Last updated: 15 September 2026
Martyn's Law risk assessment requirements: what UK premises must do
Martyn's Law — officially the Terrorism (Protection of Premises) Act 2026 — requires enhanced tier premises (800+ capacity) to complete and maintain a documented terrorism risk assessment, while standard tier premises (200–799 capacity) must follow simpler, low-cost preparedness procedures without a mandatory formal document.
Key Takeaways
- Pulse Operations notes that Martyn's Law is the common name for the Terrorism (Protection of Premises) Act 2026, named after Martyn Hett, one of 22 people killed in the 2017 Manchester Arena attack.
- Pulse Operations reports that approximately 178,900 premises across the UK fall in scope of Martyn's Law, around 154,600 in Standard Tier and 24,300 in Enhanced Tier, according to the Home Office Impact Assessment (2026).
- Pulse Operations highlights that enhanced tier premises must maintain a documented, current risk assessment; standard tier premises face lighter, procedure-based duties rather than a mandatory formal risk assessment.
- Enhanced duty breaches carry a maximum penalty of £18 million or 5% of qualifying worldwide revenue, whichever is greater, plus a daily penalty of up to £50,000, per Policy Pros' Martyn's Law Compliance Guide (2026).
- Since March 2017, the UK has experienced fifteen terrorist attacks and disrupted a further 39 late-stage terrorist plots, according to the GOV.UK Impact Assessment (2026).
What is Martyn's Law?
Martyn's Law is the common name for the Terrorism (Protection of Premises) Act 2026, a UK statute that places legal duties on those responsible for qualifying public premises and events to prepare for the possibility of a terrorist attack. The Act received Royal Assent in 2026 and is named after Martyn Hett, one of 22 people killed in the 2017 Manchester Arena bombing.
Pulse Operations notes that the campaign that pushed the law onto the statute book was led by Martyn's mother, Figen Murray, who said: "We need to ensure that what happened to my son and 21 others never happens again."
Since March 2017, the UK has experienced fifteen terrorist attacks and disrupted a further 39 late-stage terrorist plots, according to the GOV.UK Impact Assessment (2026). The Home Office assessed the cost of the five UK terrorist attacks in 2017 at £196.4 million in direct economic and social cost, using 2026 prices, per the same Impact Assessment (2026). Pulse Operations covers the full context, including the two-tier system and readiness checklist, in its guide, Martyn's Law: a readiness guide for security & FM teams.
Does Martyn's Law apply to my premises, and how do the tiers differ?
Martyn's Law applies on a tiered model based on the maximum number of people a premises or event could hold at any one time — not average daily footfall. Standard tier broadly covers premises where 200 to 799 people may be present; enhanced tier broadly covers premises and events where 800 or more people may be present, per Pulse Operations's Martyn's Law guide.
Capacity counts everyone who could be on site — the public and staff — at peak, including one-off events that push a normally quiet venue over the threshold. A community hall that hosts a 250-person wedding falls into scope on that night even if its weekday footfall is a fraction of that.
Approximately 178,900 premises across the UK fall in scope: around 154,600 in Standard Tier and 24,300 in Enhanced Tier, according to the Home Office Impact Assessment (2026). Research for the Impact Assessment found over 928,000 premises in the UK are considered a "publicly accessible location", with 178,900 of those falling in scope of Martyn's Law, per GOV.UK (2026). Separately, Pool Re's Martyn's Law Hub (2026) notes some estimates suggest over 250,000 premises will ultimately be impacted.
Standard vs enhanced tier at a glance
| Factor | Standard tier | Enhanced tier |
|---|---|---|
| Capacity threshold | 200–799 people | 800+ people |
| Core duty | Low-cost, common-sense procedures | Documented, kept-current risk assessment plus procedures |
| Formal risk assessment required | No mandatory document | Yes — documented and maintained |
| Estimated average annual cost | ~£330 per premises | ~£5,210 per premises |
| Maximum penalty for breach | £10,000, plus £500/day | £18 million or 5% of worldwide revenue, plus £50,000/day |
| Regulator | Security Industry Authority (SIA) | Security Industry Authority (SIA) |
Cost estimates are from the government's impact assessment via imabi's Martyn's Law Myth Buster (2026); penalty figures from Policy Pros' Compliance Guide (2026).
