Security Standards for Smart Devices
Cyber Security Act 2024 (Cth) No. 98, 2024, Part 2, ss. 13-24; Cyber Security (Security Standards for Smart Devices) Rules 2025 (F2025L00276), Schedule 1
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
In force 6 months, effective 4 March 2026.
A product security requirements rule binding private bodies.
As of 12 September 2026.
What it requires
- This binds a manufacturer or supplier of a relevant connectable product that will be acquired in Australia, and does not by itself reach a company that only publishes an app or other software with no connectable device of its own; the standard for consumer grade products does not reach a desktop computer, a laptop, a tablet computer, a smartphone, a therapeutic good, a road vehicle, or a road vehicle component.
- Do not manufacture or supply a consumer grade smart device with a universal default password from 4 March 2026 for a product manufactured on or after that date; the device's hardware and any pre-installed or required software must use a password unique to that unit or set by the user, for every state other than the factory default.
- Publish a means for a security issue affecting the device to be reported to the manufacturer, and provide status updates on the resolution of a reported issue.
- Publish, before supply, the period including an end date for which the device will receive security updates, provide or supply the product with a statement of compliance with the security standard, and retain a copy of that statement for five years.
If you get it wrong
Criminal exposureNo
Private right of actionNo
Who enforces it
Enforcement body
The Secretary of the Department of Home Affairs, supported by the Technology Assessment and Regulation Office (TARO).
Settledness
- As of
- 12 September 2026
- Guidance link
- https://www.homeaffairs.gov.au/cyber-security-subsite/files/factsheet-security-standards-for-smart-devices-and-consumer-grade-rules.pdf
- Guidance body
- Department of Home Affairs, Technology Assessment and Regulation Office (TARO)
- Open questions
- Section 15(5)-(6) of the Cyber Security Act 2024 confines the compliance duty, for an entity that is not a constitutional corporation and is not trading interstate or internationally, to requirements concerning the product's connection to, or use of, a telecommunications-type service and measures protecting it from an attack by such a service: does a requirement of the security standard that does not fit that description bind such an entity at all?
What it reaches
Obligation class
Security, Disclosure, Governance
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
A manufacturer of a relevant connectable product, a product able to connect directly or indirectly to the internet or to another such product by a like means, must manufacture it in compliance with the security standard the rules set for its class if the manufacturer is aware, or could reasonably be expected to be aware, that the product will be acquired in Australia, and a supplier must not supply a product that was not manufactured in compliance with that standard.
The Cyber Security (Security Standards for Smart Devices) Rules 2025 apply the standard to most consumer grade relevant connectable products manufactured on or after 4 March 2026, and a product manufactured before that date is not required to comply. The standard bans a universal default password, requiring the device's hardware and any pre-installed or required software to use a password unique to the unit or set by the user for any state other than the factory default.
It requires the manufacturer to publish a means for a security issue to be reported to the manufacturer, with status updates on the resolution of a reported issue, and to publish the period, including an end date, for which the device will receive security updates. A desktop computer, a laptop, a tablet computer, a smartphone, a therapeutic good, a road vehicle, and a road vehicle component are excluded from the standard.
The manufacturer must provide, and the supplier must supply the product with, a statement of compliance with the security standard, and each must retain a copy for five years.
The Secretary of the Department of Home Affairs enforces the regime through a compliance notice, a stop notice, and a recall notice rather than through a fine, and may publish an entity's identity, product details, and the risks posed by the product on the Department's website if the entity fails to comply with a recall notice.
When LexLint raises it
distributes_software_product
Read the law
Official text, legislation.gov.au, Cyber Security Act 2024, Part 2
specific security-standard content confirmed against the Department of Home Affairs' own factsheet, since the Rules' own legislation.gov.au page serves only a JavaScript shell