Martyn’s Law: What Building Managers Must Do Before Spring 2027

The Terrorism (Protection of Premises) Act 2025, known as Martyn’s Law, received Royal Assent on 3 April 2025. The Government has committed to an implementation period of at least 24 months before the Act comes into force, meaning commencement is expected from Spring 2027. That window is intended to give those responsible for qualifying premises time to understand their obligations and prepare, and the sensible time to start is now.

This post sets out what the law requires, who is in scope, what the Standard and Enhanced tiers mean in practice, and where physical security systems fit, including what the Act does not require, which matters just as much.

What is Martyn’s Law and why does it exist?

It is legislation requiring those responsible for qualifying public premises to prepare for terrorist threats consistently, rather than leaving preparedness to individual judgement. The Act is named after Martyn Hett, one of the 22 people killed in the Manchester Arena attack in May 2017. His mother, Figen Murray, campaigned for years for this legislation, and the Act is the answer to that campaign.

It places a legal duty on those responsible for qualifying premises to consider how they would respond to a terrorist attack and, at larger premises, to consider appropriate steps to reduce vulnerability. A new regulatory function is being established within the Security Industry Authority (SIA), which will support, advise and guide duty holders, with enforcement powers (including compliance notices and monetary penalties) reserved for serious or persistent non-compliance.

Is your building in scope?

It is if four criteria are met. The site meets the Act’s definition of premises. It is wholly or mainly used for one of the public-facing uses listed in Schedule 1 (shops, restaurants, offices, education, healthcare, hospitality, venues and more). It is reasonable to expect that at least 200 individuals, including staff, may be present at the same time, from time to time. And the premises are not excluded under Schedule 2.

The threshold is based on the number of individuals it is reasonable to expect may be present at the same time, not average footfall. If your building can reasonably be expected to accommodate 200 people on occasion (a Christmas event, a large meeting, a busy trading period), you are likely in scope. The Home Office has published a supplementary document on assessment methods, which include approaches many building managers already know, such as the safe-occupancy calculations used for fire safety.

What does the Standard Tier require (200 to 799 individuals)?

Two things: notifying the SIA of the premises, and having in place, so far as reasonably practicable, appropriate public protection procedures covering evacuation, invacuation (moving people to safety inside the building), lockdown, and communication with people on the premises. Every qualifying premises already has a responsible person under the Act: the person or organisation in control of the premises for its Schedule 1 use. They do not appoint themselves. The task is to identify the responsible person and ensure the required procedures are in place. The Home Office describes these requirements as centred on simple, low-cost activities, with costs relating primarily to time spent. No specific equipment is mandated, though in practice many organisations will find their existing door controls, CCTV and PA systems useful in making those procedures workable.

What does the Enhanced Tier add (800 or more individuals)?

Three things on top of the Standard Tier requirements. Enhanced premises must have in place, so far as reasonably practicable, public protection measures that could reduce both the premises’ vulnerability to an attack and the risk of harm if one occurred; the Home Office gives monitoring of the premises and their immediate vicinity as an example. The procedures and measures must be documented and provided to the SIA, including an assessment of how they reduce vulnerability or risk. And where the responsible person is an organisation rather than an individual, a senior individual must be designated with responsibility for compliance.

Where do physical security systems fit, and what does the Act not require?

The Act mandates no specific technology, and neither the Home Office nor the SIA endorses any third-party product in respect of compliance. Premises also do not need to spend money on consultants to comply. What the Act requires are reasonably practicable procedures and, at Enhanced Tier, reasonably practicable measures. That said, procedures have to work in practice, and three system areas are where most buildings will look when assessing theirs.

Access control. Lockdown is one of the four named procedure areas. Modern access control platforms, such as Salto or Gallagher (named purely as examples), can support this with the ability to secure entry points quickly from a central point. Legacy arrangements that rely on physically key-locking individual doors may make it more difficult to implement effective lockdown procedures where these are identified as reasonably practicable.

CCTV. At Enhanced Tier, monitoring of the premises and their vicinity is the Home Office’s own example of a public protection measure. Where CCTV forms part of a premises’ protective measures, organisations should be able to demonstrate that it supports their wider security procedures: how it is used, by whom, and how it connects to the response plan.

Evacuation and communication systems. Invacuation and lockdown are scenarios where the right instruction is emphatically not “leave the building”, and communication with people on the premises is itself one of the four required procedure areas. Many organisations may conclude that a voice alarm system provides clearer communication than a conventional alarm tone during a terrorist incident, since spoken, zone-specific messages can distinguish between “evacuate” and “stay inside” where a tone cannot. The Act does not require voice alarm. It requires communication procedures that work.

What should you do now?

Start with a premises assessment. Confirm whether you meet the four scope criteria and which tier applies, identify the responsible person, review your evacuation, invacuation, lockdown and communication procedures against how they would actually operate, and, at Enhanced Tier, consider what documented measures are reasonably practicable for your premises. The Home Office published statutory guidance under section 27 of the Act on 15 April 2026, and the SIA has separately published draft section 12 guidance for public consultation, covering how it will discharge its regulatory functions. There is no legal requirement to comply until the Act comes into force, but the Government’s stated intent is that those in scope use the implementation period to prepare.

One further point is worth planning for. At Enhanced Tier, documentation is a legal requirement, and at any tier, a regulator’s first question will be evidential: show us that your procedures, and the systems underneath them, are real and maintained. Where those systems (access control, CCTV, voice alarm) are maintained by Smartec, every asset already sits in the Client Portal with its full maintenance history in a tamper-proof Digital Logbook, so demonstrating that your lockdown capability or monitoring provision actually works is a download, not a scramble.

Smartec works with those responsible for commercial, healthcare, education and mixed-use premises on the systems that sit underneath these procedures. If reviewing your current capability against your Martyn’s Law procedures would be useful, our team is happy to help, and equally happy to point you to the free Home Office guidance and ProtectUK resources, which are the right first stop for any duty holder.

Scroll to Top