Smart Home

Australia’s smart device security rules, five months on

Since 4 March 2026 the smart gear sold to Australian consumers has had to meet three legally binding security requirements. They are genuinely useful, they exclude the device in your pocket, and breaking them carries no fine at all. Here is what the law actually says.

Published 5 August 202611 min readSnapshot: August 2026
This is a dated snapshot of an Australian legislative instrument and the regime around it — not a hands-on test of any product, so there is no score. We have read the Act and the Rules as registered and quote them directly; we have not audited what is currently on Australian shelves, and no compliance claim about any named brand appears below. This is general information about published law, not legal advice. Every claim is sourced, and the links are at the end.

The short version

On 4 March 2026, Part 2 and Schedule 1 of the Cyber Security (Security Standards for Smart Devices) Rules 2025 commenced. They are made under the Cyber Security Act 2024, and they are Australia’s first mandatory, enforceable baseline for the security of consumer smart devices — replacing a voluntary code that manufacturers were free to ignore.

The requirements are deliberately modest. Three things:

  • No universal default passwords. Passwords must be unique to each individual device, or set by the user.
  • A published way to report security bugs. At least one contact point, plus a stated timeframe for acknowledgement and status updates.
  • A published support period with an end date. How long the thing will get security updates — and once published, the manufacturer cannot shorten it.

That third one is the sleeper. For the first time, the answer to “how long will this smart lock keep getting patches?” is a number the manufacturer has to put on its own product page, in plain English, free, without you having to ask.

Two things temper the enthusiasm. Smartphones, tablets, laptops and desktops are explicitly carved out — the rules cover the doorbell, not the phone that opens it. And the Act attaches no civil penalty to any of it: enforcement runs through a ladder of notices, each with at least ten days to argue back, and the worst outcome is being named on a government website.

What the three requirements actually say

The detail lives in Schedule 1 of the Rules, and it is more precisely drafted than the summaries suggest.

Passwords (clause 2). Passwords must be either unique per product — meaning unique for each individual unit, not each model — or defined by the user. Where they are unique per product, the Rules close the obvious loopholes: a unique password must not be based on an incremental counter (the instrument gives “password1” and “password2” as its own example), must not be derived from publicly available information, and must not be derived from a serial number or other unique product identifier unless that is done with encryption or a keyed hashing algorithm meeting good industry practice. A catch-all bans anything “otherwise guessable in a manner unacceptable as part of good industry practice”.

Note what “password” excludes: cryptographic keys, API keys, and the pairing PINs used by non-internet protocols. Your Bluetooth headphones asking for 0000 is not what this clause is aimed at.

Reporting security issues (clause 3). The manufacturer must publish at least one point of contact for reporting security issues, and must publish when a reporter will get an acknowledgement and status updates through to resolution. The publication requirements are the interesting part: the information must be available without prior request, in English, free of charge, and — a nice touch — without requiring the reporter to hand over personal information first.

This is the requirement most likely to bite. Research cited by the team building Australia’s companion labelling scheme puts the share of IoT manufacturers with no clear vulnerability reporting channel at close to 60 per cent.

Support period (clause 4). The manufacturer must publish a defined support period for security updates, “expressed as a period of time with an end date”. It must not be shortened after publication; if it is extended, the extension must be published as soon as practicable. It has to be accessible, clear, transparent, free, in English, available without asking, and understandable by a reader with no technical background.

And clause 4(7) is the one that puts it in front of buyers. If the manufacturer sells the product on its own website, the support period must be published prominently alongside the information intended to inform a purchase — and wherever the main characteristics of the product appear, the support period must appear alongside them or with equal prominence. In other words: not buried in a support-portal PDF. Next to the specs.

What is in scope, and the carve-outs

The Act works in two layers. Section 13 of the Cyber Security Act 2024 defines a relevant connectable product broadly — an internet-connectable product (anything that talks IP to the internet), or a network-connectable product, which sweeps in devices that cannot reach the internet themselves but connect directly to something that can, or that link two or more devices at once. A sensor that only speaks Zigbee to a hub is captured. A bare cable is not.

