Automated Perimeter Security

Automated Perimeter Security

Martyn’s Law: What It Means For Your Site Security

Martyn’s Law: What It Means For Your Site Security

Key Takeaways

  • Martyn’s Law is the Terrorism (Protection of Premises) Act 2025, which received royal assent on 3 April 2025. With a 24 month implementation period, enforcement is expected from around spring 2027. The act establishes legally binding duties for premises and events across the UK that meet certain capacity thresholds, requiring operators to strengthen protective security and terrorism preparedness rather than relying solely on police response.

 

  • The legislation divides premises into two tiers based on capacity: standard tier premises cover venues with 200 to 799 people, while enhanced tier premises apply to venues with a capacity of 800 or more people. Standard tier sites must put proportionate public protection procedures in place. Enhanced duty premises must go further with documented public protection measures, formal risk assessments, and robust physical access control systems including perimeter gates, barriers, and turnstiles.

 

  • Site security under Martyn’s Law covers far more than CCTV and guards. It includes perimeter fencing, automated gates, road blockers, bollards, access control systems, and well rehearsed lockdown and evacuation plans. Automated Perimeter Security can help you prepare, from initial site surveys and design through to installation, maintenance and upgrade of compliant perimeter hardware. Contact us today for a site assessment and a Martyn’s Law ready access control strategy.

 

Introduction: From Tragedy To Legislation: Why Martyn’s Law Matters

In May 2017, a terrorist attack at Manchester Arena killed 22 people and injured hundreds more. Among the victims was Martyn Hett. The attack exposed significant weaknesses in how publicly accessible spaces assess and respond to security threats. Martyn’s Law, named in his memory, aims to prevent future attacks from causing similar devastation.

The terrorism protection of premises legislation is intended to standardise public safety practices across various venues throughout the UK. It encourages organisations to move from voluntary guidance to enforceable duties, building a culture of organisational preparedness. The law mandates that public premises, including stadiums, shopping centres, arenas, visitor attractions, and large outdoor event spaces, take meaningful steps to protect people. The act shifts security responsibilities to venue operators rather than just police.

This article focuses on what Martyn’s Law means specifically for physical site security: your perimeter, your gates, your barriers, your access management, and the procedures that tie everything together. The tone throughout is practical, not alarmist. The legislation requires measures that are “reasonably practicable” and proportionate, not fortress level spending for every premises.

Stadium perimeter gates

 

At A Glance: Does Martyn’s Law Apply To Your Site?

Before planning any upgrades, you need to determine whether your premises or qualifying events fall within the act’s scope. Duty holders must establish whether their site meets the capacity thresholds and is used for public facing activities.

Typical sites affected include:

  • Retail parks and shopping centres
  • Sports grounds and leisure complexes
  • Visitor attractions, museums, and galleries
  • Campuses and conference centres
  • Distribution hubs with visitor receptions or public tours
  • Large restaurants, pubs, and hotels with function spaces
  • Certain premises such as outdoor event sites with identifiable boundaries

Scope required analysis centres on three factors: capacity (how many people could be present at one time), public access (whether members of the public can enter), and the nature of activities. Purely private workplaces with no public footfall are generally outside the act’s scope. According to the government’s impact assessment, approximately 178,900 premises across the UK will fall in scope, around 154,600 in Standard Tier and 24,300 in Enhanced Tier.

Even if your site falls outside the legal scope, reviewing your security posture against Martyn’s Law guidance is sensible best practice. Facility managers and building owners should check current Home Office and ProtectUK guidance well before 2027 for detailed information on compliance.

 

Understanding The Two Tiers: Standard vs Enhanced Duties

Martyn’s Law creates two main duty tiers. Capacity is calculated by reasonable expectation of the total number of people present at any one time, including staff, contractors, and visitors, not just ticket holders.

Qualifying premises will be required to comply with the notification requirements set out by the regulator once the Act comes into force. The tier determines how deep your risk assessments, security plans, and physical measures need to go. For both tiers, a duty holder must be formally appointed to oversee compliance.

