An 800-person ticketed concert in Manchester falls under Martyn's Law. The same concert, free and with no access control, in a public park does not. The difference isn't capacity: it's whether anyone checks tickets. That's what section 3 of the Terrorism (Protection of Premises) Act 2025 decides.
What is Martyn's Law and who does it apply to?
Martyn's Law is the name given to the Terrorism (Protection of Premises) Act 2025, chapter 10 of that year's Acts of the UK Parliament. It received Royal Assent on 3 April 2025. Its purpose, according to the preamble, is to require those who control certain premises and events to "reduce the vulnerability of the premises or event" to acts of terrorism and the risk of physical harm to people present. The Home Office's overarching factsheet describes the approach as "tiered", linked to the premises' activity and the number of people it is reasonable to expect to be present at the same time.
The split is two tiers plus a separate category for events. Section 2 defines *qualifying premises*: a building, used "wholly or mainly" for one or more of the uses in Schedule 1, where it is reasonable to expect "200 or more individuals to be present at the same time" and which is not excluded under Part 1 of Schedule 2. Within these premises, *enhanced duty premises* are those that could hold "800 or more individuals at the same time"; the rest are *standard duty premises*. Events are covered under section 3 and only come into scope from 800 attendees.
The Act is not yet in force. The Security Industry Authority, the designated regulator, states on GOV.UK that "the Act is expected to come into force in spring 2027" and that, until then, "you do not need to notify us about your premises or event". That page was published on 17 July 2026. None of this replaces the event security obligations that already exist through licensing, fire safety or health and safety at work: it adds to them.
When is your event an 800-person "qualifying event"?
When it meets all six conditions in section 3 at once. They are cumulative: if one fails, the event falls outside scope. The premises must be a building or other land; it must not be, or form part of, enhanced duty premises; the public must have access to attend; it must be reasonable to expect "800 or more individuals to be present at some point during the event" at the same time; and the event must not be described in Part 2 of Schedule 2.
The fifth condition is the one that should matter most to anyone selling tickets. Section 3 requires measures "to ensure or check" that whoever is entering has paid to do so, holds a ticket or pass, or is a member or guest of a club or association. Put differently: access control is the switch. The Home Office's factsheet on scope for events confirms this from the opposite angle, citing invitation-only wedding receptions, corporate events not open to the general public, and free events with no access checks among those that fall outside scope.
Schedule 2 closes the loop from the other side. Paragraph 3 excludes open parks, gardens and recreational grounds where "there are no measures in place to ensure or check" payment or membership status. Our own reading, not the Act's: a municipal park is out of scope while it stays open, and comes into scope the day a promoter fences it off and sets up a box office with 800 people inside. Same show, same grass, two different regimes depending on who's checking codes at the gate.
The headcount includes staff. The overarching factsheet puts it this way: "200 or more individuals (including staff)". And the factsheet on calculating the number of individuals present allows "methods that premises and event managers may already be familiar with, such as safe occupancy calculations for fire safety purposes or the use of historical data". Anyone who already runs real-time capacity management with a historical record of access by time slot already has half the estimate done.
Who is the "responsible person": the venue or the promoter?
Whoever has control, not whoever's name is on the poster. Section 4 establishes that a person is responsible for a qualifying event if they "will have control of the premises at which the event is to take place, in connection with its use for the event". The Home Office's statutory guidance, laid before Parliament on 15 April 2026 and updated on 25 August 2026, puts it as "the person, organisation or business with control of the premises at which the qualifying event takes place, for the purposes of the event".
The same section 4 allows for several people to be responsible for the same premises or event, each one fully responsible. Section 8 then adds two distinct duties: those who are responsible must coordinate with each other "so far as is reasonably practicable", and those who aren't responsible but are involved must cooperate with whoever is. For a promoter hiring a venue, the practical consequence is that the hire agreement needs to spell out who does what, because the law won't divide it for them.
There's one case worth spotting early, as it saves paperwork. Condition (b) of section 3 excludes from qualifying event status any event held at enhanced duty premises. A concert at a stadium that's already at enhanced duty level because of its own use doesn't create a second regime: the obligation stays with the premises. By contrast, the same promoter staging the same concert at a temporary venue does create its own qualifying event.
