Regulation

The EAA exemptions that don't save you: microenterprise and the 2030 runway

Neither the microenterprise exemption nor the 2030 transition is the escape hatch most vendors reach for. The microenterprise exemption relieves only pure service providers that are under both size thresholds - product makers of any size are never exempt - and the 28 June 2030 transition only lets pre-existing contracts and lawfully-in-use equipment wind down to expiry, not new services or renewals. If you are selling in-scope software or hardware into the EU today, assume you are in scope now.

Dated analysis. Enforcement reading checked 18 July 2026, built on a two-angle legal-and-practice research sweep. The exemption mechanics rest on Directive 2019/882 as relayed by legal secondary sources; the exact Article 32 transition wording was not quoted from EUR-Lex in that sweep, though the figures are uniform across sources and match the directive. National fine ceilings vary by source and should be checked against the specific transposition before you quote them to anyone.

Does the microenterprise exemption cover you?

Probably not, and for two reasons people miss. The definition under the directive is narrow: fewer than 10 employees AND an annual turnover or balance sheet total of no more than €2 million. Both the headcount test and one financial test must hold; cross either - ten staff, or €2M - and the exemption is gone (webyes.com, krisrivenburgh.com).

The larger trap is what the exemption applies to. It exempts microenterprises that provide services from the service accessibility requirements. Microenterprises that manufacture, import or distribute in-scope products are not exempt from the product requirements - they receive only lighter documentation and assessment duties. So "we're a microenterprise" only helps a prospect who is a pure service provider under both thresholds and has no product in scope. Most SaaS and e-commerce software vendors selling into the EU are neither small enough nor purely service-side enough to rely on it. Treat the claim as something to verify against the two thresholds and the product/service line, not a conversation-ender.

Does the 28 June 2030 transition buy you time?

Only for legacy commitments already in flight. The transition is a wind-down of pre-existing arrangements, not a compliance holiday. In three parts:

  • Service contracts concluded before 28 June 2025 may continue unchanged until they expire, but no later than 28 June 2030 - a runway of about five years at most.
  • Products lawfully in use to provide a service before 28 June 2025 may continue to be used until 28 June 2030.
  • Self-service terminals - ATMs, ticketing and check-in machines - lawfully in use before 28 June 2025 may run to the end of their economically useful life, capped at 20 years.

What the window does not cover is the part vendors want it to cover. New services, new contracts and renewals are in scope now. A contract signed after 28 June 2025, or an existing one renewed, does not inherit the runway. Frame 2030 to a client as the expiry date on their existing inaccessible commitments, not permission to ship new inaccessible ones (accessibilityref.eu).

What does enforcement actually look like?

Not, so far, regulator fines. Across the research sweep, no confirmed named regulator-imposed monetary EAA fine was found; the live mechanisms in the first year have been civil litigation, formal notices and private warning letters. Two national channels are where real pressure sits today.

Germany enforces primarily through private unfair-competition law: §8 UWG Abmahnung warning letters, the first of which landed in e-commerce around August 2025, roughly six weeks after the BFSG took effect (Heuking). Competitors, recognised consumer associations and chambers of commerce can all send them; a typical letter runs €1,000–3,000 plus a penalty-bearing cease-and-desist, and the statutory BFSG fine ceiling is up to €100,000 for serious or systematic breaches. A common trigger is a missing or deficient accessibility declaration - the cheapest failure to fix and one of the most frequently cited.

Ireland is the outlier: the one member state with criminal liability. Under S.I. No. 636/2023, serious deliberate non-compliance is a criminal offence, carrying on conviction on indictment a fine of up to €60,000 and/or up to 18 months' imprisonment, with directors, managers and officers personally liable (DLA Piper, Mason Hayes & Curran). An all-reasonable-precautions defence exists, and the criminal route targets bad actors who ignore repeated enforcement notices rather than firms making genuine remediation efforts - but for a company with Irish exposure, personal director liability changes who in the building cares about this.

What are buyers now demanding?

Increasingly, evidence rather than assurances. The EAA itself does not name VPATs, but procurement convention plus the EU harmonised standard EN 301 549 (which incorporates WCAG 2.1 AA) has pushed buyers to ask software suppliers for a VPAT or Accessibility Conformance Report mapped to EN 301 549, an accessibility statement with a working support channel, and contract clauses covering remediation SLAs and audit rights (Level Access, corpowid).

Crucially, a scanner percentage is no longer accepted as proof. In the French Carrefour ruling of 4 June 2026, a defence of 71% RGAA conformance was rejected outright: partial accessibility is not compliance (Deque). Practitioners now cite that decision to argue automated scores are insufficient and to demand manual and assistive-technology test evidence. If your accessibility story is a green dashboard number, expect it to be challenged - see the Carrefour ruling for what a court did with exactly that defence. The practical implication for vendors is to hold conformance evidence, not just a scanner result, before a buyer's legal team asks for it.


Questions people ask

Does the microenterprise exemption mean I can skip the EAA? Only if you are a pure service provider with fewer than 10 employees AND no more than €2M turnover or balance sheet, and you have no in-scope product. Product makers of any size are never exempt, and crossing either threshold removes the relief (webyes.com).

Does the 2030 transition give me until 2030 to comply? No. It lets service contracts concluded before 28 June 2025 run to expiry (no later than 28 June 2030) and lawfully-in-use products and terminals wind down, but new services, contracts and renewals are in scope now (accessibilityref.eu).

What is the penalty for getting this wrong? It depends on the country. Germany's BFSG ceiling is up to €100,000, enforced mostly via private UWG warning letters (Heuking); Ireland is the only member state with criminal liability, up to €60,000 and/or 18 months, with directors personally liable (DLA Piper). No confirmed EU-wide regulator fine has yet been reported.

Is a scanner score enough to prove compliance? No. A French court rejected a 71% conformance defence in the Carrefour case, and buyers increasingly ask for a VPAT or ACR mapped to EN 301 549 plus manual test evidence (Deque).


Sources & caveats. Exemption and transition mechanics rest on Directive 2019/882 as relayed by legal secondary sources (accessibilityref.eu, webyes.com, krisrivenburgh.com); the exact Article 32 wording was not quoted from EUR-Lex in this pass, though the figures are uniform across sources. German enforcement is per Heuking; Irish criminal liability per DLA Piper and Mason Hayes & Curran. The Carrefour ruling is per Deque; the exact daily-penalty figure in that case is only partially corroborated and is deliberately omitted here. National fine ceilings other than Germany and Ireland come from vendor comparison blogs and should be verified against the specific national transposition before use.