The scope required for each tier is summarised below:

RequirementStandard Tier (200–799)Enhanced Tier (800+)
Terrorism awareness trainingYes (basic)Yes (formal, exercised)
Written security proceduresSimple plansDetailed, documented plans
Physical access control measuresProportionateRobust, integrated systems
Risk assessmentBasicDetailed, terrorism-focused
Designated senior individualNot requiredRequired

Automated Perimeter Security can assist both standard tier premises and larger premises in selecting proportionate perimeter and access solutions matched to their tier requirements.

 

Standard Tier Premises (200 to 799 Capacity)

Standard tier applies to venues with a capacity of 200 to 799 people. Duties are designed to be straightforward and manageable without forcing smaller businesses to spend money on major infrastructure overhauls.

Examples include small theatres, community halls, independent cinemas, mid size gyms, medium restaurants with function rooms, and some smaller stadium stands. The act requires public venues at this level to implement proportionate public protection procedures, practical steps that improve protective security without excessive cost.

Core requirements at this tier typically involve:

  • Basic terrorism awareness training for staff
  • Simple written security plans covering evacuation, invacuation, and lockdown
  • Routine checks on doors, gates, and locking mechanisms
  • Clear safe spaces and exit routes
  • Visitor sign in and basic building access controls

Even modest changes to physical access and perimeter can significantly improve protection. Lockable vehicle gates at car park entrances, static bollards at main frontages, and secure side gates all contribute to limiting access and reducing vulnerability. Owners should start now by mapping all entrances and exits and noting where improved physical access control or traffic barriers would support their emergency plans.

 

Enhanced Tier Premises (800+ Capacity)

Enhanced tier applies to venues with a capacity of 800 or more people. These sites face more stringent legislative requirements because of their higher risk profile and larger crowds.

Examples include major sports stadiums, concert arenas, large shopping centres, exhibition halls, big distribution hubs with visitor centres, and major transport interchanges. The law mandates that venues develop security plans to improve preparedness, and venues must conduct risk assessments focused on terrorism threats.

Expected obligations include:

  • Detailed terrorism risk assessments reviewed regularly
  • Formal, documented security plans with incident response procedures
  • Regular training and exercising for all relevant staff
  • Appointment of a designated senior individual
  • Robust physical security layers including perimeter fencing, road blockers, bollards, turnstiles, and high duty automated gates

For enhanced tier premises, investing in resilient physical access control systems and professional maintenance will be central to demonstrating compliance and ensuring compliance with regulatory requirements. Vehicle security barriers at these sites should meet recognised impact standards such as PAS 68 or IWA 14-1.

Car park barriers

 

The “Duty Holder”: Who Owns Site Security Under Martyn’s Law?

A designated duty holder must be appointed to ensure compliance with the law. This is a legal concept, similar to fire safety duties, identifying who holds accountability for security at each premises.

In practice, the duty holder might be a facilities manager, site manager, chief executive, premises licence holder, events director, or landlord, depending on contractual control. Responsibility can be delegated operationally, but legal accountability stays with the duty holder.

Headline responsibilities include:

  • Ensuring risk assessments are conducted and documented
  • Implementing physical and procedural protection measures
  • Making sure staff receive appropriate training
  • Understanding the current state of perimeter and access control, including how automated gates and barriers are configured

Early collaboration between duty holders, security consultants, and suppliers like Automated Perimeter Security is essential to plan upgrades and phased improvements before the 2027 deadline.

 

From Law To Layout: How Martyn’s Law Impacts Your Site Design

Martyn’s Law will influence how new sites are planned and how existing premises are reconfigured to manage threat and crowd movement. Think of your site in security zones: public areas, semi-public zones, and restricted areas where only authorised personnel should gain access.

Typical adjustments include:

  • Repositioning vehicle entrances away from crowd gathering areas
  • Hardening pedestrian approaches with bollards or planter barriers
  • Segregating delivery routes from public routes
  • Adding secure compounds for staff parking

Upgrading perimeter security before the law takes full effect spreads cost and disruption while immediately improving your current risk posture. Automated Perimeter Security can support this by conducting site surveys and advising on practical reconfiguration of gates, barriers, and fencing.

