20/07/2026

As the national threat level for a terror attack recently increased to severe, premises and event venues will welcome the recent publication of this statutory Guidance applicable across the UK, intended to support the implementation of ‘Martyn’s Law’.

With compliance likely to be required by Spring 2027 organisations only have less than 12 months left to ensure their protection procedures and measures are in place.

Background

Following the deadly terrorist attack at the Manchester Arena in 2017, the Terrorism (Protection of Premises) Act 2025 (‘the Act’) received Royal Assent on 3 April 2025 and is expected to come into force 24 months later.  It is known as ‘Martyn’s Law’, named after Martyn Hett, a victim of the 2017 Manchester Arena bombing. 

This is the government’s commitment to strengthen security at events. The Act is based on the assumption that a terrorist attack could occur anywhere.  A regulator has been created through a new function of the Security Industry Authority (SIA), intended to support and guide those responsible for premises in meeting the requirements of this new law. 

The Guidance recognises that detection is becoming harder due to an increase in attacks from those not formally part of existing terrorist groups. Whilst the Guidance confirms that it is the responsibility of the Government and its agencies to detect and disrupt terrorist activity, Martyn’s Law places more emphasis on businesses to ensure public protection and safety at events.  As the Guidance reiterates, this law is intended to ‘improve organisation preparedness and protective security’.

The Public Inquiry into the Manchester Arena bombing which killed 22 people found that there were missed opportunities for detecting and stopping the attack or reducing the harm it caused.  The Inquiry noted that the security arrangements at the Arena should have prevented or minimised the impact of the attack, but they failed to do so.  Examples identified included pushing out the security perimeter of the security operation on the night of the concert to make ‘hostile reconnaissance’ more difficult for the perpetrator, along with inadequate CCTV systems, security patrols and training for staff.

The Guidance has been issued pursuant to section 27 of the Act and has ‘security of public spaces at its heart’.  Martyn’s Law will affect a variety of premises including shops, restaurants, arenas, cinemas, attractions, universities and hospitals.  The Guidance provides useful explanation, illustrative examples along with ‘decision trees’ to help businesses assess whether their premises and events are in scope. 

Public protection procedures

Those responsible for standard and enhanced tier premises and qualifying events must ensure that appropriate public protection procedures are in place, so far as is reasonably practicable. That is likely to be a company or organisation, but it could also be an individual.

The Guidance confirms that public protection procedures should be ‘a set of actions, or a plan, that staff at qualifying premises can take to reduce the risk of harm to people (including staff) if they suspect an act of terrorism is occurring or is about to occur at the premises or in the immediate vicinity’.

Procedures should therefore aim to reduce the risk of physical harm to people. The procedures are centred around the principles of evacuation (getting people away from danger by moving them out), invacuation (moving people away to a place where there is less risk), lockdown (preventing entry or exit) and communication (ensuring people are alerted as quickly as possible).

Organisations will need to consider what procedures are appropriate and reasonably practicable to achieve the objective of ‘reducing the risk of physical harm caused to individuals if an act of terrorism were to occur’.

For an enhanced tier premise, consideration will also have to be given to measures that achieve the objective of ‘reducing the vulnerability of their premises or event to acts of terrorism’.

Organisations must consider what is appropriate and reasonably practicable in respect of every public protection procedure.  Measures will need to be tailored.  Consideration should be given to suitability taking into account the context and size of the event.  The Guidance reiterates that the one size fits all approach must be avoided. Procedures will need to be balanced alongside other considerations such as financial resources and staffing levels. 

The Guidance suggests an assessment of the following:

  • The nature of the premises, including the location and layout
  • Use of the premises
  • The number of individuals reasonably expected to be present at the same time, from time to time and the types of staff at the premises (for example, security staff, volunteers, employees or others working at the premises)
  • How planned actions may be impacted depending on where the attack is coming from (for example, inside or outside the premises)
  • Different attack methods
  • Existing equipment, structures or apparatus that may be used when implementing the procedures (for example, areas that can be easily secured, doors, locks or public address systems)

As part of those public protection procedures, organisations may already be starting to consider additional security measures recommended in the guidance such as:

  • Displaying procedures in communal areas e.g. posters
  • Reviewing staff training and induction processes to ensure awareness of procedures
  • Provision of ‘grab bag’ incident response kits containing key information and critical documentation e.g. up to date emergency contact details and floor layout plans.

Qualifying premises and events are separated into two categories; standard tier and enhanced tier.  There are some exemptions in schedule 2 of the Act (for example the Houses of Parliament, devolved governments, parks, gardens and some open-air premises used for recreation or leisure).

Standard tier duty

Standard tier premises are qualifying premises that can reasonably expect 200 to 799 individuals to be present at the same time (including staff) for the purpose of at least one qualifying Schedule 1 use (for example retail, restaurants, cinemas, theatres, sports stadiums, hospitals).

Certain premises, such as places of worship and some educational facilities (except higher education) have special consideration. These types of premises will always be standard tier premises even if the enhanced tier threshold of 800 or more individuals is reached.

