Artifact GuideUKService Scope and Categorization

UK Online Safety Act Service Scope and Categorization

First decide whether each service part is regulated. Only then test the Category 1, 2A, and 2B thresholds and compare the result with Ofcom's register.

Core Part 3 duties apply to regulated services regardless of category. Categorisation adds duties and can apply differently to the user-to-user and search parts of one combined service.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Sections
4

Structured answer sets in this page tree.

Primary sources
4

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

Use two separate decisions. Stage one establishes whether the product contains a regulated user-to-user service, regulated search service, or both. Stage two applies the statutory user-number and functionality thresholds to each regulated part. Ofcom, not the provider, makes the formal categorisation decision and published the first register of categorised services in July 2026.

Section 1

What should teams decide about Service Scope and Categorization under the UK Online Safety Act?

Stage one asks whether users can encounter content generated, uploaded, or shared by other users, whether the service is or includes a search engine, whether the service has UK links, whether Schedule 1 exempts the relevant functionality, and whether Schedule 2 excludes the service from Part 3. A combined service can contain both a regulated user-to-user part and a regulated public search engine.

Stage two uses the Online Safety Act 2023 (Category 1, Category 2A and Category 2B Threshold Conditions) Regulations 2025. Category 1 applies to a regulated user-to-user service exceeding 34 million with a content recommender system, or exceeding 7 million with both a recommender and qualifying forward-or-share functionality.

Category 2A applies to a regulated search service or search engine of a combined service exceeding 7 million , subject to the Regulations' exception for certain topic-specific searches of selected sites or databases under a relevant arrangement. Category 2B applies to a regulated user-to-user service exceeding 3 million average monthly active UK users with the specified direct-messaging functionality.

Calculate the mean monthly active UK users over the six-month period ending with the month before the assessment begins, or over the shorter operating period for a newer service. Preserve the data method, service boundary, recommender and messaging design, and search facts used in the calculation.

  • Record a separate Part 3 scope conclusion for each user-to-user and search part.
  • Apply each category threshold to the same service boundary used in the scope record.
  • Distinguish a provider's threshold estimate from Ofcom's formal entry on the register.
  • Map additional duties only to the category and service part to which they legally attach.
Section 2

Who should own Service Scope and Categorization, and what evidence should prove the decision?

Product and legal owners should approve the Part 3 service boundary. Data owners should produce the active-UK-user calculation, while engineering documents recommender, forwarding, sharing, messaging, and search functionality. One accountable regulatory owner should reconcile those records with Ofcom's published register.

Keep the scope memo, threshold workbook, data definitions, six-month extracts, architecture and user journeys, formal register entry, Ofcom correspondence, and assigned additional duties together. A category record without the underlying service boundary is not enough.

  • Name owners for scope, user metrics, functionality evidence, legal review, and Ofcom communications.
  • Keep monthly active UK user definitions stable and explain deduplication, bots, accounts, logged-out use, and combined-service allocation.
  • Save the exact version of recommender, forwarding, direct-message, and search functionality assessed.
  • Review the internal estimate after user growth, acquisitions, service redesign, or an Ofcom information request.
Section 3

Which edge cases should teams check before relying on a Service Scope and Categorization decision?

A service can meet more than one category, and the parts of a combined service can be categorised differently. Ofcom's register, for example, can identify only a public search engine within a wider product as Category 2A; that does not categorise unrelated product functionality.

Threshold wording matters. The figures are exceeded, not merely met, and the functionality conditions must be present in the regulated part. The six-month average is not a single peak-month count.

  • Do not use categorisation as a proxy for risk: a non-categorised service can still have high illegal-content or child-safety risks and remains subject to its core duties.
  • Do not apply the Category 2A topic-specific search exception without checking both selected-source and relevant-arrangement conditions.
  • Check whether direct messages are designed so no other user can encounter them unless sender or recipient takes further action; ordinary private messaging labels do not settle the test.
  • Use Ofcom's register for formal status and preserve any disagreement between the register boundary and the provider's internal model for legal review.
Section 4

How should teams implement scope and categorisation decisions?

