Artifact GuideAustraliaAustralia Cyber Security Act vs UK PSTI Act
Australia Cyber Security Act vs UK PSTI Act
Australia's Cyber Security Act 2024 covers connected-product security as well as ransomware payment reports, significant cyber incident coordination, and review-board powers. The UK PSTI comparison on this page concerns connected-product security.
This comparison helps separate reusable connected-product evidence from Australia-only reporting, notice, and critical-infrastructure workstreams.
Use this comparison when a connected product, ransomware payment decision, or Australian critical-infrastructure dependency could be affected by Australia's Cyber Security Act 2024 while the same product program is already tracking the UK's and 2023 security requirements regulations. The Federal Register displays 29 May 2025 for Australia's ransomware provisions, while Home Affairs guidance says 30 May 2025; obtain case-specific advice for an event on 29 May. Cyber Security Act Part 2 commenced on 29 November 2025, while the Smart Devices Rules' consumer-grade standard and statement requirements commenced on 4 March 2026. The has applied since 29 April 2024.
Side-by-side comparison
Australia Cyber Security Act 2024 vs UK PSTI Act: concrete compliance differences
Compare the Australian Cyber Security Act 2024 and UK only where the cited sources support it: connected-product security has overlap; ransomware reporting, incident coordination, review-board powers, and analysis remain Australia-specific.
Covers smart-device security standards where the product, consumer-acquisition circumstance, and manufacturer or supplier knowledge tests are met, plus separate ransomware payment reporting, significant incident coordination, Cyber Incident Review Board, and regulatory-powers workstreams.
Second framework
UK PSTI Act
Comparator regime for UK product security and telecommunications infrastructure, with this page limited to connected-product security facts supported by the existing UK sources and Australian explanatory statement.
Australia Cyber Security Act 2024 vs UK PSTI Act: concrete compliance differences
Australia: the Smart Devices Rules apply when a manufacturer or supplier knows, or could reasonably be expected to know, that a consumer will acquire in Australia a relevant connectable product intended, or likely, to be used for personal, domestic, or household use. The Rules exclude listed categories including desktop and laptop computers, tablets, smartphones, therapeutic goods, road vehicles, and road-vehicle components.
UK PSTI: the regime covers consumer connectable products made available to UK consumers. Official guidance lists exclusions and exceptions, including certain Northern Ireland products, EV charge points, medical devices, smart meters, specified computers without cellular connectivity, and vehicle categories covered by the 2025 amendment.
A product can reuse part of the product-security analysis only after the Australian consumer-grade and acquisition-in-Australia tests are documented separately from the UK PSTI scope decision.
Australia: the Smart Devices Rules place duties on manufacturers and suppliers. The must be prepared by or on behalf of the manufacturer, and suppliers must supply the covered product in Australia with that statement.
UK PSTI: manufacturers, importers, and distributors have duties under the Act and 2023 Regulations, including statement-of-compliance duties. Authorised representatives also have duties when a manufacturer's compliance failure arises.
Confirm the Australian actor role (manufacturer or supplier) and the UK actor role (manufacturer, importer, or distributor) separately, because the same business can hold different duties in each market.
Australia: the smart-device duty turns on the product class, the specified consumer-acquisition circumstance, and what the manufacturer or supplier knows or could reasonably be expected to know. The separate ransomware duty arises only when all section 26 incident, demand, payment, and reporting-business-entity conditions are met.
UK PSTI: the product-security duties apply when an in-scope relevant connectable product is made available to UK consumers. The UK regime has been in force since 29 April 2024.
Pin the trigger to a market event in each regime: Australian acquisition by a consumer versus UK availability on the UK market, and never assume a UK availability event satisfies the Australian acquisition test.
Australia: the product standard covers password requirements, publication of security-issue reporting information, and publication of the defined support period for security updates; manufacturers and suppliers also need statement-of-compliance evidence.
UK PSTI: the Australian explanatory statement says the Australian Schedule 1 security standards closely follow the UK 2023 relevant-connectable-product security requirements regulations, so these product-security topics are the safest overlap area.
