Resources · Compliance
Martyn’s Law in the United Kingdom: duties, tiers, notification and records
Martyn’s Law is the Terrorism (Protection of Premises) Act 2025, a United Kingdom statute requiring those responsible for qualifying premises and qualifying events to put public protection procedures in place, notify the regulator, and, at enhanced tier, document what they have done. The main duties are not yet in force.
It sits in a glossary of quality and compliance records for one reason. Like every other duty in that set, it rests on the fact that doing the thing and being able to prove you did it are two different achievements, and only the record survives to be examined.
This page covers duties, tiers, notification and records, not security guidance; for that, go to ProtectUK and the regulator’s GOV.UK guidance.
What is Martyn’s Law, and who does it apply to?
The Terrorism (Protection of Premises) Act 2025, chapter 10, received Royal Assent on 3 April 2025. It is known as Martyn’s Law in recognition of Martyn Hett, one of the 22 people killed in the Manchester Arena attack in 2017. The Act applies across the United Kingdom and requires those with control of certain premises and events to take steps to reduce the risk of physical harm arising from acts of terrorism, and, for larger premises and all qualifying events, to reduce vulnerability to such acts.
It does not apply to every building the public can enter. It reaches premises wholly or mainly used for one of the purposes listed in Schedule 1, covering uses such as retail, hospitality, leisure, places of worship, healthcare, education and transport. The regulator is the Security Industry Authority, not the police and not the fire service.
Why the record, and not the intention, is what gets tested
What the Act does to the evidence layer is visible in its verbs: in place, assessed, kept under review, stated, provided to the regulator, revised within 30 days. Compliance therefore has a version history. The Act does not ask an enhanced tier duty holder what it plans to do; it asks what was in place, what the organisation judged that would achieve, and when the answer last changed.
Two organisations can hold identical procedures and reach opposite outcomes under scrutiny, because one can show what was in place on a given date and the other can only show what is in place today. A compliance document with no history answers the wrong question, because what an incident or an inspection asks is what was in force at the time.
The organisations that will struggle are not the ones without procedures. They are the ones that cannot reconstruct a dated position from their own records. That is the same failure that makes a late reported claim expensive: the general record is intact and the particular record, the one covering the day in question, is gone.
Standard tier carries the same exposure by a different route. The duty to have appropriate procedures applies without a duty to write them down, leaving the duty holder to evidence it from whatever incidental traces exist: training registers, briefing notes, rota records. A duty that must be demonstrated but need not be documented still has to be evidenced somehow.
Everything below is the detail of which duty falls where. The test to apply to all of it is the same one: would this record let someone establish, two years later, what the position was on a particular day?
Which premises and events are in scope, and at which tier?
Three categories, one capacity test and one exclusion list. The headcount includes staff, not only members of the public, as the Home Office overarching factsheet confirms.
| Category | Test | Duties |
|---|---|---|
| Standard duty premises | Schedule 1 use, and 200 to 799 individuals reasonably expected to be present at the same time (section 2) | Public protection procedures under section 5, and notification |
| Enhanced duty premises | Schedule 1 use, and 800 or more individuals reasonably expected at the same time | Sections 5 and 6, plus the section 7 document and notification |
| Qualifying events | 800 or more expected, public access, and entry checked by payment, ticket, pass or membership (section 3) | As enhanced duty premises |
| Excluded premises and events | Listed in Schedule 2 | Outside the regime even where the capacity test is met |
Access control is what turns a large gathering into a qualifying event, so an open gathering with no ticketing or membership check is not one.
The duty follows control rather than ownership. Under section 4 a person is responsible for qualifying premises if they have control of them in connection with the relevant Schedule 1 use, and responsible for an event if they will have control of the premises at which it is held. Where more than one person has relevant control, section 8 requires them to coordinate and cooperate. Where the responsible person is a body rather than an individual, and the premises are enhanced duty premises or the event is a qualifying event, section 10 requires it to designate a senior individual concerned in its management or control to ensure compliance. That designation is itself a dated record an organisation should be able to produce on request.
