Australia Security Standards for Smart Devices
Mandatory cybersecurity standards for most consumer-grade relevant connectable products manufactured on/from 4 March 2026.
beta · ruleset 1.0.0 · reviewed 2026-09-22
Deterministic decisions
Whether the product is an in-scope consumer-grade relevant connectable product manufactured on/from 4 March 2026.
engineering_complete_legal_review_required
Role under the Australian smart-device regime.
engineering_complete_legal_review_required
Authoritative sources
Cyber Security Act 2024 (Australia)
https://www.legislation.gov.au/C2024A00098/asmade
primary_binding_law · reviewed 2026-09-22
Australian Department of Home Affairs — Security Standards for Smart Devices
https://www.homeaffairs.gov.au/cyber-security-subsite/Pages/security-standards-for-smart-devices.aspx
official_guidance · reviewed 2026-09-22
Cyber Security (Security Standards for Smart Devices) Rules 2025
https://www.legislation.gov.au/F2025L00276/asmade
primary_binding_law · reviewed 2026-09-22
Obligation library
No universal default passwords
Meet the password security standard in Schedule 1 where passwords are used by product hardware/pre-installed software in the specified circumstances.
Publish a means to report security issues
Publish a security-issue reporting mechanism and maintain the required information/status process.
Publish defined support period
Publish the defined support period, including an end date, with the required prominence.
Statement of Compliance
Prepare the required Statement of Compliance and ensure in-scope supply is accompanied by it; retain it as required.
Generated artifacts
Australia Smart Device Scope Report
report · template v1.0.0
Australia Statement of Compliance Draft
statement_of_compliance · template v1.0.0 · signature required
Security Issue Reporting Policy Starter
policy · template v1.0.0
Defined Support Period Publication Text
disclosure · template v1.0.0