Australia Cyber Security Act vs EU Cyber Resilience Act
Australia's Cyber Security Act 2024 combines smart-device security standards, statements of compliance, ransomware payment reporting, and incident coordination. The EU Cyber Resilience Act sets horizontal cybersecurity requirements for products with digital elements placed on the Union market.
This page helps separate the Australian and EU workstreams before reusing product-security evidence across markets.
The Australian Cyber Security Act 2024 and Regulation (EU) 2024/2847, the Cyber Resilience Act, use different product-scope and actor tests. One regime does not establish compliance with the other: Australian records should show the , manufacturer, supplier, or analysis, while EU records should identify each and document the product-with-digital-elements analysis. Australia's smart-device standard and ransomware reporting are in force. The Federal Register displays 29 May 2025 for Part 3 commencement, while Home Affairs guidance says ransomware reporting started on 30 May 2025; obtain case-specific advice for an event on 29 May. The EU CRA's Chapter IV conformity-assessment-body provisions have applied since 11 June 2026, Article 14 reporting starts on 11 September 2026, and most CRA requirements apply from 11 December 2027.
Side-by-side comparison
Australia Cyber Security Act 2024 vs EU Cyber Resilience Act
A concrete comparison of the Australian Cyber Security Act 2024 and the EU Cyber Resilience Act for product, security, legal, and compliance teams managing connected products across both markets.
Australian obligations focus on relevant connectable products, consumer-grade smart-device security standards, statements of compliance, ransomware payment reporting, incident coordination, and enforcement through Australian notices and regulatory powers.
Second framework
EU Cyber Resilience Act
The EU CRA applies horizontal cybersecurity requirements to products with digital elements placed on the Union market and allocates duties across economic operators such as manufacturers, authorised representatives, importers, and distributors.
Australia Cyber Security Act 2024 vs EU Cyber Resilience Act
Australia: start with relevant connectable products that the manufacturer or supplier knows, or could reasonably be expected to know, will be acquired in Australia in the specified consumer circumstance. The smart-device rules prescribe a standard for consumer-grade relevant connectable products and exclude listed product categories such as desktop computers, laptops, tablet computers, smartphones, therapeutic goods, road vehicles, and road vehicle components.
EU: start with products with digital elements and whether they are placed on the Union market. The CRA is framed as horizontal cybersecurity requirements for hardware and software products with digital elements, not only consumer smart devices.
A connected consumer device may need both reviews, but the Australian scope file should prove the relevant-connectable-product and consumer-grade analysis while the EU file proves the product-with-digital-elements and Union-market analysis.
Australia: the smart-device duties distinguish manufacturers and suppliers. Manufacturers must manufacture covered products in compliance with the security standard and prepare the statement of compliance required for Australian supply. Suppliers must not supply a covered product if they are aware, or could reasonably be expected to be aware, that it does not comply, and must supply the product in Australia with the statement of compliance.
EU: the CRA allocates duties across economic operators, including manufacturers, authorised representatives, importers, and distributors. Do not assume the Australian supplier role maps one-to-one to an EU importer or distributor role.
Build a role matrix by market: Australian manufacturer, Australian supplier, EU manufacturer, EU authorised representative, EU importer, and EU distributor may be different legal entities.
Australia: the smart-device rules specify concrete consumer-device controls, including password requirements, a published security-issue reporting contact and response information, and a published defined support period for security updates.
EU: the CRA sets essential cybersecurity requirements for products with digital elements and expects cybersecurity to be addressed across the product lifecycle.
A secure-by-design program can support both sides, but the Australian evidence should explicitly show the password, vulnerability-reporting, and support-period items required by the smart-device rules.
Australia: for covered consumer-grade relevant connectable products, the statement of compliance must be prepared by or on behalf of the manufacturer, include product and manufacturer details, declare compliance, state the defined support period, and include signature, place, and date of issue. The rules specify a five-year retention period.
EU: the CRA workstream should keep EU product technical documentation, evidence, declarations, evidence, and economic-operator records separate from the Australian statement of compliance.
Treat the Australian statement of compliance as an Australian artifact. It may reuse underlying test evidence, but it is not automatically the EU CRA conformity file.
Australia: the Act and ransomware rules create a separate ransomware payment reporting workstream. A includes certain responsible entities or a business in Australia above the rules' turnover threshold, and the report must cover the incident, extortion demand, payment, and communications to the extent the entity can find the information within the 72-hour reporting period.
EU: the CRA is not a ransomware payment reporting regime. From 11 September 2026, manufacturers must report actively exploited vulnerabilities and severe incidents affecting product security, with an early warning within 24 hours and a main notification within 72 hours. A final report is due no later than 14 days after a corrective or mitigating measure becomes available for an , or within one month after the 72-hour notification for a severe incident.
Keep the Australian payment event and the EU product-security event on separate clocks. The same incident may require both records, but payment facts do not replace the EU exploitation or severe-incident assessment, and EU product notifications do not replace the Australian payment report.
Australia: the Federal Register displays 29 May 2025 for Part 3 ransomware reporting and Part 5 review-board commencement, while Home Affairs says ransomware reporting started on 30 May 2025. Part 2 of the Act commenced on 29 November 2025. Part 2 and Schedule 1 of the Smart Devices Rules, which contain the consumer-grade standard and statement requirements, commenced on 4 March 2026.
EU: Chapter IV has applied since 11 June 2026. Article 14 vulnerability and severe-incident reporting applies from 11 September 2026, while the Regulation otherwise applies from 11 December 2027. Products placed on the market before 11 December 2027 are generally subject only if substantially modified after that date, but Article 14 also applies to in-scope products placed earlier.
Maintain separate readiness dates. Australian product and ransomware duties are operative; EU Chapter IV applies, Article 14 reporting starts on 11 September 2026, and general CRA conformity requirements apply from 11 December 2027.
Australia: reuse EU CRA engineering evidence only where it proves the specific Australian requirement, such as password design, security-issue reporting, support-period publication, statement-of-compliance content, or ransomware report content.
EU: reuse Australian engineering evidence only where it maps to the EU CRA product-with-digital-elements obligation and economic-operator file. Australian smart-device statements, records, and ransomware payment reports do not replace EU CRA conformity evidence.
Maintain a bridge table with three columns: shared engineering evidence, Australian legal artifact, and EU CRA legal artifact. Leave a row blank where the regimes do not match.
Australia: the manufacturer must publish a defined support period with an end date and must not shorten it after publication. The Rules define that period as the time for which security updates will be provided; the explanatory statement says available updates should be provided during it as far as practicable and in line with good industry practice. That explanatory statement explains the rule but is not the binding instrument.
EU: the manufacturer determines a support period that reflects the expected use time and other Article 13(8) factors. The period is at least five years unless the product is expected to be used for less than five years, and vulnerability handling and security updates continue through that support period.
A shared support policy can supply evidence to both files, but the published Australian end date and the EU Article 13(8) rationale must each meet their own rule.
Step 1: decide whether the manufacturer or supplier knows, or could reasonably be expected to know, that an Australian consumer will acquire the , and whether it falls within the consumer-grade smart-device rules. Step 2: if yes, complete the Australian statement-of-compliance and support-period records. Step 3: separately assess ransomware reporting only if the section 26 incident, demand, payment, and reporting-business-entity conditions arise.
EU: assess whether the same product is a placed on the Union market. Apply the staged dates: Chapter IV from 11 June 2026, Article 14 from 11 September 2026, and the remaining CRA requirements from 11 December 2027, subject to Article 69 transition rules.
Australia: start with relevant connectable products that the manufacturer or supplier knows, or could reasonably be expected to know, will be acquired in Australia in the specified consumer circumstance. The smart-device rules prescribe a standard for consumer-grade relevant connectable products and exclude listed product categories such as desktop computers, laptops, tablet computers, smartphones, therapeutic goods, road vehicles, and road vehicle components.
EU: start with products with digital elements and whether they are placed on the Union market. The CRA is framed as horizontal cybersecurity requirements for hardware and software products with digital elements, not only consumer smart devices.
