TacDesk
All articles

Martyn's Law Won't Regulate You. It's About to Change What Your Clients Ask For.

Duties under the Terrorism (Protection of Premises) Act 2025 are already live and full commencement lands in spring 2027. The legal duty sits with the venue, not the contractor. But the venue is about to start asking you for proof.

By Michael Bryce · 10 August 2026 · 4 min read

Somewhere on your patch, a facilities manager at a 400-capacity conference venue has just read the section 27 statutory guidance and worked out that they are now a "responsible person" under the Terrorism (Protection of Premises) Act 2025. They are not going to hire a compliance consultant to fix this. They are going to ring their security provider.

That call is coming whether you want it or not, so it is worth being ready for it before it lands.

What actually changed, and when

Martyn's Law received Royal Assent in April 2025. On 15 June 2026, the second commencement regulations switched on the core duties for real. Final SIA guidance on the specifics is due this autumn, and full enforcement is expected in spring 2027. That is not far off, and premises operators know it.

The thresholds are set by how many people can be on site at once:

  • Standard tier (200 to 799 people): the responsible person must notify the SIA and put in place "appropriate public protection procedures" covering evacuation, invacuation, lockdown and communication.
  • Enhanced tier (800 or more): on top of that, they need physical security and monitoring measures, and they have to document those procedures, assess how well they work, and submit that documentation to the SIA.

Crucially, the duty sits with the venue, the retailer, the event organiser, the place of worship, the visitor attraction, not with the security company they contract. You are not the responsible person. But you are almost certainly the person they will lean on to help them meet the duty, because you are already the one running the checkpoints, writing the incident reports and staffing the door.

The gap most venues have not clocked yet

Having a plan and being able to prove you followed it are two different things, and the Act is built around the second one. The SIA has said it will run desk-based assessments and on-site inspections, typically with at least 72 hours' notice. When that inspection happens, "we brief our guards on the lockdown procedure" is not an answer. A dated, timestamped record that the briefing happened, who attended, and what checkpoints were completed on the day in question, is an answer.

That is where most venues currently have nothing. Plenty of security contracts still run on a WhatsApp group, a paper occurrence book, and a rota in someone's inbox. None of that produces evidence on demand. It produces a scramble.

Why this is your opening, not just your client's problem

Every venue in the standard or enhanced tier is about to have a conversation with their existing security provider that goes roughly: "can you show us how you'd support this?" The providers who can answer with something concrete, not just reassurance, win that conversation. The ones who cannot are the ones who get shopped around at the next contract renewal.

That is a real commercial opening. It is also a genuinely fresh reason to have the conversation with a client you have not spoken to properly since the contract was signed. Bring them the question before they bring it to you.

Three things worth having ready when that call comes:

  1. A record of what was briefed and when. Not a memory of a toolbox talk, a logged one with names attached.
  2. Evidence checkpoints and patrols actually happened, not just that they were scheduled. Scheduled and completed are different facts, and only one of them holds up in an inspection.
  3. Incident reports that were written at the time, with a timestamp, not reconstructed three days later from memory because that is when someone finally got round to the paperwork.

None of this makes a venue compliant on its own, that is a legal assessment for them and their advisers to make. What it does is give you, the contractor, something real to put on the table when the question comes up, instead of a promise.

Where TacDesk fits

This is exactly the gap TacDesk was built to close for guarding operations generally, and it happens to line up neatly with what Martyn's Law is asking venues to prove. GPS-verified clock-ins, patrol checkpoints and incident reports are timestamped and signed as they happen, not reconstructed afterwards, and they are exportable as an audit-ready record rather than living in a notebook or a WhatsApp thread. When a client's facilities manager asks "can you show me," the answer is a report, not a conversation.

We are not going to tell you TacDesk makes a venue compliant with the Act. That is not our call to make, and anyone who tells you differently is overselling it. What we will say is that the providers who can hand a client evidence, quickly, are the ones who keep the contract when the SIA's guidance lands in full this autumn and enforcement follows next spring.

If your record-keeping currently depends on someone's memory or a filing cabinet, now is a sensible time to fix that, before a client asks and you find out the hard way what you can and cannot produce. Have a look at tacdesk.co.uk to see how the record-keeping side works.

MB

Michael Bryce

Founder of TacDesk. Writes about SIA compliance, operations, and running a UK security company — from someone who actually works the shifts.

Connect on LinkedIn →

See TacDesk in action

Win contracts, pass SIA audits, and run your whole operation from one place. Book a free 30-minute demo.

Book a Free Demo

Get Field Notes

The ACS traps, licensing changes and ops shortcuts we write about — one straight email every week or two, from someone still doing the shifts, not a marketing team. Unsubscribe anytime.