What Is EN 301 549?
EN 301 549 is the harmonized European standard defining accessibility requirements for information and communication technology (websites, mobile apps, software, hardware, and digital services generally). It exists to answer a question that laws by themselves rarely settle: when a regulation says a service must be "accessible," what does that actually require in engineering terms? EN 301 549 is the technical specification member states and courts point to for the answer, which makes it the connective tissue between accessibility law and accessibility implementation across the EU.
How it relates to WCAG
EN 301 549 does not invent its own accessibility criteria: for web content, it incorporates WCAG 2.1 Level AA by reference as its core requirement, which is why the two standards are so often mentioned in the same breath. What EN 301 549 adds is scope beyond the browser: requirements for native mobile applications, hardware interfaces like ATMs and ticket machines, real-time communication tools, and electronic documents, none of which WCAG alone was written to cover. A team building a WCAG-conformant website has satisfied the largest single piece of EN 301 549, but not automatically the whole standard if the product includes a native app or a physical interface component.
The laws that point to it
EN 301 549 is where EU accessibility legislation cashes out into testable engineering requirements. The European Accessibility Act sets legal obligations for private-sector products and services (e-commerce, banking, transport) and references EN 301 549 as the presumption-of-conformity standard: build to it, and the law presumes compliance. Germany's BFSG, the national transposition of the EAA, does the same at the domestic level. Public-sector accessibility rules across member states have relied on it even longer, since it originated as the standard for public procurement before the EAA extended similar expectations to private business.
What it means for verification specifically
Because EN 301 549 pulls in WCAG's CAPTCHA-specific criterion, any product covered by the standard has a direct, named obligation around verification challenges: they must not depend on a single sensory ability, and accessible alternatives must exist wherever a challenge is genuinely needed. The more resilient response is architectural rather than remedial: verification that relies on environmental and behavioral signals rather than visual puzzles, the approach CaptchaFox takes, satisfies the requirement by removing the failure point rather than patching around it after the fact. For a compliance team mapping EN 301 549 against a product's components, a verification layer built this way is one line item that resolves itself.
About CaptchaFox
CaptchaFox is a GDPR-compliant solution based in Germany that protects websites and applications from automated abuse, such as bots and spam. Its distinctive, multi-layered approach utilises risk signals and cryptographic challenges to facilitate a robust verification process. CaptchaFox enables customers to be onboarded in a matter of minutes, requires no ongoing management and provides enterprises with long-lasting protection.
To learn more about CaptchaFox, talk to us or start integrating our solution with a free trial.