What is the notification duty, and how long do you get?
Section 9 requires a person who becomes responsible, or ceases to be responsible, for qualifying premises or a qualifying event to notify the Security Industry Authority, and to notify the regulator again if information already given stops being accurate.
The timings sit in the Notification Requirements Regulations 2026, made on 9 July 2026. For qualifying premises, notification must be given before the end of the period of three months beginning with commencement day, or, if later, 28 days beginning with the day the person becomes a responsible person. For qualifying events the window is 14 days, beginning with commencement day where the event has already been publicised, or with the day publicity first occurred. Corrections to information that has become inaccurate must be made within 28 days for premises and 14 days for events.
Notification is therefore not a single act at go live. It is a register entry with a change duty attached, and an organisation that reorganises its estate or changes who holds control of a site starts a 28 day clock without anyone sending it a reminder.
The regulator is building an online portal for notification. It has said that from early 2027 it will invite volunteers to help test the portal before launch, so early 2027 is the start of testing rather than the date the portal becomes available.
What must enhanced tier duty holders document?
This is where the Act becomes a records regime rather than a planning exercise.
Section 5 applies to both tiers. It requires the responsible person, so far as is reasonably practicable, to ensure appropriate public protection procedures are in place: procedures for evacuation, for moving people to a place of less risk, for preventing entry or exit, and for providing information to those present.
Section 6 applies only to enhanced duty premises and qualifying events. It requires the responsible person to assess and keep under review the appropriate public protection measures, and, so far as is reasonably practicable, to ensure such measures are in place. Those measures relate to monitoring, the movement of individuals, physical safety and security, and the security of information.
Section 7 then requires a document, again only at enhanced tier and for qualifying events. It must contain a statement of the procedures in place under section 5 and an assessment of how they may be expected to reduce the risk, a statement of the measures in place or proposed under section 6 and an assessment of how they may be expected to reduce vulnerability and risk, and any further information specified in regulations. A copy must go to the Security Industry Authority as soon as is reasonably practicable after it is prepared, and, if it is revised, before the end of the period of 30 days beginning with the day of its revision.
There is no equivalent documenting duty at standard tier. Section 7 does not reach standard duty premises, and the Home Office guidance does not impose one.
What evidence demonstrates compliance, and what should be kept?
The Act names one artefact, the section 7 document, and is silent on the rest. What follows is a reading of what the duties imply, not a list published by the Home Office.
The section 7 document is the primary record at enhanced tier, and every version of it matters, not only the current one. Around it sit the ordinary traces of the duties operating: any record that the people expected to follow the procedures know what they are, who held the designated senior individual role and from when, whether the section 6 assessment was revisited rather than written once, and the notification correspondence with the regulator.
Each of those needs a date and an author, or it is worth very little. An undated procedure document proves that something was written, not that anything was in place.
How should changes to procedures be recorded and reviewed?
The Act sets two fixed clocks and one open one. The fixed clocks are the 30 days in section 7 for giving the regulator a revised document, and the 28 days in the 2026 Regulations for correcting notified information that has become inaccurate. The open clock is the section 6 duty to keep measures under review, which has no stated interval and must be given one by the organisation itself.
A review with no recorded date and no recorded outcome is indistinguishable, in evidence, from a review that never happened. That is where a change to a procedure stops being an operational matter and becomes a records matter: something changed, someone decided it, the effect was assessed, the regulator may need the new version within 30 days, and the previous version must remain retrievable. Superseding a document is not the same as deleting it.
When do the duties actually bite?
Not yet, and the position should be checked rather than assumed, because no date has been fixed in regulations.
The Act received Royal Assent on 3 April 2025. The Home Office has said the implementation period will be at least 24 months from that date, and its statutory guidance states there is no legal requirement to comply until the legislation comes into force. Some provisions have been commenced: the Commencement No. 2 Regulations 2026, made on 10 June 2026, brought section 12(2)(a), (b) and (3) and section 18(5) to (7) into force on 15 June 2026, switching on the regulator’s guidance functions rather than the duties on premises.
