The Terrorism (Protection of Premises) Act 2025 does not mention CCTV once, and that is exactly why so many venues will get it wrong. Here is what the enhanced-tier duty really asks of a camera estate, what the SIA will want to see on paper, and how to tell whether the system you already own can carry its share of the evidence.
On 3 April 2025 the Terrorism (Protection of Premises) Act 2025 received Royal Assent. It is better known as Martyn's Law, after Martyn Hett, one of the twenty-two people killed in the Manchester Arena attack of 22 May 2017, and it exists because of his mother Figen Murray's campaign. The Act creates a legal duty on the people responsible for public venues to be prepared for a terrorist attack and, for the largest premises, to take measures that reduce their vulnerability to one. The Government committed to an implementation period of at least twenty-four months, which puts the duties on a path to commence from spring 2027, with the Security Industry Authority as regulator.
This article is for the people who run cameras: security managers, estates and facilities teams, and the installers and integrators who look after them. It is deliberately not a general explainer of the Act, of which there are many. It answers a narrower question that keeps coming up in our conversations with venue operators: what does Martyn's Law actually require of my CCTV, and how do I show it?
The honest answer begins with a fact that surprises most people. The Act does not mention CCTV. Nothing in it mandates a camera, a recorder, an analytics feature or a control room. What it mandates, for enhanced-tier premises, is a set of outcomes called public protection measures, documented in a form the regulator can inspect. Cameras are one of the most common ways of meeting one of those outcomes, which is why the state of a venue's video estate will matter a great deal — but as evidence of a measure, not as a tick-box in its own right.
- Two tiers. Standard tier: premises where 200 to 799 people (including staff) may reasonably be expected at the same time. Enhanced tier: 800 or more. Only the enhanced tier carries a duty to put measures in place; the standard tier is about procedures and training.
- Four areas of measures. Section 6 of the Act lists them: monitoring of the premises and immediate vicinity; movement of individuals; physical safety and security; and security of information. CCTV sits squarely in the first and, less obviously, is itself subject to the fourth.
- The standard is proportionality. Everything is qualified by "so far as is reasonably practicable" and "appropriate". The statutory guidance defines reasonably practicable as proportionate: what can be done, weighed against cost, time and difficulty.
- It must be written down. Enhanced-tier premises must document their procedures and measures, including an assessment of how they reduce vulnerability and harm, and provide that document to the SIA.
- The penalties are real. Up to £10,000 for standard-tier contraventions; for enhanced-tier premises, the greater of £18 million or 5% of qualifying worldwide revenue, with daily penalties available for continuing breaches.
1. Is your premises in scope, and which tier?
Scope is decided by use and by numbers, not by sector label. Schedule 1 of the Act lists the uses that can bring premises into scope: shops; food and drink; entertainment and leisure; sports grounds; libraries, museums and galleries; halls; visitor attractions; hotels; places of worship; health care; bus stations and railways; aerodromes; childcare; primary, secondary, further and higher education; and public authorities. A premises used for one or more of those purposes is in scope if it is reasonable to expect, from time to time, that 200 or more individuals including staff may be present at the same time. At 800 or more it is in the enhanced tier. Qualifying events, where 800 or more people are expected and entry is controlled, are treated like enhanced-tier premises.
Some premises are excluded by Schedule 2: legislatures, open-air parks and gardens with no access control, and transport premises already covered by their own counter-terrorism regimes. The Home Office has published separate guidance on how to assess "reasonable expectation" and on what counts as the principal use of a building, and ProtectUK hosts decision flowcharts. Those are the right starting points; the arithmetic is not always obvious for mixed-use estates such as hospitals, campuses and shopping centres, where several Schedule 1 uses share one building.
The practical consequence for a camera estate is simple. If you are standard tier, the Act asks for procedures and trained people, not equipment, and nothing below applies to you as a legal matter (though some of it is good practice). If you are enhanced tier, read on.
