Martyn’s Law: What It Means for Your Venue

He entered the City Room foyer, the public area connecting the arena to Victoria station, where parents were gathering to collect their children from the Ariana Grande concert. Security staff saw him. British Transport Police community support officers saw him. Nobody challenged him. Nobody searched his bag.
He waited in the crowd. At 22:31, as thousands of people, many of them children and teenagers, began to leave the arena, the attacker detonated the device.
Twenty-two people were killed. Over a thousand were injured. It was the deadliest terrorist attack in the United Kingdom since the 7 July 2005 London bombings. The bomb went off in an unsecured public space, where nobody was legally required to have a plan for what to do if it happened.
One of those killed was Martyn Hett. He was 29. His mother, Figen Murray, spent the next six years of her life campaigning for a legal obligation: that venues should be required by law to always have protective security plans and measures in place. On the 7th May 2024, Figen started walking from the exact place where Martyn died in Manchester to Downing Street, arriving on the 22nd May, seven years to the day of her son's anniversary, to push for the legislation. On 3 April 2025, the Terrorism (Protection of Premises) Act 2025 finally received Royal Assent. It is known as Martyn's Law, named after her son. It is expected to come into force in April 2027, and preparations by public premises and venues are being made.
The Home Office estimates that around 180,000 premises across the United Kingdom will fall within scope of the new Act.
There are two tiers of obligation, based on how many people may be present at the premises at any one time.
Standard tier applies to premises where between 200 and 799 people may be present at any one time. The obligations are procedural: written plans for how the venue would respond to an attack. The cost is low. Most venues can handle this without outside help.
Enhanced tier applies at 800 people and above. The obligations are significantly greater. The venue must put physical protective measures in place, submit documentation to the regulator, and appoint a named senior individual who carries personal criminal exposure for how the venue meets its obligations.
That is the split. This Grey Prism Insight document explains what each tier involves, who it affects, and what needs to happen before enforcement begins.
Grey Prism has been preparing clients for these obligations since the Bill entered Parliament. The sections below cover scope, tier obligations, outdoor events, the Designated Senior Individual (DSI) role, information security, aerial monitoring, SIA submissions, and preparation steps.
Does this affect my venue?
The Act applies to any premises with a building where 200 or more people may be present from time to time. Here is a rough guide.
If you are not sure, count everyone who could be on site at peak occupancy. Staff, contractors, volunteers, visitors, performers. If the total crosses 200, you are likely in scope. If it crosses 800, the obligations change significantly.
Standard tier: what the Act requires of smaller venues
Standard tier applies to premises where 200 to 799 people may be present from time to time. That total includes everyone: public, staff, contractors, volunteers.
Who is the responsible person?
The responsible person is whoever controls the premises. For a pub, that is usually the licensee or the operator. This can be one person for a large organisation. For a hotel, it is the management company. For a church, it is the governing body: the PCC, the board of trustees, or equivalent. The responsible person must register with the Security Industry Authority and is accountable for compliance.
What do they actually have to do?
Put written procedures in place for four scenarios. To assist, the government's own counter-terrorism platform (protectuk.police.uk/martyns-law) provides free templates, guidance documents, and e-learning. The Home Office has been explicit that standard tier venues should be able to comply using these resources without spending money on consultants.
Do they need to buy anything? Hire anyone? Install anything?
No. Standard tier does not require physical security measures. No barriers, no scanners, no CCTV upgrades. The obligation is about plans, procedures, and training. The Home Office estimates the cost at around £330 per year, for staff time, not cash expenditure.
What does 'reasonably practicable' mean?
It means proportionate. A pub with 220 people is not expected to have airport-style security. It is expected to have a written plan that makes sense for its size, layout, and resources. If something goes wrong and the SIA investigates, the question is: did you do what a reasonable operator in your position would have done? If the answer is yes, the plan was good enough.
How often should the plan be reviewed?
The Act does not prescribe a review cycle. The procedures should be reviewed when something changes: a new layout, new staff, a new event programme. At minimum, an annual review is sensible.
How does someone actually start?
