If you run a venue or stage events, act now: you have 24 months before Martyn's Law becomes enforceable. The Terrorism (Protection of Premises) Act 2025 received Royal Assent on 3 April 2025. The Home Office set a minimum implementation period and published statutory guidance on 15 April 2026, and ProtectUK has produced scope tools and supporting material. The Security Industry Authority is building a regulator, recruiting inspectors and running pilot inspections. Use the implementation window to confirm whether you fall in scope, take proportionate steps, and respond to SIA consultations and pilot offers while there is still time to influence how enforcement will work.
How do you know whether Martyn's Law applies to a premises or event
How can an organisation tell whether it's already in scope or safe to wait? The simple answer is: use the Home Office statutory guidance as the legal reference, and treat ProtectUK's tools as the practical aids they were designed to be. The statutory guidance, published on 15 April 2026 under section 27 of the Act, is the primary text for deciding which premises and events fall within the regime. ProtectUK has published infographics, animations, a one-page leaflet, a "myth buster" and "top tips" material to help duty holders work through the assessment.
Practical thresholds have been offered as rules of thumb. The British Safety Council sets out a two-tier model in plain terms, with a general threshold at premises or events expecting at least 200 people and higher requirements for those expecting 800 or more. The guidance itself doesn't reduce to a single occupancy number in every circumstance, however, and the Home Office materials and ProtectUK repeatedly emphasise that an organisation must use the statutory guidance to make the final determination where scope is contested.
Example: a community hall that usually holds 150 people but hosts a one-off festival expecting 250 would need to assess the event against the guidance, not only rely on its usual capacity. Use ProtectUK's scope animations to run through typical scenarios and then record the statutory-guidance led decision.
Nine practical steps to prepare during the implementation period
Who should take which steps and when is the operational question that now divides venue operators. Start from the legal text and work through proportionate, documented actions.
Below is the sequence that follows the Home Office statutory guidance, ProtectUK materials and the SIA's public programme.
First, confirm whether your premises or event is in scope by using the statutory guidance and ProtectUK scope tools. The guidance is the legal reference, and ProtectUK provides infographics and animations to support that assessment. If your site or event sits near the British Safety Council thresholds, treat the 200 and 800 occupancy markers as practical guides but make the final call against the Home Office guidance.
Second, identify the Responsible person and set governance arrangements. The statutory guidance and ProtectUK materials include an infographic defining the responsible person. That individual or organisation must lead the assessment and record decisions on preparedness and, where required by tier, on vulnerability reduction. Record who's accountable, how decisions will be documented, and how they will be reviewed, because inspectors will look for clear ownership.
Third, run a pragmatic preparedness and vulnerability assessment. The Act requires duty holders to consider how premises and events would respond to a terrorist attack and, for larger venues or events, to consider steps to reduce vulnerabilities.
Use the Home Office statutory guidance and ProtectUK's top tips to frame that assessment. The emphasis in the guidance is on proportionate, risk-based decisions and reasonably practicable steps rather than a universal checklist.
Fourth, produce or update written measures and plans showing proportionate protective security and response arrangements. The statutory guidance explains what compliance looks like in practice and will be the basis for what the regulator expects to review. For premises in the higher tier, expect to show evidence of vulnerability reduction measures where appropriate.
Fifth, don't assume you must buy expensive third-party compliance packages. ProtectUK and the Home Office explicitly say duty holders can comply without specialist consultants and that neither the Home Office nor the SIA endorses private-sector compliance products. Use in-house risk owners, existing safety and security teams, or mainstream professional services where necessary, but test every purchase against the statutory guidance.
Sixth, engage with the regulator-building process and seek practical testing opportunities. The Security Industry Authority is recruiting inspectors and assessors, advertising vacancies on Civil Service Jobs and highlighting roles on its LinkedIn presence, and it's running pilot inspections and webinars.
The SIA has invited organisations to help test a digital notification platform. Participating in these pilots gives early practical insight into how the regulator will operate and offers a chance to shape inspection procedures.
Seventh, prepare records and evidence for regulatory review and possible inspection. The SIA will have powers to request information and to inspect. Keep auditable records of assessments, decisions, training and any changes made to reduce vulnerabilities. The statutory emphasis is on proportionate documentation rather than paperwork for its own sake, but regulators will expect clear, retrievable records.
Eighth, build proportionate training and response capability. The statutory guidance and ProtectUK materials stress organisational preparedness and the ability to protect the public if an attack occurs. That implies basic staff training, simple response plans and rehearsed decision routes. Use ProtectUK animations and top tips to prioritise low-cost, high-impact measures before considering extensive capital works.
Ninth, monitor guidance updates and public communications channels. The Home Office, ProtectUK and the SIA will publish further detail and operational guidance as the regulator's model is finalised.
Use GOV.UK and ProtectUK as primary sources for updated statutory guidance, supporting documents and regulator consultations. Don't rely on commercial summaries alone when making compliance decisions.
Worked example: a mid-sized theatre with a usual capacity of 650 should treat itself as likely to sit in the higher tier for some obligations. It should identify a responsible person, document a vulnerability assessment using the statutory guidance, update written response plans, roll out basic staff training and keep those records ready for SIA inspection. It does not, however, need to hire a specialist compliance package simply to be able to produce a file.
Why is the regulator building process important to get involved with now? Because the law is on the statute book while the regulator's approach is still being shaped. The Security Industry Authority will be the regulator with powers to request information, inspect premises and issue compliance notices, according to SIA briefings and its public update. The SIA has launched a draft section 12 statutory guidance and opened a public consultation that closes on 12 June 2026, as it sets out how it will exercise those powers.
The planned enforcement ladder is risk-based and supportive in design. Independent explainers and sector guidance indicate the likely sequence will start with engagement and formal notices, escalate to proportionate financial penalties where breaches aren't remedied, and reserve criminal offences for the most serious or persistent failures. That model is consistent with the SIA's stated intent to use information requests, inspections and compliance notices to drive improvement, rather than immediate criminalisation of routine errors.
Organisations should therefore expect early regulatory contact, requests for records, and an expectation that they can demonstrate a proportionate assessment of risk and preparedness. Pilot inspections and user-testing of the SIA's digital platform are the immediate opportunities to see how that expectation will appear in practice. The SIA is actively recruiting participants for pilots and user-testing and is public about those opportunities on Civil Service Jobs and its LinkedIn feed.
Example: if an inspector requests a copy of a venue's vulnerability assessment and records of staff training, a duty holder who has followed the nine steps will be able to produce proportionate, dated records and explain the decisions that led to any vulnerability-reduction work. That capacity to demonstrate proportionate decision-making is what the regulator will look for first.
Related Articles
- Angular 22: Performance gains vs migration cost
- Lifetime ISA: claim the 25% bonus, avoid charges, plan for 2028
- Retrofit a 10-euro toy robot in 7 steps
Respond to the SIA's draft section 12 consultation and consider signing up for pilot inspections or user-testing of the SIA digital notifications platform.
This article was created with AI assistance.