Map password, vulnerability-reporting, and support-period controls once, but keep an Australian compliance matrix showing each Australian clause and statement requirement is met.
Australia: the statement must be prepared by or on behalf of the manufacturer and include product type and batch identifier, manufacturer and authorised-representative details, compliance declarations, defined support period, signatory details, and place and date of issue; statements must be retained for five years.
UK PSTI: the statement must accompany the product and meet the UK requirements. A UK manufacturer or importer must retain a copy for the longer of 10 years from the issue date and the product's defined support period. The Australian explanatory statement allows the same information to support Australia only when every Australian section 9 requirement is met.
Reuse one document only after separate Australian and UK field, accompaniment, actor, and retention checks. Otherwise keep a UK PSTI statement and an Australian statement as separate records.
Australia: the Federal Register displays 29 May 2025 for Part 3, while Home Affairs guidance says the ransomware regime started on 30 May 2025. A must report when all ransomware-payment conditions apply; the rules set a $3 million previous-financial-year turnover threshold for non- businesses, subject to the Act's exclusions and the pro-rated rule for a business carried on for only part of that year. The report is due within 72 hours after payment or awareness of an on-behalf payment.
UK PSTI: the consumer connectable product regime has applied since 29 April 2024. It is a product-security regime, not a ransomware-payment reporting regime.
Do not merge ransomware-payment playbooks with UK product-security evidence; route these cases to Australian incident response, legal, and executive approval owners.
Australia: for smart-device non-compliance the Cyber Security Act supports compliance notices, stop notices, recall notices, public notification of recall-notice failure, expert examination, civil penalties, infringement notices, enforceable undertakings, and injunctions; the Act also creates a Cyber Incident Review Board process for significant incidents.
UK PSTI: enforces the product-security regime on behalf of the Department for Science, Innovation and Technology (DSIT) and says it carries out regulatory activity on a risk-based basis. Businesses must also investigate potential compliance failures, keep records, and act on compliance failures as required by the legislation.
Keep jurisdiction-specific response files. Australian remediation may involve compliance, stop, or recall notices and examinations; UK remediation should record contact, the suspected failure, the investigation, required notifications, and corrective action.
Australia: the explanatory statement says the Schedule 1 smart-device security standards closely follow the UK 2023 relevant-connectable-product security requirements regulations, so password, vulnerability-reporting, and support-period controls are the genuine overlap area with the UK regime.
UK PSTI: the 2023 security requirements regulations set the comparable password, security-issue reporting, and minimum-support-period duties for relevant connectable products that the Australian standard mirrors, while UK-only market-surveillance and enforcement detail stay outside this overlap.
Reuse mapped product-security controls across both regimes, but keep ransomware payment reporting, Cyber Incident Review Board, and critical-infrastructure obligations strictly Australia-only because they have no UK PSTI counterpart.
Australia: run the smart-device workstream when the product, specified consumer-acquisition circumstance, and manufacturer or supplier knowledge tests are met. Run ransomware, incident-coordination, review-board, and workstreams only when their separate triggers apply.
UK PSTI: run the UK workstream when an in-scope relevant connectable product is made available to UK consumers. Confirm the UK actor role, security requirements, statement, exclusions, and any compliance-failure action.
Run both product assessments for products entering both markets. Reuse technical evidence where it proves each rule, but keep the Australian and UK legal artifacts, dates, actor findings, and incident-only records separate.
Australia: the Smart Devices Rules apply when a manufacturer or supplier knows, or could reasonably be expected to know, that a consumer will acquire in Australia a relevant connectable product intended, or likely, to be used for personal, domestic, or household use. The Rules exclude listed categories including desktop and laptop computers, tablets, smartphones, therapeutic goods, road vehicles, and road-vehicle components.
UK PSTI: the regime covers consumer connectable products made available to UK consumers. Official guidance lists exclusions and exceptions, including certain Northern Ireland products, EV charge points, medical devices, smart meters, specified computers without cellular connectivity, and vehicle categories covered by the 2025 amendment.
