Martyn’s Law: preparing premises, venues and organisations for the new duties
Martyn's Law introduces new terrorism-protection duties for qualifying premises and events. Good preparation starts with understanding scope, responsibility and the operating arrangements already in place.

Martyn's Law introduces new terrorism-protection duties for qualifying premises and events. Good preparation starts with understanding scope, responsibility and the operating arrangements already in place.
Martyn's Law is moving from legislation into practical implementation. The Terrorism (Protection of Premises) Act 2025 received Royal Assent on 3 April 2025 and is expected to come into force in spring 2027. For an organisation running a qualifying site, the important question is not simply what the Act says, but how responsibility, procedures and existing security arrangements fit together in the real operation. September 2026 guidance on principal use makes that particularly important for mixed-use premises. This guide works through the operational questions organisations should resolve before commencement and should be read alongside the official guidance.
Seven areas to work through before commencement
Start by establishing exactly what you are assessing
Before looking at additional guarding, CCTV or physical measures, establish exactly what premises or event you are assessing and whether it is actually within scope. On a straightforward standalone venue this may be relatively simple. On a larger estate, mixed-use building or site containing several separately operated premises, it may not be. Define the operational footprint first, then apply the scope rules to that footprint.
For most qualifying premises, the working thresholds are straightforward: 200 to 799 people will generally place the premises in the standard tier and 800 or more in the enhanced tier. Qualifying events have separate criteria, including an expectation of 800 or more people and entry checks. Childcare, primary and secondary education, further education and places of worship have particular tier rules, so headcount alone should never be used as the final answer without checking the statutory guidance.
Questions to ask
- Are we looking at one qualifying premises, premises within other premises, or several separate premises?
- How many people, including staff, can reasonably be expected to be present at the same time?
- Which Schedule 1 use applies, and are there exclusions or special tier rules that change the answer?
Identify who actually controls the premises
Do not assign Martyn's Law accountability to the security manager, facilities team or contracted security provider by default. Operational delivery and statutory control are different issues. For premises, the responsible person is the individual, organisation or company with control of the premises in connection with the qualifying use. In leased, managed or multi-occupier settings, this should be established by working through who controls the areas in scope, who can make decisions, how access is managed, what tenants or occupiers control and where responsibilities are shared.
Where more than one responsible person exists, the interface between them must be agreed, recorded and capable of working under incident conditions. Enhanced-tier organisations must also identify a senior individual who is responsible for ensuring compliance.
Do not assume the largest activity defines a mixed-use premises
A hotel may contain a restaurant, bar, conference space and leisure facilities. A university or managed estate may contain several activities under different operational arrangements. Before deciding who owns the Martyn's Law responsibility, establish what is actually being treated as the qualifying premises and, where the principal-use rules apply, what its principal use is.
The starting point is the purpose and nature of the premises: what it was built or modified for, whether that use continues, its physical characteristics and how the local authority treats it through matters such as planning or licensing.
Use the records the site already has
Use the information the operation already holds before creating a separate theoretical assessment. Site plans, lease arrangements, licences, opening hours, staffing levels, capacity figures and floor-area use can all help evidence how the premises actually works. If the purpose and nature of the premises do not give a clear answer, the principal-use assessment should consider the space each activity occupies, how long each one operates and whether one activity supports another. Keep the outcome short and clear: what was decided, what evidence was used, who owns the decision and when it must be reviewed.
This test applies to a single mixed-use premises; it should not be used to treat separate qualifying premises as one operation for convenience.
Build procedures around real scenarios
Do not begin with a generic emergency-plan template. Work through how people would actually respond if a threat or attack affected the premises or immediate vicinity: how they would move away, move inside, secure an area or receive clear instructions. Both standard and enhanced tiers require appropriate public protection procedures, so far as is reasonably practicable. The Terrorism (Protection of Premises) Act 2025 groups those procedures under four headings: evacuation, invacuation, lockdown and communication.
Procedures only add value when they can be put into action quickly, consistently and under pressure. The colleagues expected to deliver them must know what is required, what decisions they can make and what resources or authority they can use. In practical terms, the operation should be clear on who can pause admissions, secure or open routes, control doors, issue announcements, contact emergency services, direct occupants and step in when the usual decision-maker is unavailable. The Act does not require a specific paid training course; the right approach may be a combination of site briefings, induction, supervised drills, e-learning or role-specific instruction, provided it reflects how the premises actually operates.
