News Center

Australia Introduces Mandatory Cyber Security Compliance Requirements for Smart Devices

Australia’s mandatory cyber security requirements for consumer-grade smart devices took effect on 4 March 2026, following a 12-month transition period. The requirements apply to in-scope products manufactured on or after 4 March 2026 that are intended, or could reasonably be expected, to be acquired by consumers in Australia.

Under the Rules, manufacturers must ensure applicable connected products meet minimum cyber security standards, while suppliers must not supply products that are required to comply but do not meet the standard. Applicable products must also be supplied with a Statement of Compliance prepared by or on behalf of the manufacturer. The Australian Government’s published template confirms that the Statement of Compliance is made under the 2025 Rules, authorised by the Cyber Security Act 2024.

General Requirements

  • Secure passwords: Where an in-scope device uses passwords outside its factory-default state, passwords must either be unique to each individual product or defined by the user. Unique passwords must not be easily guessable or generated using insecure methods such as simple incremental counters.
  • Security vulnerability reporting: Manufacturers must publish a clear and accessible method for reporting security issues, including at least one point of contact and information explaining when reporters will receive an acknowledgement and subsequent status updates until the issue is resolved. The information must be available in English, free of charge and without requiring personal information from the reporter.
  • Security update support period: Manufacturers must publish a defined support period for hardware and applicable software capable of receiving security updates. The support period must include an end date and cannot be shortened once published, although it may be extended.
  • Consumer visibility: Support-period information must be clear, accessible and understandable without technical knowledge. Where the manufacturer offers the product through a website it controls, the support period must be prominently displayed alongside relevant product information.
  • Statement of Compliance: The manufacturer must prepare an SoC identifying the product type and batch identifier, manufacturer and authorised representative, defined support period, compliance declaration, signatory details, and place and date of issue.
  • Record retention: Manufacturers and suppliers must retain applicable Statements of Compliance for five years.

Exclusions: The current standard excludes certain products, including desktop and laptop computers, tablets, smartphones, therapeutic goods, road vehicles and specified road-vehicle components.