Skip to main content
MicroNet Global

Compliance

Martyn's Law for venues: what it requires, and where technology helps

What Martyn's Law means for hospitality operators: the standard and enhanced tiers, the SIA's role, and where technology genuinely supports the duties.

7 min readBy the MicroNet Global team

Martyn's Law, the Terrorism (Protection of Premises) Act 2025, received Royal Assent in April 2025 and will not be implemented before April 2027. It requires qualifying venues to prepare public protection procedures, regulated by the Security Industry Authority. MicroNet Global supports hospitality operators in the UK with the technology those procedures depend on.

Martyn's Law is not a technology mandate

This point deserves stating before anything else, because the market is already blurring it. Martyn's Law is security legislation about people, planning and procedures. It does not require you to buy a camera, a radio system or a piece of software, and no vendor can sell you "Martyn's Law compliance". Any supplier claiming otherwise is describing something the Act does not say.

What the Act requires is that responsible persons at qualifying premises prepare for the possibility of a terrorist attack and put in place procedures to reduce harm to the public. Technology is one of the things those procedures rely on. It is a supporting layer, never the duty itself.

What is Martyn's Law?

Martyn's Law is the common name for the Terrorism (Protection of Premises) Act 2025, which received Royal Assent in April 2025. It places duties on those responsible for qualifying premises and events in the UK to prepare public protection procedures against terrorist attacks. It creates two tiers based on the number of individuals who may be present, and is regulated by the Security Industry Authority.

The two tiers

Premises fall into a tier according to the number of individuals reasonably expected to be present at the same time, which includes staff as well as guests. That is a capacity question, not a covers question.

DutyStandard tierEnhanced tier
Individuals present200--799800 or more
Notify the SIAYesYes
Public protection proceduresRequired, so far as is reasonably practicableRequired
Protective measuresNot requiredAdditionally required
DocumentationNot submittedDocumented and submitted to the SIA
RegulatorSecurity Industry AuthoritySecurity Industry Authority

Where technology genuinely supports the duties

Procedures only work if people can be told what to do and can act on it. That is where an IT partner has something useful to contribute.

**Internal communications.** Staff need to reach each other across a site and, in a group, between sites and head office. That means radio or equivalent coverage in basements, kitchens, plant rooms and stairwells, tested in the places where signal usually fails, and a group communication route that does not depend on one manager's mobile.

**A working PA or alerting path.** Whatever you use to address the room in an emergency needs to be audible over service noise, reachable from more than one point, and known to duty managers who were not there when it was installed.

**Access control on back-of-house, roof and plant areas.** Controlled doors on service corridors, plant rooms, roof access and delivery routes, with a current list of who holds access and prompt removal for leavers.

**CCTV that is actually recording and retrievable.** Cameras that stopped writing three months ago are common, as are systems nobody can export footage from without the installer. Check recording, retention and export as a routine task.

**Training records and evidence retention.** Who was trained, on what, and when, kept somewhere durable rather than in a folder on one laptop. High turnover makes this the control most likely to drift.

**Incident logging.** A consistent record of incidents, near misses and drills, held centrally so a group can see patterns across sites.

**Network and power resilience.** All of the above depends on connectivity and power that nobody tests until the day it fails. Resilient links, UPS on the equipment that matters, and a documented failover are the unglamorous foundation, and the same discipline as [[disaster recovery for multi-site hospitality]{.underline}](about:blank). Our [[IT infrastructure and resilience work]{.underline}](about:blank) usually starts here.

How a multi-site group should approach it

Start by working out which premises fall where. A group with forty sites will not have a single answer: some venues will sit in the standard tier, a handful of larger ones in the enhanced tier, and a number of small sites will fall below the threshold entirely. The calculation is per premises and based on capacity, so a busy 90-cover restaurant may fall outside the scope while a quieter venue with a large events floor does not.

Then assign an owner. This is not an IT project and it should not be handed to IT by default. It needs a named accountable person at group level, with security, operations, property and IT contributing. Where sites share a duty manager population, make sure the procedures are consistent enough to transfer between venues.

Finally, build the capability into the ordinary cycle of works. Comms coverage, access control and CCTV are cheapest to fix during a refurbishment or a new opening rather than as a standalone programme, which is the same argument as the [[IT critical path for a new venue opening]{.underline}](about:blank).

Plan the capability, not a specification that does not exist yet

Much of the operational detail will be set out in guidance and secondary legislation before commencement. That is not a reason to wait, but it is a reason to be careful about what you buy now.