 

Strengthening Your Perimeter: First Line Of Defence

Perimeter security is the outer ring of protection, screening vehicles and managing how people reach your doors. Under Martyn’s Law, these assets directly support duties to manage access, reduce opportunities for hostile vehicles, and provide controllable lockdown options.

Typical measures include:

All equipment must be CE or UKCA certified, correctly installed, and regularly maintained so that perimeter controls operate reliably during both day to day operations and emergencies. Sites should map all vehicle and pedestrian entry points and decide which should be normally open, supervised, or locked down under different threat levels.

 

Physical Access Control Systems: Controlling Who Comes In

Physical access control systems regulate entry to buildings and rooms, determining who can enter specific areas and when. Electronic access control uses computers to manage access, replacing physical keys with various types of credentials; an access card, a fob, mobile credentials, or biometric data linked to a user’s identity.

Access control systems can include biometric systems and smart card readers, and modern systems include biometric technologies for authentication such as fingerprint recognition. Access is granted based on the credential presented, and access control reduces the risk of unauthorized access to sensitive or high security areas.

Under Martyn’s Law, managing access means controlling public entry, backstage or staff-only areas, plant rooms, and service areas that an attacker could exploit. The act does not prescribe specific brands or third party products, but it expects premises to be able to control and restrict physical access in a planned, documented way.

Automated Perimeter Security can help by integrating turnstiles with card readers, linking gate controllers to access control management software, and configuring intercoms for visitor verification. Logging and audit capabilities are crucial for post-incident review and for evidencing that access management policies are actually applied. Modern access control systems can be cloud-native or on-premises depending on your organisation’s requirements, and they allow various credentials to replace mechanical keys across your site.

 

Implementing Access Control Models On Site

Common access control models include DAC, MAC, RBAC and ABAC. In practice, three main types of access control dominate physical security: DAC, MAC, and RBAC. Understanding these helps you choose the right approach for your site.

  • Discretionary access control (DAC): Local managers decide who can use which doors or gates. Common in smaller businesses. DAC models offer flexibility but can lack auditability and consistency.
  • Mandatory access control (MAC): Centrally dictated policies, for example, a security office controlling all external gates with no local override. Access rights are granted based on a strict security policy.
  • Role based access control (RBAC): Permissions are granted based on staff role. A loading bay door might only open for logistics staff during their shifts.
  • Attribute based access control (ABAC): Access is granted based on combinations of attributes; role, time of day, location, clearance level, offering fine grained control for modern applications.

Two-factor authentication enhances security in access control, combining something the person has (a card) with something they know (a PIN) or something they are (a biometric). Access control can be enforced through multi factor authentication methods for high risk zones. Access control allows real time management of permissions, so authorised personnel can be granted access or have it revoked instantly.

Larger or enhanced tier premises should consider moving away from ad hoc DAC to more formal MAC, RBAC, or ABAC style policies for robustness, auditability, and session controls that restrict how long access is valid. Authorized users should only be able to provide access to areas relevant to their function and responsibility.

 

Vehicle Access Management: Barriers, Road Blockers And Bollards

Hostile vehicle mitigation is a critical component of Martyn’s Law compliance for any site where vehicles approach close to crowds or buildings. Controlling vehicle access through designated choke points supports both daily logistics and event time security.

Solutions include:

  • Rising arm traffic barriers for routine vehicle flow management
  • Hydraulic road blockers for high security entrances
  • Crash-rated bollards tested to PAS 68 or IWA standards
  • Controlled loading bay gates separating deliveries from public areas

These systems work best when integrated with wider access management, visitor booking platforms, ANPR cameras, and guard instructions rather than treated as standalone devices. Automated Perimeter Security can design and install these systems, accounting for traffic flow, emergency vehicle access, and local planning constraints.

 

People Flow And Crowd Safety: Turnstiles, Gates And Exits

Martyn’s Law is as much about keeping people safe during an attack as preventing one. Venues must have evacuation, invacuation, and lockdown plans in place, so controlled but safe egress is essential.