- Step one: know how many people are able to be on the premises at the busiest time, including staff.
- Step two: register with the SIA as the responsible person.
- Step three: write down the four procedures.
- Step four: make sure staff know the plan exists and what to do.
- Step five: review it periodically.
That is the core of standard tier compliance.
Enhanced tier: what changes at 800 people
Enhanced tier applies to premises where 800 or more people may be present from time to time. The obligations are different in kind, not just degree.
Enhanced tier premises must do everything standard tier premises do: written procedures for evacuation, invacuation, lockdown, and communication. On top of those, the Act requires four additional categories of protective measures.
What those measures look like in practice depends entirely on the venue. The Act does not prescribe specific equipment or staffing. A theatre and a stadium will reach very different conclusions from the same process, and both can be compliant. What matters is that the venue has honestly assessed its exposure, decided what is proportionate, and can explain that reasoning.
The Security Industry Authority, known as the SIA, is an independent regulator appointed by the government to oversee Martyn's Law. It has significant powers to inspect premises, issue compliance notices, impose penalties, and in serious cases pursue criminal prosecution. If an incident occurs, the submission becomes the primary evidence of whether the duty holder met their obligations.
The venue must document all of this, explain why it chose the measures it chose, and submit the documentation to the SIA. The estimated annual cost is £5,210 per premises, though this will vary significantly depending on existing security posture and the conclusions of the vulnerability assessment.
A Designated Senior Individual must be appointed: a director, partner, or governing body member who carries personal criminal liability. The standard is 'reasonably practicable,' but at this tier it is judged with hindsight. The question after an incident is not 'did you follow a checklist?' It is 'could you explain why you did what you did, and why you did not do more?'

Which venues are in scope, and how does the "from time to time" threshold work?
The Act applies to premises where 200 or more individuals are present 'from time to time.' This is not average attendance. It is maximum reasonable occupancy, and it counts everyone: members of the public, staff, contractors, volunteers, visiting engineers. Everyone on site.
A restaurant with 150 seats and 60 staff. The public never exceed 150. But total occupancy hits 210. That restaurant is in scope at standard tier.
A conference centre that regularly hosts events for 750 delegates but adds 40 staff and a dozen speakers. Total occupancy crosses 800. That venue is enhanced tier, with all the obligations that follow.
Edge cases will be common. The statutory guidance, when it arrives, should clarify some of these situations. Until then, organisations near a threshold boundary should work through the analysis now rather than wait.
Outdoor venues, events without buildings, and travelling events
The Act requires premises to have at least one building. Open-air venues without any permanent structure sit outside the definition of qualifying premises. A park, a field, open common land: none of these qualify on their own.
Sports grounds and outdoor venues with permanent structures (stands, hospitality areas, facilities buildings) qualify as premises in the normal way. The tier is determined by peak occupancy across all uses, not just match days or headline events.
The events route
For events held at open-air locations without a qualifying building, the events route applies. A ticketed, publicly accessible event where 800 or more people are present at the same time is a qualifying event with full enhanced tier obligations. The responsible person is whoever has control of the site for the purposes of the event, not the landowner, unless they retain that control themselves.
For the events route to apply, the event must require express permission to enter: a ticket, an invitation, or a pass. Events that anyone can walk into freely, without any form of entry control, fall outside the qualifying event definition regardless of how many people attend.
Two areas remain unresolved pending the statutory guidance due in Summer 2026. Whether a temporary structure such as a large marquee constitutes a building under the Act is one. The boundary around express permission is another. A Christmas market in a town square, open to all with no express permission required, falls entirely outside the Act. The same market inside a marquee where entry requires a wristband, with 800 people inside at the same time, is a qualifying event with full enhanced tier obligations. The difference is a canvas wall and a ticket.
Drones, aerial threats, and the Act's monitoring requirement
For those responsible for large outdoor events, the Act's requirement to monitor the premises and their immediate vicinity deserves particular attention. At an open-air site, that vicinity has no natural boundary.
