Artifact GuideAustraliaCyber Security Act vs UK PSTI Act

Australia Cyber Security Act vs UK PSTI Act

Australia's Cyber Security Act 2024 covers connected-product security as well as ransomware payment reports, significant cyber incident coordination, and review-board powers. The UK PSTI comparison on this page concerns connected-product security.

This comparison helps separate reusable connected-product evidence from Australia-only reporting, notice, and critical-infrastructure workstreams.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Sections
2

Structured answer sets in this page tree.

Primary sources
8

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

Use this comparison when a connected product, ransomware payment decision, or Australian critical-infrastructure dependency could be affected by Australia's Cyber Security Act 2024 while the same product program is already tracking the UK's Product Security and Telecommunications Infrastructure Act 2022 () and 2023 security requirements regulations. Australia's ransomware provisions have applied since 29 May 2025. Cyber Security Act Part 2 commenced on 29 November 2025, while the Smart Devices Rules' consumer-grade standard and statement requirements commenced on 4 March 2026. The UK consumer connectable product regime has applied since 29 April 2024. Australia's separate Security of Critical Infrastructure Act 2018 () governs critical-infrastructure assets and incident reporting.

Side-by-side comparison

Australia Cyber Security Act 2024 vs UK PSTI Act: concrete compliance differences

Compare the Australian Cyber Security Act 2024 and UK only where the cited sources support it: connected-product security has overlap; ransomware reporting, incident coordination, review-board powers, and SOCI analysis remain Australia-specific.

Review all sources
First framework
Australia Cyber Security Act 2024

Covers smart-device security standards where the product, consumer-acquisition circumstance, and manufacturer or supplier knowledge tests are met, plus separate ransomware payment reporting, significant incident coordination, Cyber Incident Review Board, and regulatory-powers workstreams.

Second framework
UK PSTI Act

Comparator regime for UK product security and telecommunications infrastructure, with this page limited to connected-product security facts supported by the existing UK sources and Australian explanatory statement.

Comparison row 1

Scope boundary

Australia Cyber Security Act 2024

Australia: the Smart Devices Rules apply when a manufacturer or supplier knows, or could reasonably be expected to know, that a consumer will acquire in Australia a relevant connectable product intended, or likely, to be used for personal, domestic, or household use. The Rules exclude listed categories including desktop and laptop computers, tablets, smartphones, therapeutic goods, road vehicles, and road-vehicle components.

UK PSTI Act

UK PSTI: the regime covers consumer connectable products made available to UK consumers. Official guidance lists exclusions and exceptions, including certain Northern Ireland products, EV charge points, medical devices, smart meters, specified computers without cellular connectivity, and vehicle categories covered by the 2025 amendment.

Operational implication

A product can reuse part of the product-security analysis only after the Australian consumer-grade and acquisition-in-Australia tests are documented separately from the UK PSTI scope decision.

Comparison row 2

Covered actors

Australia Cyber Security Act 2024

Australia: manufacturers and suppliers need to keep the smart-device standard, statement-of-compliance fields, and retention obligations aligned with Australian requirements, while the Act separately reaches reporting businesses for ransomware payment reporting and the entities involved in Cyber Incident Review Board and SOCI matters.

UK PSTI Act

UK PSTI: manufacturers, importers, and distributors have duties under the Act and 2023 Regulations, including statement-of-compliance duties. Authorised representatives also have duties when a manufacturer's compliance failure arises.

Operational implication

Do not assume the same controlled party list across Australia and the UK; first identify whether the task is product compliance, ransomware reporting, or critical-infrastructure reporting.

Comparison row 3

Statement evidence and retention

Australia Cyber Security Act 2024

Australia: the statement must be prepared by or on behalf of the manufacturer and include product type and batch identifier, manufacturer and authorised-representative details, compliance declarations, , signatory details, and place and date of issue; statements must be retained for five years.

UK PSTI Act

UK PSTI: Australian source support says UK-market products can provide the same statement-of-compliance information for Australia only if all Australian section 9 requirements are met; the UK source in this file should not be treated as proving Australian retention or field requirements.

