
Businesses need to know that Martyn's Law may create new legal duties if their premises can reasonably hold 200 or more people, or if they run certain public events with 800 or more attendees. The main duties are about planning for terrorism related risks, training staff, setting clear public protection procedures, and keeping suitable records where required.
Martyn's Law is the common name for the Terrorism Protection of Premises Act 2025. It received Royal Assent on 3 April 2025 and is expected to come into force after an implementation period of at least 24 months, giving organisations time to prepare properly before enforcement begins.
For many business owners, venue managers and event organisers, the hardest part is knowing where to begin. Legal wording can feel heavy when you are already running a busy site, so a calm and practical plan is the best place to start. iSecurity Solutions helps UK organisations review risks and plan sensible security measures, from CCTV and access control to clear staff procedures that support safer public spaces.
iSecurity Solutions is a trusted UK provider of commercial and domestic security systems, helping homes and businesses stay protected round the clock. From CCTV and intruder alarms to fire safety, access control and construction site monitoring, the team designs reliable, tailored solutions backed by responsive service and modern, remotely monitored technology.
Martyn's Law was introduced after the Manchester Arena attack in 2017, where 22 people were killed, including Martyn Hett. His mother, Figen Murray, campaigned for stronger protective security at publicly accessible places, with the aim of helping organisations prepare better for serious incidents.
The law is not about making every venue feel like an airport, because nobody wants a sandwich shop with passport control at the door. It is about having sensible plans, trained staff and clear procedures, so people know what to do if the worst happens.
The official name, the Terrorism Protection of Premises Act 2025, matters because it shows the law is focused on protection rather than panic. It creates a baseline standard for qualifying premises and events across England, Wales, Scotland and Northern Ireland.
Martyn's Law received Royal Assent on 3 April 2025, which means it became an Act of Parliament. The Government has said there will be an implementation period of at least 24 months, so businesses have time to understand the requirements, prepare documents and train staff before duties are enforced.
In practical terms, many organisations are working towards an expected go live point around 2027, although businesses should keep checking official updates. The GOV.UK Martyn's Law collection is the best place to follow statutory guidance, factsheets and regulator updates.
Waiting until the final months is not a good plan, especially if your site has several entrances, changing staff teams, contractors or regular public events. A steady approach in 2026 will be much easier than trying to write evacuation, invacuation and lockdown procedures in a rush.
Martyn's Law applies across England, Wales, Scotland and Northern Ireland. It covers qualifying premises and qualifying events where members of the public may be present, subject to capacity limits and other rules set out in the Act and statutory guidance.
Premises are generally in scope if they have at least one building, are used for a listed purpose, are not excluded, and can reasonably be expected to have 200 or more people present at the same time. Examples may include shops, restaurants, hotels, theatres, sports grounds, visitor attractions, education settings, places of worship and community venues.
Events can also be in scope, but the event rules mainly apply where 800 or more people may attend and there is some form of ticketing, payment, invitation, access control or entry checking. This could include festivals, concerts, large charity events, council events, sporting fixtures and temporary public gatherings.
If your organisation runs several sites, do not assume one answer applies to every location. A small office reception may sit outside the law, while a larger conference space, shopping area or public event run by the same organisation could fall within it.
Martyn's Law uses two main capacity thresholds. Standard tier premises are those where 200 to 799 people may reasonably be expected to be present at the same time, while enhanced tier premises and qualifying events are those with 800 or more people.
Capacity is not always the same as your busiest day last year or the number of seats in a room. You should look at the number of people who may reasonably be present, including the public and, depending on the situation, staff and others on site.
A simple way to think about it is this. Under 200 is generally outside the main duties, 200 to 799 is standard tier, and 800 or more is enhanced tier. Borderline sites should record how they reached their conclusion, because a clear capacity assessment is far better than a hopeful guess on a sticky note.
If your busiest event could push you into the enhanced tier, start with three points: capacity, use and control. Once you understand those points, it becomes much easier to work out your likely tier and next steps.

Standard tier duties apply to in scope premises with a capacity of 200 to 799 people. The main duty is to put in place appropriate public protection procedures, so far as reasonably practicable, and notify the Security Industry Authority, known as the SIA.
These procedures should cover what staff do if there is a terrorism related threat or attack. They should be simple enough for staff to remember during pressure, and they should match the real layout and use of the premises.
For a smaller restaurant, this could mean briefing staff on how to move customers away from glass frontage, who calls emergency services, who checks toilets, and how managers communicate calmly without causing panic. For a retail store, it may include safer exit routes, staff code words and clear responsibility for shutters or entrance doors.
The standard tier is designed to be proportionate, which means the level of action should match the level of risk. In most cases, the big focus is having workable procedures, training people properly and reviewing plans when your layout, opening hours or public use changes.
Enhanced tier premises and qualifying events have wider duties because larger crowds usually create more complex risks. They must meet the standard tier requirements and also consider additional public protection measures that reduce weak points and the risk of physical harm.
These measures may include CCTV designed around real site risks and, where useful, aligned with BS EN 62676. They may also include access control that supports safer movement and, where relevant, follows BS EN 60839 principles. If alarm signalling is involved, intruder alarm elements should be graded appropriately under EN 50131, such as Grade 2 or Grade 3 depending on the risk.
For larger premises, a joined up approach is usually best. Business security systems can bring together CCTV, access control, intruder alarms and monitoring, so procedures are supported by reliable equipment rather than wishful thinking and a clipboard.
Enhanced tier organisations must also document their procedures and measures, assess how effective they are, and be ready to provide compliance documents to the SIA. This is where good record keeping becomes your friend, even if paperwork is nobody's favourite guest at the party.