The balance between secure entry (half height or full height turnstiles, controlled gates) and fast evacuation requires careful design. Key considerations include:

  • Anti tailgating solutions at controlled entry points
  • Outward opening emergency exits that cannot be blocked
  • Fail safe versus fail secure locks (fail safe releases on power loss for life safety)
  • Avoiding bottlenecks on escape routes during fire safety evacuations

Venue operators should test how quickly gates and barriers can be opened or overridden during drills and record these arrangements in their security plans. Automated Perimeter Security can configure systems to integrate with fire alarm releases and emergency override controls while still supporting day-to-day access management across physical spaces.

 

Linking Access Control With Wider Security Systems

Effective protective security relies on layered, integrated systems where access control, CCTV, alarms, and communications work together rather than in isolation. Access control enhances security for physical and digital assets when connected to monitoring platforms.

Door and gate events including forced entry, a door held open, an unrecognised credential, can trigger CCTV bookmarks or alerts to security teams, improving response times. Access control systems can monitor and log access attempts, creating audit trails that support both Martyn’s Law preparedness duties and post incident investigations.

Some access control systems integrate with visitor management, contractor control, and time and attendance software. This provides improved oversight of who is on site at any time, which directly supports accountability. Effective access control improves accountability in organisations by recording every access event against a verified identity.

When upgrading perimeter or gate systems, plan for future integration. Avoid closed or incompatible hardware. Choosing open protocol devices and digital resources that communicate with your existing building management systems will save time and cost in the long run.

 

Policies, Procedures And Staff Training Around Access

Technology alone cannot deliver Martyn’s Law compliance. Organisations must develop a culture of preparedness to enhance security. Clear procedures and trained staff remain essential.

Key written policies should cover:

  • Visitor sign in and contractor escorting
  • Key and access card issuance and lost card reporting
  • Gate opening and closing rules
  • Lock down and invacuation procedures
  • Managing access to restricted areas

Training staff on how to identify suspicious behavior is required under the Act. Staff should understand basic counter-terrorism awareness (ACT/SCaN or equivalent), know how to operate gates and barriers safely under pressure, and be clear on when to deny access, when to escalate, and how to keep escape routes clear even when tightening security.

Facility managers should test procedures during exercises and update them regularly, reflecting changes to physical access control and site layout. Neither the Home Office nor any other agency will do this work for you, it sits with the duty holder and their team.

 

Maintaining Compliance: Inspections, Testing And Upgrades

Martyn’s Law duties are ongoing, not a one off exercise. Physical security assets must be kept functioning and up to date. Penalties for non compliance can include fines and operational restrictions, so maintaining your systems is not optional.

Routine tasks include:

Keeping records of inspections, maintenance, faults, and fixes demonstrates diligence to insurers, regulators, and the security industry authority if your site is inspected. Automated Perimeter Security offers 24/7 call out with service contracts and can help plan phased upgrades as statutory guidance evolves up to and beyond 2027. If equipment needs repair, fast response is essential for maintaining your security posture.

 

Access Control And Compliance With Other Standards (Including PCI DSS)

Many organisations already operate under compliance frameworks that control physical access. PCI DSS, for example, strictly regulates who can reach cardholder data environments and payment processing areas. Martyn’s Law compliance adds another layer but does not conflict with these existing requirements.

Access control systems help prevent data breaches and theft by restricting who can enter server rooms, payment kiosks, and backoffice cash areas. Digital access control ensures sensitive information is accessible only to authorised users, and access logs protect both customer data and sensitive data from unauthorised exposure. The data owner retains responsibility for ensuring that physical and digital controls work together to protect resources.

The benefit of a unified access management approach is that it supports terrorism protection duties alongside existing regulatory or insurance requirements. Decision makers should treat Martyn’s Law preparations as an opportunity to rationalise and strengthen all access control documentation across digital spaces and physical spaces alike, reducing duplication and improving overall governance. Aligning your security policy across frameworks also protects against potential data breaches by ensuring consistent controls.

 

Working With A Specialist Perimeter Security Partner

Many organisations, especially those managing enhanced tier premises, will benefit from partnering with a specialist rather than relying solely on in house facilities teams. Implementing access control and perimeter upgrades to the standard Martyn’s Law demands requires expertise in design, compliance, and ongoing maintenance.