Operational implication

Reuse the same document only after adding an Australian field-by-field check and retention owner; otherwise keep a UK PSTI statement and an Australian statement as separate records.

Comparison row 4

Timing and separate incident duties

Australia Cyber Security Act 2024

Australia: Part 3 has applied since 29 May 2025. A must report when all ransomware-payment conditions apply; the rules set a $3 million previous-financial-year turnover threshold for non-SOCI businesses, subject to the Act's exclusions and the pro-rated rule for a business carried on for only part of that year. The report is due within 72 hours after payment or awareness of an on-behalf payment.

UK PSTI Act

UK PSTI: the consumer connectable product regime has applied since 29 April 2024. It is a product-security regime, not a ransomware-payment reporting regime.

Operational implication

Do not merge ransomware-payment playbooks with UK product-security evidence; route these cases to Australian incident response, legal, and executive approval owners.

Comparison row 5

Evidence record

Australia Cyber Security Act 2024

Australia: the Cyber Security Act includes voluntary information sharing with the National Cyber Security Coordinator for significant cyber security incidents and creates a Cyber Incident Review Board process; SOCI separately covers critical infrastructure asset registration, risk management programs, cyber-incident notification, and enhanced cyber obligations.

UK PSTI Act

UK PSTI: the provided UK PSTI sources support connected-product security comparison, not Australian-style review-board referrals or SOCI critical-infrastructure asset obligations.

Operational implication

When a connected product is also part of an Australian critical-infrastructure service, run product-security, SOCI, and incident-review checks as separate tracks with separate owners and evidence.

Comparison row 6

Enforcement tools

Australia Cyber Security Act 2024

Australia: for smart-device non-compliance, the Cyber Security Act supports compliance notices, stop notices, recall notices, public notification of recall-notice failure, expert examination, civil penalties, infringement notices, enforceable undertakings, and injunctions.

UK PSTI Act

UK PSTI: enforces the product-security regime on behalf of DSIT and says it carries out regulatory activity on a risk-based basis. Businesses must also investigate potential compliance failures, keep records, and act on compliance failures as required by the legislation.

Operational implication

Keep jurisdiction-specific response files. Australian remediation may involve compliance, stop, or recall notices and examinations; UK remediation should record contact, the suspected failure, the investigation, required notifications, and corrective action.

Comparison row 7

Enforcement pathway

Australia Cyber Security Act 2024

Australia: the Act also treats product non-compliance as a matter that can escalate through notices, infringement action, enforceable undertakings, and injunctions, so the Australian response can move beyond a single product-label or statement fix.

UK PSTI Act

UK PSTI: UK enforcement remains a separate process under the and Regulations; Australian notices and review-board powers do not govern the UK response.

Operational implication

Assign separate Australian and UK response owners and preserve the regulator correspondence, investigation, corrective action, and legal basis for each jurisdiction.

Comparison row 8

Connected-product control overlap

Australia Cyber Security Act 2024

Australia: Schedule 1 requires unique-per-product or user-defined passwords, published security-issue reporting information with acknowledgement and status-update processes, and publication of a defined security-update support period. Australian statement and five-year retention requirements remain separate.

UK PSTI Act

UK PSTI: the 2023 Regulations cover the comparable password, security-issue reporting, and minimum security-update-period topics, together with UK statement-of-compliance duties.

Operational implication

Map the three shared control topics once, then check the exact Australian and UK clauses and keep each market's statement, actor, scope, and retention records separate.

Comparison row 9

Practical decision rule

Australia Cyber Security Act 2024

Australia: run the smart-device workstream when the product, specified consumer-acquisition circumstance, and manufacturer or supplier knowledge tests are met. Run ransomware, incident-coordination, review-board, and SOCI workstreams only when their separate triggers apply.

UK PSTI Act

UK PSTI: run the UK workstream when an in-scope relevant connectable product is made available to UK consumers. Confirm the UK actor role, security requirements, statement, exclusions, and any compliance-failure action.

Operational implication

Run both product assessments for products entering both markets. Reuse technical evidence where it proves each rule, but keep the Australian and UK legal artifacts, dates, actor findings, and incident-only records separate.