Use a gated workflow: approve Part 3 scope; calculate every potentially relevant threshold; compare with the formal register; then assign the additional duties to the exact service part. Do not pause core risk and child-access work while waiting for a category decision.

The July 2026 register makes categorisation operational for listed services. Ofcom's current materials also set category-specific expectations, including submission of current illegal-content risk-assessment records by Category 1 and 2A providers by October 2026.

  • Record the register publication and entry date rather than backdating category-specific work to the initial Part 3 deadlines.
  • Map Category 1 user-empowerment, identity-verification, news, journalistic, democratic-importance, terms, complaints, and assessment duties to the user-to-user part.
  • Map Category 1 and 2A fraudulent-advertising and risk-record submission duties, and Category 1, 2A, and 2B transparency-reporting duties, only after checking commencement and current Ofcom directions. Fee duties use a separate qualifying-worldwide-revenue threshold and exemptions.
  • Track Ofcom consultations and issued codes separately; a draft additional-duties code is not binding law.
Primary sources

References and citations

legislation.gov.uk
Referenced sections
  • Primary source for Part 3 scope, combined services, Ofcom's categorisation process, and the additional duties attached to categories.
Related guides

Explore more topics

Does the UK Online Safety Act apply to this service?
A practical scope test for user-to-user, search, and provider-pornography services under the UK Online Safety Act, including UK links and exemptions.
How Ofcom and ICO duties overlap for online services
How the UK Online Safety Act, UK GDPR, Data Protection Act 2018, and Children's Code apply together to safety technologies and children's data.
How Ofcom enforces the UK Online Safety Act
Ofcom information notices, investigations, representations, confirmation decisions, penalties, remediation, and court-based service restrictions.
How to complete a children's access assessment
The two-stage UK Online Safety Act children's access assessment, evidence, timing, reassessment triggers, and next duties.
How to complete an illegal content risk assessment
UK Online Safety Act illegal content risk assessment scope, required elements, deadlines, review triggers, records, and resulting safety measures.
Is This a User-to-user or Search Service Under the UK Online Safety Act?
Classify user-to-user, search, and combined services under the UK Online Safety Act, apply the UK-links and exemption tests, and identify the next duties.
Ofcom Transparency Reporting FAQ
Who receives Ofcom transparency notices, what Schedule 8 can require, the 2026 notice process, first-report timing, and evidence controls.
Online Safety Act Children's Access Assessment
Decide whether children are likely to access a regulated service or part of it, document the evidence, and identify when a children's risk assessment follows.
Online Safety Act Complaints Handling Workflow
Route and decide Online Safety Act complaints, record the required response, and distinguish an internal review from an Ofcom complaint or super-complaint.
Online Safety Act Illegal Content Risk Assessment
Assess illegal-content risks by offence kind, likelihood, severity, affected users, service design, controls, evidence, and review triggers.
Online Safety Act moderation, reporting, and complaints
How UK Online Safety Act duties shape content moderation, user reporting, complaints, reinstatement, terms, records, and human oversight.
Online Safety Act: User-to-user and Search Service Scope
Decide whether an online service is a regulated user-to-user service, search service, combined service, or exempt service under the UK Online Safety Act.
UK Online Safety Act Age Assurance Options
Compare age verification and age estimation methods by assurance, privacy, accessibility, bias, evasion risk, and operational evidence.
UK Online Safety Act Age Assurance Requirements
When Online Safety Act services need age assurance, what highly effective age assurance means, and how safety duties interact with data protection.
UK Online Safety Act Age Assurance Selection Workflow
Choose an age-assurance method for an Online Safety Act duty by testing effectiveness, privacy, accessibility, evasion risk, and the consequence of error.
UK Online Safety Act Applicability Test Guide
Test whether a service is covered by the UK Online Safety Act by checking service functionality, UK links, exemptions, and the duties that follow.
UK Online Safety Act categories: thresholds and duties
