Skip to content
HIPAA-Compliant Agency•BAA Signed Before PHI•NHS Digital Standards•WCAG 2.2 AA
HIPAA-Compliant Agency•BAA Signed Before PHI•NHS Digital Standards•WCAG 2.2 AA

PSBAR NHS Website Accessibility Requirements: What Actually Applies to You

Understand PSBAR requirements for NHS websites, including WCAG 2.2 AA, accessibility statements, disproportionate burden, monitoring, enforcement, and practical steps for keeping your website compliant.

PSBAR NHS Website Accessibility Requirements: What Actually Applies to You
Qrolic Health Technical Team.
5 min read
PSBAR
NHS Compliance
WCAG 2.2 AA
Accessibility Statement
Disproportionate Burden
EHRC
GDS Monitoring
Healthcare Website
Table of Content

Healthcare Compliance Guide

Reviewed and updated for the latest developments in healthcare compliance guide and related healthcare compliance standards.

If your NHS website has been described as needing to comply with PSBAR, the difficult part is often understanding what that actually means.

PSBAR, or the Public Sector Bodies Accessibility Regulations 2018, creates accessibility obligations for relevant public sector websites and applications. For NHS organisations within scope, those obligations extend beyond achieving a technical accessibility score.

You also need to understand the required accessibility statement, the limits of disproportionate burden, monitoring arrangements, and what happens when problems remain unresolved.

Current guidance means another common assumption also needs attention. Following updated Cabinet Office guidance issued in December 2022, PSBAR now tracks the latest published WCAG version, with a 12 month grace period following a new version's release.

This article explains how those requirements affect NHS Trusts, ICBs, GP practices, and commissioned services.

What PSBAR is, and why it automatically tracks the latest WCAG version

PSBAR provides the legal framework for accessibility requirements covering relevant public sector websites and mobile applications.

For NHS teams, the practical issue is not simply whether a website meets WCAG. You must also demonstrate that the organisation understands its accessibility obligations and has published the required information.

The distinction becomes important during procurement, redesigns, content migrations, and accessibility reviews.

The regulation's legal basis and its post-Brexit status

PSBAR comes from the Public Sector Bodies (Websites and Mobile Applications) (No. 2) Accessibility Regulations 2018.

The regulations establish accessibility requirements for websites and mobile applications operated by public sector bodies, subject to their scope and applicable exceptions.

Brexit did not remove these accessibility obligations from relevant UK public sector bodies. NHS organisations therefore still need to consider PSBAR when planning, procuring, maintaining, and reviewing digital services.

The technical standard also needs to be considered alongside the legal requirements.

WCAG provides the technical accessibility framework, while PSBAR establishes the relevant public sector obligation around accessibility and accessibility statements.

Why PSBAR now follows WCAG 2.2 AA, not a fixed version number

A common procurement mistake is writing "WCAG 2.1 AA" into a project specification and treating that as the permanent PSBAR requirement.

Updated Cabinet Office and Government Digital Service guidance means PSBAR automatically tracks the latest published version of WCAG. A 12 month grace period follows the publication of a new WCAG version before GDS expects conformance evidence against that version.

For current projects, this means WCAG 2.2 AA is the relevant technical reference under the current guidance.

Your procurement documents should therefore avoid locking accessibility requirements to an outdated version without checking the current PSBAR position.

For the technical implementation side, see our WCAG 2.2 AA compliance for healthcare resource.

Received a GDS monitoring notice or unsure whether your accessibility statement is accurate?

A focused review can identify what needs attention before the correction window closes.

Talk to our NHS compliance team →

Who is actually in scope: NHS Trusts, ICBs, GP practices, and commissioned services

Scope is one of the areas where NHS teams can make incorrect assumptions.

The organisation operating the website, the source of funding, the nature of the service, and the relationship with the public sector can all affect how PSBAR applies.

A website being developed by an external agency does not automatically place the legal responsibility onto the agency.

NHS Trusts and ICBs, directly in scope

NHS Trusts and Integrated Care Boards operate within the public sector environment covered by PSBAR.

