Artifact GuideUKDeadlines and Compliance Calendar

UK Online Safety Act Deadlines and Compliance Calendar

Keep the completed 2025 implementation dates separate from deadlines created by a launch, a significant service change, categorisation, a fee year, or an Ofcom notice.

The controlling date depends on the service, duty, and trigger. Record whether an entry is a statutory deadline, an Ofcom expectation, a consultation date, or an internal target.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 25, 2026
Sections
4

Structured answer sets in this page tree.

Primary sources
10

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 25, 2026
Overview

For Part 3 services already in scope during the first implementation wave, the main deadlines were 16 March 2025 for illegal-content risk assessments, 16 April 2025 for children's access assessments, and 24 July 2025 for children's risk assessments where the service was likely to be accessed by children. The illegal-content safety duties applied from 17 March 2025 and the children's safety duties from 25 July 2025. The began for regulated user-to-user services on 7 April 2026. A later service must calculate its dates from its own trigger rather than reuse the 2025 dates.

Section 1

Which UK Online Safety Act deadlines should teams track in the compliance calendar?

For the first cohort of Part 3 user-to-user and search services, record 16 March 2025 as the illegal-content risk-assessment deadline and 17 March 2025 as the date the illegal-content safety duties took effect. These are separate milestones.

Record 16 April 2025 as the first children's access-assessment deadline. A service found likely to be accessed by children then had until 24 July 2025 to complete its first children's risk assessment, and the children's safety duties applied from 25 July 2025.

Part 5 services that publish or display regulated provider pornographic content followed a separate timetable. Their highly effective age-assurance duty took effect on 17 January 2025. Do not derive a Part 5 deadline from the Part 3 children's timetable.

From 7 April 2026, regulated user-to-user services must report detected and unreported child sexual exploitation and abuse content under the statutory reporting regime. UK providers report all such content; providers outside the UK report UK-linked content. The April 2026 regulations do not yet commence the duty for search services, and content already reported to a qualifying foreign agency is not reported again.

  • Label each entry as a statutory deadline, duty commencement, Ofcom expectation, consultation close, notice-specific deadline, or internal target.
  • Name the affected service and whether Part 3, Part 5, categorised-service, fee, or reporting duties create the entry.
  • Keep the assessment completion date separate from the date on which related safety measures must operate.
  • Attach the controlling source, accountable owner, evidence record, and escalation contact.
  • Treat the as an ongoing event-driven obligation, with portal registration, report timeframes, retention, and duplicate-report checks built into the operating process.
Section 2

Which current and upcoming 2026 dates belong in the calendar?

Ofcom published the register of categorised services on 10 July 2026. Category 1 and Category 2A providers must now give Ofcom a copy of an illegal-content risk-assessment record, and any applicable children's risk-assessment record, as soon as reasonably practicable after making or revising it. Ofcom expects current records by October 2026 and published summaries by November 2026; those months are regulator expectations, not substitutes for the statutory 'as soon as reasonably practicable' test.

A 31 July 2026 deadline applies only to providers that received Ofcom's April 2026 formal information request for risk-assessment records. For the 2027/28 fee year, the notification window for new fee-liable providers closes on 30 September 2026. Providers already in the fee process may instead receive an Ofcom information request, so the notice controls their response date.

Ofcom expects to issue invoices and publish the 2026/27 tariff in September 2026, with payment running to March 2027 and instalments possible in specified cases. Treat dates for consultations and proposed additional safety measures as planning entries until the relevant final measure and legal process are complete.

  • For Category 1 and Category 2A services, calendar the statutory record-sharing duty and separately record Ofcom's October and November 2026 expectations.
  • For an April 2026 risk-assessment information request, use the deadline in the notice; Ofcom's programme identifies 31 July 2026 for that request round.
  • For fees, distinguish a notification, a request for revenue evidence, an invoice, and a payment date.
  • Treat consultation closing dates as optional participation dates, not provider compliance deadlines.
Section 3

How should a new service or product change calculate its dates?

A Part 3 service that becomes available to UK users after the relevant guidance has been published generally has three months from the day it comes into scope to complete its first illegal-content risk assessment and children's access assessment. If it is likely to be accessed by children, it also has three months to complete a children's risk assessment. The exact statutory trigger must be checked against Schedule 3 for the service's facts.

