Written by: Paul Foster, Founder, CEO, OnePlan
Key Takeaways
Martyn’s Law introduces two compliance tiers based on venue capacity, with enforcement expected from spring 2027. Standard Tier venues document and communicate public protection procedures, while Enhanced Tier venues add a terrorism risk assessment and proportionate physical security measures. OnePlan helps you map, model, and export venue plans that support Martyn’s Law compliance.
Step 1: Determine Your Tier Classification
The first task is confirming which tier applies to your venue. The relevant figure is the greatest number of individuals reasonably expected to be present at the same time. That count includes staff, volunteers, and contractors as well as the public.
A 250-capacity nightclub falls under Standard Tier, while an 850-capacity conference centre falls under Enhanced Tier. Places of worship and most education settings remain Standard Tier regardless of capacity.
Common errors include counting only customers and leaving staff out, using average rather than peak attendance, and ignoring occasional high-attendance events. A venue that normally hosts 700 people but runs an annual event drawing 850 must treat that event as Enhanced Tier.
See how OnePlan can help you confirm your tier and map your venue layout accurately. Book a 15-minute demo.
Step 2: Conduct a Terrorism Risk Assessment for Enhanced Tier
A terrorism risk assessment is mandatory for Enhanced Tier premises and must be documented, reviewed regularly, and used to inform the public protection measures implemented. Standard Tier venues are not required to conduct a formal terrorism risk assessment, yet their procedures still need to remain proportionate to the threat.
For Enhanced Tier venues, the recommended methodology is:
- Identify threats: Consider marauding attacks, vehicle-borne threats, improvised explosive devices, and hostile reconnaissance.
- Assess vulnerabilities: Focus on entry and exit points, crowded zones, vehicle approach routes, and areas with limited visibility.
- Evaluate impact: Consider both likelihood and consequence to create a venue-specific threat profile.
- Implement mitigations: Use findings to drive proportionate physical and procedural measures.
- Document and review: Record everything and review at least annually or after significant changes.
Assessments must be site-specific and informed by the venue’s layout, access points, and crowd movement. To make this concrete, OnePlan’s to-scale mapping tools let you outline crowd areas on an accurate, geo-referenced map, identify pinch points, and model ingress and egress flow using OnePlan’s arrival calculator and exit calculator to estimate queue lengths and exit capacity before event day.

Step 3: Train Staff on Public Protection Procedures
Martyn’s Law does not require staff to undertake a specific counter-terrorism training course. However, staff with responsibilities must understand the four public protection procedures and their role in carrying them out effectively. Those four procedures are:
- Evacuation: Moving people away from danger.
- Invacuation: Moving people to a safer place within the premises.
- Lockdown: Securing the premises to prevent entry or exit and restrict movement.
- Communication: Alerting people to danger and providing clear instructions.
Free resources support this training. ProtectUK’s ACT (Action Counter Terrorism) training is free to complete and covers terror threat awareness and security vulnerabilities. The “Run, Tell, Hide” protocol, developed by Counter Terrorism Police, is a foundational principle, adapted to “Guide, Shelter, Report” for staff with responsibilities at larger venues.
For Enhanced Tier venues, the statutory guidance states that effective implementation of public protection measures will depend on appropriate training, learning, or instruction. This makes staff development a more prominent consideration at this tier.
To put those procedures into practice, OnePlan helps communicate them visually. You can place staff as dots on the map with assigned roles and routes, draw clear evacuation and invacuation paths, and share a single live plan so every team member understands their responsibilities before event day.

Step 4: Put Physical Security Measures in Place
Martyn’s Law does not impose a universal shopping list of physical measures. Enhanced Tier measures must remain appropriate and reasonably practicable for the particular premises or event. Informed by your terrorism risk assessment, measures may include the following:
- CCTV surveillance: Cover key areas and eliminate blind spots. Retention policies must comply with the UK Surveillance Camera Code of Practice, including defined retention periods and restricted access to footage.
- Access control: Controlled entry points, turnstiles, and credential management to control and count pedestrian flow.
- Bag screening: A clear prohibited-items policy, trained screeners, and a defined decision path for secondary screening and refusal.
- Hostile vehicle mitigation: Bollards, barriers, and perimeter controls where vehicle threats are identified.
- Communication systems: Clear methods for sending alerts across the site.
OnePlan lets you place security assets, such as CCTV cameras, barriers, screening points, and security personnel, on a to-scale map so you can check coverage and sightlines. Use OnePlan’s arrival calculator to model queue lengths at screening points and prevent bottlenecks before they form on event day. Silverstone uses OnePlan as its single source of truth across more than 50 events a year, achieving a 13x ROI and a 10% reduction in planning days.
Ready to place your security assets on a to-scale map and test your plans? Start your first event free in OnePlan.