For enhanced tier, test existing measures before adding new ones
Existing arrangements should be assessed before assuming something new has to be purchased. CCTV may already provide useful monitoring. Access-control arrangements may already regulate movement. Security officers may already have defined incident and escalation roles, while radios, alarms or public-address systems may already support communication. For enhanced-tier premises and qualifying events, the required public protection measures cover monitoring, movement, physical safety and security, and security of information. The question is whether the arrangements work together against the operating requirement of the site – not whether the organisation owns a particular security product.
The responsible person must then consider what is appropriate and reasonably practicable in the circumstances. Enhanced-tier procedures and measures must be documented, together with an assessment of how they are expected to reduce harm and vulnerability, and that document must be provided to the SIA in the required way once the regime is in force. The legislation does not prescribe one standard package for every site, so the reasoning behind the chosen arrangements matters.
Treat the security provider as part of the operating model
Bring the security provider into the planning early where day-to-day security delivery will form part of the response. The operation needs their practical view before procedures are finalised: where queues form, which entrances create pressure, how patrols, CCTV and radio communication actually work, where escalation is slow and what can realistically be controlled during a live incident. Guarding, monitoring, access control, patrols and event-security teams should be built into the operating plan, with clear instructions, reporting lines and handover points, rather than sitting alongside it as a separate security function.
This does not move the legal duty away from the responsible person. From an operational perspective, the important point is to remove ambiguity before it matters. Set out how building management, facilities, security, event operations, tenants and other occupiers depend on one another; who makes each decision; who carries out each action; who communicates internally and externally; and who has authority to change the response when the situation no longer matches the standard procedure.
Keep records that people can actually use
For enhanced-tier premises and qualifying events, formal documentation is part of the legal duty. Standard-tier premises do not have the same statutory submission requirement, but leaving important procedures only in people's heads creates an obvious continuity problem. A proportionate written record helps new staff, contractors, managers and occupiers understand what has been decided and gives the organisation something practical to review when the site changes.
Useful preparation records may include the scope and tier assessment, responsible-person decision, principal-use reasoning, procedures, assigned roles, briefings, escalation routes, key dependencies and review records. Give each important arrangement an owner and a reason for review. The purpose is not paperwork for its own sake; it is to make decisions clear, usable and capable of being explained if the SIA assesses compliance.
Review when the operation changes, not just when guidance changes
A new tenant, revised entrance, different opening hours, a change in capacity, a new event format or a significant incident can all change the practical answer. Enhanced-tier measures must be kept under review, and principal-use determinations should be revisited when circumstances change. The SIA has completed a first round of pilot assessments and is developing an online scope checker, optional templates and the GOV.UK notification portal. Establish a sound operational baseline now, then update it as the site and official guidance develop.
Related operational evidence.
Event security and crowd safety supporting Birmingham’s St Patrick’s Day Parade
Birmingham’s St Patrick’s Day Parade returned to Digbeth on 17 March 2024, bringing one of the city’s major public events back into the heart of Birmingham’s Irish Quarter. The parade typically attracts around 70,000 visitors and creates a complex live environment involving large crowds, parade movements, public access, traffic management and activity across multiple areas.
Read more →
Event security supporting the 2025 British Judo Championships in Nottingham
Innovative Security Solutions provided event security for the 2025 British Judo Championships at the David Ross Sports Village, University of Nottingham. The two-day national championship brought together nearly 800 registered judoka from clubs across Great Britain, with Pre-Cadet, Cadet, Junior and Senior competition taking place across seven mats under one roof.
Read more →
Responsive security patrols reducing antisocial behaviour, theft and vandalism at a Birmingham shopping centre
A Birmingham shopping centre was experiencing recurring theft, vandalism, antisocial behaviour, loitering and public nuisance across its public-facing environment. Innovative Security Solutions introduced a more active security operation combining Security Guarding, Mobile Patrols and Key Holding & Alarm Response.
Read more →More practical security guidance.
Hotel security: protecting guests without compromising hospitality
Hotel security works best when guest service, access control, staff support, late-night activity and incident response are managed as one operating model.
Read more →
How to reduce retail shrinkage and theft
Retail loss prevention works best when staff safety, store layout, stock controls, security presence and incident evidence support each other.
Read more →
Concierge security: role, value and when to use it
Concierge security works best where front-of-house service and security responsibilities genuinely overlap, with clear authority, service standards and escalation routes.
Read more →The UK national terrorism threat level is set by MI5 and reflects the likelihood of an attack in the UK.
We monitor relevant official updates and factor the risk context into site risk assessments and deployment planning.
View the current official threat level →Discuss your security requirements
Talk to Innovative Security Solutions about the operating environment, current risks and the service model you need.
Discuss Your Security Requirements →