Join our Newsletter — 33% off our NHI Course

Part 3 Services

Part 3 services are the online services covered by Ofcom’s Protection of Children Codes when children may access them. The category includes user-to-user services, search services, and services that feature provider pornographic content. Coverage depends on how the service is used and whether there are links to the UK market.

What Part 3 Services Mean in the Online Safety Regime

Part 3 services are not a generic label for all websites or apps. They are the online services that fall within Ofcom’s Protection of Children Codes when children can access them, including user-to-user services, search services, and services featuring provider pornographic content. Coverage turns on service type, use, and UK market linkage, so the classification is functional rather than purely contractual.

This matters because the term sits at the intersection of product design, distribution, and regulatory scope. A service may be in or out depending on how it is used, who can reach it, and whether it has a sufficient link to the UK market. For that reason, the phrase is best understood as a regulatory category with practical consequences for platform operators rather than a fixed technology class.

How Scope Is Determined

The key question is whether the service is one of the categories captured by the codes and whether children may access it. That means the same underlying platform can move in or out of scope if its audience, access controls, content features, or market connection change. The category is therefore sensitive to product configuration and deployment choices, not only to the service’s stated purpose.

Service type also matters. User-to-user services and search services are treated as distinct from services that feature provider pornographic content, but all three can sit within the same regulatory family if the access and market tests are met. The definition is deliberately wide enough to capture services that may expose children to harmful content or pathways to it.

For a practical policy anchor on control-oriented interpretation, Ofcom’s child-safety regime is closer to a governance framework than a content taxonomy. Broad control structures such as NIST Cybersecurity Framework 2.0 and EU NIS2 Directive illustrate the same general principle, namely that scope depends on how a service is operated and governed, not just on its name.

Why the Category Matters for Platform Design and Compliance

Once a service is in scope, the operator must treat child safety as an operating requirement, not an afterthought. That affects product architecture, age-aware access decisions, content governance, reporting workflows, and how risks are documented and reviewed. For platforms that handle content discovery or user-generated material, the category can shape moderation design and default safety settings.

The distinction also matters for organisations that assume only child-focused brands are affected. A broad platform with search, sharing, or content-hosting features may still be captured if children can access it and the UK market link exists. In that sense, the label is a trigger for compliance assessment and control design, not a branding statement.

In adjacent control domains, the same logic appears in standards that tie obligations to actual exposure and operating context, such as NIST Privacy Framework and EU General Data Protection Regulation (GDPR). Those references are useful here because they reinforce the idea that regulatory scope follows processing model, exposure, and governance duties.

The UK market connection is a critical part of the scope test. A service does not become a Part 3 service merely because it exists online or because a child could technically reach it from anywhere. There must be a meaningful link to the UK market, which makes distribution, targeting, and operational availability part of the analysis.

This is important for multinational services, because scope may differ by geography, audience targeting, or localised product availability. It also means compliance teams need to understand not only what the service does, but where it is offered and how users are reached. The category therefore creates a jurisdictional and operational decision point.

For teams building security or trust controls around cross-border services, NIST Cybersecurity Framework 2.0 is useful as a general governance reference, while the service-specific scope question remains driven by the UK child-safety regime itself.

Risk and Threat Considerations

Part 3 services carry a material exposure because the category is meant to catch services that children can access and that can surface harmful content, unsafe contact, or frictionless discovery paths. The risk is not limited to explicit pornography; user-to-user and search features can create pathways that amplify exposure if controls are weak.

Failure mechanism: Scope is misread, or access controls and content governance are treated as static, so a service that is reachable by children or linked to the UK market is not assessed against the relevant protections.

Impact: The result can be regulatory non-compliance, unsafe user journeys for children, and control gaps in moderation, discovery, and access design.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0 sets the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

Framework Control / Reference Relevance
NIST CSF 2.0 GV.OC-01 — Organizational Context Part 3 scope depends on service context, use, and market reach.
GV.RM-01 — Risk Management Strategy The classification changes regulatory and operational risk exposure for the service.
PR.AA-01 — Identity and Access Management Child access to a service depends on access decisions and exposure controls.
Recommendation — Document service scope and audience context before deciding which child-safety controls apply. Incorporate Part 3 scope into your risk strategy and control prioritisation. Apply access controls that reflect who can reach the service and under what conditions.
ISO/IEC 27001:2022 A.5.15 — Access control Scope analysis depends on who can access the service and how access is governed.
A.5.31 — Legal, statutory, regulatory and contractual requirements Part 3 is a regulatory classification that drives compliance obligations.
Recommendation — Define and enforce access rules that match the service’s actual exposure. Identify and track the legal obligations created by Part 3 service classification.

Practitioner Guidance

Governance implication: Treat Part 3 classification as an early product and legal review step, not as a late-stage policy label. The right question is whether the service’s audience, features, and UK-market presence place it within scope, because that decision drives the controls you must design and evidence.

What to watch for: Services that evolve from narrow functionality into search, messaging, recommendations, or content hosting deserve reclassification review, because product change can move them into scope even when the original launch position was outside it.

Practitioner takeaway: Keep scope assessment tied to real service behaviour and market reach, then align child-safety controls to that operating reality.