ComparisonAustralia and EUCyber product security

Australia Cyber Security Act vs EU Cyber Resilience Act

Australia's Cyber Security Act 2024 combines smart-device security standards, statements of compliance, ransomware payment reporting, and incident coordination. The EU Cyber Resilience Act sets horizontal cybersecurity requirements for products with digital elements placed on the Union market.

This page helps separate the Australian and EU workstreams before reusing product-security evidence across markets.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 25, 2026
Sections
2

Structured answer sets in this page tree.

Primary sources
8

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 25, 2026
Overview

The Australian Cyber Security Act 2024 and Regulation (EU) 2024/2847, the Cyber Resilience Act, use different product-scope and actor tests. One regime does not establish compliance with the other: Australian records should show the relevant connectable product, manufacturer, supplier, or reporting business entity analysis, while EU records should show the and economic-operator analysis. Australia's smart-device standard and ransomware reporting are in force. The EU CRA's Chapter IV conformity-assessment-body provisions have applied since 11 June 2026, Article 14 reporting starts on 11 September 2026, and most CRA requirements apply from 11 December 2027.

Side-by-side comparison

Australia Cyber Security Act 2024 vs EU Cyber Resilience Act

A concrete comparison of the Australian Cyber Security Act 2024 and the EU Cyber Resilience Act for product, security, legal, and compliance teams managing connected products across both markets.

Review all sources
First framework
Australia Cyber Security Act 2024

Australian obligations focus on relevant connectable products, consumer-grade smart-device security standards, statements of compliance, ransomware payment reporting, incident coordination, and enforcement through Australian notices and regulatory powers.

Second framework
EU Cyber Resilience Act

The EU CRA applies horizontal cybersecurity requirements to products with digital elements placed on the Union market and allocates duties across economic operators such as manufacturers, authorised representatives, importers, and distributors.

Comparison row 1

Scope boundary

Australia Cyber Security Act 2024

Australia: start with relevant connectable products that the manufacturer or supplier knows, or could reasonably be expected to know, will be acquired in Australia in the specified consumer circumstance. The smart-device rules prescribe a standard for consumer-grade relevant connectable products and exclude listed product categories such as desktop computers, laptops, tablet computers, smartphones, therapeutic goods, road vehicles, and road vehicle components.

EU Cyber Resilience Act

EU: start with products with digital elements and whether they are placed on the Union market. The CRA is framed as horizontal cybersecurity requirements for hardware and software products with digital elements, not only consumer smart devices.

Operational implication

A connected consumer device may need both reviews, but the Australian scope file should prove the relevant-connectable-product and consumer-grade analysis while the EU file proves the product-with-digital-elements and Union-market analysis.

Comparison row 2

Covered actors

Australia Cyber Security Act 2024

Australia: the smart-device duties distinguish manufacturers and suppliers. Manufacturers must manufacture covered products in compliance with the security standard and prepare the statement of compliance required for Australian supply. Suppliers must not supply a covered product if they are aware, or could reasonably be expected to be aware, that it does not comply, and must supply the product in Australia with the statement of compliance.

EU Cyber Resilience Act

EU: the CRA allocates duties across economic operators, including manufacturers, authorised representatives, importers, and distributors. Do not assume the Australian supplier role maps one-to-one to an EU importer or distributor role.

Operational implication

Build a role matrix by market: Australian manufacturer, Australian supplier, EU manufacturer, EU authorised representative, EU importer, and EU distributor may be different legal entities.

Comparison row 3

Trigger

Australia Cyber Security Act 2024

Australia: the smart-device rules specify concrete consumer-device controls, including password requirements, a published security-issue reporting contact and response information, and a published defined support period for security updates.

EU Cyber Resilience Act

EU: the CRA sets essential cybersecurity requirements for products with digital elements and expects cybersecurity to be addressed across the product lifecycle.

Operational implication

A secure-by-design program can support both sides, but the Australian evidence should explicitly show the password, vulnerability-reporting, and support-period items required by the smart-device rules.

Comparison row 4

Core obligations

Australia Cyber Security Act 2024

Australia: for covered consumer-grade relevant connectable products, the statement of compliance must be prepared by or on behalf of the manufacturer, include product and manufacturer details, declare compliance, state the defined support period, and include signature, place, and date of issue. The rules specify a five-year retention period.

EU Cyber Resilience Act

EU: the CRA workstream should keep EU product technical documentation, conformity assessment evidence, declarations, CE marking evidence, and economic-operator records separate from the Australian statement of compliance.

Operational implication

Treat the Australian statement of compliance as an Australian artifact. It may reuse underlying test evidence, but it is not automatically the EU CRA conformity file.