Complete the relevant risk assessment before making a significant change to the service. If a children's access assessment concludes that the service is not likely to be accessed by children, repeat it no more than 12 months later and sooner if a specified trigger occurs, including a relevant significant change, reduced age-assurance effectiveness, or evidence of a significant increase in child users.

  • Start the clock from the actual date the service became available to UK users or otherwise came into scope, not the company's incorporation date.
  • Run a pre-launch deadline check when adding user-to-user, search, or provider-pornography functionality.
  • Put a product-change gate before recommender, moderation, messaging, search, age-assurance, or audience changes that may alter risk.
  • If the scope or trigger date is uncertain, record the assumption and obtain case-specific legal review before relying on the calculated date.
Section 4

What evidence should sit behind each calendar entry?

Each calendar entry should identify the legal or regulatory trigger, affected service, date-calculation method, owner, and completed evidence. A reminder alone does not show compliance.

For assessments, retain the methodology, findings, relevant user groups and service features, chosen measures, approval, completion date, and next review trigger. For an Ofcom notice, retain the notice itself, receipt date, response deadline, preservation steps, data provenance, representations, submission evidence, and follow-up correspondence.

  • Link each date to the service-scope decision and source provision that created it.
  • Record the time zone and receipt method for notice-specific deadlines.
  • Keep the version of each code or guidance document used, but do not present guidance publication as the source of an underlying statutory duty.
  • Recalculate dates after launch, UK expansion, acquisition, significant functionality change, altered age assurance, or a changed conclusion about child access.
Primary sources

References and citations

ofcom.org.uk
Referenced sections
  • Confirms the 30 September 2026 notification deadline for new fee-liable providers and the current invoice and payment timetable.
legislation.gov.uk
Referenced sections
  • Binding source for assessment timing, record-keeping, information powers, categorised-service duties, and enforcement notices.
Related guides

