Last updated: 7 September 2026
Martyn's Law online training: what UK operators actually need in 2026
Martyn's Law online training is web-based instruction that helps staff at qualifying premises understand their duties under the Terrorism (Protection of Premises) Act 2026. Standard tier applies to premises where 200–799 people may reasonably be present, and enhanced tier to premises expecting 800 or more, according to The Ops Con. Online training is one part of compliance, not the whole of it — enforcement begins spring 2027, per GOV.UK.
Key Takeaways
- The Terrorism (Protection of Premises) Act 2026 received Royal Assent on 3 April 2026, with enforcement expected in spring 2027 after a 24-month implementation period, per GOV.UK.
- Standard tier covers premises where 200 to 799 people may reasonably be present, while enhanced tier applies to premises and events expecting 800 or more, according to The Ops Con.
- The Home Office estimates 178,900 premises will fall within scope of Martyn's Law, according to the Home Office Impact Assessment via publications.parliament.uk.
- Enhanced tier breaches can carry a maximum penalty of £18 million or 5% of qualifying worldwide revenue, whichever is greater, according to Policy Pros.
- Online training alone does not satisfy Martyn's Law — the Act also requires a documented risk assessment, a named responsible person, and workable procedures alongside any training records.
What is Martyn's Law online training?
Martyn's Law online training is web-based instruction designed to help staff at qualifying premises understand the duties introduced by the Terrorism (Protection of Premises) Act 2026 — the formal name for Martyn's Law. The Act is named after Martyn Hett, one of the 22 people killed in the 2017 Manchester Arena attack, and the campaign behind it was led by his mother, Figen Murray, per Pulse Operations's guide, Martyn's Law: a readiness guide for security & FM teams.
Online training courses generally cover threat recognition, invacuation, lockdown and evacuation procedures, and how staff should report concerns. Course providers offer everything from free introductory modules to paid, sector-specific courses with completion certificates. None of these courses, on their own, constitute full legal compliance — a point the government has been consistent about since the Bill was first drafted.
Why does Martyn's Law require staff training?
Martyn's Law requires operators to inform and train staff because a documented procedure is worthless if nobody on shift knows how to carry it out. The Act sits within a wider counter-terrorism context: since 2017, the UK has experienced several terrorist attacks and the security services have prevented a further 37 attack plots, according to the Home Office Impact Assessment. Training turns a paper plan into a rehearsed response.
The scale of exposure is significant. The Home Office impact assessment identifies over 928,000 Publicly Accessible Locations (PALs) across the UK, per the Home Office Impact Assessment. Of these, the Home Office estimates 178,900 premises will actually fall within Martyn's Law's scope, according to the Home Office Impact Assessment via publications.parliament.uk.
For security and FM teams managing multiple sites — shopping centres, mixed-use developments, residential estates — training can't be a one-off induction slide. It needs to be current, attributable to a named individual per site, and retrievable when the SIA (the Security Industry Authority, the body designated to regulate Martyn's Law) asks for evidence.
"Don't wait for the final guidance to start. Classify your sites by capacity, name a responsible person for each, and write procedures your night team can actually carry out. The operators who treat Martyn's Law as an extension of good practice will find enforcement a non-event." — Mo Hassan, Founder, Pulse
Standard tier vs enhanced tier: what training is expected?
The two tiers under Martyn's Law set different bars for training depth, documentation and evidence. Standard tier premises face lighter, common-sense obligations; enhanced tier premises must go further, including maintaining a documented risk assessment that stays current rather than sitting as a one-off exercise, per Pulse Operations's guide, Martyn's Law: a readiness guide for security & FM teams. Getting the tier wrong at the outset skews everything downstream, from training scope to what the SIA will expect to see.
| Factor | Standard tier | Enhanced tier |
|---|---|---|
| Capacity threshold | 200–799 people reasonably present | 800 or more people |
| Source | The Ops Con (2026) | The Ops Con (2026) |
| Core duty | Procedures for evacuation, invacuation, lockdown; responsible person named | All standard duties plus a documented, kept-current risk assessment |
| Training expectation | Practical, low-cost briefing staff can actually carry out | Structured, recorded training tied to the risk assessment |
| Max penalty (non-compliance) | £10,000, plus daily penalties up to £500 | £18 million or 5% of worldwide qualifying revenue, plus daily penalties up to £50,000 |
| Penalty source | Policy Pros (2026) | Policy Pros (2026) |
The SIA judges capacity on the maximum number of people who could be present — including public and staff at an event peak — not average daily footfall, per Pulse Operations's guide, Martyn's Law: a readiness guide for security & FM teams. A community hall that runs a busy Saturday market at 350 people is standard tier that day, even if a Tuesday sees 40.
Is online training legally sufficient on its own?