A product can reuse part of the product-security analysis only after the Australian consumer-grade and acquisition-in-Australia tests are documented separately from the UK PSTI scope decision.
Australia: the Smart Devices Rules place duties on manufacturers and suppliers. The must be prepared by or on behalf of the manufacturer, and suppliers must supply the covered product in Australia with that statement.
UK PSTI: manufacturers, importers, and distributors have duties under the Act and 2023 Regulations, including statement-of-compliance duties. Authorised representatives also have duties when a manufacturer's compliance failure arises.
Confirm the Australian actor role (manufacturer or supplier) and the UK actor role (manufacturer, importer, or distributor) separately, because the same business can hold different duties in each market.
Australia: the smart-device duty turns on the product class, the specified consumer-acquisition circumstance, and what the manufacturer or supplier knows or could reasonably be expected to know. The separate ransomware duty arises only when all section 26 incident, demand, payment, and reporting-business-entity conditions are met.
UK PSTI: the product-security duties apply when an in-scope relevant connectable product is made available to UK consumers. The UK regime has been in force since 29 April 2024.
Pin the trigger to a market event in each regime: Australian acquisition by a consumer versus UK availability on the UK market, and never assume a UK availability event satisfies the Australian acquisition test.
Australia: the product standard covers password requirements, publication of security-issue reporting information, and publication of the defined support period for security updates; manufacturers and suppliers also need statement-of-compliance evidence.
UK PSTI: the Australian explanatory statement says the Australian Schedule 1 security standards closely follow the UK 2023 relevant-connectable-product security requirements regulations, so these product-security topics are the safest overlap area.
Map password, vulnerability-reporting, and support-period controls once, but keep an Australian compliance matrix showing each Australian clause and statement requirement is met.
Australia: the statement must be prepared by or on behalf of the manufacturer and include product type and batch identifier, manufacturer and authorised-representative details, compliance declarations, defined support period, signatory details, and place and date of issue; statements must be retained for five years.
UK PSTI: the statement must accompany the product and meet the UK requirements. A UK manufacturer or importer must retain a copy for the longer of 10 years from the issue date and the product's defined support period. The Australian explanatory statement allows the same information to support Australia only when every Australian section 9 requirement is met.
Reuse one document only after separate Australian and UK field, accompaniment, actor, and retention checks. Otherwise keep a UK PSTI statement and an Australian statement as separate records.
Australia: the Federal Register displays 29 May 2025 for Part 3, while Home Affairs guidance says the ransomware regime started on 30 May 2025. A must report when all ransomware-payment conditions apply; the rules set a $3 million previous-financial-year turnover threshold for non- businesses, subject to the Act's exclusions and the pro-rated rule for a business carried on for only part of that year. The report is due within 72 hours after payment or awareness of an on-behalf payment.
UK PSTI: the consumer connectable product regime has applied since 29 April 2024. It is a product-security regime, not a ransomware-payment reporting regime.
Do not merge ransomware-payment playbooks with UK product-security evidence; route these cases to Australian incident response, legal, and executive approval owners.
Australia: for smart-device non-compliance the Cyber Security Act supports compliance notices, stop notices, recall notices, public notification of recall-notice failure, expert examination, civil penalties, infringement notices, enforceable undertakings, and injunctions; the Act also creates a Cyber Incident Review Board process for significant incidents.
UK PSTI: enforces the product-security regime on behalf of the Department for Science, Innovation and Technology (DSIT) and says it carries out regulatory activity on a risk-based basis. Businesses must also investigate potential compliance failures, keep records, and act on compliance failures as required by the legislation.
Keep jurisdiction-specific response files. Australian remediation may involve compliance, stop, or recall notices and examinations; UK remediation should record contact, the suspected failure, the investigation, required notifications, and corrective action.
Australia: the explanatory statement says the Schedule 1 smart-device security standards closely follow the UK 2023 relevant-connectable-product security requirements regulations, so password, vulnerability-reporting, and support-period controls are the genuine overlap area with the UK regime.