What risk assessment document is legally required under each tier?
Enhanced tier premises must maintain a documented terrorism risk assessment that is kept current — a living record, not a one-off exercise completed at launch and forgotten, per Pulse Operations's guide. This assessment should identify how a terrorist attack could affect the premises or event, and set out the public protection procedures the responsible person has in place in response — evacuation, invacuation (moving people to safety inside the building), lockdown and communication with people on site.
Standard tier premises do not carry the same mandatory documented risk assessment obligation. Instead, the duty focuses on straightforward, low-cost preparedness: knowing what to do in the event of an attack, briefing staff, and having basic procedures for evacuation and lockdown.
That distinction matters for budgeting and resourcing. The government's impact assessment estimates average annual costs of around £330 for standard tier premises and £5,210 for enhanced tier, according to imabi's Martyn's Law Myth Buster (2026) — a gap that reflects the extra weight of the enhanced tier's documentation and review burden. The SIA is expected to publish Section 12 guidance clarifying exactly what "reasonably practicable" measures look like at enhanced tier premises.
Who is legally responsible for the risk assessment?
The responsible person is the individual or organisation legally accountable for meeting Martyn's Law duties at a given premises — typically the operator, employer, or whoever has control of the premises in connection with their trade, business or charitable purpose. This designation sits alongside, but separately from, existing duty-holder roles under health and safety and fire safety law.
For enhanced tier sites, the responsible person must ensure the risk assessment is completed, documented, kept current, and that staff are trained and informed of the procedures it produces. Legal adviser Kevin Bridges of Pinsent Masons has warned: "Whilst there is a two year transition period, duty holders have significant work to undertake if they are to ensure compliance," adding that "duty holders should start planning now for the new duties."
In practice, this responsibility is often shared across security, facilities and estates teams — which is exactly where gaps appear, because the person accountable on paper is rarely the person who last walked the site. Pulse Operations's compliance runway (/compliance) puts SIA licensing, BS 7858 vetting, DBS checks, right to work, training and Martyn's Law assessments on one expiries timeline, so the responsible person can see at a glance what's covered and what's overdue — rather than relying on memory or a filing cabinet.
Key steps for a compliant terrorism risk assessment
A compliant enhanced tier risk assessment identifies vulnerabilities, evaluates likely attack methodologies, and sets out proportionate mitigations — it is not a generic template filled in once and filed away. The process typically follows a sequence familiar to anyone who has run a fire risk assessment under the Regulatory Reform (Fire Safety) Order 2005.
Typical steps include:
- Map the premises — identify entry and exit points, congregation areas, queuing points, and areas of higher footfall or vulnerability.
- Assess plausible attack methodologies — consider marauding attacks, vehicle-as-weapon scenarios, and bladed or bomb-related threats relevant to the venue type.
- Evaluate existing measures — record what security, CCTV, staffing and physical controls are already in place.
- Identify gaps and proportionate mitigations — decide what additional, reasonably practicable measures close identified gaps.
- Draft public protection procedures — evacuation, invacuation, lockdown and communication plans that staff can actually execute.
- Train and brief staff — ensure everyone understands their role, not just the responsible person.
- Record and date everything — a version-controlled, retrievable record the SIA can inspect on request.
A prestige central-London residential estate that Pulse Operations's founding team supports through Priority First illustrates why the record-keeping step matters as much as the assessment itself. The estate covers 16 buildings on one nightly patrol round, and could not previously show, without ringing the office, whether every building actually received its patrols. Since Pulse went live on that estate in March 2026, each building has been set up as its own site with its own checkpoints and evidence trail, and the estate now sees per-building delivered-vs-contract data in its own portal rather than a single vague "round complete" note — patrols recorded since March have run to 4,100+, roughly 250–280 per building, with checkpoint completions 100% photo-verified (production data, July 2026). That same principle — a documented, retrievable, per-site record rather than a verbal assurance — is exactly what an enhanced tier terrorism risk assessment needs to survive scrutiny.
When does Martyn's Law come into force?
Martyn's Law received Royal Assent in 2026, and the government has built in an implementation period before duties become enforceable, giving duty holders time to prepare rather than facing immediate liability. The SIA's Executive Director for Martyn's Law, Laura Gibb, has confirmed the regulator intends "to regulate when Martyn's Law comes into force in Spring 2027," as part of its consultation process on how enforcement will work.