Step 5: Create Your Martyn’s Law Documentation Checklist
Once your physical measures are in place, the next step is documenting everything to prove compliance. Documentation is essential. Enhanced Tier venues must submit a compliance document to the SIA. Standard Tier venues must be able to demonstrate their procedures are in place. Use the checklist below as a starting point.
Standard Tier:
- Confirmed tier classification within the 200–799 capacity range
- Public protection procedures documented for evacuation, invacuation, lockdown, and communication
- Staff with responsibilities understand their roles
- Procedures communicated to relevant staff
- Procedures reviewed and updated regularly
Enhanced Tier (Additional):
- Documented terrorism risk assessment completed
- Public protection measures implemented across monitoring, movement, physical security, and information security
- Designated senior individual appointed
- Compliance document prepared for SIA submission
- SIA notification completed
- Measures kept under review and updated after changes or incidents
OnePlan serves as your single source of truth throughout this process. You can build your venue security plan on a to-scale map and export high-resolution plans for SIA submissions and Safety Advisory Group meetings.
Martyn’s Law Timeline and Next Steps
The implementation window is shorter than it first appears, especially for multi-site organizations. Here are the key dates:
- 3 April 2025: Royal Assent
- 15 April 2026: Home Office statutory guidance published
- 15 June 2026: SIA guidance and advice functions commenced
- Spring 2027 (expected): Enforcement begins and the SIA notification portal opens
Implementing procedures, training staff, and running exercises can take 6–12 months for multi-site organizations. Starting close to the enforcement date is unrealistic for anything beyond the smallest single-site premises. Acting now gives you time to test and refine your plans.
Do not wait until spring 2027. Book a demo to start planning your Martyn’s Law compliance in OnePlan.
Frequently Asked Questions
How Do the Standard and Enhanced Tiers Differ?
Standard Tier applies to premises where 200–799 people may reasonably be expected at the same time. It requires public protection procedures covering evacuation, invacuation, lockdown, and communication, plus staff awareness of those procedures. In contrast, Enhanced Tier applies at 800 or more people and adds public protection measures across monitoring, movement control, physical security, and information security, plus a documented terrorism risk assessment, a designated senior individual, and a compliance document submitted to the SIA. The capacity count includes staff, volunteers, and contractors as well as the public.
Do I Need a Terrorism Risk Assessment?
Only Enhanced Tier venues in the 800+ capacity range are legally required to conduct and document a terrorism risk assessment. The assessment must be site-specific, covering threats such as marauding attacks, vehicle-borne threats, and improvised explosive devices, and must be reviewed at least annually or after significant changes to the premises. Standard Tier venues are not required to conduct a formal risk assessment but should still ensure their public protection procedures reflect the current threat environment.
What Training Should Staff Receive?
Martyn’s Law does not mandate a specific paid training course. Staff with responsibilities must understand the four public protection procedures, covering evacuation, invacuation, lockdown, and communication, and know their role in executing them. Free resources include ProtectUK’s ACT (Action Counter Terrorism) training and the “Run, Tell, Hide” protocol, adapted to “Guide, Shelter, Report” for staff at larger venues. For Enhanced Tier venues, the statutory guidance makes clear that effective implementation of public protection measures will depend on appropriate training, learning, or instruction, so staff development becomes a core compliance task.
When Will Martyn’s Law Be Enforced?
Martyn’s Law received Royal Assent on 3 April 2025. The Act includes a minimum 24-month implementation period, meaning enforcement cannot begin before April 2027. The SIA has confirmed that enforcement is expected in spring 2027 and that venues will not be able to notify the SIA until the law comes into force. The Home Office published statutory guidance in April 2026, and the SIA’s guidance and advice functions commenced on 15 June 2026. Exact commencement dates will be set by the Home Office and Parliament through statutory instruments.
Which Physical Security Measures Are Typically Used?
There is no universal shopping list of measures. Controls must be appropriate and reasonably practicable for your specific venue, informed by your terrorism risk assessment. Commonly considered measures include CCTV surveillance that covers key areas without blind spots, controlled access points and turnstiles, bag screening with a clear prohibited-items policy, hostile vehicle mitigation such as bollards and barriers where vehicle threats are identified, and communication systems for site-wide alerts. The Home Office has stated that organizations do not need to hire specialist consultants to comply, because the guidance is designed to be actionable without external expertise.
How Can OnePlan Support Martyn’s Law Compliance?
OnePlan provides a to-scale, collaborative planning platform that makes Martyn’s Law compliance visual, accurate, and documentable. Security managers can map their venue on a geo-referenced satellite base, place security assets such as CCTV cameras, barriers, and screening points to verify coverage and sightlines, model crowd flow and ingress or egress using OnePlan’s arrival and exit calculators, and assign staff roles and routes on the map. Plans export as high-resolution maps suitable for SIA submissions and Safety Advisory Group meetings. Silverstone uses OnePlan to plan the Formula 1 British Grand Prix and more than 50 events annually, achieving a 13x ROI and a 10% reduction in planning days.