Back to blog home

Are You Ready for Martyn's Law? A Practical Checklist for Security Leaders 

Team Rhombus | Rhombus Blog
by Team Rhombus, on July 21st, 2026
Physical Security
Martyn's Law

Martyn’s Law marks one of the most significant changes to physical security in the UK in decades. But despite the attention surrounding the legislation, many security leaders are still trying to answer a simpler question: 

Are we actually ready? 

Martyn’s Law, formally known as the Terrorism (Protection of Premises) Act 2025, is new UK legislation designed to improve public safety by requiring certain publicly accessible venues and events to prepare for the risk of terrorist attacks. 

The law requires organizations to implement proportionate measures such as documented emergency procedures, staff training, risk assessments, and, for larger venues, additional protective security measures based on their level of risk. Starting in April of 2025, the UK government is allowing businesses up to 24 to come into compliance. Making April of 2027 the expected date of enforcement.  

*This checklist is intended as general guidance and should not be considered legal advice. Organizations should consult the official guidance published by the UK Government and the Security Industry Authority (SIA) for compliance requirements. 

Martyn’s Law Readiness Checklist 

1. Governance & Planning 

□ Determine whether Martyn’s Law applies to your organization. 

The Act applies to many publicly accessible premises and qualifying public events. Start by confirming whether your organization falls within its scope and understanding which legal duties may apply. 

□ Identify whether you’re likely to fall within the Standard or Enhanced Tier. 

The requirements differ depending on your expected occupancy. Understanding your tier early will help you prioritize planning, budgeting, and operational changes. 

□ Assign ownership for preparedness. 

Effective preparedness isn’t owned by security alone. Identify who is responsible across security, facilities, operations, health and safety, communications, and executive leadership. Everyone should understand their role before an incident occurs. 

□ Complete and document a terrorism risk assessment. 

Understand the risks that are relevant to your organization, evaluate potential vulnerabilities, and document your findings. Risk assessments should be reviewed regularly as facilities, operations, and threat environments evolve. 

2. People & Procedures 

□ Document your emergency procedures. 

Your organization should have clearly defined procedures for situations such as: 

  • Evacuation 
  • Lockdown or invacuation 
  • Shelter-in-place 
  • Emergency communications 
  • Coordination with emergency responders 

These procedures should be easy for staff to understand and accessible when they’re needed most. 

□ Train staff regularly. 

Technology cannot replace trained people. 

Employees should understand how to: 

  • Recognize suspicious activity 
  • Report concerns 
  • Follow emergency procedures 
  • Support visitors during an incident 
  • Communicate with emergency responders 

Training should be refreshed regularly and updated whenever procedures change. 

□ Practice your response. 

Tabletop exercises and live drills often reveal operational gaps that aren’t obvious on paper. 

Ask yourself: 

  • Does everyone know their responsibilities? 
  • Can decisions be made quickly? 
  • Are communication channels effective? 
  • Are external partners included where appropriate? 

□ Review and improve after every exercise. 

Preparedness isn’t a one-time project. 

After every drill, incident, or major operational change, review what worked, identify lessons learned, and update procedures accordingly. 

3. Physical Security & Operations 

□ Review entrances, exits, and public spaces. 

Identify areas where people naturally gather or where access may be difficult to control. Understanding how people move through your facility helps prioritize protective measures where they matter most. 

□ Evaluate whether existing security measures match your risks. 

Martyn’s Law encourages organizations to implement security measures that are proportionate to their identified risks. 

Depending on your environment, this could include physical barriers, CCTV, access control, visitor management, security personnel, or other protective measures. 

□ Review your access control procedures. 

Consider questions such as: 

  • Can restricted areas be secured quickly? 
  • Are temporary credentials managed appropriately? 
  • Can emergency lockdown procedures be initiated efficiently? 

Access control should support your emergency response - not complicate it. 

□ Review visitor management processes. 

Visitors, contractors, and temporary workers should be incorporated into your emergency planning. Make sure your visitor processes support accountability and effective communication during an incident. 

4. Technology & Situational Awareness 

Technology isn’t the objective of Martyn’s Law - but it can play an important role in helping security teams respond quickly and make informed decisions. 

Ask yourself: 

□ Can operators verify an incident in seconds? 

When every minute matters, security teams should be able to quickly determine whether an alert represents a genuine threat or a false alarm. 

□ Can multiple locations be monitored from one platform? 

Organizations responsible for multiple facilities benefit from centralized visibility that allows teams to coordinate across sites during an emergency. 

□ Can security systems work together? 

Video, access control, alarms, sensors, and other security technologies should provide a unified view of what’s happening rather than forcing operators to switch between disconnected systems. 

□ Can investigations happen quickly? 

Following an incident, security teams should be able to rapidly locate relevant footage, reconstruct timelines, and share information with stakeholders or law enforcement when appropriate. 

□ Are audit trails and records easy to retrieve? 

Preparedness includes demonstrating what actions were taken before, during, and after an incident. Centralized records and audit logs make that process significantly easier. 

□ Can authorized personnel access information remotely? 

Critical incidents don’t always occur when decision-makers are sitting in a security operations center. Secure remote access can help maintain situational awareness and support faster decision-making. 

How Ready Are You? 

15–18 boxes checked 

Your organization has built a strong foundation for operational preparedness. Continue reviewing official guidance as Martyn’s Law implementation progresses and update your plans as needed. 

10–14 boxes checked 

You’re on the right path, but there may be opportunities to strengthen documentation, staff preparedness, or operational coordination before the legislation takes full effect. 

Fewer than 10 boxes checked 

Now is a good time to begin building a structured readiness plan. Developing procedures, training staff, and improving operational visibility typically takes time, and starting early can help avoid last-minute gaps. See a demo and build your safety plan today!  

Preparedness Is More Than Compliance 

Martyn’s Law isn’t intended to turn every public venue into a fortress – it’s to ensure organizations are better prepared to respond if the unthinkable happens. Organizations that begin that work today will be better prepared to protect their people, support first responders, and respond with confidence when every second counts. 

Ready to support your team? Start with Rhombus today!