If your wider safety review includes fire alarms, emergency lighting, extinguishers or fire risk assessment work, keep the usual UK standards in view, including BS 5839, BS 5266, BS 5306, PAS 79 and BAFE SP101 where relevant. For networked CCTV or access control, structured cabling should be properly tested, with BICSI and Fluke certifications giving useful assurance where they apply.
The responsible person is the person or organisation that has control of the premises or event in connection with its main use. In plain English, that usually means the operator, occupier or organiser who has real control over how the place or event is run.
For a single venue, this may be the company operating the site. For a temporary event, it may be the event organiser. For shared or mixed use buildings, the answer can be more complicated, so organisations should look carefully at who controls the relevant activity and keep agreements clear.
Enhanced tier premises and events must also identify a senior individual where the responsible person is not an individual. This person should have enough authority to make sure compliance is taken seriously, resources are considered and security planning does not get buried under daily operational pressure.
Good governance might include a board sponsor, a venue manager, a facilities lead and a security coordinator, each with clearly written responsibilities. The law may name the responsible person, but safe delivery depends on the wider team understanding their part.
The Security Industry Authority will regulate Martyn's Law. Its role includes receiving notifications, reviewing enhanced tier compliance documents, providing guidance, carrying out inspections and taking enforcement action where needed.
Businesses should expect the SIA to focus on whether arrangements are suitable, proportionate and properly understood by staff. Inspectors are unlikely to be impressed by a glossy folder that nobody has read, so training and live understanding will matter just as much as written procedures.
The SIA is also expected to publish operational guidance and templates to help organisations comply. That support is important because the aim is not to catch businesses out, but to raise preparedness across publicly accessible places in a practical and consistent way.
Non compliance can lead to civil sanctions, including compliance notices, restriction notices and financial penalties. In serious cases, offences and criminal liability may also apply, especially where there is failure to comply with certain requirements or enforcement notices.
The exact level of penalty can depend on the tier, the breach and the size of the organisation. Enhanced tier breaches can carry major financial consequences, so senior leaders should treat Martyn's Law as a board level risk rather than another facilities task to push into next month's diary.
That said, businesses should not view the law as a threat hanging over them. It is better understood as a prompt to put sensible safety systems in place, supported by official guidance, clear documents and regular staff training.
The best starting point is to decide whether your premises or event is in scope. Record your reasoning, your capacity calculation and the areas included, because this gives you a clear audit trail if questions are asked later.
A practical preparation plan could include the following steps.
Next, identify your responsible person and, for enhanced tier settings, your senior individual. If responsibility is split across landlords, tenants, event organisers or contractors, put it in writing so nobody discovers during an incident that everyone thought someone else had the keys.
Carry out a terrorism related risk assessment that looks at your layout, entrances, exits, crowd flows, public areas, vehicle routes, communications and staff capability. You do not need to become a counter terrorism expert overnight, but you do need a thoughtful view of where your site may be vulnerable and what proportionate steps would help.
Security technology can support your procedures when it is designed around real risks. For example, access control can help manage staff only areas, reduce unauthorised movement and support lockdown procedures when used alongside training and clear decision making.
Then design your public protection procedures in simple language. Staff should know where to go, who gives instructions, how to communicate with visitors, when to lock down, when to evacuate, and how to help vulnerable people who may need extra support.
Training should be regular, practical and calm. Short briefings, tabletop exercises and occasional drills can work well, especially when they are tailored to your actual building rather than copied from a generic document found in a dusty corner of the internet.
You may also find it helpful to compare your readiness with wider preparation advice, such as the Martyn's Law compliance checklist, which breaks common actions into manageable steps for smaller UK businesses.
Free guidance is available from the Home Office, SIA and ProtectUK, and it is worth using those sources before making major decisions. They include statutory guidance, factsheets on scope and duties, capacity advice, responsible person guidance, regulator information and practical resources.
Keep a routine for checking updates, especially during 2026 as templates and operational guidance develop. If you manage several venues or public events, nominate someone to track updates and brief the rest of the team, so changes do not get lost in a crowded inbox.
When you review your physical security, avoid buying equipment before understanding the risk. CCTV, access control, alarms and communication systems are useful when they solve a defined problem, but they should support your procedures rather than replace them.
Martyn's Law is a major change for UK businesses, venues and event organisers, but it does not need to feel overwhelming. Start with scope, capacity and accountability, then build practical procedures, train staff and review whether your security measures are fit for purpose.
The organisations that handle this best will be the ones that prepare early and keep the tone sensible. Public safety is serious, of course, but good planning should make teams feel more confident, not more anxious.
If you are ready to take the next step, speak with iSecurity Solutions about reviewing your premises, assessing your current security measures and building a practical plan that supports Martyn's Law readiness without making the process feel heavier than it needs to be.
Martyn's Law may apply if your premises can reasonably hold 200 or more people and is used for a qualifying public purpose. Events are generally in scope at 800 or more people where access is controlled by tickets, payment, invitation or checks.
The Act received Royal Assent on 3 April 2025 and has an implementation period of at least 24 months. Many organisations are preparing for duties to take effect around 2027, subject to official confirmation.
Standard tier covers qualifying premises with 200 to 799 people and focuses on notification, procedures and staff preparedness. Enhanced tier applies at 800 or more people and adds documented assessments, further protective measures and senior individual accountability.
The responsible person is usually the person or organisation with control of the premises or event for its main use. Enhanced tier organisations must also identify a senior individual to oversee compliance.
Where alarms, monitored CCTV or linked security measures are used, SSAIB certified and Insurance Approved installation can support insurer requirements and may be needed for a Police Response URN. The system should be proportionate to the risk and properly maintained.