Their websites and relevant digital services therefore need to address applicable accessibility requirements, including the accessibility statement obligations.

The responsibility should be reflected in project governance from the beginning.

During healthcare implementations, reviewing the existing accessibility statement can reveal a problem before any code is changed. One Trust statement reviewed against the GDS model format had been copied from another organisation's website rather than reflecting the actual service.

For project teams, the practical lesson is simple. Treat the accessibility statement as an organisational deliverable with an accountable owner, not as generic website content.

For wider regulatory context, see the NHS digital compliance standards relevant to your project.

Did You Know ?

PSBAR requires NHS Trusts, ICBs, and NHS funded websites to meet WCAG 2.2 AA and publish a compliant accessibility statement. The Government Digital Service monitors compliance, while the Equality and Human Rights Commission can enforce unresolved issues after the correction period.

GP practices using NHS funded web platforms

GP practices require more careful consideration because not every practice operates within the same organisational structure as an NHS Trust.

Where a GP practice uses an NHS funded web platform or operates a service within the relevant public sector scope, PSBAR requirements may apply.

Do not decide scope solely because the practice is independently operated.

Instead, establish:

  • Who owns the website
  • Who funds the service
  • Who operates the platform
  • What public service the website provides
  • Whether an applicable PSBAR exception exists

That assessment should happen before procurement or redevelopment.

If your project involves a shared platform across multiple practices, document the scope decision centrally. Otherwise, different teams may make inconsistent assumptions about accessibility responsibilities.

Commissioned services, and why third party build does not remove your obligation

External development does not automatically transfer the public body's accessibility responsibilities.

A healthcare organisation may commission an external supplier to design, develop, host, maintain, or provide content for its website. The contractual relationship should define responsibilities, but the commissioning organisation still needs to understand its own regulatory position.

Include accessibility requirements in the procurement specification and contract.

Ask suppliers to explain how they will test accessibility, document known limitations, support remediation, and maintain the accessibility statement.

The project should also define who approves the statement and who reviews it after major releases.

That approach prevents accessibility from becoming an unresolved responsibility between the NHS organisation and its supplier.

What your accessibility statement must contain

The accessibility statement is a core PSBAR requirement, not a footer link added after accessibility testing.

Under Regulation 8, the statement must follow the government's model format and provide users with specific information about accessibility and available remedies.

A statement can therefore fail even when parts of the website itself have been tested successfully.

The 6 elements GDS requires in the model format

Your statement needs to communicate the required information clearly.

The core elements include:

  1. 1.The website's current accessibility compliance status.
  2. 2.A description of content that is not accessible.
  3. 3.The reasons why identified content is not accessible.
  4. 4.A route for users to request accessible content or an alternative format.
  5. 5.A method for users to report accessibility problems.
  6. 6.Information about the applicable enforcement procedure.

The statement should reflect the actual website rather than describe an ideal future state.

Known accessibility limitations should be specific enough for users to understand what they may encounter.

Generic wording such as "some content may not be fully accessible" provides little useful information when the organisation already knows which components or content create barriers.

Why a generic template copied from another site fails monitoring

Copying another organisation's accessibility statement creates an immediate accuracy problem.

Different websites have different technologies, content, known issues, third party components, accessibility testing results, and remediation plans.

During a statement review, compare the published wording directly against the live website and current accessibility evidence.

Check whether the statement identifies the actual non-accessible content. Confirm that the reporting route works and that the enforcement information remains appropriate.

The statement should also reflect the organisation's current position rather than a previous version of the website.

Our complete WCAG 2.2 AA guide for healthcare can provide the technical accessibility context behind this review.

How often the statement needs reviewing

The accessibility statement needs to remain accurate as the service changes.

A major redesign, new component library, new forms, content migration, third party integration, or significant WCAG-related change can affect the statement.

At minimum, build a formal review into the website governance process.

Based on our healthcare IT experience, placing accessibility statement review alongside release governance helps prevent the common situation where the website changes repeatedly while its published accessibility information remains unchanged.