Section 8 of the Rules then narrows that to the class this security standard applies to: products intended by the manufacturer, or of a kind likely, to be used for personal, domestic or household use, that will be acquired in Australia by a consumer — “consumer” taking its meaning from section 3 of the Australian Consumer Law.

Then it lists what is not covered. There are six exclusions, and they are worth reading literally:

  • a desktop computer or a laptop;
  • a tablet computer;
  • a smartphone;
  • therapeutic goods within the meaning of the Therapeutic Goods Act 1989;
  • a road vehicle within the meaning of the Road Vehicle Standards Act 2018;
  • a road vehicle component within the meaning of that Act.

So: smart TVs, IP cameras, routers, speakers, doorbells, lights, robot vacuums, trackers, headphones, connected appliances — in. Phones, tablets and computers — out, on the reasoning that those platforms already sit under their own update and app-store regimes. Medical devices go to the TGA; cars go to the road vehicle standards. Each carve-out is defensible on its own terms. The aggregate effect is that the four screens most Australians actually own are governed by everything except this.

The bit most summaries get wrong

You will read, in more than one law firm briefing, that devices manufactured before 4 March 2026 are outside the regime. That is half the test.

Section 13(1) of the Act says the Part applies to a relevant connectable product that is manufactured on or after commencement or supplied (other than as second hand goods) on or after commencement. Both limbs. A device built in late 2025 and sold new to an Australian consumer in July 2026 engages the second limb; only genuinely second-hand supply is carved out.

That matters for anyone clearing old stock, and it matters for grey imports. It also means the sensible consumer question is not “when was this made” but “is a compliant support period published for it”.

The statement of compliance — and why you will never see one

Alongside the standard itself, the Act requires paperwork. A manufacturer must provide a statement of compliance for supply in Australia, and a supplier must supply the product with one. Section 9 of the Rules sets out what it must contain: the product type and batch identifier; the name and address of the manufacturer, of an authorised representative, and of each of the manufacturer’s other authorised representatives in Australia; a declaration that it was prepared by or for the manufacturer; a declaration that in the manufacturer’s opinion the product was made in compliance and the other obligations were met; the defined support period as at the date of issue; the signature, name and function of the signatory; and the place and date of issue. Both manufacturer and supplier must keep a copy for five years.

Read that list again and notice what it is: a business-to-business compliance artefact. It is a declaration by the manufacturer of its own opinion, retained on file, with no independent testing behind it. It is not a label, not a certificate, and not something a retailer is required to hand a shopper at the counter. The consumer-facing part of this regime is not the statement of compliance — it is the support-period disclosure required to sit next to the specs on the product page.

Enforcement: a ladder, not a stick

Regulation sits with the Technology Assessment and Regulation Office inside the Department of Home Affairs, supporting the Secretary’s powers under Division 3 of Part 2 of the Act. The sequence is strictly escalating:

  • Compliance notice (s 17) — issued where the Secretary is reasonably satisfied there is non-compliance, or is aware of information suggesting there may be. It specifies the action required and a reasonable period to take it.
  • Stop notice (s 18) — only available after a compliance notice, and only if the entity did not comply or its remedy was inadequate.
  • Recall notice (s 19) — only after a stop notice, on the same test. It can require the entity to keep the product out of Australian hands and arrange returns.
  • Public notification (s 20) — if the entity fails to comply with the recall notice, the Minister may publish its identity, the product details, the non-compliance and the risks. Section 11 of the Rules adds that the publication may include details of the recall notice and recommended consumer actions, expressly including destroying the product.

Before issuing any of the three notices the Secretary must first notify an intention to do so and allow at least ten days for representations. Only one notice of each kind may be issued per instance of non-compliance, and an entity can seek internal review within 30 days.

What is absent is the thing that usually makes product regulation move: there is no civil penalty attached to the section 15 or 16 obligations. A manufacturer that ships a device with a shared default password and no published support period faces, at worst and after several rounds of correspondence, a recall and the reputational damage of being named. Commentators have described the design as deliberately light touch. That is a fair reading of the text.

The counterweight is market access rather than money. A recall notice is a serious commercial event, and Australian Consumer Law guarantees run underneath all of this regardless.

