Skip to content
E-DOB

MARTYN'S LAW

Readiness is a record-keeping problem. Start keeping records.

The Terrorism (Protection of Premises) Act 2025 — Martyn's Law — has received Royal Assent, with enforcement expected to follow an implementation period. Qualifying venues will need to show how they identify, record and respond to incidents. That's precisely what E-DOB does.

Maryns-law

What the Act means for venues

Martyn's Law introduces duties for qualifying premises — with requirements scaling by tier — around preparedness, procedures and, for larger venues, documented measures. Whatever final form the guidance takes, one thing is certain: venues that can evidence a disciplined, consistent incident record will be in a far stronger position than venues with a cupboard of paper books.

What E-DOB gives you today

A complete, timestamped, tamper-evident incident history. A full audit trail of who did what and when. Response time records. Checklist completions proving routine checks happened. Analytics showing patterns and hotspots. Structured records you can export and present. E-DOB supports your Martyn's Law readiness with the operational discipline regulators expect to see — and we're building dedicated readiness tooling, shaped with our early customers, ahead of enforcement.

Sheets

Martyn’s Law and Your Security Logs: What Companies Actually Need to Do

Martyn’s Law (the Terrorism (Protection of Premises) Act 2025) is coming. The Act received Royal Assent in April 2025. Statutory guidance was published in April 2026. Enforcement is expected from spring 2027 after the minimum 24-month implementation period. The Security Industry Authority (SIA) will be the regulator. This is not another piece of vague “be more prepared” advice. It creates clear legal duties for the person responsible for qualifying premises and events. And while the Act does not say “you must keep a digital occurrence book,” the practical reality is simple: if you cannot produce clear, timestamped, attributable records of what your team did, when they did it, and how they responded, you will struggle to demonstrate compliance. This post explains exactly what the law requires, where security logs and incident records fit in, and what good operational record-keeping looks like in practice.

Who is in scope?

A premises is in scope if:

It is a building (or building + land) It is wholly or mainly used for one of the specified uses in Schedule 1 (shops, restaurants, venues, hotels, educational settings, places of worship, sports grounds, etc.) It is reasonable to expect that 200 or more individuals (including staff) may be present at the same time from time to time

There are two tiers:

Standard duty — reasonably expected 200–799 people Enhanced duty — reasonably expected 800 or more people (plus qualifying events)

Capacity is assessed by what it is reasonable to expect, not just licensed capacity. The official guidance contains methods for making that assessment.

What the law actually requires

Standard duty premises must:

Notify the SIA that they are responsible (and notify when they cease to be responsible). Have in place, so far as reasonably practicable, appropriate public protection procedures. These are the procedures staff should follow if an act of terrorism occurs at the premises or in the immediate vicinity. The four core types are: Evacuation Invacuation (moving people to a safer place inside) Lockdown Communication

Enhanced duty premises and qualifying events must do everything above, plus:

Have in place, so far as reasonably practicable, appropriate public protection measures that reduce both the vulnerability of the premises and the risk of physical harm. These fall into four broad categories: monitoring, control of movement, physical safety and security, and security of information. Document the procedures and measures (or those proposed) and provide that document to the SIA. The document must explain how the procedures and measures are expected to reduce vulnerability and/or harm. Where the responsible person is not an individual, designate a senior individual who is responsible for ensuring compliance.

Everything is subject to the “reasonably practicable” test. There is no one-size-fits-all checklist of physical measures. What is appropriate for a large stadium is different from a mid-sized restaurant or a university campus.

Where security logs and incident records fit in

The Act does not prescribe a specific format for day-to-day security logs. However, the ability to evidence what you have done sits at the centre of compliance and good practice. Consider what the SIA, the police, an insurer, or a client may later ask:

Did staff know the procedures? Were the procedures practised? Were suspicious behaviours or items logged and acted upon? What actions were taken during an incident or drill? Who made decisions and when? Is there a clear, contemporaneous record that cannot easily be altered after the event?

A paper occurrence book that is illegible, incomplete, or lives in a drawer fails most of these tests. A digital system that creates timestamped, user-attributed, searchable records with attached evidence succeeds at them. Good security logs support Martyn’s Law readiness in several concrete ways:

Evidence that procedures are live, not just written Recording that a lockdown was tested, that staff were briefed, that a suspicious item was reported and the correct response followed, turns a paper procedure into operational reality. Audit trail for the regulator Enhanced duty premises must document their procedures and measures. Day-to-day logs and drill records provide the supporting evidence that those procedures are understood and used. Incident response and post-incident review In a real event, a structured log of actions, communications, decisions and timings becomes critical for emergency services, investigations and learning. Pattern recognition and continuous improvement Repeated issues in the same location, at the same time, or involving the same type of behaviour are invisible in paper books. Digital analytics make them visible. Due diligence for insurers, clients and partners Many organisations already treat robust incident records as a baseline expectation. Martyn’s Law raises that expectation further.