UK PSTI: the 2023 security requirements regulations set the comparable password, security-issue reporting, and minimum-support-period duties for relevant connectable products that the Australian standard mirrors, while UK-only market-surveillance and enforcement detail stay outside this overlap.
Reuse mapped product-security controls across both regimes, but keep ransomware payment reporting, Cyber Incident Review Board, and critical-infrastructure obligations strictly Australia-only because they have no UK PSTI counterpart.
Australia: run the smart-device workstream when the product, specified consumer-acquisition circumstance, and manufacturer or supplier knowledge tests are met. Run ransomware, incident-coordination, review-board, and workstreams only when their separate triggers apply.
UK PSTI: run the UK workstream when an in-scope relevant connectable product is made available to UK consumers. Confirm the UK actor role, security requirements, statement, exclusions, and any compliance-failure action.
Run both product assessments for products entering both markets. Reuse technical evidence where it proves each rule, but keep the Australian and UK legal artifacts, dates, actor findings, and incident-only records separate.
Start with the Australian scope split: smart-device standard, ransomware payment report, significant incident coordination, Cyber Incident Review Board, or overlap.
Reuse UK PSTI evidence only for connected-product security where Australian statement, support-period, retention, and consumer-acquisition requirements are independently satisfied.
Use official UK guidance for commencement, actor, scope, exclusion, and facts; check the Act, current Regulations, and enforcement policy before stating penalty amounts or case-specific enforcement consequences.
What is comparable between the Australian and UK regimes?
Connected-product security is the main overlap. Australia's Smart Devices Rules establish a security standard for that manufacturers or suppliers know, or could reasonably be expected to know, will be acquired in Australia by a consumer. The Australian explanatory statement says those standards closely follow the UK's 2023 relevant-connectable-product security requirements regulations.
Australia's Cyber Security Act 2024 also contains ransomware payment reporting, significant cyber incident coordination, and Cyber Incident Review Board provisions. remains a separate Australian critical-infrastructure regime. UK PSTI evidence does not cover those Australian workstreams.
Use product-security evidence across both regimes only for password requirements, vulnerability-reporting publication, support-period publication, and statement-of-compliance content where the Australian rules are met.
Create separate Australian records for ransomware payment reporting, including the test, payment trigger, 72-hour report clock, and required report fields.
Keep asset scoping separate from UK PSTI product scope because SOCI is about Australian critical infrastructure assets, reporting, risk management, and enhanced cyber obligations.
Treat Cyber Incident Review Board requests and significant incident coordination as Australia-only governance matters unless another source creates a separate UK duty.
Which evidence can be reused, and which must stay Australia-specific?
For connected products, the Australian explanatory statement allows responsible entities operating across similar consumer-grade smart-device frameworks to use the same statement-of-compliance information for Australia, including UK-market products, if every Australian section 9 requirement is met. The Office for Product Safety and Standards () remains the UK enforcement authority; Australian product notices follow the separate Cyber Security Act process.
Reuse remains conditional. Australian records still need the Australian product class and consumer-acquisition analysis, manufacturer-prepared statement fields, defined support period, five-year retention, and any Australian supply decision. UK manufacturers and importers must retain their statement for the longer of 10 years from issue and the defined support period. Ransomware payment reports and records are not PSTI artifacts.
Product owner: maintain product type, batch identifier, manufacturer and authorised-representative details, support-period text, and compliance declaration for Australian statement-of-compliance use.
UK product owner: record how the statement accompanies the product and retain the UK statement for the longer of 10 years from issue and the defined support period.
Security engineering: prove unique or user-defined passwords, security-issue reporting details, acknowledgement and status-update process, and security-update support period publication.
Incident response and legal: keep Australian ransomware payment report facts separate, including ABN/address details where applicable, incident impact, demand, payment, and communications fields.
Critical infrastructure owner: document whether asset obligations apply separately from product-security duties before reusing any control or audit evidence.
Home Affairs says the ransomware payment reporting rules start from 30 May 2025, one day after the date displayed in the Federal Register's Act commencement table.