A connected consumer device may need both reviews, but the Australian scope file should prove the relevant-connectable-product and consumer-grade analysis while the EU file proves the product-with-digital-elements and Union-market analysis.
Australia: the smart-device duties distinguish manufacturers and suppliers. Manufacturers must manufacture covered products in compliance with the security standard and prepare the statement of compliance required for Australian supply. Suppliers must not supply a covered product if they are aware, or could reasonably be expected to be aware, that it does not comply, and must supply the product in Australia with the statement of compliance.
EU: the CRA allocates duties across economic operators, including manufacturers, authorised representatives, importers, and distributors. Do not assume the Australian supplier role maps one-to-one to an EU importer or distributor role.
Build a role matrix by market: Australian manufacturer, Australian supplier, EU manufacturer, EU authorised representative, EU importer, and EU distributor may be different legal entities.
Australia: the smart-device rules specify concrete consumer-device controls, including password requirements, a published security-issue reporting contact and response information, and a published defined support period for security updates.
EU: the CRA sets essential cybersecurity requirements for products with digital elements and expects cybersecurity to be addressed across the product lifecycle.
A secure-by-design program can support both sides, but the Australian evidence should explicitly show the password, vulnerability-reporting, and support-period items required by the smart-device rules.
Australia: for covered consumer-grade relevant connectable products, the statement of compliance must be prepared by or on behalf of the manufacturer, include product and manufacturer details, declare compliance, state the defined support period, and include signature, place, and date of issue. The rules specify a five-year retention period.
EU: the CRA workstream should keep EU product technical documentation, evidence, declarations, evidence, and economic-operator records separate from the Australian statement of compliance.
Treat the Australian statement of compliance as an Australian artifact. It may reuse underlying test evidence, but it is not automatically the EU CRA conformity file.
Australia: the Act and ransomware rules create a separate ransomware payment reporting workstream. A includes certain responsible entities or a business in Australia above the rules' turnover threshold, and the report must cover the incident, extortion demand, payment, and communications to the extent the entity can find the information within the 72-hour reporting period.
EU: the CRA is not a ransomware payment reporting regime. From 11 September 2026, manufacturers must report actively exploited vulnerabilities and severe incidents affecting product security, with an early warning within 24 hours and a main notification within 72 hours. A final report is due no later than 14 days after a corrective or mitigating measure becomes available for an , or within one month after the 72-hour notification for a severe incident.
Keep the Australian payment event and the EU product-security event on separate clocks. The same incident may require both records, but payment facts do not replace the EU exploitation or severe-incident assessment, and EU product notifications do not replace the Australian payment report.
Australia: the Federal Register displays 29 May 2025 for Part 3 ransomware reporting and Part 5 review-board commencement, while Home Affairs says ransomware reporting started on 30 May 2025. Part 2 of the Act commenced on 29 November 2025. Part 2 and Schedule 1 of the Smart Devices Rules, which contain the consumer-grade standard and statement requirements, commenced on 4 March 2026.
EU: Chapter IV has applied since 11 June 2026. Article 14 vulnerability and severe-incident reporting applies from 11 September 2026, while the Regulation otherwise applies from 11 December 2027. Products placed on the market before 11 December 2027 are generally subject only if substantially modified after that date, but Article 14 also applies to in-scope products placed earlier.
Maintain separate readiness dates. Australian product and ransomware duties are operative; EU Chapter IV applies, Article 14 reporting starts on 11 September 2026, and general CRA conformity requirements apply from 11 December 2027.
Australia: reuse EU CRA engineering evidence only where it proves the specific Australian requirement, such as password design, security-issue reporting, support-period publication, statement-of-compliance content, or ransomware report content.
EU: reuse Australian engineering evidence only where it maps to the EU CRA product-with-digital-elements obligation and economic-operator file. Australian smart-device statements, records, and ransomware payment reports do not replace EU CRA conformity evidence.
Maintain a bridge table with three columns: shared engineering evidence, Australian legal artifact, and EU CRA legal artifact. Leave a row blank where the regimes do not match.
