Brian Sims
Editor

Martyn’s Law: Making It Work… and How

ASK MOST individuals about Martyn’s Law – formally known as the Terrorism (Protection of Premises) Act 2025 – and you’ll no doubt receive two responses: ‘Are you in scope?’ and ‘What Tier are you?’ With the notification requirements taking clearer shape this year, notes Lloyd Major, there’s another question to be answered: ‘Inside your organisation, who’s actually going to make this work and how?’

The Security Industry Authority (SIA) has confirmed that it’s building a digital notification platform and will test this with users before it goes live. The requirements themselves will not bite until after 3 April 2027 at the earliest (the exact commencement date has yet to be confirmed), but don’t read that as signalling more time to sit on your hands.

Notification should be the output of being ready, not the start of becoming ready. If you’re running multiple sites, ‘ready’ looks like a live register of premises and events, a decision already made on which of them are in scope and at what Tier, a named legal ‘Responsible Person’ in place for each one, someone authorised internally to actually submit and a process for catching changes before they slip past you.

It’s not a case of register once and then forget about it. There are real clocks running here. It’s a collapsing timeframe. Initial notification for qualifying premises is due within three months of commencement. Changes after that generally need reporting within 28 days. Events need notifying within 14 days of the announcement of first going public.

To anyone who’s reading ‘three months’ and relaxes a little, that window isn’t for working out what you own, who’s responsible or whether you’re even in scope. It’s for notifying the regulator. Those are two completely different tasks and only one of them fits inside three months.

Who owns it?

So who owns it? Legally, the Act of Parliament’s ‘Responsible Person’ is often not an individual at all. It’s whichever organisation controls the premises for its relevant use. You can authorise someone else to submit on your behalf, but that doesn’t hand them the legal responsibility. That remains where it started. While responsibility might be delegated, accountability cannot.

Operationally, my advice is: ‘Don’t hand this to Security on its own and don’t hand it to Legal on its own either’. Security knows the protective measures, but might not know that a lease just changed hands. Legal knows the Act, but might not know Operations picked up another venue last month or that a promoter has just booked one of your halls. Events knows a concert’s gone on sale and has no reason to know that publication may have started a statutory clock ticking somewhere else in the business. This needs a workflow, not just an owner.

Ask a multi-agency operation right now who’s responsible for Martyn’s Law and you’ll probably receive five different answers: the landlord, the venue’s general manager, the head of security, the promoter, the security contractor. None of those responses can simply be assumed as correct.

Responsibility follows control of the relevant use. Once several parties are each controlling a different piece of the same site, it stops being obvious pretty fast. If it takes a meeting to answer that question, you're not ready for the notification window. That’s not a criticism by the way. It’s just where most organisations actually find themselves right now.

Boundary question

There’s also a boundary question worth sitting with. Current guidance recognises procedures may need to reach beyond the premises itself into what’s sometimes called ‘Zone Ex’ (ie the ground immediately outside a stadium or wherever a city boundary meets a venue). It matters. Put bluntly, attackers don’t care where your lease line is. Queues form outside the gates. People gather at transport nodes. Fan zones, taxi ranks and pedestrian routes all create their own crowds, often well outside anything you would call your controlled footprint.

The legal boundary tells you where your statutory duty sits. It doesn’t tell you where the threat starts or stops. One definition puts it as running ‘from the venue perimeter to the first point of transport dispersal’. Not perfect, then, but it’s a good enough starting point for a conversation most organisations haven’t had as yet.

None of this needs the regulator’s system to exist first of all. You can build a readiness register today. That task will not be wasted work as it’s the same information that, at some point down the line, goes into the SIA’s own forms in any case. As a minimum, record the legal entity and address, the operator and ‘Responsible Person’, the scope and Tier decision, the maximum expected attendance, an accountable internal owner and contact, notification status and date, anything affecting that notification and the evidence trail resident behind each decision. When it exists, the portal is just the letterbox. Your job right now is working out what needs to go through it.

Keeping track

Organisations are not static so don’t build this once and walk away. Venues change operator. Companies restructure. Capacities are altered. New sites open, events are announced and leases transfer. A register you finish in Q1/Q2 of 2027 starts going stale almost immediately if nothing’s maintaining it. The real challenge was never filling in a Government form. Rather, it’s keeping track of your own organisation – across every premises, every responsibility, every event – as it actually changes.

Which brings me to the one thing I would look to sort out before that three-month clock starts. It isn’t the risk assessment and it’s not the portal login. It’s the trigger. Can you answer this question: ‘When something changes somewhere in your organisation that affects a Martyn’s Law obligation, how does whomever’s responsible for compliance actually find out?’

Marketing announces an event on a Friday afternoon. Does anyone tell compliance a 14-day clock might have just started? Estates swaps the operator on a site. Does security hear about it? Capacity goes up. Does anyone go back and reassess scope or the Tier? A venue’s general manager leaves. Does anyone update who’s accountable? Most of the time the information exists somewhere in the building. It just doesn’t reach the person who needs it.

Current picture 

The organisations that struggle here will not be the ones with weak security. They’ll be the ones where nobody has one current picture of what they run, who’s responsible for it, what has changed and whether that change ever made it to anyone downstream.

Good readiness looks like a system of record, clear ownership, live information and workflows people have actually tested and trust. It’s not about another spreadsheet.

Lloyd Major is Founder and CEO of Halo Solutions (www.halosolutions.com)

Company Info

Western Business Media Limited

Dorset House
64 High Street
East Grinstead
RH19 3DE
UNITED KINGDOM

Login / Sign up