Last updated: 29 August 2026
Martyn's Law evidence requirements: what UK premises must be able to prove
Martyn's Law evidence requirements mean duty holders must be able to show — not just assert — that they've assessed their terrorism risk and put procedures in place. Enhanced tier premises must submit a written compliance document to the Security Industry Authority (SIA), while standard tier sites need only "reasonably practicable" evidence, though the SIA can request it during enforcement.
Key Takeaways
- Martyn's Law is the Terrorism (Protection of Premises) Act 2026, which received Royal Assent on 3 April 2026 and carries an implementation period of at least 24 months before its duties come into force, per GOV.UK (2026).
- Enhanced tier premises face fines of up to £18 million or 5% of qualifying worldwide revenue, whichever is greater, plus daily penalties of up to £50,000, according to the Policy Pros / City of London Police Authority Board Report (2026).
- Standard tier premises face a maximum penalty of £10,000, with daily penalties capped at £500, per Policy Pros (2026).
- Compliance documents must reach the SIA as soon as reasonably practicable after first preparation, and within 30 days of any revision, according to Browne Jacobson (2026).
- The standard tier covers premises expecting 200–799 people; the enhanced tier covers 800 or more, per the Martyn's Law FAQ (2026).
What is Martyn's Law and what evidence does it demand?
Martyn's Law is the public name for the Terrorism (Protection of Premises) Act 2026, legislation that requires operators of publicly accessible premises and qualifying events to plan and prepare for a terrorist attack. It exists because ordinary venues — shopping centres, places of worship, festivals, visitor attractions — have historically had no statutory duty to consider terrorism risk the way they must consider fire risk under the Regulatory Reform (Fire Safety) Order 2005.
The law is named after Martyn Hett, who died in the 2017 Manchester Arena attack. The Astutis guide notes that the estimated cost of the UK's 2017 terrorist attacks was approximately £171.8 million in direct costs, with indirect costs estimated at £3.5 billion (2026) — the economic case for preparedness sits alongside the human one.
Evidence requirements scale with tier. Enhanced tier duty holders must produce and submit a formal compliance document. Standard tier duty holders must simply be able to demonstrate they've thought it through — but "simply" doesn't mean casually, because the SIA retains inspection and enforcement powers regardless of tier.
How does the standard tier and enhanced tier differ on evidence?
The two-tier structure is the single most important thing to understand before you build an evidence file, because it determines whether you're writing a formal submitted document or holding proportionate internal records. Standard tier premises — those where 200 to 799 people may reasonably be expected to be present — face a lighter procedural duty: put in place reasonable public protection procedures and be able to point to them if asked. Enhanced tier premises, covering 800 or more people, must go further: complete a documented risk assessment, implement physical and procedural measures, appoint a named senior individual accountable for compliance, and submit a compliance document to the SIA.
| Requirement | Standard tier (200–799 people) | Enhanced tier (800+ people) |
|---|---|---|
| Formal risk assessment | Not mandated in the same form, but good practice | Required, documented |
| Written compliance document | Not required to submit | Required, submitted to the SIA |
| Named responsible person | Recommended | Required |
| SIA submission deadline | N/A unless requested | As soon as reasonably practicable; within 30 days of revision (Browne Jacobson, 2026) |
| Maximum penalty | £10,000, plus £500/day (Policy Pros, 2026) | £18m or 5% of worldwide revenue, plus £50,000/day (Policy Pros / City of London Police Authority Board Report, 2026) |
| Procedures to evidence | Invacuation, evacuation, lockdown, communication | Same, plus physical security measures and monitoring |
This table matters for procurement too. Anyone bidding into a shopping centre, stadium, or multi-site retail contract should expect Martyn's Law readiness questions in the selection questionnaire stage. Pulse Operations's own tender guide, How to win your next security tender, notes that for publicly accessible venues, buyers may now ask about Martyn's Law readiness under the Terrorism (Protection of Premises) Act 2026 as part of the pass/fail gates a bid must clear before quality is even scored.
What must a compliance document actually contain?
A compliance document is the written record enhanced tier duty holders must prepare and submit to the SIA, setting out how the premises meets its statutory duties under the Act. It's not a policy statement or a generic risk register — it needs to demonstrate the specific procedures adopted for that specific premises, tied to the tier's requirements.
Based on the statutory guidance, a compliance document should typically evidence:
- The terrorism risk assessment carried out for the premises, including how threats were identified and evaluated
- Public protection procedures covering evacuation, invacuation (moving people to safety within the building), lockdown, and communication with occupants during an incident
- Physical security measures in place — access control, screening, CCTV coverage, hostile vehicle mitigation where relevant
- The named senior individual responsible for compliance and their role in the organisation
- Staff training records showing who has been briefed on procedures and when
- Coordination arrangements for shared or multi-occupancy sites where more than one responsible person may hold duties
The Norton Rose Fulbright analysis of the Section 27 statutory guidance sets out the SIA's expectations for this documentation in detail, and is worth reading alongside the primary GOV.UK guidance.