Invest in capability that is useful regardless of the final detail: knowing your capacity numbers per site, having communications that work everywhere in the building, having access control you can audit, having CCTV that records and exports, and having training records you can produce. Avoid purchasing against a specification the regulator has not published. Where you need help translating an operational requirement into a technical one, that is what [[IT consultancy]{.underline}](about:blank) is for, and it applies across [[leisure and entertainment venues]{.underline}](about:blank) as much as hotels and restaurants.

This is not legal advice

This article is general information, not legal or security advice. Tier determination, the scope of your duties as a responsible person and the adequacy of your procedures depend on your specific premises, capacity and operating model. Take security advice from a competent adviser and legal advice on your obligations, and follow SIA guidance as it is published. An IT partner's role is to make sure the technology your procedures rely on actually works.

Frequently asked questions

The Terrorism (Protection of Premises) Act 2025 received Royal Assent in April 2025, but implementation will not begin earlier than April 2027. That is a lead-in period of at least 24 months, allowing premises to prepare and the Security Industry Authority to establish its regulatory function. Guidance and secondary legislation are expected before commencement.

Written by the MicroNet Global team. If you are working through any of this for your own estate, the specialists here are happy to talk it through.

Keep reading

Related insights

All insights
New openings6 min read

The technology checklist for a new hospitality opening

The questions operators should answer before the opening team arrives on site, from connectivity and suppliers to handover and live support.

Read article
Managed IT5 min read

Why hospitality needs a different IT support model

Hospitality does not operate in office hours. A useful support model is built around service, sites and the commercial cost of disruption.

Read article
Cyber security7 min read

A practical guide to hospitality cyber security

A plain-English starting point for protecting guest data, payment systems and the people who keep venues running.

Read article
Managed IT7 min read

What hotel IT support actually covers, and what it doesn't

What hotel IT support covers: systems in scope, who owns the PMS and door locks, contract tiers, exclusions and how response targets really work.

Read article
Managed IT7 min read

Why PMS and EPOS integrations break, and how to catch it early

Why PMS and EPOS integrations fail: stopped interface services, expired certificates, room status and API changes, and the checks that catch silent errors.

Read article
Managed IT7 min read

In-house IT team or hospitality IT partner: an honest comparison

In-house IT team or outsourced hospitality IT partner? An even-handed comparison of cover, cost, breadth, openings and the co-managed middle ground.

Read article
Networks & Wi-Fi7 min read

Why guest Wi-Fi generates complaints, and how to design it out

Why guest Wi-Fi draws complaints in hotels and restaurants, and how to design it out --- surveys, AP placement, captive portals, segmentation and peak load.

Read article
Networks & Wi-Fi7 min read

Wi-Fi 7 and the 6 GHz band: what actually changed for venues in 2026

Ofcom opened the full 6 GHz band in July 2026. What Wi-Fi 7 changes for hotels, restaurants and clubs, what it costs, and when waiting is the better call.

Read article
Managed IT7 min read

Disaster recovery when there are 180 covers booked tonight

Business continuity for hotels and restaurants with covers booked tonight. RTO and RPO explained, the failure scenarios that happen and what restores service.

Read article
Compliance7 min read

PCI DSS for restaurants and hotel groups: the practical checklist

A practical PCI DSS checklist for multi-site restaurants and hotels: who enforces it, scope reduction, segmentation, phone orders and v4.x deadlines.

Read article
Cyber Security7 min read

Hospitality cyber security: the attack paths that actually get used

The attack paths actually used against hotel and restaurant groups, the defences that work, and what to do in the first hour of a suspected incident.

Read article
Openings & Rollouts7 min read

The IT critical path for opening a restaurant, hotel or club

A week-by-week IT timeline for opening a restaurant, hotel or club, from circuit lead times and cabling first fix to soft launch and day-one support.

Read article
Managed IT7 min read

Microsoft 365 when most of your workforce never sits at a desk

How to licence Microsoft 365 across hotel and restaurant teams, covering frontline worker tiers, shared device sign-in, identity, offboarding and backup.

Read article
Managed IT7 min read

Windows 10 end of support: the estate you cannot see

Windows 10 support ended in October 2025 and ESU Year 1 expires this October. A practical refresh plan for back-office, EPOS-adjacent and AV control PCs.

Read article

Put this into practice

Services and sectors this touches

Secure, scalable and seamless IT wherever hospitality takes you.