A crowded premises does not become safer because it has a policy, a floor plan and a nominated security lead. Martyn’s Law requirements are intended to make those responsible for publicly accessible places think about foreseeable terrorist threats, prepare proportionate protective measures and ensure people can act when normal routines fail.

That is a necessary shift. Too many organisations still treat counter terrorism as either a specialist security issue or an emergency-services problem. For the dutyholder, it is neither. It is an operational responsibility involving leadership, facilities, security, front-of-house teams, contractors and anyone expected to make decisions under pressure.

The Terrorism (Protection of Premises) Act 2025, commonly known as Martyn’s Law, received Royal Assent in April 2025. Its requirements are not yet in force at the time of writing. Organisations have been given an implementation period of at least 24 months, but waiting for a commencement date is poor preparation. The work that takes time is not completing a form. It is understanding the premises, testing assumptions and developing capable people.

Who will fall within Martyn’s Law requirements?

The Act applies across Great Britain to qualifying premises and qualifying public events. The central test is not whether an organisation regards itself as a security business. It is whether people can reasonably be expected to be present at a place used for specified activities.

A premises will generally be in scope when it is used wholly or partly for a qualifying activity and has a capacity of at least 200 individuals, including staff. Qualifying activities cover a wide range of everyday environments, including shops, hospitality venues, visitor attractions, entertainment and leisure sites, places of worship, education settings, healthcare locations, transport hubs and many community premises.

The capacity figure matters. It is not simply the number of ticket holders at a popular event or the usual number of customers on a quiet weekday. Organisations need a defensible view of the maximum number of people reasonably expected to be present at the same time. That means considering employees, contractors, visitors and the practical use of all accessible areas.

There are two tiers. Standard tier premises have a capacity of 200 to 799 people. Enhanced tier premises have a capacity of 800 or more. Qualifying public events with a capacity of 800 or more can also fall within the enhanced tier where attendees have express permission to enter, such as through a ticket, pass or registration.

Some premises, activities and events are excluded or treated differently. The detail matters, particularly for mixed-use buildings, shared estates, education campuses and sites operated through leases or management agreements. Do not make a scope decision from a headline capacity number alone.

The responsible person must have real control

The law places duties on the person or organisation with control of the premises or event. That can be an individual, a company, a charity, a partnership or a public body. In a managed building, the answer is not always obvious.

A landlord may control common areas while tenants control their own spaces. A venue operator may run an event inside a premises it does not own. A facilities provider may have day-to-day influence but no authority to approve expenditure or change procedures. These arrangements create a familiar failure point: everyone assumes somebody else owns the risk.

The responsible person needs sufficient control to implement the required measures. Where control is divided, responsibilities should be agreed in practical terms before an incident exposes the gaps. Who receives threat information? Who can close access points? Who communicates with tenants? Who has authority to stop an event, move people or request police assistance? A contract clause without an agreed operating model will not answer those questions at the point of need.

What standard tier premises will need to do

The standard tier is deliberately intended to be proportionate. It does not require every smaller premises to employ security officers, install complex systems or produce a lengthy terrorism risk assessment. It does require reasonable procedural preparedness.

Standard tier responsible persons will need to notify the Security Industry Authority, which will regulate the regime, and put in place public protection procedures so staff know what to do if an incident occurs or is suspected. The core procedures relate to evacuation, invacuation, lockdown and communicating with people on site.

Those words are often used loosely. Evacuation is not automatically the right answer if moving outside takes people towards danger. Invacuation means bringing people into a safer internal area. Lockdown may involve restricting access, securing areas and accounting for those present. Communication includes how instructions reach staff, visitors, contractors and people who may not understand English or be able to hear an announcement.

A laminated instruction sheet is not a procedure. A procedure exists when the people expected to use it understand their role, can recognise the trigger for action and can communicate clearly without waiting for perfect information. At standard tier, that may be achieved through straightforward briefing, role-based learning, clear call arrangements and realistic discussion of the site. The scale may be modest. The judgement required is not.

Enhanced tier duties require a stronger security case

Enhanced tier premises and qualifying public events face additional duties because the potential consequences of an incident, and the complexity of managing people, are greater. They must assess terrorism risk, take reasonably practicable measures to reduce vulnerability and reduce the risk of physical harm, and maintain a security plan.