This is where the parallel with proving security work more broadly becomes obvious. A compliance document that says "staff are trained" without a record of who, when, and on what is exactly the kind of unverifiable assertion that fails scrutiny — whether that scrutiny comes from an SIA inspector, an insurer, or a client asking hard questions after an incident. Pulse Operations's compliance runway keeps SIA licensing, BS 7858 screening records, DBS checks, right to work, training and statutory building compliance on one expiries timeline alongside Martyn's Law assessments — so when a compliance document needs supporting evidence, it exists rather than needing to be reconstructed under pressure. See /compliance.
When and how must evidence be submitted to the SIA?
Evidence submission timing under Martyn's Law is a firm deadline, not a guideline. Compliance documents must be submitted to the SIA as soon as reasonably practicable after they are first prepared, and any revision to that document must be resubmitted within 30 days, according to Browne Jacobson (2026). That 30-day clock applies every time the document changes — after a refurbishment, a change of use, a change of responsible person, or a material update to procedures.
The SIA — the Security Industry Authority, the statutory regulator responsible for licensing the UK's private security industry — is also the enforcement body for Martyn's Law. It ran a consultation on its Section 12 enforcement guidance, which closed at 11:59pm on Friday 12 June 2026, according to GOV.UK (2026). Laura Gibb, Executive Director for Martyn's Law at the SIA, said: "This consultation is an important opportunity for all premises and events in scope of Martyn's Law to engage with us directly and understand how we intend to regulate."
The Home Office has also been explicit that early preparation matters even before the Act's requirements formally bite, noting — as cited by Burness Paull — that "while there is no legal requirement to comply until the legislation comes into force, those in scope of the Act will wish to begin considering the requirements." With Royal Assent on 3 April 2026 and an implementation window of at least 24 months, duty holders reading this in 2026 are inside the preparation period now, not years ahead of it.
What if you can't produce evidence during an SIA inspection?
Failing to produce evidence when the SIA asks for it is treated as a compliance failure, and the penalties scale sharply with tier and premises size. This is the practical reason "reasonably practicable" evidence for standard tier sites still needs to be genuinely retrievable, not theoretical.
For enhanced tier premises, the numbers are severe: penalties of up to £18 million or 5% of qualifying worldwide revenue, whichever is greater, with daily penalties running to £50,000 for continued non-compliance (Policy Pros / City of London Police Authority Board Report, 2026). For standard tier premises the ceiling is £10,000, with daily penalties up to £500 (Policy Pros, 2026). Both regimes give the SIA power to issue compliance notices, restriction notices, and — for the most serious breaches — pursue penalties through the courts.
"An audit trail you can edit isn't an audit trail. Ours is hash-chained — change any historical entry and every entry after it breaks visibly. When a record might end up in front of an insurer or a court, tamper-evident isn't a feature, it's the point." — Mo Hassan, Founder, Pulse
That principle applies just as much to Martyn's Law evidence as it does to patrol records. A training log that can be quietly edited after the fact, or a risk assessment last touched two years ago with no revision history, doesn't survive an inspector's questions. Pulse's audit log is hash-chained using SHA-256 and tamper-evident, with a built-in integrity check that walks the entire chain — the same design principle that makes it credible for security incident logs applies directly to a Martyn's Law compliance record.
In-house evidence gathering vs a compliance platform
Duty holders broadly choose between two approaches to gathering Martyn's Law evidence: building and maintaining it manually — spreadsheets, shared drives, a folder of PDFs — or running it through a platform that keeps expiries, revisions and submission history on one timeline.
Manual evidence gathering works for small, single-site standard tier premises with a stable procedure and one responsible person. It becomes fragile fast for multi-site operators, shared-occupancy buildings with more than one duty holder, or any enhanced tier premises facing a 30-day revision deadline every time something changes. The failure mode is familiar to anyone who's run compliance by spreadsheet: nobody notices a document is six months out of date until an inspector asks for it.
A platform approach puts the compliance document, its revision history, training records and the underlying risk assessment on one runway with expiry and review dates tracked automatically. For operators already using Pulse Operations for SIA licence tracking, BS 7858 screening and DBS renewals, adding Martyn's Law assessments to the same compliance runway means one place to check readiness rather than a separate system nobody remembers to update. See /compliance and the wider platform overview at /how-it-works.
How Priority First handled multi-site evidence under scrutiny
Priority First is the founding team's own London security and facilities management operation — Pulse was built inside it before being offered to other operators, and that origin is always disclosed rather than presented as an arm's-length customer win. Priority First runs 24 sites across London, and before Pulse, evidence of what had actually happened on any given site lived across paper sign-in sheets, WhatsApp messages, and a spreadsheet nobody fully trusted.
