What is a website compliance audit? A practical guide for SMBs
A website compliance audit checks accessibility, privacy, and tracking practices against the laws that apply where your visitors live. Here is the practical version for small and medium businesses.
If you run a small or medium business with a website, the rules you have to follow have multiplied in the last five years. Accessibility laws now reach private companies in the EU, UK, US, Canada, and Australia. Privacy regulators have shifted from warning letters to fines that scale with revenue. Cookie consent enforcement, once an EU-only headache, now appears in California, Colorado, Connecticut, Texas, and a growing list of states.
A website compliance audit is how you find out whether your site actually meets the laws that apply to it. This article walks through what the audit covers, how to run one without burning weeks of consultant time, and what an SMB should actually fix first.
What a compliance audit actually checks
There is no single global law called “website compliance.” The audit is a checklist drawn from the regulations that apply wherever your visitors live. For most SMBs operating in the EU, UK, or US, the four checklists below cover 90% of real-world risk.
1. Accessibility
The working target is WCAG 2.1 Level AA, but which law points at which version is worth getting right. The European Accessibility Act (in force from 28 June 2025) reaches WCAG 2.1 AA through the harmonised standard EN 301 549. The AODA mandates WCAG 2.0 AA, not 2.1 (O. Reg. 191/11 s. 14, excluding success criteria 1.2.4 and 1.2.5). The UK Equality Act 2010 names no technical standard at all; WCAG 2.1 AA is binding on the UK public sector through the 2018 accessibility regulations, and private-sector claims are settled against it by practice, not by statute. And ADA Title III adopts no standard either, the US Department of Justice’s April 2024 rule fixed WCAG 2.1 AA for Title II public entities only. Building to 2.1 AA clears all four, which is why it remains the sensible target.
An automated scan catches the machine-testable part of WCAG, conventionally put at roughly a third of the success criteria: colour contrast, missing alt attributes, broken form labels, unnamed links and buttons, missing page language, ARIA misuse. It does not catch keyboard traps, focus order, focus visibility, reflow, or whether an alt text is any good. Veracly’s own rule packs mark 29 WCAG criteria as manual and score-neutral for exactly that reason. A scan tells you whether you have the obvious problems; no scan tells you that you are compliant.
Read more: WCAG 2.1 AA accessibility audit explained.
2. Privacy & consent
For EU/UK visitors, consent for non-essential cookies and trackers is required before the script fires. A real consent audit captures network traffic on the very first page load, before the user clicks anything. Banners that say “by using this site you consent” or that drop trackers on page load are the most common failure mode, and the easiest for a regulator to spot.
Read more: What is a GDPR cookie audit?
3. Tracking and analytics
Auditors look for tracking pixels (Meta, TikTok, LinkedIn, Google Ads), session recorders (Hotjar, FullStory, Microsoft Clarity), advertising tags, and any tool that sends visitor behaviour to a third party. Each one has GDPR, ePrivacy, and increasingly US state-law implications. The fix is rarely to remove them, it is to load them only after consent and to disclose them honestly.
Read more: Tracking pixel audit: GDPR & ePrivacy.
4. Required legal pages
The documents the law expects you to publish and link to:
- Privacy policy that matches what your site actually does
- Cookie policy with a current cookie inventory
- Accessibility statement (mandatory under the EAA from June 2025)
- Imprint / Impressum (mandatory in Germany, Austria, and Switzerland)
- Terms of service if you sell anything
Be clear about which half of that list a scanner can actually settle. Veracly checks whether a privacy policy, an accessibility statement, and an imprint exist and resolve on your own domain, and it flags trackers it observed loading that are named nowhere in your privacy text. It does not read the policy for a controller, a legal basis, or a retention period; it does not compare your cookie table against the cookies we saw set; and it does not check terms of service at all. Those are a human read. We would rather say so than let a green tick imply a lawyer signed off.
