Ofcom's register of "categorised" platforms under the UK Online Safety Act went live on 10 July 2026. This is the heaviest-duty tier of the Act, reserved for the largest platforms, and being named on it triggers extra obligations around fraud advertising, transparency, and user-empowerment tools. The threshold for the top tier, Category 1, is more than 7 million UK users โ a number that puts almost every early-stage SaaS product comfortably outside it.
But the register isn't the only deadline on the calendar. Ofcom is separately consulting on fraud-advertising codes for Category 1 and Category 2A providers, and that consultation closes 2 October 2026. Related risk-assessment record obligations fall due around the same date. The mistake to avoid is assuming that because your product isn't on the categorised register, none of this applies to you โ the Online Safety Act's broader duties, including illegal content duties and risk assessments, reach considerably further down than the categorisation tiers.
Why "not Category 1" doesn't mean "not regulated"
The categorisation register is the top of a pyramid. Below it sit providers of services with user-to-user content or search functionality, who carry duties under the Act regardless of size โ assessing and managing risks of illegal content, and in some cases risks to children. According to techUK, which tracks the Act's rollout timeline, the categorisation register was itself delayed and only went live in July 2026, well after many of the Act's baseline duties had already started to bite for smaller providers.
If your product has any user-generated content, comments, forums, direct messaging, or a way for one user to reach another, you likely have obligations under the Act even at a fraction of 7 million UK users. The size threshold determines which extra layer of duties applies, not whether the Act applies at all.
What a risk-assessment record actually needs
Law firm RPC, commenting on Ofcom's publication of the categorised register, notes that the obligations tied to categorisation sit alongside the ongoing risk-assessment requirements that apply more broadly under the Act. In practice, a risk-assessment record needs to identify what illegal content risks and, where relevant, child-safety risks exist on your specific product, what features contribute to that risk (search, messaging, recommendation systems), what mitigations are in place, and evidence that the assessment was actually carried out and kept up to date โ not just a policy statement asserting compliance.
This record needs to be specific to your product's features, not a generic template copied from elsewhere. A risk assessment that doesn't reflect how your product actually works is unlikely to hold up if Ofcom asks to see it.
What to check by 2 October
Three things are worth doing before that date. First, search Ofcom's published categorised-services register directly to confirm you're not on it โ don't rely on assumption, and note that Ofcom can update the register as usage figures change. Second, work out which tier of the Act's baseline duties applies to your product given its features, independent of categorisation; a product with search or user-to-user functionality of any size has obligations. Third, if you don't already have a written risk-assessment record, start one now โ the record itself, not just the underlying safety work, is what regulators and courts will look for.
The fraud-advertising code consultation closing 2 October is formally aimed at Category 1 and Category 2A providers, so most small SaaS products won't need to respond to it directly. But it's a useful signal of where Ofcom's enforcement attention is heading next, and it's worth reading if advertising or sponsored content appears anywhere in your product.
The bottom line
Ofcom's categorised-platform register is live, the Category 1 threshold is 7 million UK users, and the next real deadline is 2 October 2026 for the fraud-advertising code consultation and related risk-assessment records. Most small SaaS products sit below Category 1, but the Online Safety Act's baseline duties reach further than the register does โ check which tier applies to you and get a written risk-assessment record in place before that date, rather than assuming the register's silence about you means the Act doesn't apply.
This is general information, not legal advice. Rules and figures can change; verify current details with a qualified professional in your jurisdiction.