What's new in WCAG 2.2 — and why you should care
WCAG 2.2 added 9 new criteria to the AA bar. Here is what they actually mean, what design and engineering changes they require, and when courts will start citing them.
Read article →Resources
Practical writing on every compliance domain Plumb audits — accessibility, security headers, privacy, performance, HIPAA, PCI-DSS, FERPA, and SOC 2. No-jargon, no-fluff, written for the people who have to actually ship the fixes.
WCAG 2.2 added 9 new criteria to the AA bar. Here is what they actually mean, what design and engineering changes they require, and when courts will start citing them.
Read article →A practical, no-jargon guide to how the Americans with Disabilities Act applies to websites in 2026 — what the DOJ has signaled, what plaintiff firms are filing, and how to reduce your exposure.
Read article →Selling to the U.S. federal government? You will need an ACR/VPAT. Here is what each section of the document actually means, what evaluators check, and where contractors most often fail.
Read article →Every accessibility tool vendor — including us — quotes that 30-40% number. Here is the actual research behind it, what automated tools genuinely do well, and what they will never catch.
Read article →CSP, HSTS, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy. What each one does, what to set it to, and which compliance frameworks check it by name.
Read article →A practical walkthrough of the four CCPA / CPRA UI obligations the California Privacy Protection Agency actively scans for — Do-Not-Sell links, sensitive-PI limits, GPC honoring, and notice at collection.
Read article →Most cookie banners fail the four-property compliance test, and most operators do not know what their banner actually allows through. Here is what regulators and plaintiffs are scanning for, and the two architectures that actually work.
Read article →LCP, INP, CLS — the three metrics that drive page-experience ranking and an increasing share of enterprise vendor questionnaires. Field vs. synthetic, what synthetic catches, and the fixes that move each metric.
Read article →PHI in URLs, missing HSTS on PHI pages, browser autofill on PHI forms, and third-party scripts on PHI pages. Each of these has been the root cause of seven-figure OCR fines. Here is what they look like and how to fix them.
Read article →Falling out of SAQ-A scope multiplies your PCI compliance overhead 20-40×. Here are the four web-development decisions that move you from SAQ-A to SAQ-A-EP or SAQ-D — and how to avoid each one.
Read article →FERPA enforcement does not run through private lawsuits — it runs through federal funding and Data Privacy Agreement violations. Both make your web stack a contractual obligation. Here are the four web-layer obligations every ed-tech vendor inherits.
Read article →SOC 2 is mostly about people and process — but a meaningful slice of the Trust Service Criteria is verifiable from the public web. Here is what auditors check for CC6.6, CC6.7, CC6.8, and CC9.1, and where audits commonly get qualified opinions.
Read article →