Protective security and compliance

Martyn’s Law: What Facilities and Property Managers Need to Know

What the Terrorism (Protection of Premises) Act 2025 means, who may be in scope and what organisations can sensibly review now.

Tornado FM Ltd Editorial Team5 min readPublished 14 July 2026
Facilities team reviewing emergency and protective security procedures for public premises

The Terrorism (Protection of Premises) Act 2025, commonly known as Martyn’s Law, establishes new requirements for certain premises and events across the UK. It is intended to improve preparedness and help reduce physical harm if a terrorist attack occurs.

The Act received Royal Assent on 3 April 2025. Home Office statutory guidance was published in April 2026. As at 14 July 2026, the substantive requirements have not yet commenced. The SIA states that the law is expected to come into force in spring 2027, and organisations do not yet need to notify the regulator.

What premises may be in scope?

A premises is not automatically in scope because it is commercial, publicly accessible or considered high risk. The statutory test considers several criteria, including the type of premises, its principal use, the number of people reasonably expected to be present and whether an exclusion applies.

The Home Office guidance states that qualifying premises generally need to be wholly or mainly used for a purpose listed in Schedule 1 to the Act and reasonably expect 200 or more people, including staff, to be present at the same time from time to time.

Standard and enhanced tiers

Certain premises have exclusions or different treatment. Qualifying events also have separate criteria. Organisations should therefore use the statutory guidance and decision tools rather than relying on headline capacity figures alone.

Who is the responsible person?

For qualifying premises, the responsible person is generally the individual or organisation with control of the premises for its relevant Schedule 1 use. This may not always be the building owner. Lease structures, management agreements and event-hire arrangements can create several parties with different areas of control.

Where there is more than one responsible person, or qualifying premises sit within other qualifying premises, the Act includes co-ordination requirements so far as reasonably practicable. Property owners, managing agents, tenants and event organisers should map responsibilities rather than assume another party is dealing with them.

What are public protection procedures?

The statutory guidance identifies four types of public protection procedure. The appropriate procedure will depend on the premises, the incident and the safest available option.

  • Evacuation – moving people out of the premises or away from a dangerous area.
  • Invacuation – moving people to a safer place within the premises.
  • Lockdown – securing the premises to control movement into or out of it.
  • Communication – alerting people to danger and providing clear instructions, where safe to do so.

Procedures must be capable of being put into effect. A document stored in an office is not enough if reception staff, security officers, managers, tenants or contractors do not understand what to do.

What additional measures apply to the enhanced tier?

Enhanced-tier premises and qualifying events will need to consider appropriate public protection measures, so far as reasonably practicable. The Act groups these around monitoring, movement, physical safety and security, and the security of information.

The responsible person must document the procedures and measures in place or planned, together with an assessment of how they are expected to reduce vulnerability or physical harm. Where the responsible person is an organisation or company, a sufficiently senior individual must be designated to ensure compliance.

What can facilities and property managers review now?

Premises should not buy generic products or training simply because they are marketed as “Martyn’s Law compliant”. The SIA, Home Office and ProtectUK do not endorse third-party products or providers that claim to guarantee compliance.

A sensible preparation programme starts with the site and the people using it.

1. Check whether the premises may fall within the Act’s scope and record the basis for the initial view.

2. Identify who controls the premises for its principal use and whether other responsible persons may exist.

3. Map occupancy patterns, including staff, visitors, tenants, contractors and event attendance.

4. Review current emergency procedures for evacuation, invacuation, lockdown and communication.

5. Check whether access control, reception, guarding and contractor-management arrangements support those procedures.

6. Confirm who can make decisions, activate procedures and communicate with people on site.

7. Review how procedures are communicated to permanent staff, temporary staff, contractors and security personnel.

8. Carry out exercises or structured walk-throughs and record lessons requiring action.

9. Maintain an action plan and monitor official implementation updates from the Home Office, SIA and ProtectUK.

The role of physical security services

A security provider cannot transfer the responsible person’s legal accountability or guarantee compliance. It may, however, support the practical operation of agreed procedures and measures.

  • Security assessments examining access, vulnerable areas and operational dependencies.
  • Manned guarding and reception security supporting access control and communication.
  • Patrols checking physical conditions, perimeter issues and unauthorised access.
  • Lock and unlock arrangements aligned with authorised opening and closing procedures.
  • Incident reporting and escalation to create a clear operational record.

The precise security role should be written into assignment instructions and co-ordinated with the customer’s emergency, fire-safety and business-continuity arrangements.

Avoid these common mistakes

  • Assuming every commercial premises is within scope.
  • Treating the threshold as the only legal test.
  • Buying a generic package before understanding the site and its responsibilities.
  • Confusing a security provider’s service with the responsible person’s legal duty.
  • Writing procedures without testing whether staff can carry them out.
  • Failing to co-ordinate with landlords, tenants, neighbouring premises or event organisers.
  • Publishing a claim that the organisation is compliant before the duties and regulator processes are fully operational.

A proportionate next step

Facilities and property managers do not need to wait until commencement to understand their premises and improve basic preparedness. The correct approach is proportionate: identify potential scope, review procedures, clarify responsibilities and address practical weaknesses that are relevant to the site.

Tornado FM Ltd provides security assessments, manned guarding, mobile patrols, keyholding, alarm response, lock and unlock services, vacant-property inspections and concierge or reception security. Any support connected with Martyn’s Law should be presented as operational security support, not a guarantee of legal compliance.

Arrange a discussion about the physical security and operational procedures at your premises.

Related Tornado FM Ltd pages

Sources and further reading

  • Home Office, Terrorism (Protection of Premises) Act 2025: Statutory Guidance, published April 2026.
  • UK Parliament / The National Archives, Terrorism (Protection of Premises) Act 2025, Royal Assent 3 April 2025.
  • Security Industry Authority, Martyn’s Law: the SIA’s new regulatory role, updated 4 June 2026.
  • ProtectUK, Martyn’s Law overview and what you need to know, published 15 April 2026.
  • ProtectUK, Martyn’s Law scope, published 15 April 2026.

Source access date: 14 July 2026.

Chat with us on WhatsApp