Discuss this signal with compliance peers, get the weekly digest, and never miss an enforcement deadline that affects your products.
Australia has introduced mandatory cybersecurity requirements for connected consumer products through the Cyber Security (Security Standards for Smart Devices) Rules 2025, which took full effect on March 4, 2026. The regulation establishes three core security obligations for manufacturers: unique passwords per device, vulnerability reporting mechanisms, and defined security update support periods. These Australia cybersecurity standards smart devices represent the country's first legally enforceable baseline security requirements for consumer-grade internet-connectable products.
The mandatory cybersecurity requirements Australia emerged from the 2023-2030 Australian Cyber Security Strategy, replacing the voluntary Code of Practice: Securing the Internet of Things for Consumers issued in 2020. According to the Department of Home Affairs explanatory document, "A government study of manufacturers' uptake of the Code revealed a low level of adoption across the country." The regulation addresses growing cybersecurity risks as global IoT device deployment is estimated to exceed 21 billion connected devices by 2030, with some projections reaching 64 billion devices.
The Australian Government's objective is to provide confidence that digital products are safe while establishing assurance that smart devices sold in the Australian market are secure by design and by default. The regulation follows international approaches, particularly aligning with the European Telecommunications Standards Institute (ETSI) EN 303 645 standard's first three principles.
The Cyber Security (Security Standards for Smart Devices) Rules 2025 were registered on March 4, 2025, with a 12-month transition period before full enforcement began March 4, 2026. The rules form part of the broader Cyber Security Act 2024, which received Royal Assent on November 29, 2024.
The regulation applies to connectable products intended for personal, domestic, or household use in Australia. Manufacturers must comply where they are aware, or reasonably expected to be aware, that the product will be supplied into the Australian consumer market. The following categories are explicitly excluded: desktop computers and laptops, tablets and smartphones, therapeutic goods, and road vehicles and road vehicle components.
The connected consumer products compliance framework operates under Part 2 of the Cyber Security Act 2024, with technical requirements detailed in the subordinate Rules. The regulation has extraterritorial reach, applying to overseas manufacturers and suppliers whose products are sold in the Australian market.
Three mandatory cybersecurity requirements Australia now govern all in-scope products:
Unique Password Requirements: Devices must not use universal default passwords. Each device must have a unique password per unit or require the user to define one during setup. Passwords must not be based on incremental counters, derived from publicly available information, or generated from serial numbers unless protected by encryption or keyed hashing.
Vulnerability Reporting Mechanisms: Manufacturers must publish a publicly accessible vulnerability reporting mechanism that includes at least one point of contact for reporting security issues, defined timelines for acknowledgement and status updates, and must be available in English, free of charge, and accessible without submission of personal information.
Security Update Support Periods: Manufacturers must publish a defined end-of-support date for security updates. This date cannot be shortened once published, and any extension must be updated and published promptly.
The smart device security obligations affect manufacturers, importers, and suppliers of consumer-grade connectable products across multiple categories including smart home devices, IoT appliances, connected entertainment systems, and wearable technology. The regulation impacts both domestic Australian companies and international manufacturers whose products enter the Australian market.
According to the government's impact analysis, "Minimum cyber security requirements for CER in Australia are expected to create marginal additional costs for suppliers into Australia, since they should already be implemented, or in the process of being implemented, for other markets." This assessment reflects Australia's alignment with international standards, particularly those already implemented in the UK market.
The cybersecurity vulnerability reporting requirement creates new operational obligations for manufacturers who must establish and maintain accessible reporting channels. The security update support period compliance Australia requirement introduces long-term support commitments that manufacturers must honour throughout the published support lifecycle.
Every in-scope product must be accompanied by a Statement of Compliance at the point of supply. The statement must include product identification details, a declaration of conformity with each of the three security requirements, the security update support period and its specific end date, and the date of issue.
Manufacturers and suppliers are required to retain all compliance documentation for five years from the date of supply. This includes technical documentation demonstrating compliance with password requirements, evidence of vulnerability reporting mechanism implementation, and records of security update support commitments.
The Australian cybersecurity regulations consumer electronics framework requires manufacturers to ensure compliance before products reach the Australian market. For products already in the supply chain during the transition period, compliance obligations applied from March 4, 2026.
The regulation became fully enforceable on March 4, 2026, following the 12-month transition period. The Cyber Security Act provides the Secretary of Home Affairs authority to issue enforcement notices, which can extend to recall notices and public notification for non-compliant products.
The connected device cybersecurity obligations Australia are immediately applicable to new products entering the market. For existing product lines, manufacturers needed to achieve compliance by the March 2026 deadline or face potential enforcement action.
Future applications of the rules will be considered as required to address risks with evolving technology, indicating the framework may expand to cover additional device categories or enhanced security requirements.
Australia's approach aligns closely with the UK's Product Security and Telecommunications Infrastructure (PSTI) Act, with both countries implementing the first three principles of ETSI EN 303 645. However, Australia has decided against introducing a mandatory labelling scheme, instead developing a voluntary labelling scheme for consumer-grade smart devices as part of its 2023-2030 Cyber Security Strategy.
The regulation positions Australia among early adopters of mandatory IoT security standards globally. According to industry analysis, nine of fourteen countries examined for consumer IoT device specifications have referenced ETSI EN 303 645, with most implementing voluntary rather than compulsory schemes.
Manufacturers must immediately verify compliance status for all products supplied to the Australian market. Conduct technical assessments to ensure unique password implementation meets the regulation's requirements, avoiding incremental counters or publicly derivable passwords unless properly protected.
Establish vulnerability reporting mechanisms that meet accessibility requirements: English language availability, free access, no personal information submission requirements, and defined response timelines. Document these mechanisms clearly and ensure they remain accessible throughout the product lifecycle.
Define and publish security update support periods for all covered products. These commitments cannot be shortened once published, so establish realistic timelines based on product lifecycle planning and technical capabilities. Update published information promptly if extending support periods.
Prepare Statement of Compliance documentation for each product variant, including specific end-of-support dates and compliance declarations. Implement record-keeping systems to maintain all compliance documentation for the required five-year retention period.
Monitor enforcement bulletins from the Department of Home Affairs and establish processes to respond to potential enforcement notices. The Secretary's authority extends to product recalls and public notifications for non-compliance.