The review should confirm both the technical position and the accuracy of the published statement.

Disproportionate burden: the exception almost no healthcare website qualifies for

Disproportionate burden is one of the most misunderstood parts of PSBAR.

It does not provide a general exemption for organisations that find accessibility expensive, technically difficult, or inconvenient.

The assessment must consider whether making particular content accessible would impose a disproportionate burden on the organisation.

What disproportionate burden actually means under the regulations

The exception requires an assessment rather than a general declaration.

An organisation needs to consider relevant factors when determining whether making particular content accessible would create a disproportionate burden.

That means the assessment should be documented rather than reduced to a statement such as "the cost is too high".

Consider the resources available to the organisation, the likely benefit to users, and the impact of making the content accessible.

The decision also needs to remain connected to the specific content or functionality being considered.

Why it must be assessed per piece of content, not the whole site

A disproportionate burden assessment should not become a blanket exemption covering an entire website.

The relevant question is whether the accessibility of particular content or functionality creates the circumstances for an applicable exception.

Across recent compliance projects, assessing a disproportionate burden claim has required narrowing the issue to specific archived content rather than applying the exception across the wider website.

That distinction matters for NHS organisations with large content libraries.

For example, an older archive may require a different assessment from the core patient information that users rely on to understand services or access care.

Document the reasoning for each applicable exception and keep the assessment available for governance review.

Why healthcare content rarely meets the threshold

Healthcare websites often contain information that directly affects patients, carers, professionals, or members of the public.

Core information about services, appointments, contact routes, clinical information, and access to care can therefore have significant user impact.

That makes broad reliance on disproportionate burden difficult to justify.

If content is important to users, the accessibility objective should normally be addressed through remediation, redesign, alternative formats, or another appropriate solution rather than assuming the exception applies.

A useful project control is to ask whether the content is operationally important before considering disproportionate burden.

If removing the content would create a meaningful service problem, accessibility should remain a delivery priority.

What happens if your website is found non-compliant

PSBAR monitoring creates a defined process for identifying accessibility issues and giving organisations an opportunity to address them.

A monitoring finding does not mean every issue immediately becomes an enforcement action.

The important point is to understand the escalation route and respond within the available correction period.

The GDS monitoring and 12 week correction process

The Government Digital Service monitors public sector websites and applications for accessibility compliance.

Where monitoring identifies outstanding issues, the organisation is given a period to correct them.

The approved regulatory guidance describes a 12 week correction window for addressing identified issues before escalation.

That period should be treated as a remediation deadline, not as additional time to decide whether the issue matters.

Once a monitoring notice arrives, establish a remediation owner immediately.

Create a short action register covering each identified issue, the affected page or component, the required fix, the responsible team, evidence of completion, and the expected completion date.

When EHRC enforcement is triggered

If issues remain unresolved after the correction period, the matter can be referred to the relevant enforcement body.

In England, the Equality and Human Rights Commission can consider further enforcement action. In Northern Ireland, the Equality Commission for Northern Ireland has the relevant enforcement role.

The escalation process makes timely remediation important.

The objective should not be to produce evidence only after escalation. A stronger governance model identifies accessibility gaps continuously and addresses them as part of normal delivery.

The narrow exceptions: heritage collections and live streamed content

PSBAR contains specific exceptions covering certain types of content.

These include narrow circumstances involving heritage collections and live streamed media.

The existence of an exception does not create a general exclusion for healthcare websites.

Most operational NHS website content will need to be assessed according to the applicable accessibility requirements.

If your organisation believes an exception applies, document exactly which content it covers and why.

Do not extend the exception to unrelated pages or functionality.

Responding to a monitoring notice

If GDS has identified issues, treat the notice as a structured remediation exercise.

A practical response should:

  1. 1.Confirm the issues identified.
  2. 2.Identify the affected pages or components.
  3. 3.Assign an accountable owner.
  4. 4.Confirm the required technical or content changes.
  5. 5.Review the accessibility statement.
  6. 6.Test the remediation.
  7. 7.Record evidence of completion.
  8. 8.Complete the required response within the available correction period.