That transition window is shorter than it looks once the practical steps are counted: capacity assessment, gap analysis, drafting, staff training, and embedding a review cycle all take time, particularly for organisations with multiple sites. Kevin Bridges of Pinsent Masons has been explicit that "duty holders should start planning now for the new duties" rather than waiting for the SIA's final Section 12 guidance to land.
Section 27 statutory guidance and the SIA's Section 12 regulatory guidance are expected to be finalised well ahead of commencement, giving duty holders a clearer picture of the SIA's expectations before enforcement begins.
Penalties and enforcement consequences for non-compliance
Standard duty breaches carry a maximum penalty of £10,000, with a daily penalty of up to £500 for continuing non-compliance, according to Policy Pros' Martyn's Law Compliance Guide (2026). Enhanced duty breaches carry a far steeper maximum of £18 million or 5% of qualifying worldwide revenue, whichever is greater, plus a daily penalty of up to £50,000, per the same source.
The Security Industry Authority (SIA) — the body that already licenses door supervisors and security officers under the Private Security Industry Act 2001 — is the designated regulator for Martyn's Law. The SIA can issue compliance notices, restriction notices and penalty notices, and it has run public consultations on its Section 12 guidance to set out how it intends to assess reasonable practicability and enforce breaches.
For most organisations, the real risk isn't a single dramatic fine — it's the daily accumulation. A £500 or £50,000 daily penalty compounds fast if a gap in documentation isn't caught and fixed quickly, which is why an auditable, continuously updated record matters more than a document produced once for a launch date.
Common mistakes organisations make preparing risk assessments
The most frequent gap is treating the risk assessment as a one-off compliance exercise rather than a maintained record — precisely the failure mode Pulse Operations's guide warns against for enhanced tier sites, where the document must stay current, not sit untouched after the first review. Other recurring mistakes include:
- Confusing capacity with average footfall — using typical daily numbers instead of peak capacity, which can wrongly place a venue in standard tier when an occasional event pushes it into enhanced tier.
- Duplicating, rather than integrating, existing fire and health and safety risk assessments — Martyn's Law sits alongside duties under the Health and Safety at Work etc. Act 1974 and the Regulatory Reform (Fire Safety) Order 2005, but it is a distinct legal requirement, not a subset of either.
- No named responsible person — leaving accountability diffuse across security, facilities and management teams.
- No training evidence — a well-drafted procedure that staff have never been briefed on won't survive an SIA inspection.
- Scattered records — assessments, training logs and incident history held across spreadsheets, email threads and personal notebooks rather than one retrievable system.
Mo Hassan, Founder of Pulse, has described the same instinct playing out in client transparency more broadly: "The opposite. We show clients the gaps as well as the hits — if there were no patrols in a period, the portal says so. The first time a client sees you being honest about a miss, they believe every number after that. Transparency is the cheapest client retention there is." The same logic applies to a Martyn's Law risk assessment — an honest, current gap analysis is worth more to a duty holder than a polished document that hides what hasn't been checked.
Reviewing risk assessments and keeping evidence for inspection
Enhanced tier risk assessments must be kept current, which in practice means a scheduled review cycle rather than a fixed statutory interval, triggered by material changes to the premises, its use, capacity, or the threat picture. A change of layout, a new event type, or a significant local security incident should each prompt a fresh look at the assessment rather than waiting for an annual date on the calendar.
For inspection readiness, the SIA is expected to expect access to the risk assessment itself, evidence of staff training and briefings, incident records, and a clear audit trail showing who reviewed the document and when. This mirrors the discipline the SIA already applies to security businesses through the Approved Contractor Scheme, where assessors review staff files, policies, contracts and site documentation rather than taking self-reported scores at face value, as Pulse Operations sets out in its guide, The ACS self-assessment: how to evidence it.
Pulse Operations's own compliance runway (/compliance) is built around that same expiries-and-evidence model — SIA licences, BS 7858 vetting, DBS checks, training records and Martyn's Law assessments tracked on one runway, so a duty holder can produce a coherent evidence pack rather than reconstructing history under pressure when an inspection is announced.
Your Martyn's Law risk assessment checklist
- Confirm your premises' peak capacity, including one-off events, to establish standard or enhanced tier.