Automated Perimeter Security offers:

  • Site surveys to map your perimeter, access points, and vulnerabilities
  • Design and supply of CE certified automated gates, traffic barriers, turnstiles, fencing, and road blockers
  • Installation to machinery safety and industry standards
  • Maintenance and upgrades with 24/7 call out for contract customers
  • Nationwide coverage with support from initial consultation through to long-term compliance

We work with your chosen third party providers; architects, consultants, and IT integrators, to deliver a joined-up solution. Unlike relying on generic contractors, a specialist partner understands the interplay between security performance, fire safety, machinery regulations, and day to day operational needs. The private sector will need trusted partners to navigate these changes.

Start early. Engaging before legislation goes live avoids last minute rushes, planning issues, and supply bottlenecks. Contact Automated Perimeter Security today to request a quotation or consultation and review your Martyn’s Law readiness.

 

Practical Next Steps To Prepare Your Site For Martyn’s Law

Use this checklist to get started:

  1. Confirm if you’re in scope: Estimate maximum capacity (staff + visitors + contractors). Check whether your site qualifies as qualifying premises.
  2. Identify your tier: 200–799 = Standard. 800+ = Enhanced. Review exclusions for your sector.
  3. Appoint a duty holder: Name the individual who will own security compliance.
  4. Map your perimeter and access points: Document every vehicle and pedestrian entrance, exit, and boundary weakness.
  5. Review current controls: Assess existing gates, barriers, fencing, locks, and access control against emerging guidance.

Conduct a gap analysis comparing your existing physical security, access management, and procedures against the statutory guidance published by the Home Office. Prioritise quick wins; improving gate locking, clarifying visitor controls, training key staff, while planning more substantial perimeter upgrades on a longer timeline. This phased approach will save time and keep disruption manageable.

Document all decisions, justifications, and planned improvements to demonstrate a “reasonably practicable” approach to risk. Proportionate, well planned enhancements to perimeter security and access control will improve everyday safety as well as ensure you comply with legislative requirements when the implementation period ends.

 

Frequently Asked Questions

Will Martyn’s Law force me to install new gates, barriers or turnstiles?

The act is risk-based and does not prescribe specific products. However, many sites will find that upgrading or adding perimeter and access control measures is the most practical way to address identified vulnerabilities. Small standard tier premises may only need procedural changes and modest physical improvements, while larger enhanced tier venues are more likely to justify substantial hardware investments. Base your decisions on formal risk assessments and choose solutions that improve both day-to-day operations and emergency preparedness. For further information on options, explore the best electric gates for commercial premises.

How soon should I start preparing my site for Martyn’s Law?

Although enforcement is expected from around spring 2027, preparation should begin now. Planning, budgeting, and installing physical security changes takes time, especially for crash rated barriers or road blockers that require foundations. A phased approach works best: awareness and scoping this year, design and procurement next, then installation, training, and exercising ahead of go live. Early action reduces disruption, spreads cost, and immediately improves your current security posture.

What if my business operates from several sites across the UK?

Multi site operators should take a centralised approach: create a standard framework for risk assessments, access control policies, and perimeter standards, then adapt it locally for each site. Prioritise higher capacity or higher profile locations for upgrades while ensuring all premises at least meet baseline good practice. Automated Perimeter Security can support programme level planning and rollout of consistent gate, barrier, and access control solutions across multiple locations nationwide.

How does Martyn’s Law interact with health and safety and fire regulations?

Terrorism protection measures cannot override life safety requirements. Emergency exits must remain usable, and evacuation must not be impeded by security hardware. Design decisions, such as choosing fail safe locks, turnstile bypass routes, and emergency gate releases, must balance security with fire and building regulations. Involve fire safety professionals, insurers, and security specialists together when designing new access control and perimeter systems to avoid conflicts between compliance obligations.

Can smaller businesses handle this without hiring a full-time security manager?

Standard tier duties are designed to be manageable by existing managers with appropriate training and external support. Smaller businesses may rely on a combination of Home Office and ProtectUK guidance, industry associations, and trusted suppliers like Automated Perimeter Security. The key is having at least one named duty holder who understands the site layout, access control arrangements, and emergency plans, and who is empowered to act on monitoring results and identified risks.

More Blogs