Most Martyn's Law guidance explains what the law says. Policy documents, compliance frameworks, briefing notes from local authorities — they all describe the legislation in detail. What they rarely answer is the more pressing question for anyone responsible for a school building: what does your school actually need to have physically in place?
This article answers that question directly, starting with the honest part: the Act itself requires no physical security infrastructure from a school. Its demands are procedural. What follows are twelve items, some legal duties and most recommended measures that make those duties workable, each with a plain-English test you can apply to your current provision today: no consultant, no specialist knowledge, no waiting for a formal audit.
None of these twelve items is unknown territory. What Martyn's Law does is put a formal accountability structure around protective procedures, and the physical items on this list are what make those procedures credible in practice. For most schools, the gap between where you are and where you want to be is smaller than you might fear, but it is real. The Act's requirements are expected to commence from 2027, with the final date still to be confirmed, and the sensible position is to be ready well before then rather than to wait.
Standard Tier vs Enhanced Tier
Standard Tier applies to premises where 200 to 799 individuals, including staff, may reasonably be expected to be present at the same time. Enhanced Tier applies at 800 or more, but early years, primary, secondary and further education settings are placed in the Standard Tier whatever their capacity, so a school is never in the Enhanced Tier. Below 200, premises are out of scope entirely. Standard Tier premises must notify the Security Industry Authority (SIA) and have public protection procedures in place covering evacuation, invacuation, lockdown and communication. The procedural items in this checklist reflect those duties; the physical items are recommended measures that make the procedures work, not compliance requirements in themselves.
The 12-Item Physical Security Checklist
01
Controlled and monitored main entrance
Your main entrance must actively control who enters the building — not merely observe them. This means a physical barrier (door, gate, or intercom-controlled access point) combined with a process for verifying identity before granting entry. A reception desk that can see the front door is not sufficient if visitors can walk past it unchallenged.
Plain-English Test
Can an unknown adult walk from your car park into your school corridor without speaking to a member of staff or being challenged by a physical barrier?
02
Visitor identity verification and logging
Every visitor entering the premises should have their identity verified and their visit logged at the point of entry. Martyn's Law does not mandate visitor logging; safeguarding guidance and common sense do. A paper signing-in book is a starting point, but it does not provide the searchable record or ID verification that a digital visitor management system does. The purpose of logging is not administrative: in a crisis, it is how you know who is in the building.
Plain-English Test
If there were an incident in your building right now, could you produce within five minutes a complete and accurate list of every non-staff adult currently on site?
03
Secondary entrances secured against unauthorised entry
Fire exits, delivery entrances, staff car park gates, sports hall side doors — every secondary entrance is a potential vulnerability. Each one must be either permanently secured (not just locked at night), or monitored and controlled in the same way as the main entrance during school hours. The most common failure mode is a door that is formally locked but propped open by staff out of habit.
Plain-English Test
Walk your perimeter at 11am on a school day. How many doors and gates are open or unlocked that you did not expect to be?
04
CCTV covering all public-facing entrance and exit points
Martyn's Law does not require CCTV; no physical installation is mandated for Standard Tier premises. What it does require are procedures, and knowing who is approaching and entering your site is what makes evacuation, invacuation and lockdown decisions timely rather than late. For schools, CCTV covering every entrance and exit that members of the public could use is the recommended way to achieve that, and it also supports your KCSiE visitor management obligations. Footage should be recorded rather than just live-viewed, stored for a defined retention period, and retrievable after an incident. Every camera should have a current maintenance record and the system should be verified working.
Plain-English Test
When did someone last verify that every CCTV camera on your site is recording, in focus, and producing footage that would identify a person clearly?
05
A named Responsible Person in senior leadership
The Terrorism (Protection of Premises) Act 2025 places its duties on the responsible person for the premises: the person or body with control of them. For a school this is typically the proprietor, trust or governing body, with day-to-day accountability usually sitting with the Headteacher or a senior leader. Naming that individual in writing, and making the designation documented and accessible to staff, is the practical way to make the accountability real rather than nominal. It should not be a vacant role or an afterthought.
Plain-English Test
Is there a named individual — with their name, role and contact details in writing — who holds formal accountability for Martyn's Law compliance at your school today?
06
Written protective procedures document
The Act requires public protection procedures to be in place, and a written document, rather than institutional knowledge, is the only realistic way to hold and evidence them. It should set out what staff should do in the event of a terrorist attack or serious security threat. This is not the same as your general emergency procedures or your safeguarding policy. It must address specifically: how staff are alerted, who takes command, how the building is locked down, how people are evacuated or sheltered, and how emergency services are contacted and briefed.
Plain-English Test
Does a written document exist that any member of senior staff could pick up right now and use to direct your school's response to a serious security incident — without needing to call anyone for guidance?
