Compliance
Martyn's Law for venues: what it requires, and where technology helps
What Martyn's Law means for hospitality operators: the standard and enhanced tiers, the SIA's role, and where technology genuinely supports the duties.
Martyn's Law, the Terrorism (Protection of Premises) Act 2025, received Royal Assent in April 2025 and will not be implemented before April 2027. It requires qualifying venues to prepare public protection procedures, regulated by the Security Industry Authority. MicroNet Global supports hospitality operators in the UK with the technology those procedures depend on.
Martyn's Law is not a technology mandate
This point deserves stating before anything else, because the market is already blurring it. Martyn's Law is security legislation about people, planning and procedures. It does not require you to buy a camera, a radio system or a piece of software, and no vendor can sell you "Martyn's Law compliance". Any supplier claiming otherwise is describing something the Act does not say.
What the Act requires is that responsible persons at qualifying premises prepare for the possibility of a terrorist attack and put in place procedures to reduce harm to the public. Technology is one of the things those procedures rely on. It is a supporting layer, never the duty itself.
What is Martyn's Law?
Martyn's Law is the common name for the Terrorism (Protection of Premises) Act 2025, which received Royal Assent in April 2025. It places duties on those responsible for qualifying premises and events in the UK to prepare public protection procedures against terrorist attacks. It creates two tiers based on the number of individuals who may be present, and is regulated by the Security Industry Authority.
The two tiers
Premises fall into a tier according to the number of individuals reasonably expected to be present at the same time, which includes staff as well as guests. That is a capacity question, not a covers question.
| Duty | Standard tier | Enhanced tier |
|---|---|---|
| Individuals present | 200--799 | 800 or more |
| Notify the SIA | Yes | Yes |
| Public protection procedures | Required, so far as is reasonably practicable | Required |
| Protective measures | Not required | Additionally required |
| Documentation | Not submitted | Documented and submitted to the SIA |
| Regulator | Security Industry Authority | Security Industry Authority |
Where technology genuinely supports the duties
Procedures only work if people can be told what to do and can act on it. That is where an IT partner has something useful to contribute.
**Internal communications.** Staff need to reach each other across a site and, in a group, between sites and head office. That means radio or equivalent coverage in basements, kitchens, plant rooms and stairwells, tested in the places where signal usually fails, and a group communication route that does not depend on one manager's mobile.
**A working PA or alerting path.** Whatever you use to address the room in an emergency needs to be audible over service noise, reachable from more than one point, and known to duty managers who were not there when it was installed.
**Access control on back-of-house, roof and plant areas.** Controlled doors on service corridors, plant rooms, roof access and delivery routes, with a current list of who holds access and prompt removal for leavers.
**CCTV that is actually recording and retrievable.** Cameras that stopped writing three months ago are common, as are systems nobody can export footage from without the installer. Check recording, retention and export as a routine task.
**Training records and evidence retention.** Who was trained, on what, and when, kept somewhere durable rather than in a folder on one laptop. High turnover makes this the control most likely to drift.
**Incident logging.** A consistent record of incidents, near misses and drills, held centrally so a group can see patterns across sites.
**Network and power resilience.** All of the above depends on connectivity and power that nobody tests until the day it fails. Resilient links, UPS on the equipment that matters, and a documented failover are the unglamorous foundation, and the same discipline as [[disaster recovery for multi-site hospitality]{.underline}](about:blank). Our [[IT infrastructure and resilience work]{.underline}](about:blank) usually starts here.
How a multi-site group should approach it
Start by working out which premises fall where. A group with forty sites will not have a single answer: some venues will sit in the standard tier, a handful of larger ones in the enhanced tier, and a number of small sites will fall below the threshold entirely. The calculation is per premises and based on capacity, so a busy 90-cover restaurant may fall outside the scope while a quieter venue with a large events floor does not.
Then assign an owner. This is not an IT project and it should not be handed to IT by default. It needs a named accountable person at group level, with security, operations, property and IT contributing. Where sites share a duty manager population, make sure the procedures are consistent enough to transfer between venues.
Finally, build the capability into the ordinary cycle of works. Comms coverage, access control and CCTV are cheapest to fix during a refurbishment or a new opening rather than as a standalone programme, which is the same argument as the [[IT critical path for a new venue opening]{.underline}](about:blank).
Plan the capability, not a specification that does not exist yet
Much of the operational detail will be set out in guidance and secondary legislation before commencement. That is not a reason to wait, but it is a reason to be careful about what you buy now.
Invest in capability that is useful regardless of the final detail: knowing your capacity numbers per site, having communications that work everywhere in the building, having access control you can audit, having CCTV that records and exports, and having training records you can produce. Avoid purchasing against a specification the regulator has not published. Where you need help translating an operational requirement into a technical one, that is what [[IT consultancy]{.underline}](about:blank) is for, and it applies across [[leisure and entertainment venues]{.underline}](about:blank) as much as hotels and restaurants.
This is not legal advice
This article is general information, not legal or security advice. Tier determination, the scope of your duties as a responsible person and the adequacy of your procedures depend on your specific premises, capacity and operating model. Take security advice from a competent adviser and legal advice on your obligations, and follow SIA guidance as it is published. An IT partner's role is to make sure the technology your procedures rely on actually works.
Frequently asked questions
The Terrorism (Protection of Premises) Act 2025 received Royal Assent in April 2025, but implementation will not begin earlier than April 2027. That is a lead-in period of at least 24 months, allowing premises to prepare and the Security Industry Authority to establish its regulatory function. Guidance and secondary legislation are expected before commencement.
Written by the MicroNet Global team. If you are working through any of this for your own estate, the specialists here are happy to talk it through.
