Understandable · 3.3 Input Assistance

Error Suggestion WCAG 3.3.3 · Level AA

When an input error is detected automatically and ways to correct it are known, those suggestions must be given to the user, unless doing so would jeopardize the security or purpose of the content, such as giving away the answers in a test.

Level
AA
Since
WCAG 2.0
Principle
Understandable
Guideline
3.3 Input Assistance

Live demo

Make mistakes and read the messages

The same task, done two ways: switch between the version that passes and the one that fails, or put them side by side. Everything in the box is live, so try it with a keyboard, a pointer or a screen reader.

Type 5 Nov in Date of travel and an email address without an @, then press Find trains. See whether the message tells you how to fix each field.

Live example

Passes

Book a train ticket

What happened

    Why it passes

    Each message names the field and shows an example of what the site expects, such as 25/12/2026 for the date, so you can fix it on the first try.

    Why it fails

    A single line says there is an error. It does not say which field is wrong or what the site expects, so you have to guess and try again.

    Examples

    Code that fails, and the fix

    Four examples, each one running: the usual ways this criterion fails, and code that passes. Listen to them, measure them, or copy the code.

    01What changes 1 line

    Fails

    Date error with no hint of the format

    Live preview

    HTML
    <label for="travel-date">Date of travel</label><input id="travel-date" name="travel-date" value="5 Nov"       aria-invalid="true" aria-describedby="travel-date-error"><p id="travel-date-error">Invalid date.</p>

    The error is identified, so 3.3.1 is met, but the site knows the format it wants and does not say it. The user has to guess.

    Passes

    Error message that states the format

    Live preview

    HTML
    <label for="travel-date">Date of travel</label><input id="travel-date" name="travel-date" value="5 Nov"       aria-invalid="true" aria-describedby="travel-date-error"><p id="travel-date-error">Enter the date as DD/MM/YYYY, for example 05/11/2026.</p>

    The message tells the user how to fix the entry and gives an example in the expected form (G85).

    Fails

    Password rejected without the rules

    Live preview

    HTML
    <label for="new-password">Create a password</label><input id="new-password" name="new-password" type="password"       autocomplete="new-password" aria-invalid="true"       aria-describedby="password-error"><p id="password-error">This password is not allowed.</p>

    The user is not told which rule the password broke, so they may try again and again or give up, although the site knows exactly what is missing.

    Passes

    Message that names the rule not met

    Live preview

    JavaScript
    function passwordProblem(value) {  if (value.length < 12) {    return "Use at least 12 characters. This password has " + value.length + ".";  }  if (!/[0-9]/.test(value)) {    return "Add at least one number, for example 7.";  }  return "";}

    Each message names the rule that failed and how to meet it. Show it next to the field and link it with aria-describedby, as in the date example.

    Why it matters

    Who it helps

    People with cognitive, learning, or language disabilities, and people with limited vision or motor difficulties, may struggle to work out how to fix an error. Specific suggestions help them correct input quickly instead of guessing.

    W3C: Understanding 3.3.3
    • Level AA

      Level AA is the level most laws and policies require.

    • In WCAG versions

      Part of WCAG 2.0 since December 2008, and of every version after it.

      No WCAG 1.0 checkpoint maps to it.

    • Where it is required

      Required where the law names WCAG 2.0 or later at this level: the United States, Canada, the European Union, the United Kingdom, France, Germany, Italy, Spain, the Netherlands, Ireland, Norway, Switzerland, India, Japan, Australia, New Zealand and Israel.

    How to test

    Checking it

    A few concrete steps. Automated tools find some failures; most need a person.

    1. Enter invalid data in fields with known rules, such as a wrong date format or an out-of-range value, and submit.
    2. Confirm the error message suggests how to fix the input, for example by stating the expected format or allowed values.
    3. Where no suggestion is given, check whether the correction is truly unknown or would compromise security or the purpose of the content.

    Common failures

    Where it breaks

    • A date field rejects input with the message Invalid date but does not state the expected format.
    • A new password is rejected without saying which password rules it failed to meet.
    • A field that accepts only certain values says the entry is invalid without listing the allowed options.