07
A tested lockdown capability
Written procedures are worthless if staff do not know them and the building does not support them. A lockdown capability means: staff know what the lockdown signal is and what to do when they hear it; internal doors can be locked quickly and reliably; there is a way to communicate with all staff simultaneously (not just via a PA system that can be heard outside); and the procedure has been practised at least once in the past twelve months.
Plain-English Test
If you initiated a lockdown signal right now, how long would it take for every classroom to be secured, every door locked, and every member of staff to know what was happening? Have you ever measured this?
08
Staff awareness training on protective procedures
Every member of staff who is regularly on site must be aware of your protective procedures — not just the senior leadership team and the designated Responsible Person. Awareness training does not need to be a specialist security course: it means every staff member knows the lockdown signal, knows where to go, knows who takes command, and knows how to communicate with leadership during an incident. This training must be documented.
Plain-English Test
Ask a teaching assistant or a caretaker what they would do if a lockdown was announced. Do they give you a confident, correct answer?
09
A site-specific threat assessment
Your protective procedures must be based on an assessment of the specific threats and vulnerabilities that apply to your site — not a generic template downloaded from a government website. This means identifying: who might pose a threat and why (based on your school's location, profile and history), which parts of your site are most vulnerable, which events or times create elevated risk, and what physical or procedural mitigations are in place for each identified vulnerability.
Plain-English Test
Does your threat assessment name specific locations on your site, specific times or events, and specific mitigations for each — or is it a generic document that could apply to any school?
10
Communication capability during an incident
During a serious incident, mobile networks frequently become congested or unusable. Your communication plan must not rely solely on mobile phones. You need: a way to alert all staff simultaneously that does not depend on individual mobile signal; a clear protocol for contacting emergency services; and a way for the Responsible Person to receive updates from different parts of the building without moving through an unsecured area. Many schools rely on a PA system — but if that PA can be heard outside, it may alert a threat actor to your response.
Plain-English Test
If mobile networks failed right now, how would you communicate with every member of staff on site simultaneously, and how would you contact emergency services?
11
Procedures covering public events and lettings
Martyn's Law applies to your school not just during the school day but at any time members of the public are admitted to the premises. Parents' evenings, school productions, sports fixtures, community lettings, open days — all of these are in scope. Your protective procedures must explicitly cover these events, including: how access is controlled when large numbers of unfamiliar people are on site, how staff are briefed for events run outside normal hours, and how the Responsible Person's obligations are met when the Headteacher is not present.
Plain-English Test
At your last parents' evening or school production, was there a named person responsible for security, was access controlled, and were staff briefed on what to do in an emergency?
12
Governor sign-off and annual review record
Compliance with Martyn's Law is not a one-time event. Your protective procedures should be reviewed at least annually, with the review and any changes documented. Governor approval of the procedures and the annual review should be minuted. This creates the evidence trail that demonstrates compliance if the Security Industry Authority (SIA), the regulator for Martyn's Law, ever asks, and it ensures that accountability sits at the right level of governance rather than residing solely with the Headteacher.
Plain-English Test
Do your governing body minutes contain a record of them formally approving your protective procedures, and a record of the most recent annual review?
What Happens if You Have Gaps
Most schools that work through this list honestly will identify between three and six gaps. That is normal, and it does not mean your school is unsafe — it means you have work to do before the Act's requirements commence. The good news is that most gaps in this list can be closed without significant capital expenditure. The most common issues — untested lockdown procedures, inadequate visitor management, secondary doors propped open — are largely procedural rather than infrastructural.
The infrastructure gaps that do require investment are typically access control (particularly on secondary entrances) and CCTV coverage of all entrance and exit points. For most schools, a targeted upgrade rather than a wholesale replacement is what is needed.
On enforcement: The Security Industry Authority (SIA) is the regulator for Martyn's Law. Its enforcement powers take effect when the Act's requirements commence, expected from 2027 with the final date still to be confirmed. Penalties for non-compliance include compliance notices with mandatory timescales, and financial penalties for responsible persons who fail to act. Schools that can demonstrate a good-faith compliance effort — documented threat assessment, trained staff, tested procedures, governor oversight — are in a substantially different position to those who have done nothing.
What to Do Next
Use this list as the basis of a gap analysis. Work through each item with your site manager or estates lead and score your current provision honestly. Where gaps exist, prioritise them by the effort required to close them — procedural gaps first, then infrastructure gaps with the longest lead times.
Present the gap analysis and a remediation plan to your governing body. Get it minuted. Even if you cannot close every gap before commencement, having a documented plan and a demonstrated commitment to compliance changes your position significantly.
If you want an independent assessment of your physical security infrastructure, Fyrfly Systems offers free site surveys for schools across the UK. We will work through your site with you, identify specific vulnerabilities, and give you an honest assessment of what needs to change — with no obligation to use us as your supplier.
You can also use our free Martyn's Law Assessment Tool to get a personalised compliance report in under five minutes, or download the Secured by Design checklist as a companion document.