SEBI Digital Accessibility Requirements for Websites
SEBI’s digital accessibility directions cover websites, apps, portals, documents and KYC. Here are the standards, duties, audit steps and latest timeline.
Direct answer: SEBI requires regulated entities to make their digital platforms and published content accessible under the Rights of Persons with Disabilities Act, 2016 (RPwD Act) and associated rules. Its July 31, 2025 circular names WCAG 2.1 or the latest version, the latest Guidelines for Indian Government Websites (GIGW), and IS 17802 as baseline references. The directions cover websites, mobile apps, portals, investor documents, media, KYC journeys, procured digital services, governance, training, audits, remediation and complaints.
The latest timeline update identified for this article is SEBI’s July 31, 2026 notice extending audit and remediation timelines. The dossier reports October 31, 2026 as the revised date, but SEBI’s notice attachment could not be extracted in this research pass. Confirm the exact date and any further updates in the official notice before relying on it for a compliance calendar.
1. Who must comply, and what counts as a digital platform?
SEBI defines a regulated entity for this circular as a SEBI-registered or recognised intermediary, or a market infrastructure institution regulated by SEBI. Examples include stockbrokers, mutual funds, KYC Registration Agencies (KRAs), registrars and transfer agents (RTAs), stock exchanges, depositories and clearing corporations.
The requirement is entity-wide. It is not limited to the public homepage: SEBI’s directions discuss websites, mobile applications and portals, as well as content published on those platforms. They also address investor-facing circulars, notices and documents; KYC and e-KYC journeys; and new or procured digital solutions, including SaaS products. A vendor-built service does not transfer the regulated entity’s responsibility for compliance. See the July 31, 2025 circular.
| Area | Include in the entity’s inventory |
|---|---|
| Public digital channels | Websites, investor portals, logged-in account areas and mobile apps |
| Published information | Investor circulars, notices, disclosures, forms, PDFs, videos and images |
| Investor workflows | Registration, onboarding, KYC, e-KYC, video KYC, service requests and complaint forms |
| Third-party services | Procured platforms, outsourced development, SaaS and vendor-managed content that supports the entity’s digital services |
2. Which laws and accessibility standards does SEBI name?
The July 2025 circular cites sections 40, 42 and 46 of the RPwD Act, 2016 and Rule 15(1)(c) of the RPwD Rules, 2017. Its named technical and guidance references are:
- WCAG 2.1 or latest: use the latest applicable version, as directed by the circular.
- Latest GIGW: the current Guidelines for Indian Government Websites.
- IS 17802: the Indian Standard on Accessibility Requirements for ICT Products and Services.
These are baseline references for digital initiatives. The circular points entities to the standards and their latest versions; do not treat this short list as a replacement for reading the standards themselves or as a claim that the circular enumerates every WCAG success criterion. The December 2025 status-report format asks entities whether each platform meets minimum AA-level accessibility under the latest WCAG. That reporting field does not mean the July circular itself spells out all AA criteria.
3. What must accessible investor content and documents provide?
SEBI specifically names Indian Sign Language (ISL) video, closed captions, descriptive audio and alternative text for images. For example, a KYC explainer video should have captions and ISL interpretation. Images conveying information need meaningful alt text; decorative images should not create noise for screen-reader users.
Investor documents need accessible structure, not merely selectable text. For PDFs and other published formats, use tagged structure, a logical reading order, properly nested headings and alt text for meaningful graphics. Check that tables, links, form fields and document language are exposed correctly to assistive technology. The circular’s annexure points to W3C PDF techniques and says to follow revised accessibility standards for text documents where applicable. See the circular and annexure.
4. What do accessible KYC and registration require?
SEBI’s directions call for workable alternatives in KYC, e-KYC and video KYC, including human-assisted video KYC, scanned-document uploads and voice-assisted KYC for blind and low-vision users. These should be usable ways to complete the process, not dead-end options that simply send someone back to an inaccessible flow.
