Published 19 September 2026
Martyn's Law splits premises into two tiers by how many people may be present: standard at 200 to 799, enhanced at 800 or more. Both tiers must notify the Security Industry Authority and have public protection procedures. Only the enhanced tier must document those procedures and hand the document to the regulator. That distinction is the one most coverage gets wrong.
The Terrorism (Protection of Premises) Act 2025 received Royal Assent on 3 April 2025, with an implementation period of at least 24 months before the requirements bite. That puts commencement at around April 2027 at the earliest. It is far enough away that nobody is panicking, and close enough that the organisations who start now will not have to.
Scope is driven by the number of individuals who may be present, not by floor area, staff headcount or turnover. That wording matters, because a venue that averages 150 people but can hold 400 is judging itself on the wrong number.
| Tier | Capacity | Core duties |
|---|---|---|
| Out of scope | Under 200 | The Act does not apply |
| Standard | 200 to 799 | Notify the SIA; have appropriate public protection procedures. No requirement for physical security measures. |
| Enhanced | 800 or more | As standard, plus appropriate measures to reduce vulnerability, plus document the procedures and measures and provide that document to the SIA. |
Less than most people assume. Standard tier premises notify the SIA that they exist, and put in place appropriate public protection procedures that could reasonably be expected to reduce the risk of physical harm if an act of terrorism occurred at or near the premises.
The official ProtectUK guidance is explicit that there is no requirement to put physical security measures in place in the standard tier. Nobody is being asked to install bollards. The emphasis is on simple, low-cost procedures that staff actually know: what to do, where to go, who to tell.
Everything above, plus two additions. Enhanced tier premises must put in place appropriate measures reducing both the vulnerability of the premises to an attack and the risk of physical harm. And they must document the public protection procedures and measures in place, or proposed to be put in place, and provide that document to the Security Industry Authority.
That is a statutory documentation duty with a named recipient. It is not a policy folder that sits on a shelf; it is a document that goes to a regulator, and by implication one that has to be kept current as the premises, the layout and the staff change.
Because the standard tier still has to have appropriate procedures, and there is a practical difference between having something and being able to show it.
A procedure that lives in one duty manager's head is not really a procedure. It cannot be trained against, it cannot be reviewed, it cannot be handed over, and it leaves the building when that person does. If the SIA, an insurer, a local authority licensing team or a corporate client asks what your procedures are, "we all know what to do" is not an answer anyone accepts.
So the honest position is this: documenting is a legal duty at enhanced tier and a practical necessity at standard tier. We would rather say that plainly than imply a requirement that does not exist.
The duties fall on the person responsible for the premises or event, broadly the person or organisation with control over them. Where a building has multiple occupiers, or an event runs in a venue somebody else owns, working out who holds the duty is one of the first questions to settle rather than one to discover later. The published Home Office factsheets are the place to confirm it for your own arrangement.
Whichever tier applies, the organisations that will find commencement straightforward are the ones who can answer four questions quickly:
None of that is exotic. It is the same problem every regulated sector has, which is why food manufacturers preparing for a BRCGS audit and NHS organisations applying retention schedules end up describing their difficulties in almost identical words. The standard differs. The records problem does not.
Two things, neither of which depends on the final guidance:
For venues in hospitality this sits alongside the records you already keep. Our guide to document management for hotels, restaurants and multi-site groups covers how those obligations tend to stack up, and a document management system is how most organisations stop them living in inboxes.
Sources: tier thresholds, the duties on each tier and the documentation requirement follow ProtectUK's Martyn's Law overview, the Terrorism (Protection of Premises) Act 2025 collection and the Home Office factsheets on gov.uk. Commencement had not been set at the time of writing.
Premises documentation is not the only duty of this shape. Workflow automation for compliance covers how the evidence gets produced without anyone chasing it, and the construction golden thread is the same obligation applied to buildings.
Not yet, and not before spring 2027. The Terrorism (Protection of Premises) Act 2025 received Royal Assent on 3 April 2025, and the government committed to an implementation period of at least 24 months before the requirements come into force. That puts the earliest realistic date at around April 2027, and it could be later. The period exists so that premises can prepare and so the Security Industry Authority can stand up as regulator.
Scope is set by how many individuals may be present. The standard tier covers premises where 200 to 799 individuals may be present. The enhanced tier covers larger premises and events where 800 or more may be present. Below 200, the Act does not apply. The figure is about the number of people who may reasonably be expected to be present, not the size of the building or the number of staff.
Two things. Notify the Security Industry Authority of the premises, and have in place appropriate public protection procedures that could reasonably be expected to reduce the risk of physical harm if an attack occurred. Importantly, there is no requirement in the standard tier to put physical security measures in place. The emphasis is on simple, low-cost procedures that the people working there actually know.
The explicit duty to document procedures and provide that document to the SIA sits in the enhanced tier, not the standard tier. That said, the standard tier still has to have appropriate procedures, and a procedure that exists only in one manager's head is difficult to evidence, difficult to train against and disappears when that person leaves. Writing it down is good practice rather than a legal requirement at standard tier.
Enhanced tier premises must also put in place appropriate measures that could reasonably be expected to reduce both the vulnerability of the premises to an act of terrorism and the risk of physical harm. On top of that, they must document the public protection procedures and measures in place, or proposed, and provide that document to the Security Industry Authority. This is a genuine, statutory documentation and notification duty.
The Security Industry Authority. The SIA is the body premises notify, the body that receives enhanced tier documentation, and the regulator that will oversee compliance once the requirements commence.
Work out your tier honestly, using the number of people who may be present rather than the number you hope for. Then get whatever procedures you already have into one place where they can be found, updated and evidenced, along with the record of who has been trained on them. Neither task depends on the final guidance, and both take longer than people expect when the information is spread across email, noticeboards and memory.
See how DocFlow holds procedures, training records and review history in one place, with version control and an audit trail, so producing them for a regulator takes a search rather than a scramble.