Drones have been used for surveillance of public events, payload delivery, and disruption of airspace above crowded places. This is operational reality, documented and growing. A venue with an outdoor or elevated threat profile that considers only the horizontal plane has addressed only part of what the monitoring requirement demands. Under the reasonably practicable standard, assessed with hindsight after an incident, that gap becomes difficult to explain.
As part of the protective security service Grey Prism provides, aerial intelligence and counter-UAS capability addresses exactly this obligation. For enhanced tier venues and events where the threat profile extends beyond ground level, it forms part of a broader assessment and response that considers the full threat environment, ground level and above.

How does Martyn's Law apply to shopping centres, campuses, and multi-occupancy premises?
When an incident occurs in a large, multi-occupancy building, an effective response depends on every part of it moving in the same direction. Where procedures are uncoordinated and work in isolation, they often fail, or worse, cause harm. Martyn's Law recognises this.
A large shopping centre with dozens of shops and restaurants, a university campus spread across multiple buildings, a mixed-use development where residents, offices, and leisure facilities share the same entrances and corridors. All of them face the same underlying challenge. When something happens, it happens to the whole site. The response has to match.
The Act places the coordination obligation on the enhanced tier responsible person. In a shopping centre, that is typically the centre management company, and their procedures must account for every occupier and shared space, from the car park to the independent coffee shop on the food court.
In some complexes, there may be tenants who are qualifying premises in their own right. A large department store with 800 or more people across its floors carries its own enhanced tier obligations independently, with its own DSI and its own SIA submission. It remains the shopping centre's responsibility to make sure coordination works across the whole site.
The same is true of university campuses, hospital complexes, and mixed-use developments. The stakeholders differ. The coordination obligation does not.
Getting this right means every tenant and occupier understands their role, and that understanding is negotiated and documented by the primary enhanced tier responsible person before the SIA comes to assess it.
Grey Prism's team brings operational experience from environments where coordination has saved lives. That background informs how we approach multi-occupancy sites, assessing how procedures interact across a complex, identifying where they break down under pressure, and producing documentation that reflects how a building would actually function in a crisis, rather than how it looks on a plan.

Who is the Designated Senior Individual (DSI) and what is their personal liability?
Where the responsible person for enhanced tier premises is a company or organisation, the Act requires a Designated Senior Individual to be named. The DSI must be a director, partner, or member of the governing body, a person at the top of the organisation who can be held to account.
The DSI carries personal criminal liability. If the SIA finds the premises non-compliant, and determines that the non-compliance occurred with the DSI's consent, connivance, or neglect, the DSI faces prosecution as an individual. That liability sits with the named person, alongside whatever liability the organisation itself carries under the Act.
Think about what that means in practice. The DSI signs off the vulnerability assessment. The DSI approves the SIA submission. The DSI is the person whose name appears on the regulatory record. If there is an incident, and the subsequent investigation finds the protective security measures were inadequate, the DSI is the person interviewed. The quality of the work done before that moment determines whether they are protected or exposed.
The Act is specific about who can hold the role. The DSI must be someone who manages the affairs of the responsible person as a whole. For a large organisation operating multiple enhanced tier sites, that means one person at the top of the entire organisation. A pub chain with qualifying premises across the country has a single DSI. A retail group with enhanced tier stores in every major city has a single DSI.
Many boards will not yet have discussed the DSI appointment in any depth. With less than a year before enforcement begins, the governance implications deserve serious attention. The person who accepts this role is accepting personal criminal exposure for the quality of work that may not yet have been done. That conversation sits alongside directors' and officers' liability, fiduciary duties, and corporate risk appetite.
What is the information security requirement under Martyn's Law?
A stadium commissions a vulnerability assessment. The report identifies entry points, crowd flow weaknesses, blind spots in camera coverage, and the response time of on-site security. It names the areas where a person could cause maximum harm. It is a document that describes, in detail, how to attack the venue.
That document is emailed to the facilities team. It is stored on a shared drive accessible to dozens of people. It is discussed in a meeting with contractors who have their own IT systems. Extracts are included in the SIA submission. At every stage, the information is moving through systems that were never designed to protect it.
