Skip to Content

Beyond the Headlines: 5 Surprising Realities of the Terrorism (Protection of Premises) Act 2025 (Martyn's Law)

Five practical realities of Martyn's Law every responsible person, event planner, and venue operator needs to understand
22 July 2026 by
Quick answer: Martyn's Law brings scope thresholds, the Sanctuary Cap, a reasonably practicable standard, an immediate-vicinity duty, and penalties up to £18 million. Five practical realities every responsible person, event planner, and venue operator needs to understand.

Originally published on LinkedIn: 30 April 2026.

The Terrorism (Protection of Premises) Act 2025, known as Martyn's Law, requires organisations to build counter-terrorism preparedness into their core operations, with the same legal weight as fire safety. Named for Martyn Hett, one of the 22 victims of the 2017 Manchester Arena attack, the Act is the product of years of campaigning to make protective security a statutory duty rather than a voluntary good practice. Legal responsibility for compliance sits solely with the "responsible person" and cannot be delegated, even when specific security tasks are contracted out. Failure to implement reasonably practicable evacuation, invacuation, lockdown, and communication procedures exposes organisations to serious regulatory scrutiny — Enhanced Tier civil penalties run up to £18 million or 5% of global revenue, with criminal prosecution possible for senior personnel in cases of neglect.

1. The "Occasional Peak" Rule: Why Your Business Might Be in Scope

Scope is set by two tiers: Standard (200–799 people) and Enhanced (800+). A common misconception is that this is based on average daily attendance — it isn't. The Act uses the test of "from time to time": if your premises occasionally hit these numbers, during a seasonal sale, a particular night of the week, or a major televised sporting event, you are likely in scope. The count must include all staff, defined broadly to cover employees, contractors, and volunteers. Genuinely unforeseeable one-off crowds aren't captured, but predictable periodic peaks are.

2. The "Power of Hello": Customer Service as a Security Asset

Rather than relying only on hard security measures like bollards or scanners, the Act promotes the See, Check and Notify (SCaN) approach: See — recognising what's normal and staying alert to suspicious activity; Check — using the "Power of Hello," where simple, friendly customer service signals that a person has been noticed, which is often enough to deter a hostile actor; Notify — knowing how and when to escalate. The intended effect is straightforward: hostile reconnaissance gets detected, useful planning information gets denied, and the hostile actor gets deterred before anything happens.

3. The Sanctuary Cap: Why Schools and Churches Face Different Rules

Schedule 1 of the Act introduces a tier cap for certain institutions. Places of worship, childcare facilities, and primary, secondary, sixth-form, and further education settings are capped at Standard Tier regardless of how many people they host. That said, there's an important exception: universities do not receive this cap and can fall into the Enhanced Tier if they cross the 800-person threshold.

4. "Reasonably Practicable": The Law Doesn't Demand Bankruptcy

Compliance is a balancing test — the responsible person weighs the cost, time, and difficulty of a measure against how much physical harm it would actually reduce. A village hall isn't expected to install military-grade security or take on measures that would compromise staff safety or cause financial ruin. Enhanced Tier organisations that decide a measure — blast-resistant glazing, for instance — isn't reasonably practicable due to cost must document that reasoning for the SIA. The law is built to be proportionate and sustainable, not disproportionate.

5. The "Immediate Vicinity": Safety Extends Beyond the Door

A responsible person's duty doesn't stop at the threshold. The Act's definition of "premises" includes associated land, and public protection procedures must account for the immediate vicinity — areas functionally linked to the venue where crowds gather because of it. A theatre queue stretching into a public square is the clearest example: the theatre's team needs a plan for how an attack there would trigger invacuation. This doesn't extend to general street crime or passers-by — the duty is scoped to the area that provides access to the premises and where patrons actually gather.

What This Means for Event Planners and Venue Operators

For events and major venues, the practical questions are the same but higher-stakes. Tier is set by expected attendance "at the same time," calculated from ticket sales, historic data, or safe occupancy figures, and includes staff and contractors. Responsibility usually sits with whoever controls the premises for the event — if a qualifying event (800+) happens on a site not already in Enhanced Tier, such as a park or private field, the organiser typically becomes the responsible person for its duration, and site and organiser must coordinate so procedures don't conflict. Enhanced Tier events carry extra obligations: monitoring (CCTV, patrols), movement control (bag searches, screening), physical security (bollards, blast-resistant glazing), information security, a compliance document submitted to the SIA, and a designated Senior Individual overseeing compliance. Training isn't mandated to a specific standard, but staff must be competent — free resources include ACT Awareness e-learning, ACT Security training for frontline operatives, and SCaN training for spotting hostile reconnaissance. The SIA can inspect events, usually with 72 hours' notice, and enforcement ranges from £10,000 civil penalties at Standard Tier up to £18 million or 5% of global revenue at Enhanced Tier, with criminal prosecution reserved for serious non-compliance.

A 24-Month Window for a Safer Future

Organisations have 24 months from Royal Assent to establish their roles, designate a Senior Individual where required, and notify the SIA. Preparedness ultimately comes down to whether everyone — from the board to the frontline volunteer — knows their role in an evacuation, invacuation, lockdown, or communication response. If an incident happened outside your doors tomorrow, would your team know whether to run, hide, tell, or simply say hello?

Tony Ridley, MSc CSyP FSyI SRMCP, is a Chief Security & Risk Advisor with over 30 years of enterprise risk governance experience across critical infrastructure, capital programs, Australian Defence Force service, and international advisory through EMA Global. Organisations uncertain of their tier, responsible-person designation, or compliance-document readiness under Martyn's Law should get an independent gap assessment before the 24-month window closes — contact Tony Ridley to scope a protect-duty compliance review.

The 2026 Travel Map is Being Redrawn: 5 Crucial Realities from the EMEA Risk Forecast
The Strait of Hormuz closure, EASA restrictions, and Russian hybrid attacks have pushed EMEA travel risk into emergency-protocol territory