
Martyn’s Law will be regulated by the Security Industry Authority, usually called the SIA, while the Home Office will manage policy, statutory guidance and the wider government framework.
The legal basis is the Terrorism (Protection of Premises) Act 2025, which received Royal Assent in April 2025 and is expected to become enforceable after a preparation period of at least 24 months. For businesses, venues and event organisers, iSecurity Solutions can help turn the legal wording into clear, practical security planning that works for real premises, not just a folder that sits unopened on a shelf.
That difference matters because the law does not say every venue must buy the same security equipment. It creates duties to think, plan, train and act in a sensible way, based on the size, use and risk level of each premises or event.
Martyn’s Law is a UK wide law designed to improve public protection against terrorism at publicly accessible premises and events. Its official name is the Terrorism (Protection of Premises) Act 2025, and it applies across England, Wales, Scotland and Northern Ireland.
The Act was introduced after the Manchester Arena attack and is named in memory of Martyn Hett. Its purpose is to make sure organisations that welcome the public have suitable procedures in place to reduce the risk of physical harm if a terrorist attack happens.
For larger venues and qualifying events, the law goes further by requiring measures that reduce weakness to attack. This could include better communication procedures, safer movement of people, clearer lockdown planning, staff awareness and suitable protective security arrangements.
Martyn’s Law is not a one size fits all shopping list. It is a legal framework that asks responsible people to take reasonable, practical steps based on their setting, resources and likely attendance.
The Terrorism (Protection of Premises) Act 2025 sets out who is covered, what duties apply, how the SIA will regulate compliance and what happens when duties are ignored. The official legal text is available through legislation.gov.uk, which is the main source for the Act.
The Act covers qualifying premises and qualifying events. In broad terms, qualifying premises need to be a building, or a building with land, used for a listed public purpose, with a reasonable expectation of at least 200 people present at the same time from time to time.
Qualifying events are usually public events where at least 800 people may be present at the same time. Access also needs to be controlled by payment, ticket, pass or membership, and the site must not already be enhanced duty premises. This matters for festivals, exhibitions, ticketed outdoor events and temporary gatherings that may not look like a normal venue on paper.
The Act also uses the phrase reasonably practicable. In simple terms, this means you must balance the protective benefit against the cost, time, difficulty and circumstances. It is proportionate, but it is not optional, so doing nothing and hoping for the best is not a safe plan.
The SIA is the designated regulator for Martyn’s Law. It will support compliance, assess notifications, review evidence, inspect premises, issue notices and use enforcement powers where needed.
The Home Office has a different role. It is responsible for policy, statutory guidance, consultation, Parliamentary laying of guidance and overall government oversight, but it is not expected to be the day to day inspector visiting venues.
ProtectUK and the National Protective Security Authority also provide useful protective security advice. Their materials can help organisations prepare, but not every recommendation in supporting guidance is a direct legal duty, so it is important to understand what you must do, what you should do and what may be useful.
If your organisation is still working out what applies to your site, our practical Martyn’s Law compliance checklist explains the early steps small and medium sized businesses can take without making the process harder than it needs to be.
Martyn’s Law uses two main levels of duty. Government guidance often calls them standard tier and enhanced tier, while the Act refers to standard duty and enhanced duty. Both terms describe the same basic split.
Standard tier premises are generally those where 200 to 799 people may reasonably be expected to be present at the same time. These premises must notify the SIA and put in place suitable public protection procedures, so far as reasonably practicable.
Those procedures are likely to cover evacuation, invacuation, lockdown and communication. Evacuation means getting people out, invacuation means moving people to safer areas inside, lockdown means limiting movement or access, and communication means telling staff and the public what to do quickly and calmly.
Enhanced tier applies to premises where 800 or more people may reasonably be expected, along with qualifying events. Enhanced duty organisations must meet the standard public protection procedures and also consider public protection measures, such as monitoring, managing movement, physical security and reducing weakness to attack.
There are important exceptions. Places of worship, childcare, primary education, secondary education and further education premises are generally treated as standard tier even if 800 or more people may be present. Some transport premises are excluded where separate security rules already apply.

Responsible persons for qualifying premises and qualifying events will need to notify the SIA. Notification is how the regulator knows which premises and events fall within scope, who is responsible and which tier applies.
The final details of the notification process, including exact information fields, deadlines and online portal arrangements, will be confirmed through regulations and SIA guidance. The SIA has said that an online system is being developed, which should make the process more straightforward.
Businesses should start gathering sensible information now. This includes legal entity details, site addresses, event details, attendance calculations, the Schedule 1 use, responsible person information, tier assessment and, for enhanced duty premises, details about the senior individual.
For operators reviewing their wider safety and security set up, our business security support can help align protective security, access control, CCTV planning and day to day operating procedures in a more joined up way.
The responsible person is the person or organisation that controls the premises for the relevant public use. Ownership alone does not settle the question, so a landlord is not automatically responsible if a tenant controls the space for the public activity.
For events, the responsible person is usually whoever controls the premises for the purposes of that event. In leased, hired or shared premises, contracts can allocate tasks, but they cannot remove the statutory duty from the person or organisation that the law makes responsible.
Enhanced duty premises and qualifying events need a senior individual where the responsible person is an organisation. Many people call this the Senior Individual Responsible, or SIR, although the Act uses the wording senior individual.
The senior individual must be sufficiently senior and involved in management or control. They can delegate tasks to security managers, facilities teams or external specialists, but overall accountability must remain clear at the right level in the organisation.
The SIR is not automatically personally liable for every organisational breach. However, senior people can face prosecution in serious cases where an offence by the organisation happened with their consent, connivance or neglect, so board level attention is important.
