The short version
On 4 March 2026, Part 2 and Schedule 1 of the Cyber Security (Security Standards for Smart Devices) Rules 2025 commenced. They are made under the Cyber Security Act 2024, and they are Australia’s first mandatory, enforceable baseline for the security of consumer smart devices — replacing a voluntary code that manufacturers were free to ignore.
The requirements are deliberately modest. Three things:
- No universal default passwords. Passwords must be unique to each individual device, or set by the user.
- A published way to report security bugs. At least one contact point, plus a stated timeframe for acknowledgement and status updates.
- A published support period with an end date. How long the thing will get security updates — and once published, the manufacturer cannot shorten it.
That third one is the sleeper. For the first time, the answer to “how long will this smart lock keep getting patches?” is a number the manufacturer has to put on its own product page, in plain English, free, without you having to ask.
Two things temper the enthusiasm. Smartphones, tablets, laptops and desktops are explicitly carved out — the rules cover the doorbell, not the phone that opens it. And the Act attaches no civil penalty to any of it: enforcement runs through a ladder of notices, each with at least ten days to argue back, and the worst outcome is being named on a government website.
What the three requirements actually say
The detail lives in Schedule 1 of the Rules, and it is more precisely drafted than the summaries suggest.
Passwords (clause 2). Passwords must be either unique per product — meaning unique for each individual unit, not each model — or defined by the user. Where they are unique per product, the Rules close the obvious loopholes: a unique password must not be based on an incremental counter (the instrument gives “password1” and “password2” as its own example), must not be derived from publicly available information, and must not be derived from a serial number or other unique product identifier unless that is done with encryption or a keyed hashing algorithm meeting good industry practice. A catch-all bans anything “otherwise guessable in a manner unacceptable as part of good industry practice”.
Note what “password” excludes: cryptographic keys, API keys, and the pairing PINs used by non-internet protocols. Your Bluetooth headphones asking for 0000 is not what this clause is aimed at.
Reporting security issues (clause 3). The manufacturer must publish at least one point of contact for reporting security issues, and must publish when a reporter will get an acknowledgement and status updates through to resolution. The publication requirements are the interesting part: the information must be available without prior request, in English, free of charge, and — a nice touch — without requiring the reporter to hand over personal information first.
This is the requirement most likely to bite. Research cited by the team building Australia’s companion labelling scheme puts the share of IoT manufacturers with no clear vulnerability reporting channel at close to 60 per cent.
Support period (clause 4). The manufacturer must publish a defined support period for security updates, “expressed as a period of time with an end date”. It must not be shortened after publication; if it is extended, the extension must be published as soon as practicable. It has to be accessible, clear, transparent, free, in English, available without asking, and understandable by a reader with no technical background.
And clause 4(7) is the one that puts it in front of buyers. If the manufacturer sells the product on its own website, the support period must be published prominently alongside the information intended to inform a purchase — and wherever the main characteristics of the product appear, the support period must appear alongside them or with equal prominence. In other words: not buried in a support-portal PDF. Next to the specs.
What is in scope, and the carve-outs
The Act works in two layers. Section 13 of the Cyber Security Act 2024 defines a relevant connectable product broadly — an internet-connectable product (anything that talks IP to the internet), or a network-connectable product, which sweeps in devices that cannot reach the internet themselves but connect directly to something that can, or that link two or more devices at once. A sensor that only speaks Zigbee to a hub is captured. A bare cable is not.
Section 8 of the Rules then narrows that to the class this security standard applies to: products intended by the manufacturer, or of a kind likely, to be used for personal, domestic or household use, that will be acquired in Australia by a consumer — “consumer” taking its meaning from section 3 of the Australian Consumer Law.
Then it lists what is not covered. There are six exclusions, and they are worth reading literally:
- a desktop computer or a laptop;
- a tablet computer;
- a smartphone;
- therapeutic goods within the meaning of the Therapeutic Goods Act 1989;
- a road vehicle within the meaning of the Road Vehicle Standards Act 2018;
- a road vehicle component within the meaning of that Act.
So: smart TVs, IP cameras, routers, speakers, doorbells, lights, robot vacuums, trackers, headphones, connected appliances — in. Phones, tablets and computers — out, on the reasoning that those platforms already sit under their own update and app-store regimes. Medical devices go to the TGA; cars go to the road vehicle standards. Each carve-out is defensible on its own terms. The aggregate effect is that the four screens most Australians actually own are governed by everything except this.
The bit most summaries get wrong
You will read, in more than one law firm briefing, that devices manufactured before 4 March 2026 are outside the regime. That is half the test.