Registration forms must capture disability status and requested accommodations, with options such as a helpdesk callback. If an applicant with a disability is rejected by an automated process, that must not be the final decision: the circular calls for designated human review and an authorised person who can override the system and approve the application case by case. SEBI’s separate May 23, 2025 digital KYC circular also addresses accessibility and inclusion in digital KYC.
5. What governance, training and complaint process should be in place?
Compliance should be reviewed and approved by the managing director, managing partner or proprietor, as applicable. A senior officer should be designated as the nodal officer. If no one is formally named, the compliance officer or proprietor is deemed to serve. The nodal officer coordinates audits, remediation, implementation guidance and grievance redressal, and acts as the SEBI contact.
Establish an accessibility-specific grievance process with usable channels such as email, a helpline or an accessible web form, plus escalation to senior officers. The December 8, 2025 clarification says investors may lodge digital-platform accessibility complaints against regulated entities through SCORES, which has an “Accessibility” complaint category. The entity must remediate the issue to close the complaint. See SEBI’s December clarification.
Include accessibility training in internal programs for employees and third-party service providers who develop or publish digital content. The circular’s direction is that the digital platform shall be “accessible by design.” Put this into design reviews, content workflows, engineering acceptance criteria, procurement and release processes instead of leaving it to a final check.
6. What audits, user testing and remediation are expected?
SEBI calls for a comprehensive accessibility audit across websites, mobile apps and portals through IAAP, following the latest WCAG, GIGW, the RPwD Act and Rules, and SEBI directions. The audit should include usability testing by persons with disabilities. Entities must prepare and implement a remediation plan, upgrade existing platforms within the applicable transition timeline, and conduct annual audits through IAAP-certified professionals.
- Inventory every platform and journey. Record ownership, vendor, technology, login requirements, content types, user tasks and dependencies. Include documents, mobile flows and third-party components.
- Set the audit scope. Map each surface against the latest referenced standards and SEBI directions. Include common templates and representative end-to-end investor journeys, not only a landing page.
- Combine methods. Use an accessibility audit with qualified professionals and usability sessions with persons with disabilities. Automated checks can help find issues, but are not a substitute for human review and assistive-technology testing.
- Track findings to closure. Give each issue an owner, user impact, affected platforms, corrective action, target date and retest evidence. Prioritise barriers that stop essential tasks such as account access, KYC, reading notices or submitting a complaint.
- Re-audit annually and after significant changes. Retain evidence, update the remediation plan and include new releases, acquired platforms and changed vendor services in ongoing governance.
The circular leaves responsibility with the regulated entity even when services are supplied through SaaS or another vendor. Put accessibility requirements, audit access, remediation duties, change notification and evidence delivery into requests for proposals and contracts. Confirm that the vendor can support the entity’s audit and reporting obligations; procurement language alone does not establish that a platform is accessible.
7. What are the reporting deadlines and latest timeline changes?
| Date | SEBI update | Practical reading |
|---|---|---|
| July 31, 2025 | Circular 2025/111 issued the mandatory directions and initial milestones. | Use this as the core requirements document. |
| August 29, 2025 | Circular 2025/121 extended early reporting dates, set auditor appointment for December 14, 2025, audit for April 30, 2026, and remediation for July 31, 2026; it also updated reporting authorities. | Check the circular’s reporting table for the entity’s category and submission destination. |
| September 25, 2025 | Circular 2025/131 issued compliance guidelines tied to the July directions. | Read it with the original circular. |
| December 8, 2025 | SEBI’s clarification replaced the auditor-appointment compliance milestone with a platform-wise readiness and compliance status report due March 31, 2026. It also addressed periodic audits by certified accessibility professionals and SCORES complaints. | Use the prescribed status format and report each digital platform. |
| July 31, 2026 | SEBI issued a further extension notice for compliance timelines. | The research dossier reports October 31, 2026 for audit and remediation, based on a secondary summary. Verify that date in the official attachment and check for later updates before setting a deadline. |
Reporting destinations vary by entity. The cited circulars identify stock exchanges and depositories for brokers and depository participants, BSE Ltd. for investment advisers and research analysts, and SEBI for MIIs and other categories. The December clarification’s table assigns departments for direct-reporting entities including AIFs, clearing corporations, credit rating agencies, custodians, KRAs, merchant bankers, mutual funds and AMCs, portfolio managers, RTAs and venture capital funds. Check the applicable circular annexure for the exact destination; do not infer it from a broad entity label.