- Name a single responsible person accountable for Martyn's Law duties at each site.
- Map entry points, congregation areas and vulnerabilities across the premises.
- Draft evacuation, invacuation, lockdown and communication procedures specific to the site.
- Document the enhanced tier risk assessment and set a review trigger for material changes.
- Train and brief all staff, and keep dated evidence of that training.
- Store the assessment, training records and incident logs in one retrievable, auditable system.
- Track review dates alongside SIA licensing, BS 7858 and other compliance expiries on a single runway.
FAQ
What is Martyn's Law and what is its official name?
Martyn's Law is the common name for the Terrorism (Protection of Premises) Act 2026, which places legal duties on operators of qualifying public premises and events to prepare for a terrorist attack. It is named after Martyn Hett, one of 22 people killed in the 2017 Manchester Arena attack, following a campaign led by his mother, Figen Murray.
Does Martyn's Law apply to my premises?
Martyn's Law applies if your premises could hold 200 or more people at any one time, including staff and one-off events. Standard tier covers 200–799 people and enhanced tier covers 800 or more, with capacity judged on peak occupancy rather than typical daily footfall.
What risk assessment is required under enhanced tier?
Enhanced tier premises must maintain a documented terrorism risk assessment that identifies vulnerabilities, evaluates plausible attack methodologies, and sets out public protection procedures. It must be kept current rather than completed once and filed away.
Do standard tier premises need a formal risk assessment?
No. Standard tier premises face lighter, low-cost duties focused on basic preparedness — knowing what to do, briefing staff, and having simple evacuation and lockdown procedures — without a mandatory documented risk assessment.
Who enforces Martyn's Law and what are the penalties?
The Security Industry Authority (SIA) regulates Martyn's Law. Standard duty breaches carry a maximum penalty of £10,000 plus £500 a day; enhanced duty breaches carry a maximum of £18 million or 5% of qualifying worldwide revenue, whichever is greater, plus £50,000 a day, according to Policy Pros (2026).
When does Martyn's Law come into force?
Martyn's Law received Royal Assent in 2026 with an implementation period before enforcement. The SIA has indicated it intends to regulate from Spring 2027, giving duty holders a window to prepare — though legal advisers stress organisations should start planning now rather than waiting.
How much does a Martyn's Law risk assessment cost?
Government impact assessment figures put average annual costs at around £330 for standard tier premises and £5,210 for enhanced tier, per imabi (2026). Smaller sites often complete assessments in-house using SIA and Home Office guidance; larger or higher-risk enhanced tier venues frequently bring in external security consultants for the initial assessment.
How does Martyn's Law differ from fire and health and safety risk assessments?
Martyn's Law is a distinct legal duty focused specifically on terrorism preparedness, sitting alongside — not replacing — obligations under the Regulatory Reform (Fire Safety) Order 2005 and the Health and Safety at Work etc. Act 1974. Organisations should integrate the three assessments operationally, but each remains a separate legal requirement with its own regulator.
Securing your Martyn's Law compliance with Pulse Operations
Martyn's Law risk assessments fail inspection for the same reason patrol records fail audits: the evidence lives in someone's head, an email thread, or a folder nobody's opened since it was created. Pulse Operations built its compliance runway to solve exactly that problem — SIA licensing, BS 7858 vetting, DBS checks, right to work, training records and Martyn's Law assessments sitting on one expiries timeline, so a responsible person can see what's current and what's overdue without chasing paperwork.
The same discipline runs through Pulse Operations's wider platform: every patrol checkpoint is completed by a mandatory watermarked photograph — officer, site, GPS, time — with no tag scans by design, so the record of what was actually checked is never in dispute. That's the same evidentiary standard a Martyn's Law risk assessment needs to survive an SIA inspection: dated, retrievable, and honest about gaps rather than polished over them.
If your organisation is preparing for standard or enhanced tier duties, read Pulse Operations's Martyn's Law readiness guide for a practical checklist, or get in touch with Pulse Operations to see how the compliance runway (/compliance) fits alongside your existing security and facilities operations ahead of the Spring 2027 enforcement date.
Related Reading
- Martyn's Law for Outdoor Events: 2026 UK Guide
- Martyn's Law Training Course: 2026 Buyer's Guide
- Martyn's Law Online Training: 2026 UK Compliance Guide
