What the Act is
The Accessible Canada Act is federal legislation whose purpose is to identify, remove and prevent barriers for people with disabilities. It works through obligations rather than a single rule: covered organisations publish accessibility plans, set up a way to receive feedback, and report on their progress. The technical detail, including anything specific about websites, comes through regulations made under the Act.
That structure is why searching for "the website requirement" produces confusing answers. There are three different things people are usually looking for, and they are on separate tracks.
| Obligation | Status | Timing |
|---|---|---|
| Accessibility plan, feedback process, progress reports | In force | Ongoing cycle; next progress report 1 June 2026 |
| Compliance reporting | In force | Next deadline 31 December 2026 |
| Digital conformance to a technical standard | Proposed in regulations | 1 June 2028 for medium and large organisations |
So the reporting is real now, and the technical conformance deadline is further out and still at the proposal stage. Both matter, and the honest answer to "must my site be accessible by 2028" is that this is the proposed date for federally regulated medium and large organisations and you should verify it, because proposals are amended.
Who it covers
This is the question most people get wrong, and getting it wrong in either direction is expensive. The Act applies to federally regulated organisations, not to every business in Canada.
- The federal government, Parliament and Crown corporations
- Banking
- Telecommunications and broadcasting
- Interprovincial and international transportation
- Other private-sector sectors under federal jurisdiction
Most Canadian businesses are provincially regulated, which means a retailer, a clinic, a local manufacturer or a software company is almost certainly outside the Accessible Canada Act. That is not the same as being outside accessibility law, which we come back to below.
Where the Act does apply, size determines what you owe. The proposed regulations distinguish organisations averaging 100 to 499 employees from those averaging more than 500, and both would be subject to web and digital accessibility requirements. Smaller federally regulated organisations face a lighter set.
The reporting cycle is the part already running
If you are covered, reporting is the live obligation. Two dates are worth putting in a calendar now: the next progress report for federally regulated private-sector organisations is due 1 June 2026, and the next compliance report deadline is 31 December 2026.
A progress report is not a form you fill in at the deadline. It is supposed to describe what you have actually done against your published accessibility plan, and what feedback you received and how you responded to it. That means the feedback mechanism has to have existed and been monitored, which is the part organisations most often discover late.
- Check your published accessibility plan exists and is findable on your site
- Check the feedback process works, including by keyboard and with a screen reader
- Check somebody is actually reading what comes in, and that responses are recorded
- Collect what changed since the last report, with dates
- Write the report against the plan, not as a general statement of intent
Step two has a certain irony to it that is worth avoiding: an accessibility feedback form that a screen reader user cannot complete is the most quotable possible failure.
The technical standard is EN 301 549, which means WCAG 2.1 AA
The Act identifies CAN/ASC-EN 301 549 as the technical benchmark for digital accessibility. That standard covers information and communications technology broadly: websites, software, mobile apps, electronic documents, hardware interfaces and communications tools.
For web content specifically, the standard incorporates WCAG 2.1 Level AA by reference. So the practical target for your website is WCAG 2.1 AA, and the broader standard is what extends the obligation past your website to your apps, your documents and your internal tools.
Three consequences follow that catch teams out:
- Internal systems count. The proposed requirements cover employee-facing pages as well as public ones, so your intranet and internal tools are in scope.
- Documents count. A PDF is electronic content. An inaccessible PDF behind an accessible page is still a barrier.
- Procurement matters. If you buy a tool your staff must use, its accessibility becomes your problem. Ask vendors for conformance information before purchase, not after.
The detail of the standard, and how it differs from WCAG alone, is covered in EN 301 549 compliance. For the WCAG fundamentals themselves, start with our web accessibility guide.
The proposed digital deadline, and why 2028 is not far away
Under the proposed regulations, medium and large federally regulated private-sector organisations would have until 1 June 2028 to ensure that all public-facing and employee-facing web pages conform to the standard.
That sounds comfortable. It is not, for organisations of that size, and the reason is scope rather than difficulty. "All public-facing and employee-facing web pages" in a 500-person business is not a website. It is a website, several microsites nobody owns, a careers portal, a customer login, an intranet, a handful of internal tools bought from vendors, and years of PDFs.
- Inventory first. You cannot remediate what you have not listed, and the list is always longer than expected.
- Triage by use. Fix what people actually use, starting with anything an employee must use to do their job.
- Fix systematically. Contrast, focus styles and form patterns usually come from a design system, so one change fixes many pages.
- Handle procurement in parallel, because a tool bought in 2027 without accessibility questions becomes a 2028 problem.
- Deal with documents last and deliberately, deciding which PDFs get remediated and which become web pages instead.
Step one is the deliverable to aim for this year. An accurate inventory turns an open-ended obligation into a finite list of work, and it is also the evidence that you are taking it seriously.
Federal is not the only layer
If you concluded above that you are provincially regulated and therefore outside the Act, read this part before relaxing.
Provincial accessibility law exists and in some provinces it is more demanding of ordinary businesses than the federal regime. Ontario's AODA requires organisations with 50 or more employees to meet WCAG 2.0 Level AA on public-facing websites, and requires organisations with 20 or more employees to file an accessibility compliance report. Other provinces have their own legislation at various stages.
Underneath all of it, human rights obligations apply regardless of which government regulates you. A customer who cannot use your website to buy something has a complaint available to them that does not depend on an accessibility statute.
The practical conclusion is unglamorous: the target is WCAG 2.1 AA, almost everybody should be working towards it, and the main thing that differs between regimes is the paperwork and the deadline.
What to do about it
- Determine whether you are federally or provincially regulated, and write the answer down
- If federally regulated, diarise 1 June 2026 and 31 December 2026 now
- Inventory every web property, internal tool and document set you are responsible for
- Run an automated scan across the top pages of each, to find the mechanical failures
- Keyboard test your most important journeys, because no scanner will tell you about those
- Fix the systematic issues in your design system, where one change covers many pages
- Add accessibility questions to procurement, so you stop acquiring new problems
- Keep a record of what was tested, when, what was found and what was fixed
Step eight is what you will rely on. Nobody certifies conformance, so the only thing you can show is your own evidence of work done. It also makes each reporting cycle a confirmation rather than an investigation.
We audit and remediate websites and web applications against WCAG 2.1 AA, including the internal tools and login areas that tend to be left out of the first pass. Send us your URL and we will tell you what we find and what it would take to fix, before you commit to anything.