What is coming next: the label

The mandatory rules are a floor. The part designed to be visible to shoppers is the voluntary Security Labelling Scheme for Smart Devices, being co-designed by the Connected Technology Alliance — formerly IoT Alliance Australia — with the Australian Government, and developed with Standards Australia as an independently certified mark rather than a self-declaration.

On the timeline published by the program in April 2026: scheme design was completed in December 2025, label design was due for release around July 2026, supporting systems in September 2026, a pilot from October 2026 and national launch in 2027. Coverage in February 2026 put the launch at March 2027. It is intended to work like an energy rating — a security claim you can compare at the point of sale — and to align with international schemes such as the US Cyber Trust Mark. Frank Zeichner, the program director and founding chief executive of IoT Alliance Australia, framed the change bluntly in February: the shift, he said, has already happened.

Two caveats worth holding onto. The scheme is voluntary, so absence of a label will not mean non-compliance. And it inherits the same exclusions — phones and laptops are outside it too.

So what should a buyer actually do

Look for the support end date on the product pageThis is the single most useful consequence of the rules. If a manufacturer sells the device on its own site, the defined support period must appear prominently alongside the main product information — not in a buried PDF. A vendor that cannot show you an end date is telling you something.
Treat a missing security contact as a red flagEvery in-scope manufacturer must publish a way to report security issues, free, in English, without you registering or handing over personal details. It takes thirty seconds to check, and the published research suggests a large minority still fail it.
Expect a unique or self-set passwordA device that ships with the same admin password as every other unit of its model has not met the standard. If setup hands you a shared default and does not force a change, that is the clearest visible non-compliance signal available to an ordinary buyer.
Do not read the exclusions as a security rankingPhones, tablets and laptops are excluded because they are governed elsewhere, not because they are safer. Conversely, an in-scope device meeting all three requirements has cleared a low bar — three baseline controls, self-declared.
Clearance stock is still coveredBecause supply on or after 4 March 2026 engages the Act independently of manufacturing date, discounted old stock sold new is in scope. Genuinely second-hand goods are not — so marketplace purchases carry none of this.
Wait for the label, but do not wait on itThe certified security label is voluntary, pilots from October 2026 and launches in 2027. Until then its absence means nothing, and the support-period disclosure is the more reliable signal.
Report what you findEnforcement here is complaint-driven and the regulator is the Technology Assessment and Regulation Office within Home Affairs. A device with no published support period is a reportable gap, not just an annoyance.

The bottom line

Australia has done the sensible, unglamorous thing: taken the first three provisions of the international consumer IoT baseline — the same three the United Kingdom picked for its PSTI regime, drawn from ETSI EN 303 645 — and made them law. Nothing here is technically demanding. Any manufacturer that could not meet these three requirements in March 2026 had been choosing not to.

The honest assessment five months in is that the disclosure requirement is worth more than the security requirements. Unique passwords and a bug-report inbox are hygiene. A published, non-retractable support end date, sitting next to the specifications where a shopper can see it, changes what can be compared before money changes hands — and quietly makes abandonware a disclosed product attribute rather than a discovery you make two years later.

What the regime does not have is teeth. No penalties, an escalation ladder with ten-day pauses at each rung, and a compliance artefact that never reaches the customer. Whether it works will come down to whether Home Affairs uses the notices and whether the 2027 label gives manufacturers a commercial reason to go past the floor. Neither is knowable yet. What is knowable is the question to ask in a shop, and until March 2026 you had no right to an answer: how long does this get security updates, and what is the end date?

Sources

Facts, dates and quoted requirements above are drawn from these primary and reputable sources, captured 5 August 2026:

New Technology is an independent editorial publication. This article summarises published Australian legislation and reputable commentary on it; it is general information, not legal advice, and anyone with a compliance obligation should read the instrument itself or take advice. We have not tested any device against these requirements and make no compliance claim about any manufacturer. Law, timelines and the labelling scheme’s dates change — check the Federal Register of Legislation and the Department of Home Affairs for the current position.
← All reviews Matter 1.5 & Thread in 2026 Suggest a correction