Section 10 closes off the chain of command. If the person responsible for enhanced duty premises or a qualifying event is not an individual, they must designate "an individual who is involved in the management or control" of the entity to ensure the entity complies. It's not a new role: it's putting a name and surname where there used to be just a limited company.
Standard and enhanced: what each tier requires
Both tiers share the same starting point and diverge on everything else. Section 5 requires both tiers to have *public protection procedures*: procedures for evacuating, for moving people "to a part of the premises or event where there is less risk of physical harm", for "preventing individuals from entering or leaving" and for "providing information to individuals who are present". These are the Act's four verbs: evacuate, shelter, lock down and inform.
| Obligation | Standard duty (200-799) | Enhanced duty (800+) and qualifying events | Section |
|---|---|---|---|
| Notify the SIA | Yes | Yes | s. 9 |
| Public protection procedures | Yes | Yes | s. 5 |
| Public protection measures | No | Yes | s. 6 |
| Document procedures and submit to the SIA | No | Yes | s. 7 |
| Designate a senior responsible individual | No | Yes, if the responsible person is not an individual | s. 10 |
| Maximum fine for non-compliance | £10,000 | £18 million or 5% of qualifying worldwide revenue | s. 18 |
| Maximum daily fine | £500 per day | £50,000 per day | s. 19 |
| Criminal offence for failing to comply with a notice | No | Yes, up to 2 years' imprisonment | s. 24 |
What the enhanced tier adds is set out in section 6: *public protection measures* across four areas — "monitoring of the premises or event and its immediate vicinity", "the movement of individuals into, out of and within the premises or event", "the physical security of the premises" and "the security of information relating to the premises or event". Section 7 additionally requires procedures and measures to be documented and the document submitted to the SIA.
When do you have to notify the SIA, and within what deadlines?
The deadlines aren't in the Act itself, they're in the secondary legislation. Section 9 requires notification to the Security Industry Authority when someone becomes, or stops being, responsible for qualifying premises or a qualifying event, and leaves the "required time" to regulations. The Home Office's notification guidance, published on 14 July 2026, sets out the figures.
For premises: whoever is responsible on the day the duty comes into force must notify "within a period of three months". After that, changes of responsible person are reported "within 28 days", and information that stops being accurate is also corrected within 28 days. For events the clock is tighter and less forgiving: once the event date is first made public, "the responsible person must notify the SIA before the end of a period of 14 days beginning with the date of that publicity". Corrections also have a 14-day window.
That detail shifts a regulatory obligation onto the commercial calendar. The clock doesn't start with the event or the licence: it starts on the day of the announcement, which is usually the on-sale date. The guidance lists what the form asks for: contact details, address and postcode, identification of the responsible person, capacity figures, website and social media, and licensing details. It also flags something worth reading twice: someone can submit the notification on behalf of the responsible person, but "legal responsibility for complying with the Act cannot be delegated". The SIA is building an online portal and plans to invite volunteers to test it "from early 2027".
The first cogs are already turning. The Terrorism (Protection of Premises) Act 2025 (Commencement No. 2) Regulations 2026, dated 10 June 2026, brought into force on 15 June 2026 section 12(2) and (3), which concerns SIA guidance, and section 18(5) to (7), which requires publication of what counts as "qualifying worldwide revenue". Its explanatory note recalls that an earlier instrument, S.I. 2026/320, had activated section 27 on 10 April 2026. The scaffolding for enforcement is being built before enforcement itself.
How much does non-compliance cost?
The cap depends on the tier, and the gap between the two is enormous. Section 18 sets £10,000 as the maximum where the breach relates to standard duty premises. For enhanced duty premises and qualifying events, the maximum is "the greater of: (a) £18 million and (b) 5% of the person's qualifying worldwide revenue for their last complete accounting period". If the accounting period isn't twelve months long, the amount is adjusted proportionately.
Section 19 adds a daily fine for as long as non-compliance continues after the payment deadline: up to £500 a day for standard duty premises and up to £50,000 a day for enhanced duty premises and qualifying events. Both figures are maximums that the Secretary of State can amend by regulations.