Section 13(1) of the Act says the Part applies to a relevant connectable product that is manufactured on or after commencement or supplied (other than as second hand goods) on or after commencement. Both limbs. A device built in late 2025 and sold new to an Australian consumer in July 2026 engages the second limb; only genuinely second-hand supply is carved out.
That matters for anyone clearing old stock, and it matters for grey imports. It also means the sensible consumer question is not “when was this made” but “is a compliant support period published for it”.
The statement of compliance — and why you will never see one
Alongside the standard itself, the Act requires paperwork. A manufacturer must provide a statement of compliance for supply in Australia, and a supplier must supply the product with one. Section 9 of the Rules sets out what it must contain: the product type and batch identifier; the name and address of the manufacturer, of an authorised representative, and of each of the manufacturer’s other authorised representatives in Australia; a declaration that it was prepared by or for the manufacturer; a declaration that in the manufacturer’s opinion the product was made in compliance and the other obligations were met; the defined support period as at the date of issue; the signature, name and function of the signatory; and the place and date of issue. Both manufacturer and supplier must keep a copy for five years.
Read that list again and notice what it is: a business-to-business compliance artefact. It is a declaration by the manufacturer of its own opinion, retained on file, with no independent testing behind it. It is not a label, not a certificate, and not something a retailer is required to hand a shopper at the counter. The consumer-facing part of this regime is not the statement of compliance — it is the support-period disclosure required to sit next to the specs on the product page.
Enforcement: a ladder, not a stick
Regulation sits with the Technology Assessment and Regulation Office inside the Department of Home Affairs, supporting the Secretary’s powers under Division 3 of Part 2 of the Act. The sequence is strictly escalating:
- Compliance notice (s 17) — issued where the Secretary is reasonably satisfied there is non-compliance, or is aware of information suggesting there may be. It specifies the action required and a reasonable period to take it.
- Stop notice (s 18) — only available after a compliance notice, and only if the entity did not comply or its remedy was inadequate.
- Recall notice (s 19) — only after a stop notice, on the same test. It can require the entity to keep the product out of Australian hands and arrange returns.
- Public notification (s 20) — if the entity fails to comply with the recall notice, the Minister may publish its identity, the product details, the non-compliance and the risks. Section 11 of the Rules adds that the publication may include details of the recall notice and recommended consumer actions, expressly including destroying the product.
Before issuing any of the three notices the Secretary must first notify an intention to do so and allow at least ten days for representations. Only one notice of each kind may be issued per instance of non-compliance, and an entity can seek internal review within 30 days.
What is absent is the thing that usually makes product regulation move: there is no civil penalty attached to the section 15 or 16 obligations. A manufacturer that ships a device with a shared default password and no published support period faces, at worst and after several rounds of correspondence, a recall and the reputational damage of being named. Commentators have described the design as deliberately light touch. That is a fair reading of the text.
The counterweight is market access rather than money. A recall notice is a serious commercial event, and Australian Consumer Law guarantees run underneath all of this regardless.
What is coming next: the label
The mandatory rules are a floor. The part designed to be visible to shoppers is the voluntary Security Labelling Scheme for Smart Devices, being co-designed by the Connected Technology Alliance — formerly IoT Alliance Australia — with the Australian Government, and developed with Standards Australia as an independently certified mark rather than a self-declaration.
On the timeline published by the program in April 2026: scheme design was completed in December 2025, label design was due for release around July 2026, supporting systems in September 2026, a pilot from October 2026 and national launch in 2027. Coverage in February 2026 put the launch at March 2027. It is intended to work like an energy rating — a security claim you can compare at the point of sale — and to align with international schemes such as the US Cyber Trust Mark. Frank Zeichner, the program director and founding chief executive of IoT Alliance Australia, framed the change bluntly in February: the shift, he said, has already happened.
Two caveats worth holding onto. The scheme is voluntary, so absence of a label will not mean non-compliance. And it inherits the same exclusions — phones and laptops are outside it too.