The SIA is expected to use a risk based approach. This means it may carry out desk based assessments, request documents, review notifications and inspect premises where needed.
For standard tier premises, the regulator will focus on whether suitable public protection procedures exist and whether notification duties have been met. For enhanced duty premises and qualifying events, the SIA can also look at public protection measures, compliance documents and senior accountability arrangements.
An on site inspection may involve looking at documents, electronic records, equipment, site layout, staff instructions, photographs, measurements and recordings. Inspectors may also ask staff to explain what they would do in different situations, which is why training should be practical rather than a box ticking exercise.
The SIA will usually give notice of inspections, with government guidance referring to at least 72 hours in normal circumstances. However, the Act also allows warrants in certain cases, such as where access is refused, urgent entry is needed or notice could defeat the purpose of the inspection.
An information notice is a formal request from the SIA requiring a person to provide specified information by a deadline. It may also require attendance at an interview and answers to relevant questions.
This is one reason record keeping matters. If a venue has clear attendance assumptions, training records, procedure documents, review dates and named responsibilities, responding to the SIA should be much less stressful.
Enhanced duty premises and qualifying events must prepare a compliance document. This should explain how the organisation is meeting the relevant requirements, and it must be provided to the SIA as required after preparation and after revisions.
In plain English, do not build your Martyn’s Law evidence around one helpful person who keeps everything in their inbox. Use controlled documents, version history, clear ownership and secure storage, because people change roles, laptops fail and inboxes are easy places for important work to get lost.
The SIA will have several enforcement tools. The first is a compliance notice, used where the regulator reasonably believes a relevant requirement has been breached. A compliance notice can require specific steps within a set period and may require evidence that the issue has been fixed.
For enhanced duty premises and qualifying events, the SIA can issue restriction notices. These are more serious and may limit how premises are used, when they are used, how many people may attend or whether an event can go ahead in the planned way.
The SIA can also issue penalty notices. These are civil penalties, meaning they are financial penalties rather than criminal convictions, although the sums can be significant for serious enhanced tier breaches.
Standard tier penalties can reach up to £10,000 for relevant contraventions. Enhanced tier or qualifying event penalties can reach up to £18 million or 5 per cent of qualifying worldwide revenue, whichever is higher.
There can also be daily penalties for continuing breaches after relevant notices. These may reach up to £500 per day for standard tier contraventions and up to £50,000 per day for enhanced tier or qualifying event contraventions.
Not every mistake will be a criminal offence, and that is worth saying clearly before anyone starts worrying too much. The regime includes civil enforcement tools, but serious breaches can become criminal matters.
Criminal offences may include failing to comply with an enhanced tier compliance notice, failing to comply with a restriction notice, providing false or misleading information, failing to comply with an information notice, obstructing an authorised inspector or pretending to be one.
Some serious offences can result in unlimited fines and, for certain offences, imprisonment of up to two years on indictment. The exact outcome would depend on the offence, the jurisdiction and the facts of the case.
Recipients of compliance notices, restriction notices and penalty notices will generally have appeal rights to a tribunal, often within 28 days. That appeal route is important because regulation must be firm, but it also needs to be fair and accountable.
The Act received Royal Assent on 3 April 2025. The Home Office has described an implementation period of at least 24 months, giving organisations time to understand the law and giving the SIA time to build its regulatory processes.
In practical terms, enforcement is expected from spring 2027, with April 2027 often discussed as the likely timeframe. The exact commencement date should still be checked against the latest Home Office and SIA announcements before making final decisions.
During 2026, organisations should not wait for the last possible moment. Start by assessing whether your premises or event is in scope, then identify the responsible person, calculate attendance including staff and contractors, and decide whether standard or enhanced tier duties apply.
Next, review public protection procedures, identify gaps, assign ownership and record decisions. Enhanced duty organisations should also begin preparing compliance documentation, senior individual arrangements and evidence management processes.
Martyn’s Law will be regulated through notification, guidance, inspection, evidence review, notices, civil penalties and criminal offences for the most serious breaches. The SIA will regulate day to day compliance, while the Home Office will manage the policy and statutory guidance behind the regime.
The best approach is calm preparation. Work out whether you are in scope, understand your tier, document your reasoning, train your people and keep your arrangements under review. Good security is rarely about dramatic gestures. It is usually about clear thinking, sensible planning and making sure everyone knows what to do when it matters.
iSecurity Solutions is a trusted UK provider of commercial and domestic security systems, helping homes and businesses stay protected around the clock. From CCTV and intruder alarms to fire safety, access control and construction site monitoring, our expert team designs reliable, tailored solutions backed by responsive service and modern remotely monitored technology.
Not yet. The Act has passed, but the government has allowed an implementation period of at least 24 months, with enforcement expected from spring 2027.
The Security Industry Authority will regulate compliance, carry out assessments and use enforcement powers. The Home Office remains responsible for policy, statutory guidance and oversight.
The Act does not automatically require CCTV or alarms for every venue, but suitable systems may support protective security where proportionate. If intruder alarms or monitored CCTV are installed, they should follow relevant British Standards, such as BS EN 50131 for intruder alarms and BS 8418 where detector activated CCTV applies. SSAIB certified and Insurance Approved systems are normally needed for insurer confidence and Police Response URN eligibility.
For enhanced duty premises and qualifying events, the SIA can issue restriction notices where needed to reduce the risk of physical harm. These may limit use, opening times, attendance numbers or whether an event can proceed as planned.
The senior individual is not automatically personally liable for every organisational breach. However, senior people may face prosecution if an organisational offence happened with their consent, connivance or neglect.
iSecurity Solutions installs and maintains CCTV, intruder alarms, access control and fire alarm systems for homes and businesses across the UK.