The Security Industry Authority states that the Act is expected to come into force in spring 2027. As at 16 September 2026 that is an expectation and not an appointed day. When commencement regulations are made, the three month notification window runs from commencement day.
Timing matters because the penalties are substantial: section 18 sets a maximum non-compliance penalty of £10,000 for standard duty premises, and the greater of £18 million or 5% of qualifying worldwide revenue for enhanced duty premises and qualifying events.
Where the guidance is still developing
As at 16 September 2026, three things are unfinished and should be tracked rather than designed around.
The Home Office published its section 27 statutory guidance on 15 April 2026 and updated it on 25 August 2026, so it is reliable but still being revised. The Security Industry Authority consulted on its draft section 12 guidance between 15 April and 12 June 2026 and has not given a date for the final version, saying only that it will publish nearer to commencement, so the regulator’s account of how it will inspect and enforce is not yet settled. Neither body has published document templates, though the regulator has said it will share them before Martyn’s Law comes into effect.
Anyone reading a Martyn’s Law page written before spring 2026 should check its date, because the statutory guidance, the notification regulations and the regulator’s draft guidance all postdate it.
Frequently asked questions
What is Martyn’s Law, and who does it apply to?
The Terrorism (Protection of Premises) Act 2025, chapter 10, received Royal Assent on 3 April 2025. It is known as Martyn’s Law in recognition of Martyn Hett, one of the 22 people killed in the Manchester Arena attack in 2017.
Which premises and events are in scope, and at which tier?
Three categories, one capacity test and one exclusion list. The headcount includes staff, not only members of the public, as the Home Office overarching factsheet confirms.
What is the notification duty, and how long do you get?
Section 9 requires a person who becomes responsible, or ceases to be responsible, for qualifying premises or a qualifying event to notify the Security Industry Authority, and to notify the regulator again if information already given stops being accurate.
What must enhanced tier duty holders document?
This is where the Act becomes a records regime rather than a planning exercise. Section 5 applies to both tiers.
What evidence demonstrates compliance, and what should be kept?
The Act names one artefact, the section 7 document, and is silent on the rest. What follows is a reading of what the duties imply, not a list published by the Home Office.
How should changes to procedures be recorded and reviewed?
The Act sets two fixed clocks and one open one. The fixed clocks are the 30 days in section 7 for giving the regulator a revised document, and the 28 days in the 2026 Regulations for correcting notified information that has become inaccurate.
When do the duties actually bite?
Not yet, and the position should be checked rather than assumed, because no date has been fixed in regulations. The Act received Royal Assent on 3 April 2025.
Sources
- Terrorism (Protection of Premises) Act 2025 (c. 10)
- Section 2, qualifying premises and section 3, qualifying events
- Section 4, persons responsible and section 8, more than one responsible person
- Section 5, public protection procedures and section 6, public protection measures
- Section 7, documenting compliance
- Section 9, notification requirements and section 10, designating a senior individual
- Section 18, maximum amount of a non-compliance penalty
- The Terrorism (Protection of Premises) (Notification Requirements) Regulations 2026 (SI 2026/793)
- The Terrorism (Protection of Premises) Act 2025 (Commencement No. 2) Regulations 2026 (SI 2026/622)
- Terrorism (Protection of Premises) Act 2025: statutory guidance, published 15 April 2026, updated 25 August 2026
- Terrorism (Protection of Premises) Act 2025: overarching factsheet
- Understanding Martyn’s Law and the SIA’s role as regulator, published 17 July 2026
- SIA launches consultation on section 12 guidance for Martyn’s Law
- Martyn’s Law overview and what you need to know
Related terms
Last reviewed: 16 September 2026
About Logincident. Logincident is a data and software company whose configurable platform captures structured evidence at the point of work and presents it in dashboards and reports, including compliance records such as procedures, reviews and notifications. We are not a law firm or a claims handler, and nothing on this page is legal advice.