Comparison row 5

Evidence record

Australia Cyber Security Act 2024

Australia: the Act and ransomware rules create a separate ransomware payment reporting workstream. A reporting business entity includes certain SOCI responsible entities or a business in Australia above the rules' turnover threshold, and the report must cover the incident, extortion demand, payment, and communications to the extent the entity can find the information within the 72-hour reporting period.

EU Cyber Resilience Act

EU: the CRA is not a ransomware payment reporting regime. From 11 September 2026, a manufacturer that becomes aware of an actively exploited vulnerability or a severe incident affecting product security must use the CRA reporting process, starting with a 24-hour early warning and a 72-hour full notification. The final-report deadline differs between a vulnerability and a severe incident.

Operational implication

Keep the Australian payment event and the EU product-security event on separate clocks. The same incident may require both records, but payment facts do not replace the EU exploitation or severe-incident assessment, and EU product notifications do not replace the Australian payment report.

Comparison row 6

Timing and deadlines

Australia Cyber Security Act 2024

Australia: the Federal Register displays 29 May 2025 for Part 3 ransomware reporting and Part 5 review-board commencement, while Home Affairs says ransomware reporting started on 30 May 2025. Part 2 of the Act commenced on 29 November 2025. Part 2 and Schedule 1 of the Smart Devices Rules, which contain the consumer-grade standard and statement requirements, commenced on 4 March 2026.

EU Cyber Resilience Act

EU: Chapter IV has applied since 11 June 2026. Article 14 vulnerability and severe-incident reporting applies from 11 September 2026, while the Regulation otherwise applies from 11 December 2027. Products placed on the market before 11 December 2027 are generally subject only if substantially modified after that date, but Article 14 also applies to in-scope products placed earlier.

Operational implication

Maintain separate readiness dates. Australian product and ransomware duties are operative; EU Chapter IV applies, Article 14 reporting starts on 11 September 2026, and general CRA conformity requirements apply from 11 December 2027.

Comparison row 7

Evidence reuse

Australia Cyber Security Act 2024

Australia: reuse EU CRA engineering evidence only where it proves the specific Australian requirement, such as password design, security-issue reporting, support-period publication, statement-of-compliance content, or ransomware report content.

EU Cyber Resilience Act

EU: reuse Australian engineering evidence only where it maps to the EU CRA product-with-digital-elements obligation and economic-operator file. Australian smart-device statements, SOCI records, and ransomware payment reports do not replace EU CRA conformity evidence.

Operational implication

Maintain a bridge table with three columns: shared engineering evidence, Australian legal artifact, and EU CRA legal artifact. Leave a row blank where the regimes do not match.

Comparison row 8

Support periods and lifecycle

Australia Cyber Security Act 2024

Australia: the manufacturer must publish a defined support period with an end date and must not shorten it after publication. The Rules define that period as the time for which security updates will be provided; the explanatory statement says available updates should be provided during it as far as practicable and in line with good industry practice. That explanatory statement explains the rule but is not the binding instrument.

EU Cyber Resilience Act

EU: the manufacturer determines a support period that reflects the expected use time and other Article 13(8) factors. The period is at least five years unless the product is expected to be used for less than five years, and vulnerability handling and security updates continue through that support period.

Operational implication

A shared support policy can supply evidence to both files, but the published Australian end date and the EU Article 13(8) rationale must each meet their own rule.

Comparison row 9

Practical decision rule

Australia Cyber Security Act 2024

Australia: use the smart-device workstream when the manufacturer or supplier knows, or could reasonably be expected to know, that an Australian consumer will acquire the covered product. Confirm the consumer-grade exclusions, actor role, and statement-of-compliance record separately.

EU Cyber Resilience Act

EU: assess whether the product is placed on the Union market as a , then apply the staged dates: Chapter IV from 11 June 2026, Article 14 from 11 September 2026, and the remaining CRA requirements from 11 December 2027, subject to Article 69 transition rules.

Operational implication

If the same product enters both markets, run both assessments. Apply the current duties and retain a dated plan for duties that have not yet started.

Practical decision rule

How to use this comparison

  • Start with market and product scope: Australian relevant connectable product and consumer-grade analysis on one side, EU product-with-digital-elements and Union-market analysis on the other.
  • Assign actors separately: Australian manufacturer and supplier roles do not automatically equal EU manufacturer, authorised representative, importer, or distributor roles.
  • Keep ransomware payment reporting outside the EU CRA evidence file unless the same incident also creates a separate EU product-security issue.
  • Use shared engineering controls where possible, but keep the Australian statement of compliance and EU CRA conformity evidence as separate legal artifacts.
Section 1

Where the regimes overlap and where they do not

Connected-product security is the main overlap. Australia uses the Cyber Security Act 2024 and the Cyber Security (Security Standards for Smart Devices) Rules 2025 to regulate relevant connectable products, with a consumer-grade smart-device standard, statement-of-compliance requirements, and notice powers for non-compliance.