So what should a buyer actually do
| Look for the support end date on the product page | This is the single most useful consequence of the rules. If a manufacturer sells the device on its own site, the defined support period must appear prominently alongside the main product information — not in a buried PDF. A vendor that cannot show you an end date is telling you something. |
|---|---|
| Treat a missing security contact as a red flag | Every in-scope manufacturer must publish a way to report security issues, free, in English, without you registering or handing over personal details. It takes thirty seconds to check, and the published research suggests a large minority still fail it. |
| Expect a unique or self-set password | A device that ships with the same admin password as every other unit of its model has not met the standard. If setup hands you a shared default and does not force a change, that is the clearest visible non-compliance signal available to an ordinary buyer. |
| Do not read the exclusions as a security ranking | Phones, tablets and laptops are excluded because they are governed elsewhere, not because they are safer. Conversely, an in-scope device meeting all three requirements has cleared a low bar — three baseline controls, self-declared. |
| Clearance stock is still covered | Because supply on or after 4 March 2026 engages the Act independently of manufacturing date, discounted old stock sold new is in scope. Genuinely second-hand goods are not — so marketplace purchases carry none of this. |
| Wait for the label, but do not wait on it | The certified security label is voluntary, pilots from October 2026 and launches in 2027. Until then its absence means nothing, and the support-period disclosure is the more reliable signal. |
| Report what you find | Enforcement here is complaint-driven and the regulator is the Technology Assessment and Regulation Office within Home Affairs. A device with no published support period is a reportable gap, not just an annoyance. |
The bottom line
Australia has done the sensible, unglamorous thing: taken the first three provisions of the international consumer IoT baseline — the same three the United Kingdom picked for its PSTI regime, drawn from ETSI EN 303 645 — and made them law. Nothing here is technically demanding. Any manufacturer that could not meet these three requirements in March 2026 had been choosing not to.
The honest assessment five months in is that the disclosure requirement is worth more than the security requirements. Unique passwords and a bug-report inbox are hygiene. A published, non-retractable support end date, sitting next to the specifications where a shopper can see it, changes what can be compared before money changes hands — and quietly makes abandonware a disclosed product attribute rather than a discovery you make two years later.
What the regime does not have is teeth. No penalties, an escalation ladder with ten-day pauses at each rung, and a compliance artefact that never reaches the customer. Whether it works will come down to whether Home Affairs uses the notices and whether the 2027 label gives manufacturers a commercial reason to go past the floor. Neither is knowable yet. What is knowable is the question to ask in a shop, and until March 2026 you had no right to an answer: how long does this get security updates, and what is the end date?
Sources
Facts, dates and quoted requirements above are drawn from these primary and reputable sources, captured 5 August 2026:
- Federal Register of Legislation — Cyber Security (Security Standards for Smart Devices) Rules 2025 (F2025L00276): made by the Minister for Home Affairs, dated 27 February 2025 and registered 4 March 2025; commencement table (Part 2 and Schedule 1 on 4 March 2026); section 6 meaning of consumer; section 8 class and the six exclusions; section 9 statement of compliance contents; section 10 five-year retention; section 11 matters publishable with a recall-notice failure; Schedule 1 clauses 2, 3 and 4 on passwords, security issue reports and defined support periods.
- Federal Register of Legislation — Cyber Security Act 2024 (Cth): section 13 application (manufactured on or after commencement, or supplied other than as second hand goods on or after commencement) and the definitions of internet-connectable and network-connectable products; sections 15 and 16 manufacturer and supplier obligations; sections 17–20 compliance, stop and recall notices, the minimum ten-day representation period and public notification; section 22 internal review within 30 days.
- Department of Home Affairs — Security standards for smart devices: the 12-month transition to 4 March 2026, and the Technology Assessment and Regulation Office as the regulator supporting the Secretary’s enforcement powers.
- MinterEllison — Cyber security standards for consumer smart devices: analysis of the three requirements, the in-scope device categories, the statement of compliance and the enforcement notices. Also the source of the manufactured-date framing this article qualifies against section 13(1).
- A&O Shearman — Australia: new security standards for smart devices: the exclusion list, the requirement that a published support period cannot be shortened but may be extended, and the reliance of suppliers on manufacturer statements.
- Bird & Bird — Australia’s first standalone cyber security law: the observation that no civil penalties attach to the smart device regime and that enforcement is designed to be light touch, in contrast to the 60-penalty-unit exposure for late ransomware payment reporting elsewhere in the Act.
- Nemko — Mandatory cybersecurity: Australia’s new regulations from 4 March 2026: the mapping of the three requirements to ETSI EN 303 645 as the recognised consumer IoT baseline, and the excluded product categories.
- iTnews — Don’t wait for 2027: make your smart product security visible now (7 April 2026): the labelling scheme timeline — design complete December 2025, label design around July 2026, supporting systems September 2026, pilot October 2026, launch 2027 — the Connected Technology Alliance as co-developer, and the cited figure that close to 60 per cent of IoT manufacturers provide no clear way to report vulnerabilities.
- iTnews — Security for smart devices: time to step forward (26 February 2026): the March 2027 launch date for the voluntary labelling scheme, the energy-rating comparison, and comments from program director Frank Zeichner.
- Standards Australia — Smart Devices Cybersecurity Labelling Scheme: the scheme’s basis in independent certification against Australian or adopted international standards before a device may carry the label.