Free cookie consent management tool by TermsFeed
September 15, 2024
|
Analysis & Commentary

Martyn’s Law: What the Terrorism (Protection of Premises) Act Means for Facilities Managers

September 15, 2024
|
Analysis & Commentary
Download Resource;

Martyn’s Law represents one of the most significant changes to protective security requirements for UK premises and public events in recent years.

Formally known as the Terrorism (Protection of Premises) Act 2025, the legislation received Royal Assent on 3 April 2025 following years of campaigning by Figen Murray OBE. It is named in memory of her son, Martyn Hett, who was one of the 22 people killed in the Manchester Arena attack in May 2017.

The Act is intended to improve the preparedness and protective security of qualifying premises and events. Rather than expecting organisations to prevent every possible attack, it requires those responsible for certain locations to consider how they would respond and reduce the risk of physical harm if an incident occurred. Larger premises and qualifying events will also be expected to consider proportionate measures that reduce their vulnerability to terrorism.

For Facilities Managers, security teams and property leaders, the legislation is likely to bring protective security more firmly into routine building governance, operational planning and staff development.

From Campaign to Legislation

The legislation followed more than seven years of campaigning by Figen Murray, who called for stronger and more consistent security arrangements at publicly accessible locations.

The original Bill was introduced to Parliament on 12 September 2024. Following scrutiny and amendments, it became the Terrorism (Protection of Premises) Act 2025.

Although the Act has received Royal Assent, most of its substantive duties are not yet in force. The Government has provided for an implementation period of at least 24 months from April 2025, giving the Security Industry Authority and affected organisations time to prepare. Statutory guidance was published in April 2026 to help responsible persons understand the scope and requirements.

Organisations should therefore begin reviewing their arrangements now, while recognising that legal compliance will only become mandatory when the relevant provisions formally commence.

Which Premises Will Be Covered?

The Act uses a tiered approach based on the number of people it is reasonable to expect may be present at the premises at the same time.

For a location to qualify, it must generally include at least one building, be wholly or mainly used for a purpose listed in the Act, be accessible to the public and meet the relevant attendance threshold. Covered uses include areas such as entertainment, hospitality, retail, education, healthcare, places of worship, transport and public services, although exclusions and special rules apply.

Standard-Duty Premises

Premises where it is reasonable to expect 200 to 799 people may be present will generally fall within the standard tier.

This threshold is higher than the 100-person figure included in earlier versions of the proposals.

The responsible person will be expected to put in place reasonably practicable public-protection procedures covering how the organisation would respond to a terrorist attack.

These procedures may address matters such as:

  • Evacuation
  • Invacuation
  • Lockdown
  • Communication with people on the premises

The emphasis is on practical preparedness rather than expensive physical security installations.

Enhanced-Duty Premises

Premises where 800 or more people may reasonably be expected to be present will be subject to enhanced duties.

In addition to public-protection procedures, the responsible person will need to consider reasonably practicable measures to reduce the premises’ vulnerability to an attack and minimise the risk of physical harm.

Enhanced-duty organisations will also face additional requirements relating to documentation, notification and organisational accountability.

The Act does not automatically require every enhanced-tier premises to install CCTV or employ additional security officers. Measures must be appropriate and proportionate to the premises, its use and the risks involved.

Qualifying Events

Certain public events may also fall within the legislation where:

  • It is reasonable to expect at least 800 people to attend at the same time.
  • The event is open to the public.
  • Entry is controlled through a ticket, payment, pass, membership or similar condition.
  • The event is not already taking place at premises covered as enhanced-duty premises.
  • No statutory exclusion applies.

This means organisers of some festivals, exhibitions, performances and temporary events may have responsibilities even where the location itself would not ordinarily fall within the enhanced tier.

Who Is the Responsible Person?

For qualifying premises, the responsible person will generally be the individual or organisation that controls the premises in connection with its relevant use.

Depending on the property arrangement, this could be:

  • The occupier
  • A venue operator
  • A business
  • A public body
  • A charity
  • An event organiser
  • In some circumstances, another organisation with operational control

Landlords will not automatically be responsible simply because they own the building. Responsibility depends on who controls the relevant use of the premises.

Complex or multi-occupied buildings may require careful analysis to determine where responsibility lies and how different parties should cooperate.

The Role of the Security Industry Authority

The Security Industry Authority, or SIA, will become the regulator for the new regime.

Its role will include supporting and advising responsible persons, monitoring compliance and taking enforcement action where appropriate. The Act provides the regulator with powers relating to information gathering, inspection and sanctions.

Facilities teams should therefore expect protective-security records, procedures and governance arrangements to become increasingly important evidence of organisational preparedness.