8. A practical implementation checklist
- Assign executive approval and name the nodal officer.
- Maintain a platform register covering web, mobile, portals, documents, KYC and vendor services.
- Identify the latest applicable versions of WCAG, GIGW and IS 17802 for the program.
- Audit complete investor tasks, content and documents, not just page templates.
- Include persons with disabilities in usability testing and test assistive technology.
- Provide KYC alternatives, accommodation capture and human review for disability-related application decisions.
- Make grievance channels accessible and document escalation and remediation.
- Train staff and third-party publishers; add accessibility requirements to procurement and contracts.
- Keep issue logs, remediation evidence, retest records, annual audit plans and platform-wise reporting.
- Re-check SEBI’s circulars and category-specific reporting annexures before each submission.
9. Capturing pages as audit evidence
Screenshots can help document a page’s visible state, compare releases or attach an example to an issue ticket. They do not establish WCAG conformance, prove keyboard or screen-reader usability, or replace an IAAP audit and usability testing with persons with disabilities. For repeatable evidence, record the URL, date, viewport, browser state, relevant user journey and issue identifier alongside each capture. Redact personal or account information before storing or sharing evidence.
A do-it-yourself browser capture can use Playwright in Node.js. Install it with npm install playwright, install a browser with npx playwright install chromium, save the following as capture.mjs, and run node capture.mjs https://example.com:
import { chromium } from 'playwright';
const url = process.argv[2];
if (!url) throw new Error('Usage: node capture.mjs https://example.com');
const browser = await chromium.launch({ headless: true });
try {
const page = await browser.newPage({ viewport: { width: 1440, height: 1000 } });
await page.goto(url, { waitUntil: 'networkidle', timeout: 60000 });
await page.screenshot({ path: 'evidence.png', fullPage: true });
} finally {
await browser.close();
}
For pages that keep polling or loading analytics, networkidle may never settle. Change the wait condition to domcontentloaded and wait for a meaningful page landmark or a short, bounded delay. Authenticated captures need an authorised test account and careful handling of session data. Full-page screenshots can be large; capture the relevant viewport or component when that preserves the evidence needed.
Or skip the browser setup
ScreenshotNeo is a website screenshot API and MCP server from Yorker Media. One GET request captures a URL as PNG, JPEG, WebP or PDF. For audit evidence, use it to capture representative visible states; it is not an accessibility audit or conformance checker. Its clean-shot flow accepts cookie and consent banners and removes more than 60 known consent platforms, newsletter popups and chat widgets before capture, with each step configurable. Bot checks, blank pages and failed loads are never billed, and response headers report the page verdict and billing status. An MCP server provides take_screenshot, get_page_info and capture_pdf tools for AI agents. The free plan includes 1,000 screenshots per month with no card; paid plans start at $5 for 3,000.
See the ScreenshotNeo API documentation. Example with cURL:
curl -G "https://api.screenshotneo.com/v1/shot" \
-d access_key=YOUR_API_KEY \
--data-urlencode url=https://example.com \
-o evidence.webp
Python:
import requests
r = requests.get(
"https://api.screenshotneo.com/v1/shot",
params={"access_key": "YOUR_API_KEY", "url": "https://example.com"},
timeout=90,
)
r.raise_for_status()
with open("evidence.webp", "wb") as f:
f.write(r.content)
Node.js:
const q = new URLSearchParams({
access_key: 'YOUR_API_KEY',
url: 'https://example.com'
});
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);
if (!res.ok) throw new Error(`Screenshot request failed: ${res.status}`);
await Bun.write('evidence.webp', await res.arrayBuffer());
Cookie banners, popups and chat widgets are removed before the shot; bot checks, blank pages and failed loads are never billed; an MCP server lets AI agents take screenshots; and 1,000 screenshots a month are free with no card, with paid plans starting at $5 for 3,000. Sign up for 1,000 free screenshots a month, with no card.
