3.3.9 Accessible Authentication (Enhanced)
A cognitive function test is not required for any step in an authentication process, unless an alternative is provided that does not rely on a cognitive function test, with no exception for object recognition or personal content.
Last reviewed: September 9, 2026
Understanding 3.3.9
This is the AAA-level version of 3.3.8, and it closes the one exception that 3.3.8 allows. Object recognition tasks ("select all images with a bus") and identifying personal content ("which of these is your photo") can no longer be used as the sole authentication step, because they still exclude some people with cognitive, visual, or memory disabilities. At this level, authentication must never rely on any cognitive function test unless a non-cognitive alternative is also offered.
How to Meet It
Code Examples
<!-- Only authentication path is an image CAPTCHA -->
<div class="captcha">
<p>Select all images containing a traffic light</p>
<!-- ...image grid... -->
</div><!-- Passkey / WebAuthn offered as a path requiring no puzzle -->
<button onclick="navigator.credentials.get({ publicKey: options })">Sign in with a passkey</button>Frequently Asked Questions
How is this different from 3.3.8 Accessible Authentication (Minimum)?
3.3.8 (AA) still permits object recognition and personal-content-identification tests, such as picture CAPTCHAs, as an allowed exception. 3.3.9 (AAA) removes that exception entirely, so even those tests require a non-cognitive alternative to be offered.
Related Success Criteria
Quick Facts
- Criterion3.3.9
- LevelAAA
- IntroducedWCAG 2.2
Automate Compliance
AccessiSight automatically scans and identifies 3.3.9 issues in your codebase.
Try Scanner Free