Skip to main content

Article

Martyn’s Law: new UK guidance clarifies expectations ahead of the Terrorism (Protection of Premises) Act 2025

New UK guidance on Martyn’s Law clarifies scope, duties, and compliance. See what the Terrorism Protection of Premises Act 2025 means now.

The UK Government has published key statutory guidance under the Terrorism (Protection of Premises) Act 2025 – known as Martyn's law. The Act received royal assent on 3 April 2025. It is expected to come into force in spring 2027. It will require many publicly accessible premises and certain events to take proportionate steps to reduce the risk of physical harm from terrorist incidents and terrorist attacks.

The new guidance gives organisations clearer direction on how the duty is expected to work in practice. This includes whether they are in scope, who is accountable, and what proportionate measures may look like in real settings. The Home Office published the statutory guidance on 15 April 2026. It includes decision trees, compliance steps, and other detailed information. It also addresses misconceptions and provides further information on how the duty should be applied.

The law is named after Martyn Hett. Many people continue to pay tribute to him, to Martyn's mother, and to others affected by the horrific Manchester arena attack.

Why this matters now

Although the duty is not yet in force, organisations can now move from general awareness to practical planning, as the guidance has been published, and the regulator has been identified.

For many organisations, this will not be only a security or facilities issue. It may affect board accountability, operations, supplier oversight, and reputation.

The Act marks a significant milestone in UK legislation. It turns counter terrorism planning into a clearer statutory obligation. It also creates new obligations for parts of the private sector, with wider implications for claims trends and insurance planning. There will be an implementation period before enforcement, which should give organisations sufficient time to prepare.

What the statutory guidance covers (at a glance)

The Home Office guidance explains how the duty will apply to qualifying premises and qualifying events. It covers:

  • Definitions: what counts as a qualifying premises or event within the act's scope
  • Tiering: the standard tier and enhanced tier framework using a tiered approach
  • Capacity thresholds: standard tier premises are generally those with a capacity of 200 to 799, while enhanced tier premises are those with a capacity of 800 or more
  • Accountability: how to identify the organisation’s responsible person and who is responsible for premises
  • Complex operating models: how the duty may apply where several organisations operate at one site or event
  • Regulator engagement: duties to inform, cooperate, and respond appropriately as part of the SIA’s regulatory function

A key message runs through the guidance. Examples are illustrative, not final answers. Organisations must consider the specific circumstances of their own premises or events. This fits with the Act’s focus on what is reasonably practicable.

The guidance also makes clear that private events are excluded from the main compliance regime. That helps explain which certain premises are likely to be covered.

More broadly, the act establishes a framework for better public protection. Its purpose is to support public safety in public spaces and other public premises.

What types of organisations could be affected?

The guidance includes examples from a wide range of settings, such as:

  • Retail, including large stores and shopping centres
  • Leisure and hospitality venues
  • Healthcare sites
  • Tourist attractions and community venues
  • Outdoor events and festivals
  • Sports grounds and mass participation events
  • Conferences and ticketed events
  • Places of worship and faith-based settings

This matters because many organisations will have a portfolio of sites. Some may fall into different tiers. Some may also host events that change their risk and compliance position.

That may include smaller premises, larger premises, and certain larger premises. The right answer will depend on the use of the site, its capacity, and the scope required by the Act. The guidance points to a reasonable expectation that organisations assess each site on its own facts.

Regulator focus: what to expect 

The Security Industry Authority (SIA) has been named as the regulator for the new duty. Its published guidance, referenced in a Clyde & Co article, explains how it expects to engage with duty-holders. This includes inspection, enforcement, and sanctions for serious non-compliance.

This means organisations should be ready to comply with the legal duty and related legislative requirements. The wider material also refers to a supplementary document and a non statutory supplementary document that support the main guidance.

Practical steps to take now (before spring 2027)

Organisations can use the guidance to build a practical readiness plan. Typical next steps include:

Scope mapping

  • Identify which premises and events may meet the qualifying criteria.
  • Consider peak footfall and event “at the same time” attendance assumptions.
  • Check whether venues with a capacity of 200 or more may be in scope.
  • Review which certain premises may fall within the duty.

Governance and accountability

  • Define who will act as the responsible person.
  • Confirm internal ownership across security, FM, HR, legal, risk, and communications.
  • Clarify legal responsibility early, especially where more than one organisation is involved.
  • Good ownership will support organisational preparedness.

Proportionate risk controls

  • Review existing protective security measures and incident response arrangements.
  • Identify tier-specific gaps and reasonably practicable improvements.
  • Assess exposure to terrorist threats and other developing threats.
  • Review physical security measures, public protection procedures, and wider public protection measures.
  • Look for effective protective security without assuming every organisation must immediately spend money on major changes.
  • Consider how staff may identify suspicious behaviour and respond to incidents.

Third-party and tenant coordination

  • Where sites involve landlords, managing agents, tenants, contractors, or event partners, clarify roles, information-sharing, and escalation routes.
  • This is especially important where third party providers are involved.
  • Organisations should also think carefully before relying only on third party products.

Training, exercising, and documentation

  • Ensure policies, procedures, training, and recordkeeping are fit for inspection and supported by a strong safety culture.
  • Make sure records show decision-making and continual improvement.
  • The duty includes reviewing gaps in security and emergency procedures.
  • In practice, some organisations will face the same requirements in principle, even if the detail differs by tier.

What the guidance is really asking organisations to do

The new protect duty does not require every venue to take the same steps. It encourages organisations to take proportionate action based on their own risks.

That means what is right for smaller premises may differ from what is right for larger premises or enhanced tier premises. The guidance does not say every organisation must remove all risk. Rather, it expects venues to assess vulnerabilities and improve preparedness where needed.

In simple terms, neither the home office nor the regulator is saying that every venue must do everything at once. The aim is practical improvement, clearer ownership, and better readiness.

How Marsh can help

Marsh works with clients to strengthen resilience against evolving security risks and regulatory expectations. Support can include:

  • Premises and event risk reviews aligned to the Act’s practical requirements.
  • Scenario planning and tabletop exercises for incident response and crisis management.
  • Governance and accountability frameworks, including portfolio approaches for multi-site organisations.
  • Insurance programme review, to assess potential implications for coverage, risk information and insurer engagement as the regulatory environment develops.

If you would like to discuss how Martyn’s Law may affect your organisation, and how to plan for proportionate compliance, we can help you build a roadmap ahead of 2027.

Related insights