The trigger wasn't Martyn's Law specifically — it was a client's recurring 7am question: "was everything okay last night?" The team needed to prove work rather than ask to be believed. They moved security and FM operations onto one login, made every patrol checkpoint photo-mandatory, and gave clients branded portals showing delivered-vs-contract.
The pattern is directly relevant to Martyn's Law evidence: a compliance document is only as credible as the records behind it, and records that live in someone's head or a WhatsApp thread don't survive an inspection any better than they survive a client audit. Since going live in February 2026, Priority First has recorded over 4,900 patrols on the platform, with every checkpoint backed by a watermarked photograph — up from 0% before. As Mo Hassan, Managing Director of Priority First, put it: "We used to take everyone's word for it. Now every checkpoint has a photo and the client can see it before we've finished the shift — it's changed how we win work."
Your Martyn's Law evidence checklist
- Confirm your tier by estimating reasonably foreseeable occupancy — 200–799 for standard, 800+ for enhanced (Martyn's Law FAQ, 2026)
- Appoint a named senior individual accountable for Martyn's Law compliance at enhanced tier premises
- Complete a written terrorism risk assessment covering evacuation, invacuation, lockdown and communication procedures
- Draft the compliance document to the standard set out in the Section 27 statutory guidance, then keep a revision history
- Submit to the SIA as soon as reasonably practicable, and resubmit within 30 days of any revision
- Keep training records per person, not a general policy statement asserting staff are briefed
- Coordinate with other responsible persons at shared or multi-occupancy premises, and document who owns what
- Store evidence somewhere retrievable within the same day an inspector or client asks for it — not somewhere it needs reconstructing
FAQ
What evidence do you need to comply with Martyn's Law?
You need a documented terrorism risk assessment, written public protection procedures, and — for enhanced tier premises — a formal compliance document submitted to the SIA. Standard tier premises need "reasonably practicable" evidence that procedures exist and are followed, retrievable on request rather than formally submitted.
What is a Martyn's Law compliance document and what must it include?
A compliance document is the written record enhanced tier duty holders submit to the SIA setting out their risk assessment, public protection procedures, physical security measures, named responsible person and staff training records. The Norton Rose Fulbright analysis of the statutory guidance covers the SIA's expectations in detail.
How often must a Martyn's Law compliance document be submitted or updated?
The document must be submitted as soon as reasonably practicable after it's first prepared, and resubmitted within 30 days of any revision, according to Browne Jacobson (2026). This applies every time procedures, occupancy, or the responsible person changes materially.
Is formal documentation legally required for standard tier premises?
No formal submission is required, but standard tier premises must still be able to demonstrate reasonable public protection procedures if the SIA asks. The bar is lower than enhanced tier, but "no formal requirement" doesn't mean no evidence at all.
What happens if you cannot provide evidence of compliance during an SIA inspection?
Failure to evidence compliance can trigger enforcement action, including compliance notices and financial penalties. Standard tier premises face fines up to £10,000 plus £500 daily; enhanced tier premises face fines up to £18 million or 5% of worldwide revenue plus £50,000 daily, per Policy Pros (2026).
How do you evidence a terrorism risk assessment under Martyn's Law?
A terrorism risk assessment is evidenced through a dated, written document identifying threats to the specific premises, the reasoning behind chosen procedures, and a review history showing it's kept current. It should sit alongside — not replace — existing fire and health and safety risk assessments under the Regulatory Reform (Fire Safety) Order 2005.
What powers does the SIA have to request evidence or inspect premises?
The SIA can inspect premises, request compliance documents, and issue compliance or restriction notices where duty holders fail to meet their obligations. Its Section 12 enforcement guidance, consulted on until 12 June 2026 per GOV.UK, sets out how these powers will be exercised in practice.
Keeping Martyn's Law evidence audit-ready with Pulse Operations
Martyn's Law evidence fails inspection for the same reason patrol evidence fails a client audit: because it was never designed to be retrieved quickly, or it relies on someone's memory rather than a timestamped record. Pulse Operations built its compliance runway to solve exactly this problem — SIA licensing, BS 7858 screening, DBS checks, right to work, training records and Martyn's Law assessments sit on one expiries timeline, so a compliance document's supporting evidence is a query away rather than a reconstruction project.
The same hash-chained, tamper-evident audit log that underpins Pulse's incident records and daily occurrence book applies to compliance evidence too — a design built inside the founding team's own 24-site London security operation, Priority First, before being opened to other operators. That's a disclosure Pulse Operations makes deliberately, because knowing the system was stress-tested on a live estate rather than designed in the abstract is part of why it holds up under real inspection pressure.
If your premises falls under the standard or enhanced tier and you want to see how a compliance runway would sit alongside your existing security and FM operations, get in touch with Pulse Operations for a walkthrough, or explore the guide at /guide-martyns-law.
Related Reading
- Guardhouse Alternative 2026: Best UK Options Compared
- SmartTask Alternative 2026: Best Options Compared
- TrackTik Pricing 2026: UK Cost Guide & Alternatives