Manual audit vs. continuous scanning
A manual audit by a consultancy typically takes 2 to 6 weeks and costs €5,000, €20,000 for a single SMB site. That is fine for a one-off snapshot, but most compliance regressions happen after the audit, during normal product work. A new third-party widget, a redesigned signup form, an analytics tool added by marketing without telling engineering. Continuous scanning catches these the day they ship instead of months later when the regulator’s letter arrives.
The pragmatic combination is one manual baseline (or a thorough scan) and then weekly automated scans that compare against the previous run. Most SMBs do not need a compliance team; they need a scanner that yells when something breaks.
What an SMB should actually fix first
If you are starting from zero, do these in order. Most teams can finish the list inside a sprint.
- Stop firing trackers before consent. This is the highest-risk and easiest-to-fix issue. Move every Meta/TikTok/LinkedIn pixel and any non-essential analytics behind a consent check.
- Replace the “by using this site you consent” banner. Replace it with a banner that has equally weighted Accept and Reject buttons. The CNIL and the Garante have both fined for the alternative. The ICO has never fined over banner design, but it does run sweeps and write to sites, most recently the UK top 1,000 in January 2025.
- Fix the top WCAG violations. Colour contrast, missing alt text, form labels, focus states, and keyboard traps. These are the 5 issues that account for the majority of accessibility complaints.
- Publish an accessibility statement. The EAA requires one from June 2025 for in-scope products. Even if you are out of scope, having one signals good-faith effort and helps in any subsequent dispute.
- Update your privacy policy to match what your site actually does. Most SMB privacy policies are a template that bears no relationship to the live site. Regulators check.
Common mistakes to avoid
Trusting an accessibility overlay. The FTC fined accessiBe USD 1 million in January 2025 for misleading marketing about its overlay widget. Overlays do not create legal compliance. They mask issues at runtime; the underlying code still fails for many users and is still a basis for a lawsuit.
Treating compliance as a US-only or EU-only problem. Most SMB sites today serve visitors from multiple jurisdictions. A scan that only reports against one framework will miss issues that matter for the others.
Auditing once and never again. The most common pattern: a thorough audit, a clean report, six months of routine releases, and a regulator letter. Make the audit part of your release process.
How Veracly approaches this
Veracly was built specifically for the SMB version of this problem. One scan reports against the EAA, GDPR and ePrivacy, the ADA, the UK Equality Act, and the AODA at the same time. US state privacy laws are not in the engine, and we would rather name the gap than pad the list.
The free scan covers one page, once per email address per rolling seven days. It runs the same analyzers, the same rule packs, and the same scoring as a paid scan, so the findings are real, but it deliberately ships with AI explanations limited to its top three findings, without evidence screenshots or copy-paste remediation, and it is a single snapshot rather than continuous monitoring. Those arrive with a paid plan. Run the free scan at veracly.app and see what your site looks like to a regulator before they look at it for you.
Common questions
What does a website compliance audit cover?
A full audit looks at four buckets: accessibility (WCAG 2.1 AA at minimum), privacy and consent (GDPR, ePrivacy, state laws like CCPA), tracking and analytics setup, and required legal pages (privacy policy, accessibility statement, imprint where required).
Is a website compliance audit legally required?
No regulator mandates the audit itself, but the underlying laws, GDPR, the European Accessibility Act, the ADA, the UK Equality Act, are enforceable today. An audit is the practical way to know whether you are exposed before someone files a complaint.
How often should we run an audit?
Run a baseline audit once, then continuous scans whenever the site changes. Most SMB compliance issues are introduced during routine releases, a new tracking script, a redesigned form, a third-party widget, not during the original build.
How long does an audit take?
A scanned audit covering accessibility, cookies, and trackers finishes in minutes. A full manual audit by a consultant typically runs 2 to 6 weeks for an SMB site and costs €5,000, €20,000.
See where your site stands.
Run a free Veracly scan and get a multi-jurisdiction report, EAA, GDPR, ADA, UK Equality Act, AODA, with copy-paste developer fixes.
Run a free scan