A practical checklist to confirm your PSBAR position

Use the following checklist during procurement, project kickoff, annual governance reviews, and major website releases.

  1. 1.Confirm that your organisation and website are within PSBAR scope. (Required)
  2. 2.Confirm the applicable WCAG version under current GDS guidance. (Required)
  3. 3.Assess the website against WCAG 2.2 AA where applicable. (Required)
  4. 4.Publish an accessibility statement using the government model format. (Required)
  5. 5.Identify inaccessible content and explain the reasons. (Required)
  6. 6.Provide a working route for users to request accessible formats. (Required)
  7. 7.Provide a working method for users to report accessibility problems. (Required)
  8. 8.Include the applicable enforcement procedure within the statement. (Required)
  9. 9.Document any disproportionate burden assessment for specific content. (Required where applicable)
  10. 10.Review accessibility after significant website changes. (Required)
  11. 11.Assign clear ownership for accessibility remediation and statement maintenance. (Required)
  12. 12.Keep evidence of accessibility testing and completed remediation. (Recommended)

Do not treat the checklist as a one-time certification exercise.

Your website can change through new content, templates, forms, integrations, and releases. The compliance position therefore needs to remain connected to the live service.

Our full NHS website compliance checklist provides a broader project-level view across NHS digital standards, including requirements that sit alongside PSBAR.

Keep your PSBAR position accurate as the website changes

An incomplete accessibility statement is itself a compliance problem. Reviewing the live website, evidence, and published statement together helps identify gaps before they become harder to resolve.

Talk to our NHS compliance team →

Frequently Asked Questions

What is PSBAR and who does it apply to?

PSBAR is the Public Sector Bodies (Websites and Mobile Applications) Accessibility Regulations 2018. It applies to relevant public sector websites and applications, including NHS organisations and services that fall within its scope.

Does PSBAR require WCAG 2.2 AA or WCAG 2.1 AA?

Current guidance means PSBAR automatically tracks the latest published WCAG version. Under the current position, WCAG 2.2 AA is the relevant reference, following the applicable transition period for the updated version.

What must an NHS accessibility statement include?

The statement needs to follow the government model format and explain compliance status, inaccessible content and reasons, routes for accessible formats, problem reporting, and the applicable enforcement procedure.

Can a GP practice claim it is not covered by PSBAR?

Coverage depends on the organisation, funding arrangements, platform ownership, and applicable scope. An independent GP practice should not assume it falls outside PSBAR simply because it is independently operated.

What is a disproportionate burden, and can a healthcare website use it?

Disproportionate burden is a narrow exception requiring an assessment based on the relevant circumstances. It should not be used as a blanket exemption, particularly for core healthcare information that users rely on.

Who enforces PSBAR in England?

The Government Digital Service monitors accessibility compliance. Where identified issues remain unresolved through the applicable correction process, the Equality and Human Rights Commission can consider further enforcement action.

How often should a PSBAR accessibility statement be reviewed?

Review the statement whenever the website changes materially and as part of regular governance. At minimum, an annual review helps ensure the published information still reflects the live website and current accessibility position.

Are there any content types exempt from PSBAR?

PSBAR contains narrow exceptions, including certain heritage collection archives and live streamed media. These exceptions do not generally remove accessibility obligations from operational NHS website content or core patient-facing information.

Qrolic Health Technical Team.

Qrolic Health Technical Team.

Updated for 2026 Compliance Guidance.
Qrolic Health - Healthcare Website Design Specialists

Qrolic Health supports healthcare organisations with accessibility, compliance, and patient-facing digital platform delivery where regulatory requirements must remain aligned with the live service.

Qrolic Health - Healthcare Website Design Specialists

Ready to Build Your Healthcare Platform?

Work with a team that understands HIPAA, accessibility, and healthcare digital experiences from day one.

Service we offer:
HIPAA-Compliant Websites
Healthcare Website Design
Telehealth Platforms
Website Redesign & Migration
Healthcare SEO