No — Martyn's Law online training is necessary but not sufficient on its own. The Act's core duties, as set out in Pulse Operations's guide, Martyn's Law: a readiness guide for security & FM teams, require operators to understand their risk, put in place public protection procedures such as evacuation and lockdown, appoint a designated responsible person, train and inform staff, and keep records to cooperate with the regulator. A completion certificate from an e-learning module addresses only the "train and inform" limb.
The government's own position, reflected in guidance published via ProtectUK, the police-run protective security hub, is that most standard tier premises should not need to hire a consultant. Free and low-cost resources exist. But a training certificate filed in a drawer proves nothing to an inspector — what matters is that staff on shift can actually carry out the procedure, and that the operator can show when that training happened, for whom, and against which site.
This is precisely where paperwork-based compliance breaks down in practice. Pulse's own work inside Priority First — the founding team's own London security & FM operation, where Pulse was built before being offered to other operators — showed this repeatedly on multi-site contracts. At a prestige central-London residential estate covering 16 buildings on one nightly round, the estate's original problem wasn't a lack of policy; it was that nobody could prove every building actually received its patrol, every night, without ringing the office. Since going live on Pulse in March 2026, the estate has recorded over 4,100 patrols — roughly 250-280 per building — with checkpoint completions moving from 0% photo-verified to 100%. The lesson translates directly to training: a record that can be produced instantly, tied to a named person and a named site, is worth more than a policy that asserts good intentions.
When does Martyn's Law come into force, and what's the compliance timeline?
Martyn's Law comes into force in spring 2027, following an implementation period of at least 24 months from Royal Assent. The Terrorism (Protection of Premises) Act 2026 received Royal Assent on 3 April 2026, per GOV.UK. That gap exists deliberately to let the SIA — newly designated as regulator under the Act — consult on guidance and let operators prepare without a cliff-edge deadline.
The SIA ran a consultation on its section 12 enforcement guidance, confirmed via GOV.UK's news release, which has since closed, per GOV.UK's follow-up announcement confirming the spring 2027 commencement date. Laura Gibb, Executive Director for Martyn's Law at the SIA, said: "This consultation is an important opportunity for all premises and events in scope of Martyn's Law to engage with us directly and understand how we intend to regulate when Martyn's Law comes into force in Spring 2027."
For operators, the practical timeline looks like this:
- Now to late 2026: classify every site by tier, name a responsible person, build training content and records infrastructure.
- Autumn 2026 (expected): SIA publishes finalised section 12 guidance following consultation.
- Spring 2027: enforcement begins; the SIA can inspect, request records, and issue penalties for non-compliance.
Operators managing schools, colleges and universities should also check the government's specific guidance on how Martyn's Law will affect education settings, since capacity thresholds and event days can shift a campus between tiers.
How should security and FM teams document Martyn's Law training?
The SIA's enforcement model depends on operators producing records on request, not simply asserting compliance verbally. An enhanced tier site with 30 staff, three shift patterns and a training completion rate scattered across email inboxes and spreadsheets will struggle the moment an inspector asks "show me." A standard tier community venue with one weekend supervisor has a simpler job, but still needs to know who was trained, when, and on what.
Good documentation practice, drawn from how tender evaluators already assess related compliance areas — per Pulse Operations's guide, How to win your next security tender — should show records per person, not a policy that merely asserts training happened. The same logic that applies to BS 7858 screening (records held per individual against BS 7858, the British Standard for security screening) applies to Martyn's Law training: name, date, module, site, and refresher due date.
Buyers are already asking about this. Publicly accessible venues going through procurement are increasingly asked about Martyn's Law readiness under the Terrorism (Protection of Premises) Act 2026 as part of tender pass/fail gates, per Pulse Operations's guide, How to win your next security tender. A contractor who can produce a live training expiries dashboard, rather than a static spreadsheet last updated in January, has a genuine tender advantage — the same advantage covered in Pulse Operations's security patrol app buyer's guide when comparing how different platforms handle compliance evidence.
This is the same discipline Pulse applies to SIA licences, DBS checks and right-to-work documents on its compliance runway — one expiries view across every statutory and training requirement, including Martyn's Law assessments, rather than five separate trackers that fall out of sync. Pulse's audit log is hash-chained (SHA-256) and tamper-evident, with a built-in integrity check that walks the whole chain — the same "record it once, prove it forever" principle that Martyn's Law compliance ultimately depends on.
In-house training vs outsourced compliance support: which suits your sites?
Small, single-site operators — a village hall, an independent retail unit — can often manage Martyn's Law training in-house using free resources from ProtectUK. The Home Office's stated position is that most standard tier premises shouldn't need a consultant at all. Larger, multi-site operators face a different calculation.
A security or FM contractor running 20 sites across several tiers, with turnover among event-day and volunteer staff, faces a genuine administrative burden trying to track who is trained, on which module, expiring when, at which site — manually. That's the trade-off: in-house training content can be free or low-cost, but the record-keeping overhead scales with site count and staff turnover, not with training cost.
