The recent publication of statutory guidance under the Terrorism (Protection of Premises) Act 2025, colloquially known as Martyn’s Law, marks a significant evolution in the UK’s approach to counterterrorism preparedness for publicly accessible premises and events. Named in remembrance of Martyn Hett, who tragically lost his life in the 2017 Manchester Arena bombing, this legislation aims to embed a proactive and comprehensive security culture, moving beyond a reactive stance to potential threats. The detailed guidance, released in April, now provides organizations with a clearer understanding of their responsibilities, the tiered framework of obligations, and the critical importance of documented decision-making processes. Liam Lane and Constance Strasser of Peters & Peters offer an expert examination of these developments and outline practical steps for stakeholders to consider.

A Cultural Shift: From Reactive to Embedded Security

The bedrock of Martyn’s Law, as elucidated in the statutory guidance, is a fundamental shift in the perception of security responsibilities. The legislation operates under the assumption that a terrorist attack could occur at any publicly accessible location, irrespective of its profile or the scale of an event. This necessitates a proactive stance, placing the onus on those who operate such venues and organize events to ensure robust preparedness at all times.

This represents a departure from a past where counterterrorism measures were often viewed as a specialized or an after-the-fact concern. Instead, the Act mandates that counterterrorism considerations must be integrated into the core fabric of planning, risk management, and operational decision-making processes. For event organizers, this means that security is no longer an add-on but an intrinsic element of delivering a successful and safe experience for attendees. This cultural recalibration is crucial for fostering a resilient society capable of withstanding and mitigating the impact of potential terrorist threats.

The Tiered Framework: Tailored Obligations for Varying Risks

The statutory guidance introduces a two-tiered system to categorize qualifying premises and events, ensuring that obligations are proportionate to the potential risk posed by their capacity. This tiered approach allows for a more nuanced and effective application of the law.

  • Standard Tier: This tier applies to premises and events with a capacity of between 200 and 799 persons. Organizations within this category are expected to implement a baseline level of security measures. This includes conducting a basic risk assessment to identify potential vulnerabilities and putting in place appropriate mitigation strategies. While less extensive than the enhanced tier, these measures are still designed to provide a foundational level of protection against terrorist threats.

  • Enhanced Tier: For premises and events with a capacity of 800 or more persons, the obligations escalate to the enhanced tier. The guidance specifies that these entities will face more comprehensive requirements. This includes a more detailed and thorough assessment of vulnerabilities, a proactive plan to reduce identified risks, and the implementation of specific security measures proportionate to the assessed threat. The emphasis here is on a robust and evidence-based approach to security planning, ensuring that significant venues and large-scale events are equipped to handle a wider spectrum of potential threats.

The guidance clarifies that qualifying events are treated in alignment with enhanced-tier premises, meaning that event organizers, regardless of whether they own the venue, must adhere to the more stringent requirements if their event capacity reaches the threshold. This ensures that large gatherings, irrespective of their location, are subject to a commensurate level of security scrutiny.

Defining Responsibility: Navigating Complex Stakeholder Relationships

A critical and often complex aspect of Martyn’s Law revolves around the clear identification of responsibility. The guidance firmly establishes that the obligation rests with the person or organization that has "control" of the premises or event. In the context of events, this control can be multifaceted, involving a spectrum of parties such as venue operators, event promoters, production companies, and security contractors.

The guidance acknowledges this inherent complexity and introduces key concepts of "co-operation" and "co-ordination." "Co-operation" is mandated when multiple parties are involved in the delivery of an event, requiring them to work together to ensure security. "Co-ordination" becomes essential when there is more than one "responsible person" identified, necessitating a clear delineation of roles and responsibilities to avoid gaps or overlaps in security provision.

In practical terms, this means that event organizers must meticulously define and document responsibilities at the earliest stages of contracting. It is imperative to ensure that all parties understand their roles, and that assumptions are not made regarding the sole responsibility of venues or third-party providers for security. A failure to establish clear lines of accountability can lead to significant compliance risks and operational confusion, particularly in the unfortunate event of an incident. This clarity is not merely a bureaucratic exercise; it is fundamental to effective security planning and response.

The "Reasonably Practicable" Standard: Proportionality and Safety First

Central to the operation of Martyn’s Law and its accompanying guidance is the principle of "reasonably practicable." This standard acknowledges that while security is paramount, it must be balanced against the practicalities of implementation. The guidance explicitly states that organizations are not required to undertake actions that are not reasonably practicable due to their own safety implications or those of their staff.

This principle moves away from a rigid, one-size-fits-all approach and instead emphasizes proportionality. Measures must be appropriate to the specific circumstances, considering factors such as cost, effort, and operational impact. Crucially, the guidance reinforces that organizations are not expected to implement measures that would place staff or attendees at undue risk. The overarching priority remains the safety and well-being of everyone present.