How Category 1, 2A, and 2B thresholds work, how Ofcom categorises services, and what the July 2026 register means.
UK Online Safety Act Categorisation Guide
Apply the UK Online Safety Act Category 1, 2A, and 2B thresholds, calculate active UK users, and use Ofcom's register published in June 2026 and updated in July.
UK Online Safety Act Checklist
Verify UK Online Safety Act scope, assessments, controls, reporting, complaints, records, child safety, and category-specific work.
UK Online Safety Act Children's Safety Duties Guide
Apply the UK Online Safety Act children's access, risk-assessment, safety, age-assurance, reporting, complaints, and record-keeping duties.
UK Online Safety Act Compliance Guide
Build a UK Online Safety Act compliance program from service scope through assessments, controls, evidence, review, and Ofcom response.
UK Online Safety Act Content Moderation and Appeals Guide
Design UK Online Safety Act moderation, content-reporting, complaints, and review processes for illegal content and content harmful to children.
UK Online Safety Act Deadlines and Compliance Calendar Guide
UK Online Safety Act compliance dates for risk assessments, child safety, categorised services, fees, and event-based deadlines.
UK Online Safety Act Enforcement and Penalties Guide
How Ofcom investigates Online Safety Act breaches, issues decisions, requires remedies, imposes penalties, and seeks court orders.
UK Online Safety Act FAQ: scope, duties, and deadlines
Standalone answers and decision paths for UK Online Safety Act scope, risk assessments, child protection, age assurance, categories, reporting, and enforcement.
UK Online Safety Act ICO Overlap Guide
Apply the Online Safety Act and UK data protection law together for age assurance, moderation, profiling, recommender systems, and safety-data sharing.
UK Online Safety Act Illegal Content Duties Explained
Understand the illegal-content risk assessment, safety, reporting, complaints, record-keeping, and review duties for regulated user-to-user and search services.
UK Online Safety Act Moderation, Complaints and Appeals
Build moderation, content-reporting, and complaints procedures for regulated services, and understand where the Online Safety Act does and does not require an appeal.
UK Online Safety Act Ofcom Enforcement Guide
How Ofcom assesses Online Safety Act concerns, gathers information, investigates suspected breaches, and reaches enforcement decisions.
UK Online Safety Act Penalties and Fines Guide
The Online Safety Act penalty ceiling, qualifying worldwide revenue, daily penalties, penalty factors, and payment consequences.
UK Online Safety Act Regulated Service Scope Guide
Understand which user-to-user, search, combined, and provider-pornography services the UK Online Safety Act regulates and which exemptions narrow scope.
UK Online Safety Act Requirements Guide
See which UK Online Safety Act requirements apply to Part 3 services, child-accessible services, provider pornography, and categorised services.
UK Online Safety Act Risk Assessment Template
A field-by-field template for recording service facts, statutory risks, evidence, controls, residual risk, approval, and reassessment triggers.
UK Online Safety Act Risk Assessment Workflow
Run illegal-content and children's risk assessments in the right order, with evidence for risks, controls, governance, and reassessment triggers.
UK Online Safety Act Risk Assessments Playbook
Organise recurring Online Safety Act risk assessments across product, safety, data, engineering, legal, and governance teams.
UK Online Safety Act Senior Manager Liability Explained
Understand when a named senior manager or corporate officer can face personal liability for Online Safety Act information offences and how to control the risk.
UK Online Safety Act Service Classification Workflow
Decide whether a service is regulated, whether it is user-to-user or search, which exemptions apply, and whether Ofcom categorisation adds duties.
UK Online Safety Act Transparency Reporting
Understand who must publish an Online Safety Act transparency report, what an Ofcom notice controls, and how to prepare traceable reporting data.
UK Online Safety Act vs DSA: scope and duties
Compare UK Online Safety Act and EU DSA scope, service classes, child-safety and platform duties, dates, evidence, exemptions, and enforcement.
When Are Senior Managers Liable Under the UK Online Safety Act?
When section 110 can make a named senior manager liable for an Online Safety Act information offence, the available defences, and the controls to keep.
When is age assurance required under the UK Online Safety Act?
When UK Online Safety Act services need highly effective age assurance, what Ofcom expects, and how UK data protection law applies.