The EU Cyber Resilience Act is framed more broadly around horizontal cybersecurity requirements for hardware and software products with digital elements, but its Article 2 exclusions and sectoral overlap rules still require a product-specific check. A product team may be able to reuse vulnerability-handling, support-period, secure-by-design, and technical-documentation evidence, but it should keep separate Australia and EU scope records.

  • Use the Australian workstream for relevant connectable products, consumer-grade smart-device standards, statements of compliance, supplier records, ransomware payment reports, and SOCI overlap checks.
  • Use the EU CRA workstream for products with digital elements, Union-market placement, economic-operator roles, essential cybersecurity requirements, vulnerability handling, conformity assessment, and CE marking evidence.
  • Reuse product-security evidence only after confirming that the product version, support period, vulnerability process, market role, and cited obligation align.
Section 2

What evidence should stay separate

For Australia, keep the product classification, manufacturer and supplier role analysis, statement of compliance, defined support period, password and vulnerability-reporting evidence, recall or notice correspondence, and any ransomware payment report file in a distinct Australian record set.

For the EU CRA, keep the economic-operator role, product-with-digital-elements scope assessment, essential cybersecurity requirement mapping, vulnerability-handling process, technical documentation, conformity evidence, and market-surveillance correspondence in a distinct EU record set.

  • Do not use an Australian statement of compliance as a substitute for EU CRA conformity evidence without a separate EU CRA analysis.
  • Do not use EU CRA technical documentation as proof that an Australian supplier supplied the product with the required Australian statement of compliance.
  • Do not merge ransomware payment reporting with EU CRA vulnerability or incident handling; the Australian ransomware report has its own trigger, threshold, 72-hour clock, and content fields.
  • From 11 September 2026, an EU manufacturer that becomes aware of an actively exploited vulnerability or a severe incident affecting the security of its must use the CRA reporting process. The early warning is due within 24 hours and the full notification within 72 hours. The final report is due no later than 14 days after a corrective or mitigating measure becomes available for an actively exploited vulnerability, or within one month after the full notification for a severe incident.
Primary sources

References and citations

legislation.gov.au
Referenced sections
  • Supports the Australian workstream structure for smart-device standards, statements of compliance, ransomware reporting, and enforcement.
"Cyber Security Act 2024"
homeaffairs.gov.au
Referenced sections
  • Home Affairs says ransomware payment reporting started on 30 May 2025, one day after the date displayed in the Federal Register's commencement table.
"start from 30 May 2025"
digital-strategy.ec.europa.eu
Referenced sections
  • Supports the Article 14 manufacturer trigger and the 24-hour, 72-hour, and final-report sequence from 11 September 2026.
"manufacturers are required to report actively exploited vulnerabilities and severe incidents"
legislation.gov.au
Referenced sections
  • Supports SOCI overlap context where ransomware reporting applies to responsible entities for critical infrastructure assets to which Part 2B applies.
"Security of Critical Infrastructure Act 2018"
Related guides

