What the statutory guidance requires, how insurers are likely to respond, and why a joined-up broking and advisory approach sets firms apart.
There is often a period between legislation being passed and brought into force when obligations are defined, timelines published and the regulator identified, but enforcement has not yet begun. For organisations within scope of the Terrorism (Protection of Premises) Act 2025, that period is narrowing quickly.
The Act, commonly known as Martyn’s Law, received Royal Assent on 3 April 2025. The Home Office published statutory guidance in April 2026, with accessible material updated in May 2026, and the Security Industry Authority (SIA) has consulted on its approach to assessment and review. There is no legal requirement to comply until the Act comes into force, but boards, operators, landlords and insurers are unlikely to wait until commencement before testing how prepared organisations are in practice.
Less than twelve months is not long to move from awareness of the law to an embedded set of public protection procedures: trained staff, documented plans, coordinated responsibilities across landlords and tenants and, for larger premises, vulnerability assessments capable of withstanding regulatory scrutiny. Nor is this solely a legal or operational exercise. For many organisations, preparedness under Martyn’s Law will increasingly influence how insurers and underwriters assess risk quality.
Two tiers, two postures
The Act takes a tiered approach. Premises that can reasonably be expected to host between 200 and 799 individuals at the same time, from time to time, for a Schedule 1 use fall within the standard tier. Premises that can reasonably be expected to host 800 or more individuals fall within the enhanced tier. Qualifying public events are also enhanced-tier where they are expected to host 800 or more people and have access controls, such as ticket checks or payment barriers. Some categories, including places of worship, childcare premises and certain education premises, remain within the standard tier even where attendance exceeds that threshold.
The Schedule 1 list, which sets out the categories of premises use that bring a premises within scope, is broader than it first appears. Shops, hospitality venues, leisure and entertainment sites, sports grounds, libraries, museums, galleries, halls, visitor attractions, hotels, places of worship, healthcare settings, transport hubs, aerodromes, childcare and education premises, and public authorities may all fall within scope. A separate part of an otherwise out-of-scope building may itself qualify. Publicly accessible events expected to draw 800 or more people, with some form of perimeter entry checks, may also qualify even where they take place outside enhanced tier premises.
The practical implication is that scope is often less straightforward than it first appears. A community trust operating a hall, a hotel group with a 250-cover restaurant, a faith building with an associated nursery, or a developer letting parts of a mixed-use site may each require careful analysis. In many cases, determining scope becomes a substantive exercise in its own right.
What “reasonably practicable” actually asks of the responsible person
Every qualifying premises and event will have a ‘responsible person’, typically the organisation in control of the premises for the Schedule 1 use, or in control of the premises in connection with the event. For enhanced tier premises or qualifying events, a senior individual must be designated to ensure the Act’s requirements are met. The guidance is clear that this must be someone sufficiently senior and that responsibility cannot be delegated, even if tasks can.
All premises and events in scope must ensure appropriate public protection procedures are in place so far as is reasonably practicable, covering four areas:
- Evacuation
- Invacuation
- Lockdown
- Communication
The phrase “so far as is reasonably practicable” signals proportionality and aligns with health and safety legislation, but it does not make compliance optional. The procedures expected of a 250-seat regional theatre will differ from those expected of a 30,000-seat arena. Staff responsible for carrying out procedures should be adequately informed and, where appropriate, trained.
Enhanced tier premises and qualifying events face additional duties. The responsible person must put in place appropriate public protection measures, again so far as is reasonably practicable, across four areas:
- Monitoring the premises or event and its immediate vicinity for suspicious activity.
- Controlling the movement of people.
- Mitigating the potential impact of an attack or hindering attackers.
- Protecting sensitive information about the premises or event from those who do not need it.
Enhanced-tier procedures and measures must be documented, with an assessment of how they reduce the vulnerability of the premises or event and the risk of physical harm. Compliance documents must be provided to the SIA.
The term “immediate vicinity” is used deliberately without a fixed distance. The guidance recognises that what counts as the immediate vicinity will vary by premises, event, and circumstance. This reflects a familiar protective security pattern: assessment, judgement, proportionate measures, and documentation.
Preparation, not products
In publishing the statutory guidance, the Home Office and ProtectUK have been explicit that neither the Home Office nor the SIA endorses third-party products offered by the private sector in respect of compliance with the legislation. The Government’s stated intent is that those responsible for premises and events in scope can comply without needing to buy specialist compliance services.
