On 3 April 2025, a new law reshaped the rules for event organisers across the UK. The Terrorism (Protection of Premises) Act 2025, known as Martyn's Law, creates for the first time a legal duty for public venues and events to prepare and plan for public safety.
It is expected to take effect in spring 2027. That may sound far off. It isn't.
From 200 people present at the same time, your event falls within the scope of the law. Above 800, the requirements step up considerably.
Many organisers still believe this only concerns stadiums and large arenas. That's a misreading. Conferences, exhibitions, corporate seminars: most B2B formats are affected.
The good news? The law rests on a principle of proportionality. You don't have to turn your event into a fortress. You have to show that you have taken reasonable steps.
This article breaks it down. What Martyn's Law actually says, which tier you fall into, and above all how to prove that you control the number of people present. Because that is where it all comes together.
Understanding Martyn's Law and why it exists
Behind this law lies a personal story.
In May 2017, a serious incident took place at a concert venue in Manchester. Among those affected was a young man named Martyn Hett. The law now carries his first name.
His mother, Figen Murray, turned that experience into a campaign. For years, she pushed for a law that would require public venues to prepare better.
So Martyn's Law is not just another piece of red tape. It is a direct response to a gap in preparedness identified through the official review that followed the incident.
This law also reflects a broader context: public safety planning for large gatherings has become a growing area of focus in the UK, with authorities encouraging venues to plan ahead rather than react after the fact.
So what does the law actually change? It places a duty to prepare on venues and events open to the public. The Security Industry Authority (SIA) is the designated regulator.
The Act introduces a new logic for many players. Until now, this kind of preparedness rested mostly on goodwill. It becomes a regulated duty, with a regulator, thresholds and penalties attached.
And the penalties are not symbolic. For the enhanced tier (the stricter tier, above 800 people), fines can reach £18 million or 5% of worldwide revenue, with daily penalties for persistent breaches. Senior individuals can also be held personally liable in certain cases.
For organisers, event security compliance moves from good practice to legal obligation.
One principle guides the whole framework: "reasonably practicable." In other words, your duties are proportionate to your size and your means. A 250-person seminar will never face the same requirements as a 5,000-strong convention.
The aim is not to multiply security gates. It is to reduce risk in a reasonable, documented way.
Then there's the timeline. Royal Assent dates from April 2025. The government has set an implementation period of roughly 24 months. The law is expected to take effect in spring 2027, though the exact date has not yet been confirmed.
Put simply: you have time to prepare. You don't have time to ignore it. The statutory guidance is being firmed up throughout 2026, and serious organisers are already building their approach.
Why get ahead rather than scramble? Because a proper compliance effort touches your organisation, your teams and your tools. These are jobs that take months, not days. Recurring events have every reason to build Martyn's Law thinking into their next editions.
First concrete step: work out which category you fall into.
Standard tier (200-799): the baseline duties
This is the category that covers the majority of B2B events.
The trigger threshold is worth pausing on. It covers venues and events where 200 to 799 people may be present at the same time, at peak times.
The phrase "at the same time" is decisive. It's not the daily total. It's the peak footfall at any given moment. An exhibition that sees 1,500 visitors across eight hours, but never more than 600 at once, sits in the standard tier.
At this level, the duties remain manageable. They come down to two strands:
- Notify the SIA as the person responsible for the venue or event.
- Put in place reasonable public protection procedures: evacuation, invacuation, lockdown, communication in the event of an incident.
One point reassures from the outset. No costly physical measures are required at the standard tier. No mandatory security gates, no heavy equipment to fund.
The spirit of the law lies elsewhere. It's about preparedness, not fortifying the site.
What does "preparing" mean in practice? Training your teams in the right reflexes. Knowing who raises the alarm, who evacuates, who coordinates. Documenting your procedures so you can present them.
Take a simple example. In an alert, do your front-of-house teams know where to direct attendees? Does your production desk know how to cut the music and broadcast a clear instruction? These reflexes are built in advance.
Picture a 400-person annual staff seminar in a conference centre. You sit in the standard tier. In practice, you'll need to have identified your exits, appointed zone leads, and briefed your suppliers on what to do. Nothing insurmountable, but nothing improvised either.
It's also a matter of operational common sense. Many of these reflexes overlap with what you already do for crisis management or fire evacuation.
So the difficulty isn't technical. It's organisational. You have to appoint owners, write the procedures, drill the teams.
A tip from the field: don't start from scratch. Most organisers already have evacuation plans and safety instructions. Martyn's Law asks you to formalise them, extend them to cover this specific type of risk, and check that everyone knows them.
Think about traceability too. A procedure that exists but that no one can evidence counts for little in front of a regulator. Date your documents, keep a record of your training, archive your team briefings.
Above 800 people, however, the bar rises sharply.
Enhanced tier (800+): the stricter duties
At this level, the requirements change in nature.
The enhanced tier covers large events: major congresses, large-scale exhibitions, conventions gathering several thousand attendees.