2. What the enhanced-tier duty says, in the Act's own words
Section 6 requires the responsible person to "assess and keep under review the public protection measures that are appropriate" and, so far as is reasonably practicable, to ensure that such measures are in place. The measures must further two objectives: reducing the vulnerability of the premises or event to acts of terrorism, and reducing the risk of physical harm to individuals if an attack occurs. They relate to four matters:
| Section 6 area | What the statutory guidance says it is for | Where a camera estate contributes |
|---|---|---|
| Monitoring of the premises, event and immediate vicinity | "to enable the detection and identification of suspicious activities and items that may be indicators of a terrorist attack" | Directly. Live coverage of approaches, entrances, queues and the immediate vicinity; the ability to see and act on suspicious behaviour in real time; retrievable footage afterwards. |
| Movement of individuals into, out of and within the premises | "to control, prohibit, restrict or reduce the movement of people" | Indirectly. Cameras on search lanes, barriers and crowd pinch points support the people and processes that do the controlling. |
| Physical safety and security of the premises | "to strengthen the physical safety and security of premises and events to mitigate the potential impacts of attacks and/or deter or hinder attackers" | Supporting role. Coverage of hostile-vehicle mitigation, stand-off zones and perimeter; camera-tamper and offline alerting as a measure of the system's own integrity. |
| Security of information about the premises | "to ensure that information about the premises, their operation, design, usage or internal workings are not widely available and accessible to those who may use it for planning a terrorist attack" | Here the camera system is a risk as much as a tool. Footage, camera placement plans, network diagrams and VMS logins are precisely the information an attacker planning reconnaissance would want. |
Paragraph 8.11 of the statutory guidance adds that measures may be implemented through people (briefed and trained staff), policies or processes, and physical mitigations, naming "hostile vehicle mitigation measures or CCTV systems" as examples of the last. Paragraph 8.12 is the one to pin above the control-room door: implementation "needs to be tailored to each qualifying premises or qualifying event, avoiding a one-size-fits-all approach."
3. "Monitoring" is a capability, not a camera count
Because the duty is framed as detection and identification of suspicious activity, the questions the SIA is entitled to ask of a monitoring measure are about capability and operation, not hardware inventory. For a camera estate they reduce to five:
- Coverage. Do the cameras actually see the places where an attacker would need to be — approaches, queues outside the line of control, entrances, the immediate vicinity — or only the places that mattered for shoplifting and slips? Attack planning depends on reconnaissance, and reconnaissance happens outside and at the edges, not in the middle of the sales floor.
- Liveness. Is anyone watching, or able to be alerted, at the times the premises is busy? Recorded-only CCTV is evidence after the fact; it is not monitoring in the sense the guidance describes.
- Detection. Can the system draw an operator's attention to the patterns that matter — a person dwelling at a location for an unusual time, a vehicle stopped where it should not be, an object left and walked away from, a camera that has been covered or moved — or does detection depend entirely on a human noticing in a wall of tiles?
- Retrieval and evidence. Can footage of a specific place and time be found quickly, exported with its integrity preserved, and handed to the police in a form they can rely on?
- Integrity of the system itself. Does anyone know when a camera has gone offline, when it was last patched, and who has logged into the recorder?
None of these requires a particular brand or a particular analytics vocabulary. All of them can be evidenced in the compliance document with a camera plan, an operating procedure, an alert configuration and a test log. That is the shape the evidence should take.
4. Security of information: the measure that points back at the CCTV system
This is the part of Section 6 that most camera estates fail without realising it, because it inverts the usual way of thinking about surveillance. The system that watches the premises is also one of the richest sources of information about the premises: camera positions reveal blind spots; recorded footage reveals routines, guard changeovers and search procedures; the VMS login reveals all of it to anyone who has it.