For operators already running a compliance platform for SIA licences, BS 7858 screening and DBS checks, adding Martyn's Law training expiries to the same runway is usually cheaper in time than running it separately — even before counting the risk of a missed renewal surfacing during an SIA inspection rather than during a routine internal check. Contractors weighing up platform options more broadly may also find it useful to compare approaches in Pulse Operations's property maintenance software buyer's guide, which covers how FM providers track statutory compliance alongside day-to-day work orders.
Your Martyn's Law online training checklist
- Confirm your premises' tier by checking maximum possible capacity, not average footfall, against the 200–799 (standard) and 800+ (enhanced) thresholds.
- Name a responsible person for each site, not just one for the whole organisation.
- Select or build training content covering threat awareness, invacuation, lockdown and evacuation, and internal reporting lines.
- Record training per person, per site, with completion date and refresher due date — never as a single organisation-wide policy statement.
- Link training records to your documented risk assessment if you're enhanced tier, so the SIA can see the two are connected.
- Set refresher reminders well ahead of any renewal date rather than relying on memory.
- Review the SIA's finalised section 12 guidance once published (expected autumn 2026) and adjust training content accordingly.
- Keep a single, exportable view of training status across all sites ready for a tender pass/fail gate or an SIA inspection.
FAQ
What is Martyn's Law and who does it apply to?
Martyn's Law is the common name for the Terrorism (Protection of Premises) Act 2026, which places new legal duties on operators of qualifying public premises and events to prepare for a terrorist attack. It applies on a tiered basis: standard tier covers premises where 200–799 people may reasonably be present, and enhanced tier covers premises and events with 800 or more, per The Ops Con.
Is Martyn's Law online training legally required?
Martyn's Law itself does not name a specific accredited training course as mandatory, but it does require operators to "train and inform" staff as one of its core duties, per Pulse Operations's guide, Martyn's Law: a readiness guide for security & FM teams. Online training is one practical route to meeting that duty, provided it's backed by records and a workable procedure.
When does Martyn's Law come into force?
Martyn's Law comes into force in spring 2027. The Terrorism (Protection of Premises) Act 2026 received Royal Assent on 3 April 2026, with an implementation period of at least 24 months, per GOV.UK.
What is the difference between standard tier and enhanced tier training requirements?
Standard tier premises need practical, low-cost procedures that staff can actually follow, covering evacuation, invacuation and lockdown. Enhanced tier premises need the same plus a documented, kept-current risk assessment, and training should visibly connect to that risk assessment, per Pulse Operations's guide, Martyn's Law: a readiness guide for security & FM teams.
Is free Martyn's Law training available?
Yes — ProtectUK, the police-run protective security hub, provides free guidance, FAQs and preparation resources aimed at helping operators meet their duties without hiring a consultant.
What happens if my organisation doesn't complete Martyn's Law training?
Standard tier non-compliance carries a maximum penalty of £10,000, with daily penalties up to £500. Enhanced tier breaches carry a maximum of £18 million or 5% of qualifying worldwide revenue, whichever is greater, with a daily penalty of up to £50,000, according to Policy Pros.
Who is the 'responsible person' under Martyn's Law?
The responsible person is the named individual an operator designates to oversee Martyn's Law duties for a given premises, including ensuring staff are trained and procedures are current. Per Pulse Operations's guide, Martyn's Law: a readiness guide for security & FM teams, this appointment is one of the Act's core duties alongside understanding risk and keeping records.
Does completing online training alone mean my organisation is compliant?
No. Online training addresses only the "train and inform" duty. Full compliance also requires understanding your risk, having workable evacuation and lockdown procedures, naming a responsible person, and keeping records the SIA can request, per Pulse Operations's guide, Martyn's Law: a readiness guide for security & FM teams.
Keeping Martyn's Law training evidence ready, with Pulse Operations
Training is only half the problem Martyn's Law creates for security and FM teams — the other half is proving it happened, per site, per person, on demand. Pulse Operations's compliance runway puts SIA licences, BS 7858 screening, DBS checks, right to work, training expiries and Martyn's Law assessments on one view, so a training gap surfaces as an expiry, not as a surprise during an inspection.
Pulse's audit trail is hash-chained (SHA-256) and tamper-evident, with a built-in integrity check that walks the whole chain — the same standard of evidence Pulse Operations applies to photo-verified patrol checkpoints across its live operations, currently running at a 96.2% photo-verification rate over a trailing 90 days (see the benchmark, as of July 2026). If you manage multiple sites across standard and enhanced tiers and want a single place to track training alongside licensing and screening, get in touch with Pulse Operations for a walkthrough of the compliance runway ahead of spring 2027.
Related Reading
- Guardhouse Alternative 2026: Best UK Options Compared
- SmartTask Alternative 2026: Best Options Compared
- TrackTik Pricing 2026: UK Cost Guide & Alternatives