What Martyn’s Law Means for Facilities Managers

The legal duty will rest with the designated responsible person, but Facilities Managers are likely to play a central role in implementation.

Their detailed knowledge of buildings, occupancy, contractors, emergency systems and operational risks makes them essential to the preparation process.

Reviewing the Scope of the Estate

FM leaders should identify which premises and events could fall within the Act.

This will involve reviewing:

  • The primary use of each building
  • Public access
  • Expected occupancy
  • Event arrangements
  • Control and management responsibilities
  • Any relevant exclusions

The Act focuses on the number of people reasonably expected to be present, rather than relying solely on a building’s theoretical maximum capacity.

Developing Public-Protection Procedures

Facilities teams may help create, review and test procedures covering evacuation, invacuation, lockdown and communication.

These plans should be practical, proportionate and aligned with wider emergency arrangements such as:

  • Fire procedures
  • Business continuity
  • Major incident plans
  • Security escalation
  • First aid
  • Emergency-services access

A response appropriate for a theatre may differ considerably from one designed for a school, shopping centre or office campus.

Training and Awareness

Procedures are only effective when employees understand them.

Facilities Managers may need to coordinate proportionate awareness and instruction for:

  • Front-of-house staff
  • Security teams
  • Receptionists
  • Duty managers
  • Contractors
  • Event personnel
  • Senior decision-makers

Training should reflect people’s roles. Not every employee needs to become a security specialist, but those responsible for implementing procedures must know what to do.

Reviewing Physical and Operational Measures

For enhanced-duty premises, FM teams may help assess whether additional measures are reasonably practicable.

These could relate to:

  • Access control
  • Vehicle management
  • Perimeter arrangements
  • Security monitoring
  • Public-address systems
  • Emergency communications
  • Zoning
  • Staff deployment
  • Control-room procedures

Any investment should be based on the individual premises rather than a generic checklist.

Maintaining Documentation

Enhanced-tier premises and qualifying events will need more formal records explaining the measures in place.

Facilities Managers may be responsible for keeping relevant documentation current, ensuring that responsibilities are clear and recording when procedures are reviewed, exercised or amended.

Existing CAFM, compliance or document-management platforms may help organisations control this information.

Working With Other Stakeholders

Compliance will require cooperation across multiple functions, including:

  • Senior leadership
  • Security
  • Health and safety
  • HR
  • IT and cybersecurity
  • Communications
  • Legal teams
  • Property management
  • Event operations
  • Emergency services

Protective security should not sit in isolation. It needs to form part of wider organisational resilience.

Practical Steps FM Leaders Can Take Now

Organisations do not yet need to demonstrate full legal compliance, but the implementation period provides an important opportunity to prepare.

Facilities leaders can begin by:

  1. Mapping potentially qualifying premises and events.
  2. Identifying who controls each location and may be the responsible person.
  3. Reviewing expected occupancy and public access.
  4. Comparing existing emergency arrangements with the statutory guidance.
  5. Checking whether evacuation, invacuation, lockdown and communication procedures are workable.
  6. Reviewing staff awareness and training needs.
  7. Identifying gaps in documentation and governance.
  8. Engaging senior leaders before budgets and resources become urgent.
  9. Testing arrangements through proportionate exercises.
  10. Monitoring official Home Office and SIA guidance as implementation develops.

The Government has cautioned that neither the Home Office, SIA nor the National Counter Terrorism Security Office endorses private-sector products marketed as guaranteed solutions for Martyn’s Law compliance. Organisations should be cautious of suppliers suggesting that purchasing a particular system or package will automatically satisfy the Act.

Proportionate Security, Not a One-Size-Fits-All Regime

A central principle of Martyn’s Law is proportionality.

Smaller premises will not be expected to adopt the same measures as a major arena or stadium. Equally, compliance should not become a purely administrative exercise involving documents that cannot be applied during a real incident.

The objective is to ensure organisations have considered credible responses, prepared their people and introduced sensible measures that reflect the scale and nature of their operations.

A Growing Responsibility for Facilities Management

Martyn’s Law reinforces the increasingly strategic role of Facilities Management.

FM professionals already oversee fire safety, building compliance, emergency planning, contractor control and business continuity. Protective security now becomes another important part of that interconnected responsibility.

The strongest preparations will combine detailed knowledge of the physical estate with clear leadership, effective communication and regular testing.

The legislation cannot remove the threat of terrorism. It can, however, encourage organisations to think more carefully about how they would protect people and respond under pressure.

For Facilities Managers, that means moving beyond passive security arrangements and helping create buildings, teams and procedures that are genuinely prepared for the unexpected.