Explore more topics

Does the UK Online Safety Act apply to this service?
A practical scope test for user-to-user, search, and provider-pornography services under the UK Online Safety Act, including UK links and exemptions.
How Ofcom and ICO duties overlap for online services
How the UK Online Safety Act, UK GDPR, Data Protection Act 2018, and Children's Code apply together to safety technologies and children's data.
How Ofcom enforces the UK Online Safety Act
Ofcom information notices, investigations, representations, confirmation decisions, penalties, remediation, and court-based service restrictions.
How to complete a children's access assessment
The two-stage UK Online Safety Act children's access assessment, evidence, timing, reassessment triggers, and next duties.
How to complete an illegal content risk assessment
UK Online Safety Act illegal content risk assessment scope, required elements, deadlines, review triggers, records, and resulting safety measures.
Is This a User-to-user or Search Service Under the UK Online Safety Act?
Classify user-to-user, search, and combined services under the UK Online Safety Act, apply the UK-links and exemption tests, and identify the next duties.
Ofcom Transparency Reporting FAQ
Who receives Ofcom transparency notices, what Schedule 8 can require, the 2026 notice process, first-report timing, and evidence controls.
Online Safety Act Children's Access Assessment
Decide whether children are likely to access a regulated service or part of it, document the evidence, and identify when a children's risk assessment follows.
Online Safety Act Complaints Handling Workflow
Route and decide Online Safety Act complaints, record the required response, and distinguish an internal review from an Ofcom complaint or super-complaint.
Online Safety Act Illegal Content Risk Assessment
Assess illegal-content risks by offence kind, likelihood, severity, affected users, service design, controls, evidence, and review triggers.
Online Safety Act moderation, reporting, and complaints
How UK Online Safety Act duties shape content moderation, user reporting, complaints, reinstatement, terms, records, and human oversight.
Online Safety Act: User-to-user and Search Service Scope
Decide whether an online service is a regulated user-to-user service, search service, combined service, or exempt service under the UK Online Safety Act.
UK Online Safety Act Age Assurance Options
Compare age verification and age estimation methods by assurance, privacy, accessibility, bias, evasion risk, and operational evidence.
UK Online Safety Act Age Assurance Requirements
When Online Safety Act services need age assurance, what highly effective age assurance means, and how safety duties interact with data protection.
UK Online Safety Act Age Assurance Selection Workflow
Choose an age-assurance method for an Online Safety Act duty by testing effectiveness, privacy, accessibility, evasion risk, and the consequence of error.
UK Online Safety Act Applicability Test Guide
Test whether a service is covered by the UK Online Safety Act by checking service functionality, UK links, exemptions, and the duties that follow.
UK Online Safety Act categories: thresholds and duties
How Category 1, 2A, and 2B thresholds work, how Ofcom categorises services, and what the July 2026 register means.
UK Online Safety Act Categorisation Guide
Apply the UK Online Safety Act Category 1, 2A, and 2B thresholds, calculate active UK users, and use Ofcom's register published in June 2026 and updated in July.
UK Online Safety Act Checklist
Verify UK Online Safety Act scope, assessments, controls, reporting, complaints, records, child safety, and category-specific work.
UK Online Safety Act Children's Safety Duties Guide
Apply the UK Online Safety Act children's access, risk-assessment, safety, age-assurance, reporting, complaints, and record-keeping duties.
UK Online Safety Act Compliance Guide
Build a UK Online Safety Act compliance program from service scope through assessments, controls, evidence, review, and Ofcom response.
UK Online Safety Act Content Moderation and Appeals Guide
Design UK Online Safety Act moderation, content-reporting, complaints, and review processes for illegal content and content harmful to children.
UK Online Safety Act Enforcement and Penalties Guide
How Ofcom investigates Online Safety Act breaches, issues decisions, requires remedies, imposes penalties, and seeks court orders.
UK Online Safety Act FAQ: scope, duties, and deadlines
Standalone answers and decision paths for UK Online Safety Act scope, risk assessments, child protection, age assurance, categories, reporting, and enforcement.
UK Online Safety Act ICO Overlap Guide
Apply the Online Safety Act and UK data protection law together for age assurance, moderation, profiling, recommender systems, and safety-data sharing.
UK Online Safety Act Illegal Content Duties Explained
Understand the illegal-content risk assessment, safety, reporting, complaints, record-keeping, and review duties for regulated user-to-user and search services.
UK Online Safety Act Moderation, Complaints and Appeals
Build moderation, content-reporting, and complaints procedures for regulated services, and understand where the Online Safety Act does and does not require an appeal.
UK Online Safety Act Ofcom Enforcement Guide
How Ofcom assesses Online Safety Act concerns, gathers information, investigates suspected breaches, and reaches enforcement decisions.
UK Online Safety Act Penalties and Fines Guide
The Online Safety Act penalty ceiling, qualifying worldwide revenue, daily penalties, penalty factors, and payment consequences.
UK Online Safety Act Regulated Service Scope Guide
Understand which user-to-user, search, combined, and provider-pornography services the UK Online Safety Act regulates and which exemptions narrow scope.
UK Online Safety Act Requirements Guide
See which UK Online Safety Act requirements apply to Part 3 services, child-accessible services, provider pornography, and categorised services.
UK Online Safety Act Risk Assessment Template
A field-by-field template for recording service facts, statutory risks, evidence, controls, residual risk, approval, and reassessment triggers.
UK Online Safety Act Risk Assessment Workflow
Run illegal-content and children's risk assessments in the right order, with evidence for risks, controls, governance, and reassessment triggers.
UK Online Safety Act Risk Assessments Playbook
Organise recurring Online Safety Act risk assessments across product, safety, data, engineering, legal, and governance teams.
UK Online Safety Act Senior Manager Liability Explained
Understand when a named senior manager or corporate officer can face personal liability for Online Safety Act information offences and how to control the risk.
UK Online Safety Act Service Classification Workflow
Decide whether a service is regulated, whether it is user-to-user or search, which exemptions apply, and whether Ofcom categorisation adds duties.
UK Online Safety Act Service Scope and Categorization Guide
Move from UK Online Safety Act service scope to Category 1, 2A, or 2B threshold analysis without confusing categorisation with basic coverage.
UK Online Safety Act Transparency Reporting
Understand who must publish an Online Safety Act transparency report, what an Ofcom notice controls, and how to prepare traceable reporting data.
UK Online Safety Act vs DSA: scope and duties
Compare UK Online Safety Act and EU DSA scope, service classes, child-safety and platform duties, dates, evidence, exemptions, and enforcement.
When Are Senior Managers Liable Under the UK Online Safety Act?
When section 110 can make a named senior manager liable for an Online Safety Act information offence, the available defences, and the controls to keep.
When is age assurance required under the UK Online Safety Act?
When UK Online Safety Act services need highly effective age assurance, what Ofcom expects, and how UK data protection law applies.