10. Troubleshooting common implementation problems
| Problem | Likely cause | Fix |
|---|---|---|
| A public homepage passes checks, but investor tasks remain inaccessible. | The audit sampled only a landing page or automated scans. | Test end-to-end journeys, logged-in areas, mobile flows and documents; include disabled-user usability testing. |
| A PDF looks correct but fails assistive-technology review. | Visual layout was checked without tags, reading order, headings or image descriptions. | Inspect the document structure and reading order, add semantic tags and alt text, then test with assistive technology. |
| A user cannot finish KYC despite an “accessible” entry page. | The alternative is missing, unusable, or returns to the same inaccessible step. | Offer and validate workable human-assisted, scanned-document or voice-assisted alternatives appropriate to the journey. |
| An application is automatically rejected. | An automated decision is being treated as final for an applicant with a disability. | Route it to designated human review with an authorised override path, as directed by the circular. |
| A vendor says the product is compliant, but evidence is unavailable. | Procurement did not require accessible deliverables, audit cooperation or remediation records. | Make those duties contractual, obtain evidence and test the integrated service. The entity remains responsible. |
| Audit findings keep reopening after releases. | Accessibility was handled as a one-time audit rather than part of design, content and release processes. | Add checks to design and acceptance criteria, assign owners and retest fixes; maintain annual audits. |
| The reporting date or authority is unclear. | Several circulars changed dates and destinations by entity category. | Check the latest SEBI circular, the July 2026 attachment and the relevant reporting annexure before submission. |
11. Performance, reliability and cost considerations
SEBI’s cited directions establish obligations, not a published budget, performance target or implementation-cost estimate. Plan costs around the number and complexity of platforms, document volume, audit and user-testing scope, remediation work, vendor dependencies, training and recurring annual audits. Do not infer that a single accessibility widget or automated scan makes a platform compliant.
For reliable delivery, keep an owner and evidence trail for every issue, test representative journeys after changes, include vendor-managed components, and budget for annual review. Prioritise fixes by whether they block an investor from completing an essential task, while tracking all findings through remediation. Keep the compliance calendar tied to the latest official circulars because SEBI has issued multiple timeline updates.
12. Frequently asked questions
Does this apply only to websites?
No. The directions cover digital platforms and content including mobile apps, portals, documents, KYC processes and procured digital services.
Does an automated accessibility scanner satisfy the audit requirement?
The circular calls for comprehensive audits through IAAP and usability testing by persons with disabilities. Automated checks can support that work, but do not provide that full evidence by themselves.
Can a SaaS provider take responsibility for compliance?
A vendor can perform work under contract, but SEBI leaves responsibility with the regulated entity. The entity needs oversight, evidence, remediation and reporting.
Where should an investor file an accessibility complaint?
The December 2025 clarification provides an “Accessibility” category in SCORES for digital-platform accessibility complaints against regulated entities. The entity must remediate the issue to close the complaint.
What is the current audit and remediation deadline?
The July 2026 SEBI notice confirms that timelines were extended. The research dossier reports October 31, 2026 as the revised audit and remediation date, but advises confirming the specific date in the official attachment because its text was not extractable during research.
Sources and update note
Core sources: SEBI’s July 31, 2025 circular; August 29, 2025 extension; September 25, 2025 guidelines; December 8, 2025 clarification; and the July 31, 2026 extension notice. This article reflects the research available as of October 3, 2026. Re-check SEBI’s latest circulars and the July 2026 attachment before publication or regulatory action.