The guidance's objective is that information about the premises' "operation, design, usage or internal workings" is not available to those who would use it for attack planning. Applied to a video estate, that produces a short, concrete checklist:
- Where can the cameras be reached from? A camera on the same network as guest Wi-Fi, or exposed to the internet through a port forward for remote viewing, is reachable by exactly the people the measure is meant to exclude. Camera networks should be isolated, with no inbound path from the internet and only an outbound, authenticated path to wherever the video is viewed.
- Who holds the credentials? Default passwords, shared operator logins and camera passwords stored in plain text on a recorder are an information-security failure in their own right. Credentials belong in an encrypted store on the device that needs them, under named accounts with multi-factor authentication for anything reachable off site.
- Where does the footage go? If recordings are copied to a cloud service, the operator should be able to say in which jurisdiction, under whose encryption keys and under what access rights. The guidance does not prohibit cloud; it asks that information be controlled, which means being able to answer those questions in writing.
- Is there an audit trail? Who viewed what, who exported what, and when. Without it the operator cannot show control of the information, and cannot investigate a leak.
- Are the devices themselves trustworthy? Firmware age, vendor patch cadence and the ability to keep a camera on a supported, authenticated protocol all bear on whether the estate can be kept secure. This is where the ONVIF Profile S deprecation in March 2027 and the UK Government's 2022 direction on Chinese-manufactured equipment at sensitive sites converge with Martyn's Law on the same estates, often in the same budget year.
Treated this way, the information-security measure is not an abstract policy; it is a set of properties of the camera network that can be inspected, tested and written down.
5. The document the SIA can ask for
Section 7 requires enhanced-tier premises and qualifying events to document their public protection procedures and measures and to provide that document to the Security Industry Authority. The document must include an assessment of how the procedures and measures will reduce vulnerability and the risk of harm, and Section 10 requires a designated senior individual to be responsible for compliance where the responsible person is an organisation. Chapter 8 of the statutory guidance covers both; Chapter 9 sets out the compliance regime around them.
For the video estate, the pages of that document that an inspector will turn to first can be anticipated now:
| What to include | Why it matters |
|---|---|
| A camera plan marked against the areas Section 6 names: approaches, vicinity, entrances, movement-control points, physical-security features | Shows coverage was designed against the measures, not inherited from a previous purpose |
| The monitoring operating procedure: who watches, when, how alerts are raised and escalated, how it links to the evacuation, invacuation, lockdown and communication procedures required by Section 5 | Turns hardware into a measure |
| The alert and detection configuration, with a record of when it was last tested | Evidence that detection is real and maintained |
| The evidential-export procedure and a sample export with its integrity record | Evidence the footage can be relied on |
| The information-security statement: network isolation, credential handling, access control, audit logging, where footage is stored and under whose keys, firmware and vendor support status | The Section 6 fourth area, applied to the system |
| Maintenance, uptime and camera-offline records | Shows the measure stays in place, which the Act requires |
| The review date and the name of the designated senior individual | Section 6 requires measures to be kept under review; Section 10 requires accountability |
Note what is absent from that list: a vendor certificate. There is no such thing as "Martyn's Law compliant" CCTV. The Home Office factsheet states plainly that premises "do not need to spend money on consultants to be compliant" and that neither the Home Office nor the SIA endorses third-party products. Any supplier offering a compliance badge should be asked which section of the Act it refers to.
6. How the SIA has said it will behave
The regulator's public statements so far point the same way as the legislation. In March 2026 the SIA committed to "a proportionate, supportive approach as the regulator", to inspection that is "fair and realistic", and to regulatory decisions "guided by risk". Statutory guidance under Section 27 was published by the Home Office in April 2026 and updated in August; the SIA consulted on its own Section 12 guidance in April. A notification requirement — telling the SIA that a premises is in scope — has its own guidance published in July 2026.
The sensible reading is that the first period of enforcement will reward venues that can show a considered, documented, proportionate set of measures, and will concentrate on those that cannot show anything. A camera estate with a plan, a procedure, a test log and an information-security statement is in the first group even if the hardware is modest. A brand-new system with no documentation is in the second.