The Act requires enhanced tier premises to protect information that could assist in the planning or execution of an attack. The obligation is clear: if a document describes your vulnerabilities, the way that document is created, stored, shared, and discussed is itself a security question.
In practice, this means asking a set of simple questions before any vulnerability assessment is even written. Where will the document be stored? Who will have access? How will it be transmitted to contractors, to the SIA, to the landlord in a multi-occupancy coordination? Will it be discussed in a meeting room that has been checked for listening devices? If the answer to any of these is that it has not been thought about, then this obligation has not been addressed.
Technical Surveillance Countermeasures, known as TSCM, directly address this. TSCM covers the detection of covert listening devices, the security of meeting environments where sensitive plans are discussed, and the protection of electronic communications carrying protective security information. The connection between TSCM and Martyn's Law has not been made anywhere else in the market. The logic is straightforward: if the Act requires you to protect information about how to attack a venue, then the environments where that information is created, stored, and discussed need to be secure. Grey Prism provides TSCM capability as part of its Martyn's Law advisory work.
Drones, aerial threats, and the Act's monitoring requirement
Keeping watch over a venue and its immediate vicinity sounds straightforward. For most enhanced tier premises it is — cameras, patrols, controlled entry points, all proportionate to the site and the threat. For stadiums, festival sites, and large outdoor venues, the picture is more complex.
Drones have conducted pre-attack reconnaissance at major public events. They have been used to map security deployments, identify crowd concentrations, and probe perimeter responses. They have delivered payloads and forced the closure of airspace above crowded sites. The technology is cheap, accessible, and increasingly sophisticated. For a venue with an open-air profile, the airspace above the site is as much a part of the immediate vicinity as the car park.
The reasonably practicable standard requires a venue to assess its actual threat environment and respond proportionately. For venues where the aerial dimension is real, that assessment needs to include it. As part of the protective security service Grey Prism provides, aerial intelligence and counter-UAS capability addresses exactly this obligation. For enhanced tier venues where the threat extends beyond ground level, it sits within a broader assessment that covers the full environment.
What makes an SIA submission defensible?
The SIA expects enhanced tier duty holders to submit documented procedures and measures, with full reasoning of what was done and why.
A defensible submission starts with an honest vulnerability assessment that identifies real weaknesses and describes them plainly. From that assessment, the duty holder applies the reasonably practicable standard: here is what we identified, here is what we did about it, here is what we considered but rejected, and here is why. That reasoning is the core of the submission. It is what separates a document that protects the DSI from one that exposes them.
The penalties for getting it wrong are significant. The Act provides for fines up to £18 million or 5% of qualifying revenue, whichever is greater. Daily penalties of up to £50,000 for ongoing non-compliance. Restriction notices that can limit or shut down operations. And criminal liability for the DSI where the non-compliance involved their consent, connivance, or neglect.
What enhanced tier duty holders should do before enforcement begins in 2027
The statutory guidance has not arrived. The SIA has said it will come in Summer 2026. Enforcement begins no earlier than April 2027. That sounds like time. It is not, if the work has not started.
Martyn's Law is an Act that will affect 180,000 venues across the UK, with an estimated 25,000 enhanced tier premises in scope. There is significant complexity beneath the Act's words.
Just some examples: multi-occupancy coordination with no prescribed mechanism. Capacity thresholds that catch venues that do not expect to be in scope. Information security obligations the market has not connected to countermeasures. Monitoring requirements that extend into airspace. SIA submissions that must be defensible, not just complete.
Stadiums, arenas, shopping centres, festivals, universities, places of worship. Somewhere in each of those organisations, a named individual will carry personal criminal exposure for the quality of the work done between now and enforcement.
Laura Gibb, the SIA's Executive Director for Martyn's Law, said in March 2026 that 'no one can offer a full informed or accurate compliance solution' while statutory guidance remains unpublished. She is right. The statutory guidance will explain the requirements. It will not conduct your vulnerability assessment, coordinate your tenants, or produce a submission that protects your DSI. That work is specific to your premises, your people, and your circumstances. April 2027 is just a year away.
.webp)



.webp)