Smart device security standard: what makers and sellers must do
Since 4 March 2026, most internet-connected consumer devices made for the Australian market must ship without guessable shared passwords, with a published way to report security bugs, and with a stated end date for security updates. Suppliers must also hand over a statement of compliance. Here is who is caught, what the three rules mean in practice, and what to check before you stock or buy a device.
The Cyber Security (Security Standards for Smart Devices) Rules 2025 are made under Part 2 of the Cyber Security Act 2024. They were registered on 4 March 2025 and the security standard itself (Part 2 and Schedule 1 of the Rules) commenced on 4 March 2026, after a 12-month transition. The Department of Home Affairs says the standard reflects international practice; its three core requirements line up with the baseline in ETSI EN 303 645 and the UK product security regime, so a device already built to those will usually be close.
Who is caught. The standard applies to 'relevant connectable products', meaning devices that can connect directly or indirectly to the internet, that are intended or likely to be used for personal, domestic or household purposes and will be acquired in Australia by a consumer (consumer has its Australian Consumer Law meaning). Typical examples are smart TVs, cameras, doorbells, speakers, plugs, wearables, routers sold at retail and connected appliances. Section 8 of the Rules excludes desktop and laptop computers, tablets, smartphones, therapeutic goods under the Therapeutic Goods Act 1989, and road vehicles and road vehicle components under the Road Vehicle Standards Act 2018. Products manufactured before 4 March 2026 do not have to comply, according to Home Affairs. The obligations fall on manufacturers (who must build to the standard if they know, or should know, the product will be sold to Australian consumers) and on suppliers, who must not supply a non-compliant product and must supply it with a statement of compliance.
Rule 1: no universal default passwords. Outside the factory default state, any password for the device hardware, its pre-installed software, or software that must be installed to use the product (such as the companion app) must be unique per product or set by the user. A unique password must not come from an incrementing counter (password1, password2), from public information, or from an identifier such as the serial number unless it is derived with an encryption method or keyed hash accepted as good industry practice, and must not otherwise be guessable. A shared default is still allowed while the device is in factory default state, as long as the user must replace it to move out of that state. Cryptographic keys, API keys and pairing PINs for non-IP protocols such as Bluetooth are not 'passwords' for this rule.
Rule 2: a published way to report security issues. The manufacturer must publish at least one point of contact for reporting security problems in the hardware, the pre-installed software, required apps and other software used with the product, and say when the reporter will get an acknowledgement and status updates until the issue is resolved. The information must be clear, in English, free, available without asking for it and without demanding the reporter's personal details. In practice that means a public vulnerability disclosure page (and ideally a security.txt file) with a monitored inbox and stated response times.
Rule 3: a defined support period. The manufacturer must publish how long security updates will be provided, expressed as a period with an end date, for the device and the software that comes with it or is needed to use it. Home Affairs' examples are 'no earlier than 30 June 2027' or 'ending on 30 June 2029'. The period cannot be shortened once published; an extension must be published as soon as practicable. It must be understandable without technical knowledge, and if the manufacturer sells the product on its own website, the support period must sit with the product's main characteristics and be given equal prominence.
The statement of compliance. Prepared by or for the manufacturer, it must state the product type and batch identifier; the name and address of the manufacturer, an authorised representative and any authorised representatives in Australia; a declaration that the manufacturer prepared it and believes the product complies; the defined support period at the date of issue; the signatory's signature, name and role; and the place and date of issue. Manufacturers and suppliers must keep it for five years. The Act requires suppliers to supply the product 'accompanied' by the statement but does not define how, so each supplier decides whether that is in the box, on the product page or by link; Home Affairs publishes a template.
Enforcement. The Technology Assessment and Regulation Office in Home Affairs regulates the standard for the Secretary of the department, and says it will start with an uplift-focused approach. Part 2 of the Act gives the Secretary compliance, stop and recall notices. If a recall notice is not followed, the Secretary can publish that fact (s 20), and the Rules add that the notice details and suggested consumer actions, such as destroying the product or taking extra precautions, may be published too.
What to do. Manufacturers and importers: map each product line against section 8, confirm passwords are per-device or user-set across the device and companion app, stand up and publish a disclosure contact with response times, publish an end-dated support period for hardware, firmware and app, and generate a statement of compliance per batch with five-year retention. Retailers and marketplaces: ask suppliers for the statement before listing, check that the support end date and reporting contact are public, and pull products built after 4 March 2026 that cannot show them. Organisations buying consumer-grade devices for offices or staff: prefer devices with a long published support period, record the end date in your asset register so it becomes a refresh trigger, and remember the standard does not cover laptops, phones or tablets, so those still need your own patching and Essential Eight controls.
See also:
