Technical Support Questions? Please visit our Support Page
Martyn’s Law, formally known as the Terrorism (Protection of Premises) Act, introduces requirements for venues and public spaces across the United Kingdom. The law is designed to improve the preparedness and safety of individuals in the event of a terrorist attack.
So, understanding Martyn’s Law in the UK is critical if you’re operating a public-facing organization. This guide will cover everything you need to know about the law, how it may impact your business, and how you can prepare.
Important note: This article is intended as general information only and should not be considered legal or regulatory advice. Organizations should review the official Martyn’s Law legislation and guidance from the Security Industry Authority (SIA) to understand their specific obligations and compliance requirements.
The Terrorism (Protection of Premises) Act 2025, widely known as Martyn’s Law, is a UK legislation that requires certain publicly available locations and venues to implement security solutions and policies that help protect the public from possible terrorist attacks.
The legislation is named after Martyn Hett, one of the 22 people killed in the Manchester Arena terrorist attack in 2017. Following the attack, Martyn’s mother, Figen Murray, led a campaign requesting stronger security requirements for publicly accessible venues.
Martyn’s Law received Royal Assent in 2025 and became law in the UK.
However, the government has indicated there will be a 24-month period, from April 3, 2025, to implement the requirements. This will allow organizations to understand their responsibilities, prepare documentation, train staff, and establish appropriate security procedures before enforcement begins.
The requirements under Martyn’s Law depend on the size of your premises or event. The legislation uses a tiered approach to ensure organizations take security measures that are proportionate to their level of risk and public attendance.
Organizations covered by the law must register with the Security Industry Authority (SIA), the regulator responsible for overseeing compliance. The specific requirements then vary depending on whether a venue falls within the Standard Tier or Enhanced Tier, which the Martyn’s Law Factsheet details.
The Standard Tier applies to qualifying premises with a maximum occupancy of 200 to 799 individuals, including staff.
Martyn’s Law requirements for Standard Tier premises focus on practical, low-cost measures that improve preparedness and help reduce harm during a terrorist incident. Organizations are not expected to invest in major security infrastructure or make significant physical changes to their premises.
Organizations in the Standard Tier will generally be required to:
The Enhanced Tier applies to qualifying premises and events with a capacity of 800 or more individuals, including staff.
Enhanced Tier organizations must meet all Standard Tier requirements while implementing additional measures that reflect the increased complexity and risk associated with larger venues and events.
Requirements for Enhanced Tier premises generally include:
For qualifying premises, the responsible person is typically the individual, organization, or company that controls the premises. For qualifying events, the responsible person is the individual, organization, or company that has control of the premises for the purpose of the event.
While certain compliance tasks can be delegated to employees, security teams, or third-party providers, the legal responsibility for meeting Martyn’s Law requirements remains with the responsible person and cannot be transferred.
The law applies to publicly accessible premises and qualifying public events where 200 people or more can gather.
So, some organizations that may fall under these requirements include:
Martyn’s Law does not apply to premises with a capacity of 199 people or fewer.
However, many smaller organizations are still choosing to adopt basic security awareness training, emergency response procedures, and preparedness planning as part of their broader duty of care.
You still have time to prepare for when Martyn’s Law is enforced. It’s important you take steps to comply with this legislation for the safety and security of your employees, customers, and the public.
Follow the steps below to prepare your organization for Martyn’s Law.
First, determine whether Martyn’s Law applies to your organization. Review the requirements of the legislation and identify whether your premises or events fall within the Standard Tier or Enhanced Tier.
If your organization is not publicly accessible or has a capacity of 199 people or fewer, the legislation is unlikely to apply. However, you should review the Act carefully and seek guidance from the SIA if you are uncertain.
Even if your organization falls outside the scope of Martyn’s Law, strengthening emergency preparedness, staff awareness, and security procedures is still a worthwhile investment in protecting people and property.
Martyn’s Law places legal responsibility on the individual, organization, or company that controls the premises or event. And Enhanced Tier organizations are required to appoint a designated individual responsible for Martyn’s Law compliance. As a result, it is important to clearly establish who will oversee compliance activities within your organization.