Standard tier premises must ensure that appropriate public protection procedures are in place, so far as is reasonably practicable. This could include ensuring evacuation routes are in place, staff are aware of lockdown procedures and communication with customers is effective.

There is no legal requirement to prepare a document confirming that the procedures are in place.  Nor do organisations need to prepare an assessment of how they may be expected to reduce the risk of physical harm if an act of terrorism were to occur. However, the Guidance does recommend that the responsible person should prepare a document akin to this to ‘provide a basis for ensuring the procedures can be effectively understood and communicated to staff’.  It will of course also go towards evidencing compliance.

Enhanced tier duty

Enhanced tier premises are qualifying premises that can reasonably expect 800 or more individuals to be present at any one time, from time to time, for the purpose of a Schedule 1 use.

There are additional requirements for enhanced tier premises (covered in chapter 8 of the Guidance). In the same way as a standard tier premises, enhanced tier premises must ensure appropriate public protection measures are in place so far as is reasonably practicable. In addition though, it must document the procedures that are in place, and measures that are in place (or are planned to be put in place).  Furthermore, it must assess how they are expected to reduce the risk of physical harm to individuals and/or reduce the vulnerability of the premises or event.

Organisations will need to designate a senior individual with responsibility for ensuring compliance.  Those that have control of premises (but are not the responsible person) must co-operate with the responsible person as required.

The Guidance recognises that given the larger and/or more complex nature of enhanced tier premises and qualifying events, the public protection procedures may themselves be more complex. Procedures must be appropriate to the scale and nature of the premises or qualifying event.

Enhanced tier premises must assess and keep under review the public protection measures to ensure they are appropriate to reduce the vulnerability of the premises or event to acts of terrorism, and to reduce the risk of physical harm caused by an attack. This could include CCTV (monitoring for suspicious activity/control rooms and ensuring there are no ‘blind spots’), bag and people searches, access controls (e.g. ID/badge checks).  Premises may also consider hostile vehicle mitigation measures or security staff patrols (perimeter, entry and exit).  Security lighting, voice based alerts and physical mitigations e.g. shutters and barriers and protective glazing are all additional measures that could be considered.

Enforcement

The SIA will be the regulator and therefore responsible for compliance. There is a notification requirement for premises that are in scope. Qualifying premises or qualifying events must notify the SIA when they become responsible and when they cease to be responsible. 

The responsible person for enhanced tier premises or qualifying events must document their compliance. The SIA is to publish specific guidance on this.  Evidence may need to be provided as to how the number of individuals has been calculated.  Organisations must satisfy the SIA, if necessary, that it is a reasonable way of assessing attendance in the particular circumstances of the premises.

The SIA will also have powers to inspect premises and events and to obtain information.  They can also issue various compliance and restriction notices along with financial penalties to address non-compliance. The SIA’s guidance will provide further detail on these notices and rights of appeal. The SIA will also no doubt look to prosecute in the most serious of cases.

Implications - What to do now

Premises are being afforded an opportunity to understand their new obligations and implement the requirements of the Act.  Businesses should now get ready and begin considering how they will meet the legislative requirements.  What steps have you taken in preparation for a terrorist attack?

The Guidance makes it clear that the Act ‘does not require separate procedures to be developed for every individual type of attack. It does not mandate different versions of evacuation, invacuation, lockdown and communication procedures for each terrorist attack method. However, certain procedures may be more effective than others depending on the nature of the attack. For example, initiating an evacuation in response to a fire as a weapon attack could be more appropriate than implementing a lockdown’.

The primary focus when implementing procedures should be identifying where the threat is coming from and what that means for keeping people safe at the premises or event.

The Guidance reiterates that protective security is based on a good security culture. Those responsible for certain premises and events will now need to consider how they would respond to a terrorist attack.

Organisations can comply with the new requirements without the need to spend significant sums on specialist equipment, consultancy services or third parties.

The Guidance will be kept under review which is to include a monitoring and evaluation programme aimed at understating implementation in practice.

A review of your public protection measures is essential.  Consider whether your organisation’s procedures can be implemented rapidly and effectively.  Are your communication methods effective?  Are you able to alert people to dangers as quickly as possible?  Are your staff induction processes sufficient?  Review your evacuation procedures, whether they are a full, partial or phased style process, are there ways they could be improved?

We can assist with:

  • Regulatory readiness and compliance reviews
  • Enforcement risk management
  • Strategic projects and policy engagement
  • Enforcement strategy

Our use of cookies

We use necessary cookies to make our site work. We'd also like to set optional analytics cookies to help us improve it. We won't set optional cookies unless you enable them. Using this tool will set a cookie on your device to remember your preferences. For more detailed information about the cookies we use, see our Cookies page.

Necessary cookies

Necessary cookies enable core functionality such as security, network management, and accessibility. You may disable these by changing your browser settings, but this may affect how the website functions.

Analytics cookies

We'd like to set Google Analytics cookies to help us to improve our website by collection and reporting information on how you use it. The cookies collect information in a way that does not directly identify anyone.
For more information on how these cookies work, please see our Cookies page.