A criminal route exists, but it's narrow. Section 24 creates two offences: failing to comply with a compliance notice where the breach relates to enhanced duty premises or a qualifying event, and failing to comply with a restriction notice. The penalty reaches up to two years' imprisonment, a fine, or both, on indictment. There's a defence: that the person "took all reasonable steps to comply with the notice". Our own reading: for a premises with 200 to 799 people, the risk is financial and reputational, not criminal, because section 24 doesn't reach their compliance notices.
How many premises and events are in scope: the Home Office figures
The scale has been measured and published. The Bill's impact assessment, dated 16 July 2024 and published on 17 September 2024, estimates in its Table 1 a total of 928,554 public locations in the UK: 749,662 out of scope, 154,623 at standard tier and 24,268 at enhanced tier. It also identifies around 975 festivals and expects all of them to fall at enhanced tier as qualifying events.
Three calculations of our own on that table, not the Home Office's. First: 178,891 in-scope premises out of 928,554 is 19.3%; four out of five public locations in the country fall outside scope. Second: 24,268 out of 178,891 is 13.6%, so the enhanced tier — the one with documentation duties and eight-figure fines — is a minority within what's regulated. Third, the one that hits the budget: the assessment calculates £3,313 of cost per standard premises and £52,093 per enhanced premises in ten-year present value terms, that's 15.7 times more. Crossing the 800-person threshold doesn't nudge the cost up a little: it multiplies it.
It's also worth knowing that the entry threshold moved during the Bill's passage. The consultation on the standard tier, open from 5 February to 18 March 2024, described that tier as covering premises "with a capacity of 100 to 799 individuals". The Act as passed says 200 in section 2. The published document and the final text don't match: anyone who prepared using the consultation has the wrong threshold.
What doesn't Martyn's Law require?
It doesn't require buying anything specific. The statutory guidance expands on the four procedures in section 5 and the four categories of measures in section 6, but it doesn't mandate cameras, scanners or a set number of security staff. It defines "appropriate" as fitting the context of the premises or event, and "reasonably practicable" as proportionate: you have to weigh "what can be done to achieve the aims of the procedures or measures, against the cost, time and difficulty of implementing them". A 250-person pub and a 40,000-seat stadium don't respond the same way, because the Act doesn't ask the same of them.
Nor does it replace the licence. The *premises licence* under the Licensing Act 2003, fire safety rules and health and safety at work obligations remain where they were. The only thing the Act touches in that territory is the publication of plans: section 34 and Schedule 4 amend the Licensing Act 2003 and the Licensing (Scotland) Act 2005 to restrict the disclosure of information from plans that would be "useful to a person committing or preparing an act of terrorism". It's the least-discussed part of the Act, and the one that most affects anyone consulting public registers of premises.
And it's not a Spanish-style self-protection plan. In Spain the equivalent obligation is organised by capacity and by region, with different thresholds and documents attached to the licence, as seen in promoters' obligations for festivals there. The British model doesn't ask for a document per authorisation: it asks for standing procedures, registration with a national regulator and, at enhanced tier, a document handed over to that regulator. They're two different architectures for the same problem.
Schedule 2 excludes, besides parks with no access control, Parliamentary premises and devolved administration premises, and those already covered by a transport security plan: aerodromes, rail assets, the Channel Tunnel and port facilities. Part 2 excludes events held at premises used "wholly or mainly" for worship, childcare or education.
Checklist before spring 2027
Eight tasks. None of them need to wait for the final regulations.
Calculate the number of people present and keep a record of the method. This is what decides the tier. Use fire safe occupancy figures or your access history, include staff, and write down where the figure comes from. An estimate with no audit trail doesn't hold up to the SIA.
Check whether your premises fall under Schedule 1. Paragraph 3 covers entertainment, leisure and recreation "primarily for the benefit of visiting members of the public"; paragraph 4 covers sports grounds; paragraph 7 covers attractions "of cultural, historic, tourist or educational interest". If it doesn't fit any of these uses, there's no qualifying premises.
