MARTYNS LAW ENHANCED TIER COMPLIANCEYour plan is not your procedure. And your fire alarm system is not a counter-terrorism tool.With the Terrorism (Protection of Premises) Act coming into force in spring 2027, enhanced tier venues and events face obligations that go far beyond writing a policy document. Here is what compliance actually requires - and where communication technology makes the difference. |
The clock is running. Spring 2027 is not a distant horizon - it is less than twelve months away. For any venue or event that brings together 800 or more people, Martyn’s Law will impose statutory obligations that cannot be satisfied with a folder on a shelf. The Act requires a genuinely operational communication procedure, formal documentation submitted to the Security Industry Authority, and a named senior individual who is personally accountable for compliance.
This is the legislation that Figen Murray - the mother of Martyn Hett, killed in the Manchester Arena attack - campaigned for with extraordinary determination. It is named in his memory, and its purpose is serious: to ensure that the people responsible for public spaces have done everything within their power to protect the people in them. That framing matters. This is not a box-ticking exercise. The Act asks whether your procedure actually works.
| The statutory guidance is explicit: using a fire alarm signal during a terrorist incident is not just inadequate - it is potentially dangerous. Attackers use secondary devices specifically designed to exploit predictable evacuation patterns. A fire alarm drives people toward exits. That can mean driving them into harm. |
Martyn’s Law operates across two tiers, calibrated to venue size. The distinction matters
more than many organisations have yet appreciated.
STANDARD TIER200–799
|
ENHANCED TIER800+ All standard obligations plus:
|
The government has been at pains to say that standard tier compliance does not require expensive technology. That is deliberately reassuring - and accurate. A well-run venue of 300 people can meet its obligations with clear procedures and trained staff.
But at the enhanced tier, the nature of the obligation changes. It is no longer sufficient to have a plan. The Act asks whether your communication procedure can be implemented rapidly and effectively, whether it reaches everyone who needs to be reached - including people who have already evacuated - and whether you can demonstrate all of this to a regulator with an evidence trail, not assertions
“We have a communication procedure” is an assertion. An alert log with timestamps, recipient counts, and exercised templates is evidence. The SIA will ask for the latter.
The Act’s guidance is not merely suggesting that fire alarms are suboptimal. It explains why relying on them during a terrorist incident creates additional danger. Any venue whose communication plan defaults to the alarm system has not read the guidance carefully - and will not pass SIA scrutiny.
Public address systems speak to people inside the building. The Act specifically requires communication procedures that cover the “immediate vicinity” - including people who have evacuated, people in adjacent areas, and people still travelling to the venue. A PA system cannot reach them. SMS can.
The people working at a large event - security contractors, AV teams, caterers, medical staff, staging crews - do not work for the same organisation. They have no shared contact system. The event organiser cannot simply broadcast to all staff via their own HR database, because most staff are not on it. This is the contact problem at the heart of enhanced tier compliance.
A written plan describes what you intend to do. The compliance document that enhanced tier venues must submit to the SIA needs to demonstrate that your procedure is operational. That requires a system that creates a record: alert history, recipient counts, template library, exercise logs.
The named senior individual at an enhanced tier venue is personally accountable for compliance. A senior individual who bears personal liability will want to know that their communication procedure is real, tested, and documented. A plan they cannot exercise is not, in any meaningful sense, a plan at all.
YUDU Sentinel is not the only way for an enhanced tier venue to meet its obligations. The Act does not mandate any particular technology. But the gap between a plausible plan and a genuinely operational communication procedure is significant - and that gap is where Sentinel sits.
The platform was designed for exactly this kind of environment: multiple parties who don’t share infrastructure, communications that need to reach people wherever they are, and an evidence trail that can withstand regulatory scrutiny. Its core capabilities map directly to the enhanced tier requirements.
| Sentinel can reach 100,000 registered contacts via SMS in under 60 seconds. It operates entirely independently of your internal systems - so it remains functional precisely when primary infrastructure is most likely to be compromised. |
Visitors scan a QR code or text a number on arrival. Staff - including every contractor from every third-party organisation on site - register the same way. No app. No pre registration requirement. No shared employer system needed. The multi-employer contact problem is solved frictionlessly, in the seconds it takes to scan a code.
Evacuation, invacuation, lockdown, and all-clear: Sentinel provides pre-configured templates for each. A single click triggers the appropriate message to all registered contacts. Follow-on instructions reach people already outside the venue perimeter - where PA systems fall silent. Every alert is logged automatically.
The compliance document your designated senior individual must maintain is only as credible as the evidence behind it. Sentinel’s full alert history - timestamps, recipient counts, template records - provides the evidential layer. Drills can be run against live templates. Exercises are logged. The SIA asks for demonstrated capability, not stated intention.
Collecting visitor phone numbers at scale creates data obligations. Sentinel handles this by design: mobile numbers are automatically deleted after a venue-configured window. No residual data risk. GDPR-compliant from day one, which also reduces friction at registration - visitors are more likely to register if the data handling is transparent and limited.
|
60s |
24hr |
ISO 27001 |
The burden on hospitality and events businesses is real. Martyn’s Law was not designed to be punitive - the standard tier provisions reflect that. But enhanced tier venues operate at a different scale, with different risk profiles and different legal exposure. The personal accountability of the designated senior individual, the SIA submission requirement, and the potential sanctions for non-compliance change the calculation.
The question is not simply what Sentinel costs. The question is what the absence of a demonstrable, evidenced communication procedure costs if something goes wrong.
| YUDU Sentinel has been designed to be an affordable solution for the events and hospitality sector. The proposition scales from single events to permanent venues with ongoing compliance obligations, and grows with you as your footprint extends. |
Spring 2027 is not far away, and many organisations are discovering that the distance between “we have a plan” and “we have a compliant, operational communication procedure” is greater than they initially assumed. The people who are ready when the Act comes into force are the ones who are building and testing their systems now.
YUDU Sentinel's communication compliance tool for Martyn's Law is operational within 24 hours. The compliance document it supports is built from evidence, not assertions. The people it reaches include everyone who needs to be reached - inside, outside, and beyond your venue.
That is what the Act requires. That is what a communication procedure actually looks like.
Compliant in 24 hours. Evidenced for life.Whether you manage an enhanced tier venue or run qualifying events, Sentinel gives you the communication procedure your compliance requires - deployed fast, documented automatically. |