What companies should be recording now

You do not need to wait for enforcement to start building the right habits. Practical areas to cover in your security and operational logs include:

Routine security activity (patrols, opening/closing checks, access control events) Suspicious behaviour or items, including what was observed, who was notified, and what action was taken

Activation or testing of public protection procedures (lockdown, invacuation, evacuation, communications)

Staff briefings and training related to the procedures Drills and exercises, including participation, timings, issues identified and follow-up actions

Any actual security or safety incident, with clear timeline, people involved, decisions made and evidence attached

Coordination with neighbouring premises or events where relevant Reviews of procedures and any changes made

The quality of the record matters as much as the fact of recording. Ideal characteristics are:

Contemporaneous (captured at the time or as soon as practicable)

Timestamped with reliable system time

Attributable to a named user

Structured enough to be searchable and filterable

Capable of attaching or linking supporting evidence (photos, CCTV references, statements, maps)Protected against casual alteration (edit history / audit trail)

Exportable in a clear format when needed

What companies should be recording now

You do not need to wait for enforcement to start building the right habits. Practical areas to cover in your security and operational logs include:

Routine security activity (patrols, opening/closing checks, access control events) Suspicious behaviour or items, including what was observed, who was notified, and what action was taken

Activation or testing of public protection procedures (lockdown, invacuation, evacuation, communications)

Staff briefings and training related to the procedures Drills and exercises, including participation, timings, issues identified and follow-up actions

Any actual security or safety incident, with clear timeline, people involved, decisions made and evidence attached

Coordination with neighbouring premises or events where relevant Reviews of procedures and any changes made

The quality of the record matters as much as the fact of recording. Ideal characteristics are:

Contemporaneous (captured at the time or as soon as practicable)

Timestamped with reliable system time

Attributable to a named user

Structured enough to be searchable and filterable

Capable of attaching or linking supporting evidence (photos, CCTV references, statements, maps)Protected against casual alteration (edit history / audit trail)

Exportable in a clear format when needed

Practical steps to take before spring 2027

Confirm whether you are in scope and which tier applies Use the official Home Office statutory guidance and the ProtectUK resources. Document your capacity assessment. Identify the responsible person (and senior individual if required).

Write or review your public protection procedures Keep them simple, actionable and matched to your premises. Staff must be able to follow them under pressure.

Put the procedures into the hands of the people who will use them Briefing and realistic practice matter more than polished documents.

Establish clear logging standards Decide what must be recorded, by whom, and to what standard. Move away from free-text paper books where they create gaps.

Create a single place for compliance evidence Procedures, training records, drill logs, incident history and reviews should be easy to find and present.

Test your ability to produce records quickly If the SIA or police asked tomorrow for the last six months of relevant incidents and procedure activations, how long would it take you to produce a clear, complete pack?

Review regularly Procedures and measures should not be static. Log the reviews and the reasons for any changes.

How a modern digital occurrence book helps

Systems designed for real security operations (rather than generic form builders) make the above far easier. Features that matter for Martyn’s Law readiness include:

Fast, structured incident and activity logging from any device

Automatic timestamps and user attribution

Ability to attach evidence and link related entries

Checklists for routine procedures and drills

Searchable history and simple analytics

Controlled access and full audit trails

Secure sharing of specific incidents when required by police or partners

Export options that produce clean, professional records

The goal is not to generate more paperwork. It is to make the necessary record-keeping the natural byproduct of good operational practice.

This post is practical guidance based on the published Act, the Home Office statutory guidance, and current understanding of the SIA’s role. It is not legal advice. Requirements are subject to the “reasonably practicable” test and the specific circumstances of each premises. Always refer to the official Home Office statutory guidance and, when available, the SIA’s own guidance on how it will regulate. Martyn’s Law is about reducing the risk of harm if the worst happens. Clear procedures that staff actually know and can execute, supported by honest, reliable records of what happens on the ground, are the foundation of that readiness. The organisations that treat record-keeping as part of operational discipline rather than an afterthought will be in the strongest position when the duties take effect.

Frequently asked questions

The Act received Royal Assent in April 2025, with an implementation period before enforcement — currently expected around 2027. Preparing your record-keeping now is the low-cost, high-value move.
No software makes you compliant — compliance will depend on your procedures and your tier's requirements. E-DOB supports your readiness with the documented records and audit trail those procedures rest on.
Broadly, premises open to the public above capacity thresholds, tiered by size — check the official guidance for your circumstances, and take advice on your specific duties.

Be ready before you're required to be.

Start your 14-day free trial today. No card required.

No card required

We use cookies

We use essential cookies to make E-DOB work, and optional analytics cookies to help us understand how the site is used. You can accept everything, reject non-essential cookies, or manage your preferences.

Read our Cookie Policy →