Australia: the manufacturer must publish a defined support period with an end date and must not shorten it after publication. The Rules define that period as the time for which security updates will be provided; the explanatory statement says available updates should be provided during it as far as practicable and in line with good industry practice. That explanatory statement explains the rule but is not the binding instrument.
EU: the manufacturer determines a support period that reflects the expected use time and other Article 13(8) factors. The period is at least five years unless the product is expected to be used for less than five years, and vulnerability handling and security updates continue through that support period.
A shared support policy can supply evidence to both files, but the published Australian end date and the EU Article 13(8) rationale must each meet their own rule.
Step 1: decide whether the manufacturer or supplier knows, or could reasonably be expected to know, that an Australian consumer will acquire the , and whether it falls within the consumer-grade smart-device rules. Step 2: if yes, complete the Australian statement-of-compliance and support-period records. Step 3: separately assess ransomware reporting only if the section 26 incident, demand, payment, and reporting-business-entity conditions arise.
EU: assess whether the same product is a placed on the Union market. Apply the staged dates: Chapter IV from 11 June 2026, Article 14 from 11 September 2026, and the remaining CRA requirements from 11 December 2027, subject to Article 69 transition rules.
Start with market and product scope: Australian and consumer-grade analysis on one side, EU product-with-digital-elements and Union-market analysis on the other.
Assign actors separately: Australian manufacturer and supplier roles do not automatically equal EU manufacturer, authorised representative, importer, or distributor roles.
Keep ransomware payment reporting outside the EU CRA evidence file unless the same incident also creates a separate EU product-security issue.
Use shared engineering controls where possible, but keep the Australian statement of compliance and EU CRA conformity evidence as separate legal artifacts.
Connected-product security is the main overlap. Australia uses the Cyber Security Act 2024 and the Cyber Security (Security Standards for Smart Devices) Rules 2025 to regulate relevant connectable products, with a consumer-grade smart-device standard, statement-of-compliance requirements, and notice powers for non-compliance.
The EU Cyber Resilience Act is framed more broadly around horizontal cybersecurity requirements for hardware and software products with digital elements, but its Article 2 exclusions and sectoral overlap rules still need a product-specific check. A product team may be able to reuse vulnerability-handling, support-period, secure-by-design, and technical-documentation evidence, but it should keep separate Australia and EU scope records.
Use the Australian workstream for relevant connectable products, consumer-grade smart-device standards, statements of compliance, supplier records, ransomware payment reports, and overlap checks.
Use the EU CRA workstream for products with digital elements, Union-market placement, economic-operator roles, essential cybersecurity requirements, vulnerability handling, , and evidence.
Reuse product-security evidence only after confirming that the product version, support period, vulnerability process, market role, and cited obligation align.
Separate Australian and EU product-security evidence
This comparison helps split Australian smart-device, ransomware, and SOCI overlap records from EU CRA product-with-digital-elements evidence before assigning implementation work.
For Australia, keep the product classification, manufacturer and supplier role analysis, statement of compliance, defined support period, password and vulnerability-reporting evidence, recall or notice correspondence, and any ransomware payment report file in a distinct Australian record set.
For the EU CRA, keep the economic-operator role, product-with-digital-elements scope assessment, essential cybersecurity requirement mapping, vulnerability-handling process, technical documentation, conformity evidence, and market-surveillance correspondence in a distinct EU record set.
Do not use an Australian statement of compliance as a substitute for EU CRA conformity evidence without a separate EU CRA analysis.
Do not use EU CRA technical documentation as proof that an Australian supplier supplied the product with the required Australian statement of compliance.
Do not merge ransomware payment reporting with EU CRA vulnerability or incident handling; the Australian ransomware report has its own trigger, threshold, 72-hour clock, and content fields.
From 11 September 2026, the EU CRA requires manufacturers to report an or severe incident through the CRA process. The early warning is due within 24 hours of awareness and the main notification within 72 hours; the final-report deadline differs for a vulnerability and a severe incident.
The explanatory statement, rather than the text of clause 4 itself, says an available security update should be provided during the defined support period as far as practicable and in line with good industry practice.
"as far as practicable and in line with good industry practice"