Martyn's Law has changed the landscape for public-facing organisations across the UK. The Terrorism (Protection of Premises) Act 2025 does not simply ask organisations to be aware of the threat , it requires them to take meaningful, proportionate action to protect the people on their premises.
That raises a practical question that many responsible persons, security managers and venue operators are now asking: what does genuine preparedness actually look like, and how do you demonstrate it?
Two qualifications sit at the heart of the answer. The SFJ Awards Level 3 Award in Counter-Terrorism Protective Security and Preparedness (CTPSaP) builds the knowledge and understanding needed to prepare well. Level 4 Physical Penetration Testing training develops the capability to test whether that preparation is actually working. Together, they create something more valuable than either can provide alone.
The Three Stages: From Legal Duty to Operational Assurance
The relationship between Martyn's Law, Level 3 counter-terrorism training and Level 4 physical penetration testing is easiest to understand as three connected stages.
Stage 1 — The legal and moral driver Martyn's Law creates the duty. It requires organisations to think seriously about how they would reduce harm if a terrorist attack occurred on their premises. Qualifying venues must have plans, procedures and people capable of responding.
Stage 2 — Building the knowledge to prepare properly The SFJ Level 3 Counter-Terrorism Protective Security and Preparedness course equips individuals and organisations with a deep understanding of the threat environment, terrorist attack methodologies, risk assessment principles and appropriate mitigation measures. It provides a strong foundation for protective security planning and a positive security culture.
Stage 3 — Testing whether preparation translates into practice Physical penetration testing, supported by Level 4 training, provides a practical method of challenging whether security arrangements work in the real world. It identifies weaknesses, validates whether controls are genuinely embedded, and produces evidence-based findings that support meaningful improvement.
Each stage builds on the one before it. Skipping to Stage 3 without Stage 2 produces findings without the context to act on them. Stopping at Stage 2 without Stage 3 leaves organisations relying on assumption rather than evidence.
The Counter-Terrorism Security Cycle
One of the most useful ways to think about Martyn's Law preparedness is as a continuous cycle rather than a one-off exercise. That cycle looks like this:
- Understand the threat — know how attacks are planned, what hostile reconnaissance looks like, and what types of incidents are most likely at your premises
- Assess the risk — apply a structured counter-terrorism risk assessment process to your specific environment
- Introduce proportionate measures — implement physical, procedural and behavioural security controls appropriate to your threat profile
- Train staff — ensure people at every level understand their role in protective security and know how to respond
- Test the measures — challenge whether controls work under realistic conditions, not just on paper
- Learn from the findings — translate test results and vulnerabilities into specific, actionable improvements
- Improve the system — embed changes, retest where needed, and maintain momentum
This cycle is far more effective than a static compliance model. It creates organisations that are genuinely safer, not just better documented.
From Paper Compliance to Operational Confidence
One of the risks with any new legislation is that organisations focus on documentation rather than capability. Policies, checklists and procedures matter, but they do not automatically make people safer.
Martyn's Law should encourage organisations to go beyond paper compliance and develop genuine operational confidence. That means asking harder, more practical questions:
- Would staff know what to do during a hostile incident?
- Would security officers identify suspicious behaviour before it escalated?
- Would access control procedures prevent unauthorised entry?
- Would a hostile reconnaissance attempt be noticed?
- Would emergency plans hold together under the pressure of a real incident?
- Would management be able to coordinate an effective initial response?
Training helps organisations understand these questions. Physical penetration testing helps answer them.
The gap between the two is where many organisations currently sit. They have completed awareness training, written new procedures and believe their site is reasonably secure. But belief is not assurance. Without testing, it is genuinely difficult to know whether security culture is embedded, whether controls are working as intended, or whether the people responsible for security would recognise a threat when it arrived.
Why This Matters Across Sectors
Martyn's Law is not only relevant to large arenas and major public events. The wider protective security principles apply across hospitality, education, healthcare, retail, logistics, corporate offices, local authorities, entertainment venues and places of worship.
The threat picture varies from site to site. The scale of measures should be proportionate to the risk. But the underlying need is consistent: organisations responsible for publicly accessible premises must understand their vulnerabilities and take reasonable steps to protect the people on their premises.
The SFJ Level 3 CTPSaP course supports responsible persons, security managers and operational staff in understanding the counter-terrorism context relevant to their environment. Level 4 Physical Penetration Testing supports security professionals in assessing whether the physical controls, staff behaviours and procedural safeguards at a given site are effective in practice.
Used together, they help organisations move from assumption to assurance.
How HZL Supports Organisations Preparing for Martyn's Law
HZL Specialist Solutions is well placed to support organisations at every stage of this process, because HZL provides both the training and the operational testing needed to move from awareness to genuine security assurance.
Counter-terrorism training HZL delivers the SFJ Level 3 Award in Counter-Terrorism Protective Security and Preparedness (CTPSaP) — the only counter-terrorism qualification in the UK endorsed by Counter-Terrorism Policing and developed in partnership with the National Counter-Terrorism Security Office (NaCTSO). The course is Ofqual-regulated, runs over five days, and covers terrorist methodologies, threat awareness, protective security principles, preparedness planning and proportionate mitigation measures.
Physical penetration testing training HZL also delivers Level 4 Physical Penetration Testing training, supporting security professionals who need to understand how authorised physical security assessments should be planned, conducted and reported. This ensures testing is carried out ethically, lawfully and in a way that produces actionable findings.
Operational physical penetration testing In addition to training, HZL carries out physical penetration testing for organisations directly. This means HZL can not only help teams understand what good protective security looks like. It can test whether existing measures hold up in practice. Assessments can cover access controls, staff vigilance, visitor management, perimeter security, contractor procedures, emergency processes and wider security culture.
For organisations preparing for Martyn's Law, this creates a complete support model:
- Training builds the knowledge to prepare properly
- Physical penetration testing provides evidence of what is and is not working
- Reporting identifies specific vulnerabilities with clarity
- Recommendations support targeted, prioritised improvement
- Retesting demonstrates progress and validates changes
The Key Takeaway
Martyn's Law sets the expectation that qualifying premises must be better prepared to protect the public from terrorism.
The SFJ Level 3 Counter-Terrorism Protective Security and Preparedness course builds the understanding to prepare properly. Level 4 Physical Penetration Testing develops the capability to test, evidence and improve that preparedness.
In modern protective security, it is no longer sufficient to believe that a site is secure. Organisations must be able to demonstrate that their people, procedures and physical controls are prepared, proportionate and effective.
That is where training, testing and continuous improvement come together.