For event organizers, this necessitates a move from a superficial "checklist" mentality to a structured, risk-based methodology. Instead of simply ticking boxes, they must engage in a thoughtful assessment of their specific environment and potential threats. Examples of practical steps under this standard might include:

  • Enhanced Security Personnel Training: Ensuring staff are trained in threat awareness, suspicious behaviour identification, and basic emergency response procedures.
  • Crowd Management Strategies: Implementing effective plans for managing attendee flow, ingress, and egress to prevent overcrowding and potential stampedes.
  • Physical Security Measures: Assessing and, where appropriate, enhancing the physical security of the venue, such as access control points, lighting, and perimeter security.
  • Emergency Communication Systems: Establishing clear and reliable communication channels for internal staff and for disseminating information to the public during an incident.
  • Collaboration with Emergency Services: Maintaining strong working relationships with local police, fire, and ambulance services to ensure seamless coordination during an emergency.

For enhanced-tier events, the requirement extends to proactively identifying vulnerabilities and taking appropriate steps to mitigate them. The key here is that all decisions must be evidence-based, tailored to the specific context, and not generic. This requires a deep understanding of the event’s nature, the venue’s characteristics, and the prevailing threat landscape.

The Imperative of Clear and Recorded Decision-Making

Accountability under Martyn’s Law extends beyond the tangible outcomes of security measures to the very process of decision-making. Given the inherent flexibility of the "reasonably practicable" standard, organizations must be able to demonstrate how they arrived at their security decisions. This includes evidencing the identification of risks, the consideration of various mitigation options, and the rationale behind selecting or rejecting specific measures.

The maintenance of clear, contemporaneous records is therefore not merely good practice but a critical necessity. For event organizers, these records could encompass:

  • Risk Assessments: Detailed documentation of identified threats, vulnerabilities, and the likelihood and impact of potential incidents.
  • Mitigation Plans: Comprehensive outlines of the security measures implemented, including their scope, purpose, and operational deployment.
  • Meeting Minutes: Records of discussions and decisions made regarding security planning and implementation, involving all relevant stakeholders.
  • Training Logs: Documentation of staff training undertaken, ensuring that personnel are adequately prepared.
  • Incident Reports: Thorough records of any security-related incidents, including the response and any lessons learned.
  • Communication Records: Evidence of communication with regulatory bodies, emergency services, and other relevant parties.

Such documentation will be invaluable not only for demonstrating compliance with the law but also for defending against potential enforcement actions by the Security Industry Authority, mitigating civil claims following an incident, and navigating reputational scrutiny, such as that encountered during a public inquiry. These requirements draw parallels with established regulatory regimes, such as health and safety legislation, where documented reasoning and the proportionality of implemented measures are fundamental to demonstrating due diligence.

Practical Steps for Event Organizers: Preparing for Implementation

Although the Terrorism (Protection of Premises) Act 2025 is not yet in full force, the published statutory guidance signals the urgency for organizations to commence preparations during the implementation period. Proactive engagement now will ensure smoother compliance and a more robust security posture. Key practical steps include:

  • Understanding Capacity Thresholds: Accurately determining the maximum capacity of all events and premises to ascertain which tier of obligations applies. This requires a thorough review of floor plans, seating arrangements, and fire safety regulations.
  • Mapping Control and Responsibility: Clearly identifying all parties with control over premises and events and meticulously documenting their respective roles and responsibilities. This should be a collaborative process involving legal counsel and operational leads.
  • Developing Risk Assessment Methodologies: Establishing a systematic approach to identifying and evaluating security risks specific to each venue and event type. This should involve considering a wide range of potential threats beyond conventional attacks.
  • Implementing Record-Keeping Systems: Putting in place robust systems for documenting all aspects of security planning, implementation, and review. This should be integrated into existing operational and compliance frameworks.
  • Reviewing Contractual Agreements: Amending and creating new contractual clauses to clearly define security responsibilities between venue operators, promoters, security providers, and other stakeholders.
  • Enhancing Staff Training and Awareness: Investing in comprehensive training programs for all staff, focusing on threat detection, emergency response, and communication protocols. This should be a continuous process, not a one-off event.
  • Engaging with Security Professionals: Seeking expert advice from security consultants and counterterrorism specialists to ensure that measures are appropriate, effective, and legally compliant.
  • Liaising with Local Authorities and Emergency Services: Strengthening relationships with local police forces, fire services, and other emergency responders to facilitate coordinated planning and response.

Looking Ahead: A Stepped Change in Protective Security

The statutory guidance confirms the overarching ambition of Martyn’s Law: to deliver a "step-change" in protective security across the United Kingdom. For event organizers, the challenge lies in translating the inherent flexibility of the legislation into security measures that are not only robust and defensible but also practical to implement and maintain.

From a risk management perspective, encompassing reputational risk, operational safety, and insurance considerations, organizations must adapt to this evolving landscape. Those that proactively begin by clarifying responsibilities, adopting a structured and evidence-based approach to risk assessment, and embedding clear decision-making processes will be best positioned to meet the legislative requirements. More importantly, they will be demonstrating effective and proportionate security standards in an increasingly complex and challenging risk environment, ensuring the safety and security of the public while enabling the vibrant cultural and social life of the UK to continue. The legacy of Martyn Hett serves as a poignant reminder of the imperative to remain vigilant and prepared.

By