That is the right framing for the next twelve months. The priority is not to purchase a purported compliance solution. It is to understand scope, identify the responsible person and senior individual where required, determine what is reasonably practicable, draft procedures and enhanced-tier measures, train relevant staff, and create the documentary record the SIA will expect to see. It is also to consider how that preparedness will be evidenced to insurers and underwriters, for whom operational resilience and risk presentation are increasingly linked.
The SIA has powers to access premises and events, gather information, and issue compliance, restriction, and penalty notices. In serious cases, criminal offences are available and senior personnel involved in management or control of the organisation may be prosecuted. The Act does not create a private compensation right, but the regulatory and reputational consequences are substantial.
An insurance market question, not merely compliance
Insurance is not a substitute for the statutory duty, but Martyn’s Law is not merely a compliance issue. It is also an insurance market issue. Five areas merit particular attention:
- Insurance programme coherence will matter more than individual lines. The question is not simply whether each policy responds, but how property, active assailant, liability, management liability, terrorism, and political violence cover holds together in a live incident. Where wording definitions, notification conditions, or coverage triggers do not align across lines, the programmes may fracture at the point it most needs to hold.
- Risk presentation to insurers will become more exacting. Underwriters are likely to ask more detailed questions about preparedness under Martyn’s Law. Procedures, governance, training, and documentation will increasingly shape how the risk is understood and presented to the market. Organisations that can evidence preparedness coherently will be better differentiated than those that cannot.
- Claims defensibility may depend on documented preparedness. After an incident, procedures, training records, assessments, and decision-making may shape the evidential context for claims, investigations, and stakeholder scrutiny. Preparedness is relevant not only to prevention, but also to resilience after the event, and the insurance programme needs to be structured with that in mind before an incident occurs, not during it.
- Governance, senior accountability, and people exposures will matter more. The prosecution risk noted earlier sits alongside management liability exposure. Where a senior individual carries designated responsibility under the Act, how governance, reporting lines, and insurance are documented becomes a live question. A designated individual who cannot demonstrate reasonable steps may be personally exposed.
- Market impact remains unsettled, but insurer confidence will matter. Pricing and capacity implications are still developing. Organisations with proportionate, well-evidenced preparedness will be better placed; those that cannot articulate their arrangements clearly may find placement discussions more difficult.
The new compliance and insurance market expectations go hand in hand. Organisations that treat them separately may find both responses lacking.
The value of a joined-up broking and risk advisory approach is that it connects operational preparedness with insurer expectations, programme design, and claims resilience.
Where to begin
For most organisations clearly within scope, four steps merit attention now:
- Confirm scope properly. Apply the qualifying criteria from sections 2 and 3 of the Act to your sites and events. The grey cases; mixed-use buildings, faith-and-childcare combinations, and parts of premises with separate uses, are where assumptions go wrong.
- Identify the responsible person and, for enhanced-tier premises or qualifying events, the senior individual. Document responsibilities. Where landlords and tenants both control aspects of a site, coordinate now rather than later, and confirm that management liability arrangements reflect the designated individual’s exposure.
- Build the documentary trail. Procedures, enhanced-tier measures where required, training records, vulnerability assessments, and a written rationale for what “reasonably practicable” means in your context. Together, these form the evidentiary record the Act requires, and insurers will increasingly expect to see.
- Review your insurance programme as a whole. Ask one question: if a Martyn’s Law incident occurs at one of your venues, how does the insurance programme actually respond? The answer depends not only on individual policies, but on how those policies interact.
Spring 2027 is closer than it may appear. The purpose of the Act is one most organisations support: to ensure that publicly accessible premises and events are better prepared to keep people safe. The task between now and commencement is to translate that principle into operational reality across people, assets, operations, and reputation, and to ensure that risk, governance, and insurance strategy develop alongside it.
If you would like to discuss how Martyn’s Law affects your sites, events or insurance arrangements, our broking and advisory specialists work together to address the operational, regulatory and insurance implications in the round.
Contact: info@blackthornrisk.com.
What's the difference between the standard and enhanced tiers?
Premises expected to host 200–799 people for a Schedule 1 use fall in the standard tier; 800 or more puts them in the enhanced tier. Qualifying public events with access controls are enhanced-tier at 800-plus, though some categories stay standard-tier regardless of attendance.
Who is the 'responsible person' and can the duty be delegated?
Every qualifying premises or event has a responsible person, usually the organisation in control of it. Enhanced-tier premises and qualifying events must also designate a sufficiently senior individual, and while tasks can be delegated, responsibility cannot.
Does Martyn's Law change my insurance?
There’s no requirement to buy insurance to comply, but preparedness increasingly shapes how underwriters assess and price risk, from programme coherence to claims defensibility. Compliance answers to the regulator, and your insurance programme is what responds if an incident occurs.