7. A practical audit of the estate you already have
The question most enhanced-tier operators will face in the next twelve months is not "what should we buy" but "can what we already own carry its share of the evidence, and what is the smallest change that gets it there." A useful audit takes a few days and asks, for each site:
- Coverage against Section 6: map every camera to monitoring, movement, physical security or none, and identify the approaches and vicinity that are not covered.
- Operation: who monitors, when, and how an operator is alerted; whether any detection is configured and whether it has ever been tested.
- Evidence: time-to-retrieve for a given place and time; export format; whether exports carry an integrity record.
- Information security: network reachability of every camera and recorder; credential handling; remote-access path; audit logging; where footage is stored and under whose keys.
- Device health: firmware versions and vendor support status; cameras that will lose standards support in 2027; equipment affected by the UK Government direction on sensitive sites.
- Documentation: whether any of the above is written down in a form the designated senior individual could sign.
The usual outcome is that most of the cameras stay, a minority need to move or be replaced, and the biggest gap is not hardware at all but the operating procedure, the alerting, the information-security controls and the paperwork. That is good news for budgets and bad news for anyone who was hoping a purchase order would make the question go away.
Where DevSpark fits
DevSpark is a UK engineering company working on video interoperability, edge AI and the security of camera networks, and the platform we build is designed around the properties this article describes: cameras kept on an isolated network with no inbound path, credentials held encrypted on the edge device rather than in a cloud, detection running on site, an append-only audit trail, evidential export with integrity hashes, and offline and tamper alerting. We also do the engineering behind the estate questions — ONVIF Profile S to T migration, camera refresh with allied-manufactured equipment, and the network and credential work that the security-of-information measure turns on.
What we offer enhanced-tier operators and their integrators is the audit in Section 7 as a fixed-scope piece of work, a written monitoring and information-security section for the compliance document, and, where the estate needs it, the platform underneath. We do not offer a compliance certificate, because none exists, and we will say so if an existing system already does the job.
See also: ONVIF Profile S deprecation 2027: what it means for your estate → — the other 2027 deadline landing on the same cameras. DevSpark VMS → — the platform.
Sources: Terrorism (Protection of Premises) Act 2025 (2025 c. 10), sections 2, 3, 5, 6, 7, 10, 12, 18 and Schedules 1–2, legislation.gov.uk; Home Office, Terrorism (Protection of Premises) Act 2025: statutory guidance (published April 2026, updated 25 August 2026), Chapters 3, 4, 8 and 9, in particular paragraphs 8.11–8.14; Home Office, Martyn's Law factsheet (3 April 2025) and Terrorism (Protection of Premises) Act 2025: factsheets (24 July 2026); Home Office, notification requirement guidance (14 July 2026) and principal use of premises guidance (10 September 2026); Security Industry Authority, A proportionate approach to Martyn's Law regulation (5 March 2026) and Martyn's Law: draft section 12 statutory guidance consultation (15 April 2026); ProtectUK, Martyn's Law resources. Quotations are from the Act and the statutory guidance as published; this article is engineering and operational guidance, not legal advice, and the responsible person should take their own advice on scope and compliance. Current at the date of publication.
More from Info
Related reading
30 Sep 2026
Profile S to Profile T: The Engineering Migration Guide for Camera Manufacturers
ONVIF stops accepting Profile S declarations on 31 March 2027. For a manufacturer with a Profile S only product line tha…
29 Sep 2026
How Much Storage Do 40 Cameras Need? A Worked Answer, With Sources
The same forty cameras, the same codec, the same thirty days, sized two defensible ways, come out at 12.7 TB and 36.9 TB…
27 Sep 2026
What a VMS Really Costs: Per-Camera Licensing Over Five Years
Most video management software is priced per camera, per year. That single decision, compounded over a five-year contrac…
Bring us the challenge
The one that has been handed back, sits between two suppliers, or nobody can say is possible yet. A short call costs you nothing and you will speak to one of our consultants.
Engineer to engineer. No handoffs.