Decide event by event whether each one is a qualifying event. The six conditions in section 3 are assessed per event. The same venue could have an entire season out of scope and one festival inside it.
Set out in the contract who the responsible person is. Section 4 looks at effective control, not who's invoicing. If there's more than one responsible person, section 8 requires coordination: make sure that split is in the venue hire agreement, not in an email.
Put together the four procedures required by section 5. Evacuate, shelter, lock down and inform, with a designated person per shift and a documented rehearsal. It's the only thing the Act requires of both tiers.
If you're at enhanced tier, start the document now. Sections 6 and 7 require measures across four areas and the document to be submitted to the SIA. Pulling together monitoring, flow management, physical security and information security takes months.
Put the notification reminder in the launch calendar. It's 14 days from when the event date is made public. Whoever announces the event also has to notify, so the reminder belongs next to the on-sale date, not in the security folder.
Review what access data you keep. Access control is what brings the event into scope, and it's also the evidence of how many people were there. Access control with logging by point and time slot serves both purposes.
And what does Futura Tickets bring to this?
None of this gets solved by software alone, but two things do depend on the ticketing and access system. The first is capacity data: Futura Tickets recommends in its operational guide setting alerts at 80% and 95% of each zone's capacity, which is the same type of threshold section 6 asks you to monitor for the movement of people. The second is traceability: with Futura Tickets, the attendee database belongs 100% to the organiser, and access control keeps a record of validations that lets you reconstruct how many people were there and when. What no provider can honestly say today is that it complies with Martyn's Law on your behalf: the Act binds the person responsible for the premises or event, and that responsibility cannot be delegated.
Conclusion
Martyn's Law is not yet in force, and the official timetable points to spring 2027. What's already been published is enough to act on: the 200 and 800 thresholds in section 2, the six conditions in section 3, the 14 days to notify an event once it's announced, and the jump from £3,313 to £52,093 in estimated cost between tiers. Calculating the number of people present is the first step, and it doesn't depend on the SIA publishing anything else.
Sources
- Terrorism (Protection of Premises) Act 2025, c. 10: contents (legislation.gov.uk)
- Section 2: qualifying premises, 200 and 800 thresholds (legislation.gov.uk)
- Section 3: qualifying events, the six conditions (legislation.gov.uk)
- Section 4: persons responsible for premises or events (legislation.gov.uk)
- Section 5: public protection procedures (legislation.gov.uk)
- Section 6: public protection measures (legislation.gov.uk)
- Section 9: notification to the SIA (legislation.gov.uk)
- Section 10: designation of a senior responsible individual (legislation.gov.uk)
- Section 18: maximum penalty amount (legislation.gov.uk)
- Section 19: daily penalties (legislation.gov.uk)
- Section 24: offences for failing to comply with a notice (legislation.gov.uk)
- Section 34: plans of licensed premises (legislation.gov.uk)
- Schedule 1: specified uses (legislation.gov.uk)
- Schedule 2: excluded premises and events (legislation.gov.uk)
- The Terrorism (Protection of Premises) Act 2025 (Commencement No. 2) Regulations 2026, S.I. 2026/622 (legislation.gov.uk)
- Terrorism (Protection of Premises) Act 2025: Overarching Factsheet (Home Office, GOV.UK)
- Terrorism (Protection of Premises) Act 2025: Scope (events) (Home Office, GOV.UK)
- Terrorism (Protection of Premises) Act 2025: Statutory guidance, laid 15-04-2026 and updated 25-08-2026 (Home Office, GOV.UK)
- Terrorism (Protection of Premises) Act 2025: Notification requirement, 14-07-2026 (Home Office, GOV.UK)
- Understanding Martyn's Law and the SIA's role as regulator, 17-07-2026 (Security Industry Authority, GOV.UK)
- Terrorism (Protection of Premises) Bill: Impact assessment, 16-07-2024, Table 1 and costs per premises (Home Office, GOV.UK)
- Terrorism (Protection of Premises) Bill: standard tier consultation, 05-02-2024 to 18-03-2024 (Home Office, GOV.UK)
- Martyn's Law Factsheet, 03-04-2025 (Home Office in the media)