First difference, and a significant one. Documentation becomes mandatory. You must document your procedures and measures, then submit them to the SIA. The burden of proof becomes formal.
Second difference: measures to reduce vulnerability. It's no longer only about knowing how to react. You also have to reduce the site's exposure to safety and security risks.
That can include surveillance, access control, or protective measures where they are practicable. Always under the principle of proportionality: what's expected of a large convention centre differs from what's asked of an outdoor event.
Third difference, often underestimated: governance. Someone has to own compliance. A named lead, with a clear mandate and follow-through over time.
Picture a trade show of 2,000 visitors over three days. You sit in the enhanced tier. You'll need to assess the site's vulnerabilities, define suitable measures, appoint a lead, then submit the whole package to the SIA. All of this is prepared months ahead, in coordination with the venue and your security suppliers.
The venue and the organiser share the responsibility, incidentally. Clarify who does what at the contract stage, not the night before doors open.
In practice, the enhanced tier calls for a genuine project approach. You don't tick a box the day before. You build a framework, document it, and keep it up to date.
Watch out for a common trap. An event that grows year on year can shift from the standard to the enhanced tier without the organiser having anticipated it. Going from 750 to 900 attendees changes your category, and therefore your duties.
Hence the importance of tracking your real footfall over time. Not just on the day, but from edition to edition. Your registration and attendance figures become a regulatory management indicator.
This documentary requirement has a direct consequence. You must be able to demonstrate, with evidence, that you control your event. Including the number of people present.
And this is precisely where many organisers discover a blind spot.
The real challenge: proving how many people are present
It all starts with a number. You still have to know it.
Look closely at how the law works. Your tier depends on the number of people present at the same time. Your duties flow from it. So does your ability to prove your compliance.
Yet many only know that number approximately. A rough estimate. A manual count at the end of the day. A paper register quickly overtaken when the crowd builds.
The problem is obvious. If you underestimate your footfall, you think you're in the standard tier when you actually fall under the enhanced tier. You're non-compliant without even knowing it.
The reverse is costly too. Overestimating means imposing disproportionate duties on yourself, and therefore wasting time and money.
Manual counting quickly shows its limits. At peak times the flow accelerates, the queues stretch, and no one keeps a reliable tally with a handheld counter. The result? A rough figure, impossible to defend in front of a regulator.
In the event of an inspection, the stakes become even more concrete. How do you show you controlled your headcount at a given moment? A handwritten notebook won't cut it. Nor will a verbal estimate.
This is where a real-time registration and check-in solution changes everything. Each entry is scanned, timestamped, counted. You know, to the minute, how many people are inside your venue.
At Digitevent, we support more than 3,000 organisers, and this live visibility on who's present is increasingly high on their list. Registration data stops being a mere logistics tool. It becomes a piece of compliance evidence.
Since Martyn's Law was passed, we've seen a shift in what UK teams ask for. Check-in is no longer seen only as a way to speed up the door. It becomes a way to secure a legal duty.
"With Martyn's Law, counting who's present is no longer a nice-to-have, it's evidence. Knowing exactly how many people are in the room, and being able to document it, is what will make the difference during an inspection" says Jonathan Astruc, Co-founder at Digitevent.
A real-time check-in delivers three simple things:
- A precise, timestamped count of every entry and exit.
- Live visibility on the exact number of people present at any moment.
- An exploitable history, ready to be presented to the SIA if needed.
This data serves far beyond compliance. It helps you decide in real time. Should you stagger entries? Open an extra room? Trigger a crowd management plan? You steer on figures, not on a hunch.
A word on personal data, since the question often comes up. Tracking a headcount doesn't mean collecting more information than necessary. What matters is the number and the timestamp, in line with the UK GDPR.
In short: you turn a regulatory constraint into reliable data. And you stop steering your headcount blind.
Spring 2027 is prepared now
Let's recap. Martyn's Law imposes a duty to prepare from 200 people present at the same time, stepped up above 800. The regulator is the SIA. The law is expected to take effect in spring 2027.
Under the Terrorism (Protection of Premises) Act 2025, event security compliance is now something you can plan for, not a surprise to absorb.
Your next steps are clear. Identify your tier based on your real peak footfall. Notify the SIA when the time comes. Document your procedures. Train your teams. And equip yourself with the tools that prove, with figures, that you control the flow of your attendees.
That last point often makes the difference. Organisers who build their check-in and attendance tracking now will approach the deadline a step ahead. The rest will meet the requirement in a rush.
One final piece of advice, whatever your tier. Don't treat Martyn's Law as an isolated box to tick. Tie it to what you already do: registration, on-site welcome, evacuation plans, post-event reporting. Compliance then becomes an extension of your operation, not an extra layer of admin.
Spring 2027 feels far off. It's prepared in 2026.
Want to know exactly how many people are at your event, at every moment, and be able to prove it? Request a demo of Digitevent and see how real-time check-in secures your compliance.
For more insights, explore our event registration and check-in resources on the blog.