For larger organizations, this may involve assigning responsibilities across security, facilities, operations, and risk management teams. While specific tasks can be delegated, accountability ultimately remains with the responsible person.
Establishing ownership early helps ensure requirements are understood, documented, and consistently managed.
Many organizations already have processes in place that support the objectives of Martyn’s Law. Existing emergency plans, business continuity procedures, health and safety policies, and incident response processes may already address some of the requirements.
Review your current documentation and identify any gaps related to evacuation, lockdown procedures, or communication during an incident. This can help you understand where improvements may be needed before the legislation comes into force.
For organizations in the Enhanced Tier, reviewing existing security measures will be an important part of compliance. However, organizations of all sizes can benefit from understanding their vulnerabilities and preparedness levels.
Consider how effectively your organization can detect, assess, and respond to potential threats. Think about public access areas, entry points, crowd movement, visitor management procedures, and how information would be communicated during an emergency.
The goal is not to eliminate every risk, but to ensure reasonable and proportionate measures are in place to protect people.
Martyn’s Law emphasizes preparedness, so staff should understand what actions they need to take in the event of a terrorist attack and where to find relevant procedures.
Training should focus on practical response activities, such as:
The Enhanced Tier of Martyn’s Law includes monitoring requirements, meaning a unified security solution is vital for both compliance and public safety. Organizations operating multiple buildings, campuses, or locations should consider whether their security systems provide the visibility needed to support decision-making during an emergency.
Disconnected alarms, video systems, access control platforms, and monitoring tools can make it more difficult to understand what is happening and coordinate an appropriate response. A more unified approach can help security teams gain better situational awareness when it matters most.
Preparedness involves more than learning the policies and procedures once. It requires regular exercises and reviews to ensure they remain effective. After all, building layouts, events, personnel, and security risks are ever-changing.
Regular exercises, tabletop scenarios, and plan reviews can help identify gaps, validate processes, and improve confidence among staff and stakeholders. Organizations that regularly test and refine their procedures are often better positioned to respond effectively when an incident occurs.
For organizations in the Enhanced Tier, security technology will play a critical role in your public protection measures.
Depending on the nature of the premises, this could include solutions like:
It’s important to note that Martyn’s Law does not require Standard Tier premises to purchase or invest in security equipment or upgrades for their sites. The focus for these organizations is on having appropriate public protection procedures in place and ensuring staff understand how to respond during an incident.
For organizations in the Enhanced Tier, investing in integrated security technology can also help support compliance efforts. These technologies improve oversight of activity on the premises and give security teams greater confidence in public protection. It also supports incident responses, so teams have the information they need to act properly.
Martyn’s Law applies throughout the United Kingdom to qualifying publicly accessible premises and events that meet the criteria established in the legislation.
Yes, if a school or university is a publicly accessible premises where 200 people or more may gather. It’s important that schools research if their organization meets the qualifying thresholds.
For more guidance on how schools can prepare for Martyn’s Law, read insights from PACOM’s Senior Director of Sales, Richard Joslin, in the latest issue of Professional Security Installer (PSi) Magazine.
Yes, certain outdoor events may fall within the scope of Martyn’s Law.
The determining factors include:
Large festivals, sporting events, and public gatherings may be subject to additional requirements under the Enhanced Tier.
Yes, churches and other places of worship may be included in Martyn’s Law if they meet relevant criteria.
Yes, hotels may fall within the scope of Martyn’s Law, particularly where occupancy levels or event facilities meet qualifying thresholds.
Hotels often host events that are covered by the legislation, such as:
As organizations review their public protection procedures and measures, many are discovering that fragmented security systems can make it difficult to maintain visibility during an emergency. When alarms, video surveillance, access control, and incident management tools operate independently, security teams may struggle to understand what’s happening and coordinate a response.
PACOM helps organizations centralize these systems through a unified security management platform. By centralizing security operations, teams can gain greater visibility across their sites, streamline incident response, and improve situational awareness when every second matters.
Unifying your security solutions with PACOM supports the following: