Type something to search..
Selling software to Dutch public sector bodies

Your government customers have to prove their digital channels are accessible, and your software is one of those channels. Here is what they will ask you for

Every Dutch government body must publish an accessibility statement for each website, app and portal, with an audit behind it. When that channel runs on your software, the evidence they need is evidence about your product. This page tells you what the Dutch rules require, what your customers will ask, and how an audit of your product answers it.

The rule: a statement per channel in the Dutch Register, substantiated by an audit following WCAG-EM, valid for 36 months
What lands on you: your customers cannot claim status A or B without evidence about the technology you deliver
Who can help: an independent audit of your product against WCAG 2.2 and EN 301 549, in English, that your customers can use for their statements

Audited for, among others

Province of North Holland Province of South Holland IPO, the association of provinces City of Amersfoort City of 's-Hertogenbosch City of Alkmaar

What the Dutch rules mean for a supplier

The obligation

The law binds your customer. The evidence has to come from you

Dutch government bodies and other public sector bodies fall under the Besluit digitale toegankelijkheid overheid, the Dutch implementation of the EU Web Accessibility Directive, in force since 2018. The standard is EN 301 549, which currently points to WCAG 2.1 level A and AA. Every digital channel needs its own accessibility statement in the Dutch Register: the main website, subsites, application forms, portals behind a login, intranets and apps. A statement with status A or B needs an audit behind it; without one, the Register marks the substantiation as insufficient. When the channel is your product, your customer will come to you for that audit, or ask you to allow one.

The Register

Five statuses your customer can claim

  • A: fully compliant
  • B: partially compliant
  • C: audit in progress or first measures taken
  • D: does not comply
  • E: no owner
  • Only an audit following WCAG-EM counts. A report expires after 36 months.
Where it goes wrong

Most statements in the Register are missing the evidence

In August 2026 we analysed all 9,075 websites in the Dutch Register. 42% had no audit report at all. At 603 statements with status A or B the Register marked the substantiation as insufficient, usually because a part of the audit was missing. That is the situation your customers are in, and the missing evidence is often about software they bought. A supplier who can hand over a current WCAG-EM report saves the customer that problem, and answers the accessibility question in the next tender before it is asked.

Beyond the web page

EN 301 549 covers more than WCAG

  • Web content, chapter 9, adopts the WCAG success criteria
  • Software and apps have their own requirements, such as following the user’s text size and working in both orientations
  • Documentation and support you deliver must be accessible too
  • A product that passes WCAG can still fall short on the standard
What we audit

Your product, as your customers deploy it

We audit the product the way a citizen or civil servant uses it: a web application, a citizen portal, a case system, a form builder, an iOS or Android app. Behind a login, on a test environment or on a live customer instance, with a non-disclosure agreement where needed. We test by hand, with a screen reader, the keyboard alone and zoom, following WCAG-EM, and we report per component: everything that is wrong with the date picker is in one place, with the fix. A senior auditor runs the audit, a second auditor reviews it, and every report is checked by three people before delivery.

What you get

A report your customers can use

  • A report per component with a user story, a screenshot and a fix per finding
  • In English or in Dutch, so your customer can file it as it is
  • A CSV for your backlog and a retest per finding after your fixes
  • Findings that belong to the customer’s own content marked separately from findings in your product

From tender question to a report your customers can rely on

  1. 1

    Scope

    In a 30-minute call we go through your product, the roles and flows your customers use, and which customer instance we test on. You get a quote within two working days. A web application costs from approximately €2,250 to around €5,100 excl. VAT depending on size; an app costs €2,150 per platform.

  2. 2

    Audit

    Three to five weeks. We test the sample WCAG-EM prescribes, by hand, and we tell you which findings you own and which belong to the content your customer puts in.

  3. 3

    Fix and retest

    Your team fixes, asks the auditor questions through accessibility credits, and we retest per finding. The retest report is what your customers put behind their statement.

Frequently asked questions

Can one audit of our product serve all our government customers?

The audit covers your product: the technology, the components, the flows. That part is the same for every customer and they can all use it. What differs per customer is their own content and configuration, and the Register asks for evidence about the whole channel. A content audit of a customer’s instance is a smaller, separate job that builds on the product audit. We only do a content audit alongside an audit of the technology, because a statement needs evidence about the whole website and not just the editorial layer.

A customer's tender asks for proof of accessibility. What do we send?

A current audit report following WCAG-EM, against EN 301 549 and WCAG, with a retest that shows what has been fixed. Our report is written to be used without a briefing, so a procurement officer can read it. If you do not have one yet, a mini audit of €495 gives you an overview of the biggest issues within five working days, so you know what you are promising.

Do you test against WCAG 2.1 or 2.2?

Against WCAG 2.2 level AA. The legal standard, EN 301 549, currently points to WCAG 2.1 level A and AA; a new version of the standard that adopts WCAG 2.2 exists as a draft. WCAG 2.2 contains everything in 2.1 plus nine new criteria, so a product that passes 2.2 passes 2.1.

Our product is a SaaS platform with hundreds of instances. Which one do you test?

One representative instance, agreed with you: usually a demo or test environment with realistic data, or a live customer instance with that customer’s permission. Findings in the product apply to every instance. We note in the report which instance we used, so your customers know what the evidence is based on.

Do you sign NDAs and can you work behind a login?

Yes to both. We test intranets, portals and environments with sensitive data, we treat that data with care, and we sign a non-disclosure agreement when you or your customer asks for it.

Can you also help our customer write the accessibility statement?

Yes. After the audit we help your customer draft a correct statement in the format of the Dutch Register, based on our findings, and we guide them through the DigiToegankelijk environment where the statement is filed. That saves you the explaining.

Who does the work, and who do we talk to?

A senior auditor runs the audit, a second auditor does the internal review, and every report is checked by three people before delivery: the six-eyes principle. Once your report is delivered you have direct access to the auditor for questions, through accessibility credits. Before that, a relationship manager is your point of contact.

Get clarity on your digital accessibility — without stress

Schedule an introductory meeting. No commitments — just valuable insight into your risks and opportunities.

Schedule an introduction
Julia Tol Directeur
Phi Pham Projectmanager