The difference is significant. A generic risk assessment copied across a portfolio will not be enough. A credible assessment considers the particular premises, its layout and operating hours, crowd flows, access arrangements, temporary works, deliveries, neighbouring activity, staffing pattern and likely ability to respond. It also identifies dependencies such as public-address systems, access-control arrangements, control rooms, outsourced guarding, mobile connectivity and emergency services access.

The resulting security plan should describe the measures in place, how they are maintained and how people will operate them. It needs to be usable by managers, supervisors and those delivering the response, not written only for an audit file. If a plan cannot help a duty manager make sense of a fast-moving situation at 9pm on a busy Saturday, it is not serving its purpose.

Enhanced tier dutyholders will also need to designate a senior individual where the responsible person is an organisation. This should not become a nominal appointment. Senior ownership matters because protective security decisions compete with commercial pressures, customer experience, operational convenience and budget. Those trade-offs need authority, not just enthusiasm from a security manager.

Reasonable measures are not a fixed shopping list

The Act uses the language of reasonable measures and reasonably practicable steps. That is appropriate, but it will disappoint anyone looking for a universal checklist. The right measures depend on the site and the risk.

For one premises, the immediate weakness may be poor staff reporting and no reliable way to alert tenants. For another, it may be uncontrolled public access during peak periods, poorly managed queuing or a control room that is unable to verify what is happening. At a major event, the challenge may be command arrangements across the organiser, venue, stewarding contractor and emergency planning partners.

Physical security has a role, but equipment is not capability. Cameras do not assess a situation. Access systems do not make a difficult decision. A public-address system is useless if the person with the microphone has never considered what to say, who approves the message or how to avoid causing unnecessary confusion.

This is where many programmes lose their way. They invest in visible security measures because they are easier to buy and demonstrate, while neglecting the less visible work of exercising decisions, reporting concerns, briefing temporary staff and resolving command ambiguity. Modern threats expose old security thinking. A premises needs both sensible protective measures and people who can use them well.

Prepare now without treating it as a compliance project

The most useful first step is a grounded gap assessment. Establish whether each premises or event is in scope, who holds control and what tier applies. Then look beyond the legal label. Ask what staff would actually do if they received a credible warning, identified suspicious behaviour or faced an uncertain incident during a busy period.

Walk the premises at the times it is most difficult to manage, not just when it is quiet. Include reception staff, facilities teams, event managers, security personnel and operational leaders. Their accounts will often expose the difference between the intended process and the real one. Pay attention to handovers, agency staff, lone workers, out-of-hours arrangements and occasions when normal access routes are unavailable.

Training should be proportionate and role-specific. Everyone does not need the same depth of knowledge, but everyone needs to know enough to contribute. Frontline teams need confidence to report and act on instructions. Supervisors need to make decisions and coordinate. Senior leaders need to understand their responsibilities, resource requirements and the consequences of accepting unresolved gaps.

Test the arrangements through discussion and carefully designed exercises. The objective is not to create theatre or catch people out. It is to reveal whether communication, authority and judgement hold up when information is incomplete. Record what is learned, assign actions and revisit the plan when the premises, event format or operating model changes.

The organisations best placed for Martyn’s Law will not be those with the thickest files. They will be the ones where staff can explain, in plain language, what they would do, who they would tell and how they would protect people when the usual plan no longer fits.

Why Mildot Group?

Built on Experience. Focused on Capability.

Mildot Group helps individuals and organisations build practical capability through professional learning, capability evaluations, premium publications and specialist consultancy. Every solution is designed to bridge the gap between theory and practical application, helping people and organisations perform with greater confidence in real-world environments.

Our Mission

Our mission is to help individuals and organisations build practical capability through professional learning, capability evaluations, expert guidance and real-world application. Everything we create is designed to bridge the gap between theory and practice, helping people make better decisions, strengthen resilience and perform with confidence.

Our Philosophy

We believe capability is developed through structured learning, practical application and continuous improvement, not simply by completing a course or meeting a compliance requirement. Every learning programme, capability evaluation, publication and consultancy engagement is designed to help individuals and organisations apply knowledge with confidence in real-world environments.

What Makes Mildot Group Different?

Real Operational Experience
Built on experience gained across military, corporate and international environments.

Practical Learning
Professional learning designed to develop skills that can be applied immediately.

Capability Focused
Building practical capability rather than simply delivering awareness or compliance.

Evidence-Based
Combining operational experience with research, proven frameworks and practical methods.

Individuals & Organisations
Supporting personal development, professional capability and organisational performance.

Continuous Development
A growing platform with new learning programmes, evaluations and professional publications added regularly.

Privacy Preference Center