Explore more topics

Australia Compliance Statement Evidence Workflow
Evidence workflow for preparing, supplying, and retaining statements of compliance under Australia's Cyber Security Act 2024 and Smart Devices Rules.
Australia Cyber Security Act 2024 scope and definitions
Official source scope guide for Australia's Cyber Security Act 2024: relevant connectable products, consumer-grade smart devices, reporting business entities, ransomware payment reports, and SOCI overlap.
Australia Cyber Security Act and SOCI Act overlap
How the Australia Cyber Security Act overlaps with the Security of Critical Infrastructure Act for responsible entities, ransomware payment reporting, smart devices, and evidence records.
Australia Cyber Security Act Applicability Test
Decide whether the Australia Cyber Security Act 2024 applies to a smart-device product, supplier, manufacturer, or ransomware payment reporting scenario.
Australia Cyber Security Act Commencement Timeline
Cyber Security Act 2024 commencement timeline for ransomware reporting, CIRB reviews, smart-device duties, statement retention, and statutory review.
Australia Cyber Security Act Compliance Checklist
Concrete checklist items for Australian Cyber Security Act smart-device and ransomware duties, with SOCI and APRA CPS 234 evidence checks.
Australia Cyber Security Act Compliance Guide
A cited compliance guide for Australia Cyber Security Act smart-device statements, ransomware payment reporting, incident coordination, and review-board readiness.
Australia Cyber Security Act Deadlines and Calendar
Cyber Security Act 2024 dates and event-driven deadlines for ransomware payment reports, smart-device duties, records, notices, and statutory review.
Australia Cyber Security Act FAQ
Answers to Australia Cyber Security Act questions on smart device scope, statements of compliance, ransomware reports, enforcement notices, and incident review.
Australia Cyber Security Act penalties and fines
Cyber Security Act 2024 civil penalties explained by section, including ransomware reports, protected information, CIRB notices, and smart-device enforcement.
Australia Cyber Security Act recordkeeping FAQ
What records to keep for Cyber Security Act 2024 smart-device statements, ransomware payment reports, and supported SOCI or APRA overlap checks.
Australia Cyber Security Act Requirements
Australia Cyber Security Act requirements for smart-device security standards, statements of compliance, ransomware payment reports, notices, and evidence records.
Australia Cyber Security Act Statement of Compliance Evidence
Evidence guide for Australia Cyber Security Act smart-device statements of compliance: required fields, manufacturer and supplier records, five-year retention, and examination readiness.
Australia Cyber Security Act templates
Source-backed field lists for Australia Cyber Security Act smart-device scope, statements of compliance, ransomware reports, notices, SOCI overlap, and records.
Australia Cyber Security Act vs EU Cyber Resilience Act
Compare Australia's Cyber Security Act 2024 with the EU Cyber Resilience Act across smart-device duties, ransomware reporting, product-with-digital-elements scope, actors, records, and enforcement routes.
Australia Cyber Security Act vs UK PSTI Act Guide
Compare Australia's Cyber Security Act 2024 smart-device, ransomware, and SOCI-adjacent obligations with the UK's PSTI connected-product regime.
Australia ransomware payment reporting 72-hour duty
Explain when Australia's Cyber Security Act 2024 requires a ransomware payment report, when the 72-hour clock starts, and what information the report must contain.
Australia Ransomware Payment Reporting Workflow
Operational workflow for Australia Cyber Security Act 2024 ransomware payment reports: scope, 72-hour trigger, report fields, owners, evidence, and cited Act and Rules sources.
Australia Ransomware Payment Reporting: Threshold and Report Content
FAQ answer on Australia's Cyber Security Act ransomware payment reporting scope, $3 million turnover threshold, 72-hour trigger, report fields, and evidence.
Australia Smart Device Applicability Workflow
Decide whether Australia's mandatory smart-device security standard applies, including commencement, connectivity, consumer use, exclusions, roles, and evidence.
Australia Smart Device Compliance Statement
What a smart-device statement of compliance must contain under Australia's Cyber Security Act 2024 and Smart Devices Rules, who prepares and supplies it, how long to retain it, and how to prepare for examination.
Australia Smart Device Security Standards under the Cyber Security Act
Plain-English guide to Australia's Cyber Security (Security Standards for Smart Devices) Rules 2025: scope, passwords, vulnerability reporting, support periods, statements of compliance, and evidence records.
CSA 2024 Smart Device Applicability Test
Check whether a smart device is a consumer-grade relevant connectable product under Australia's Cyber Security Act and Smart Devices Rules.
Cyber Security Act 2024 Smart Device Compliance Checklist
Checklist for Australia Cyber Security Act 2024 smart-device scope, password controls, vulnerability reporting, security-update support periods, statements of compliance, retention, and evidence.
Cyber Security Act 2024 Statements of Compliance FAQ
Australian smart-device statements of compliance: covered products, responsible actors, required contents, supporting evidence, and five-year retention.
Cyber Security Act vs UK PSTI Act: device security obligations compared
Compare Australia's Cyber Security Act 2024 smart-device, ransomware, and SOCI-adjacent obligations with the UK's PSTI connected-product regime.
How do notices and recalls work under the Australia Cyber Security Act?
FAQ on Australia Cyber Security Act compliance notices, stop notices, recall notices, public notifications, owners, evidence fields, and cited timing.
How does the Australia Cyber Security Act overlap with the SOCI Act?
FAQ on when Australia Cyber Security Act ransomware reporting overlaps with SOCI critical infrastructure assets, responsible entities, and smart-device duties.
Manufacturer, Importer, and Supplier Duties under Australia's Cyber Security Act 2024
Cyber Security Act 2024 smart-device duties for manufacturers, importers, and suppliers, including role tests, scope, statements, and records.
SOCI overlap triage workflow for Australia Cyber Security Act
Triage SOCI Act overlap with Australia Cyber Security Act ransomware reporting and smart-device standards using separate owners, evidence, and cited scope checks.
Which smart devices are in scope under Australia's Cyber Security Act 2024?
FAQ on Cyber Security Act 2024 smart-device scope: relevant connectable products, consumer-grade criteria, exclusions, Australian consumer acquisition, and records to keep.