3.3.8 Accessible Authentication (Minimum)
A cognitive function test (such as remembering a password or solving a puzzle) is not required for any step in an authentication process unless that step provides an alternative.
Last reviewed: September 9, 2026
Understanding 3.3.8
The intent of this criterion is to ensure that people with cognitive disabilities can log in to websites. Forcing users to memorize and transcribe complex passwords or solve CAPTCHAs can be an insurmountable barrier for individuals with memory, reading, or processing differences.
How to Meet It
Code Examples
<input type="password" onpaste="return false;" /> <!-- Blocks password managers, failing 3.3.8 --><input type="password" autocomplete="current-password" /> <!-- Supports password managers -->Frequently Asked Questions
Are passwords completely banned under WCAG 2.2?
No. You can still use passwords, but you cannot FORCE the user to memorize them. Allowing a password manager to autofill the password satisfies the requirement because the password manager handles the cognitive load.
Do traditional picture-based CAPTCHAs fail this criterion?
Yes, identifying objects in a picture is a cognitive function test. You must provide an alternative, such as support for third-party SSO (Log in with Google) or a hardware token.
Related Success Criteria
Quick Facts
- Criterion3.3.8
- LevelAA
- IntroducedWCAG 2.2
Automate Compliance
AccessiSight automatically scans and identifies 3.3.8 issues in your codebase.
Try Scanner Free