026. Build the habit of checking the primary regulatory page before every proposal, and cite the date you checked it in the proposal itself. Clients notice that, and it protects you when a date changes mid-engagement.
You are often auditing someone else's mistake. The person who hired you may have signed off the design that fails. Findings land better when written about the interface than about decisions, and the auditor who makes the client's team look incompetent does not get the retainer.
Legal risk runs both ways. Be careful with certainty in writing. Report what you tested, when, and what you found. Resist requests to sign statements asserting compliance, and price legal support work, such as responding to a complaint, as its own separate engagement.
Scope creep is the default. "While you're in there, can you check the intranet?" is the shape it takes. Templates, journeys, assistive technology combinations and documents should be enumerated in the statement of work with a stated rate for additions.
Behind the Scenes: What the Work Actually Feels Like
A first audit of a mid-sized site is less glamorous than the deadline-driven story suggests.
You start by inventorying templates, not pages, and this alone often surprises the client, who has never counted. You pick representative pages per template and enumerate the journeys.
Then you do the automated sweep, which takes an afternoon and produces a long, largely repetitive list. You triage it, discard the false positives, and collapse the rest by cause.
Then comes the slow part, and it is most of the engagement. Keyboard walk of every journey. Screen reader walk of every journey, in at least two combinations, narrating aloud what you hear so you notice when the announcement makes no sense. Zoom to 400% and reflow at 320 pixels. Colour vision simulation. Reduced motion. Form validation with deliberately bad input. Each pass is slow, repetitive and produces findings the tools never saw.
Then writing, which is longer than people budget for. Each finding needs a reproduction path a developer can follow, and a user impact sentence that survives being read by someone who has never used a screen reader.
Then the presentation, which is the part that decides whether you get more work. A 40-page PDF emailed without a walkthrough tends to be skimmed. Ninety minutes on a call demonstrating three findings live, with a screen reader audible, changes how a team thinks about the whole document.
The emotional shape of it is worth naming. The first audit feels like you are missing things, because you are. Fluency arrives somewhere around the fifth or sixth engagement, when the common patterns start announcing themselves before you finish tabbing to them.
Where This Goes Next
Some predictions, offered as reasoning rather than certainty.
The 2027 and 2028 US deadlines will produce a procurement wave, then a support market. Public bodies do not act early. Expect a concentration of demand in the twelve months before each date, followed by a quieter but steadier market for regression testing, because a site that reached conformance in April drifts out of it by September.
The vendor pass-through becomes the bigger market. Public bodies rarely build their own systems. Once an agency is obligated, it pushes the obligation into contracts with its content management vendor, its payments provider and its bookings platform. Those vendors then need audits for a reason that has nothing to do with their own legal exposure, which makes them a larger and less deadline-bound buyer than the agencies themselves.
Automated coverage improves at the edges without closing the gap. Machine detection will keep getting better at pattern-shaped criteria. It will not answer whether alternative text conveys the right meaning, whether an error message is actually helpful, or whether a journey is completable. The human share of the work shrinks slightly and moves upmarket.
Design systems shift the work left. The efficient fix for an organisation running 30 products on one component library is to audit the library. That is a different, more technical and better-paid engagement than auditing a website, and it is where the specialists are heading.
WCAG 2.2 adoption in regulation lags the specification by years. The DOJ rule names 2.1. Regulation moves slowly, so expect to be testing against 2.1 for legal purposes while advising against 2.2 for practical purposes for some time yet, and expect to explain the difference on most calls.
Documents remain the neglected half. PDFs, spreadsheets and slide decks are inaccessible at scale across the public sector, remediation is tedious, and few people want the work. Tedious and unwanted is frequently where the margin is.