Practical decision rule

How to use the comparison without overreaching

  • Start with the Australian scope split: smart-device standard, ransomware payment report, significant incident coordination, Cyber Incident Review Board, or SOCI overlap.
  • Reuse UK PSTI evidence only for connected-product security where Australian statement, support-period, retention, and consumer-acquisition requirements are independently satisfied.
  • Use official UK guidance for commencement, actor, scope, exclusion, and facts; check the Act, current Regulations, and enforcement policy before stating penalty amounts or case-specific enforcement consequences.
Section 1

What is comparable between the Australian and UK regimes?

The closest overlap is connected-product security. Australia's Smart Devices Rules establish a security standard for that manufacturers or suppliers know, or could reasonably be expected to know, will be acquired in Australia by a consumer. The Australian explanatory statement says those standards closely follow the UK's 2023 relevant-connectable-product security requirements regulations.

Australia's Cyber Security Act 2024 also contains ransomware payment reporting, significant cyber incident coordination, and Cyber Incident Review Board provisions. The remains a separate Australian critical-infrastructure regime. UK PSTI evidence does not cover those Australian workstreams. In the UK, the Office for Product Safety and Standards () enforces the product-security regime on behalf of the Department for Science, Innovation and Technology.

  • Use product-security evidence across both regimes only for password requirements, vulnerability-reporting publication, support-period publication, and statement-of-compliance content where the Australian rules are met.
  • Create separate Australian records for ransomware payment reporting, including the test, payment trigger, 72-hour report clock, and required report fields.
  • Keep SOCI asset scoping separate from UK PSTI product scope because SOCI is about Australian critical infrastructure assets, reporting, risk management, and enhanced cyber obligations.
  • Treat Cyber Incident Review Board requests and significant incident coordination as Australia-only governance matters unless another source creates a separate UK duty.
Section 2

Which evidence can be reused, and which must stay Australia-specific?

For connected products, the Australian explanatory statement allows responsible entities operating across similar consumer-grade smart-device frameworks to use the same information for Australia, including UK-market products, if every Australian section 9 requirement is met. The Australian Rules use details as statement fields but do not define that role.

That reuse is conditional. Australian records still need the Australian product class and consumer-acquisition analysis, manufacturer-prepared statement fields, , five-year retention, and any Australian supply decision. A also needs a separate ransomware payment report when every Part 3 trigger is met. Ransomware payment reports and SOCI records are not PSTI artifacts.

  • Product owner: maintain product type, batch identifier, manufacturer and authorised-representative details, support-period text, and compliance declaration for Australian statement-of-compliance use.
  • Security engineering: prove unique or user-defined passwords, security-issue reporting details, acknowledgement and status-update process, and security-update support period publication.
  • Incident response and legal: keep Australian ransomware payment report facts separate, including ABN/address details where applicable, incident impact, demand, payment, and communications fields.
  • Critical infrastructure owner: document whether SOCI asset obligations apply separately from product-security duties before reusing any control or audit evidence.
Primary sources

References and citations

legislation.gov.au
Referenced sections
  • Supports the Australian multi-workstream split across smart devices, ransomware reporting, incident coordination, review board, and regulatory powers.
"Cyber Security Act 2024"
Related guides

Explore more topics

Australia Compliance Statement Evidence Workflow
Evidence workflow for preparing, supplying, and retaining statements of compliance under Australia's Cyber Security Act 2024 and Smart Devices Rules.
Australia Cyber Security Act 2024 scope and definitions
Official source scope guide for Australia's Cyber Security Act 2024: relevant connectable products, consumer-grade smart devices, reporting business entities, ransomware payment reports, and SOCI overlap.
Australia Cyber Security Act and SOCI Act overlap
How the Australia Cyber Security Act overlaps with the Security of Critical Infrastructure Act for responsible entities, ransomware payment reporting, smart devices, and evidence records.
Australia Cyber Security Act Applicability Test
Decide whether the Australia Cyber Security Act 2024 applies to a smart-device product, supplier, manufacturer, or ransomware payment reporting scenario.
Australia Cyber Security Act Commencement Timeline
Cyber Security Act 2024 commencement timeline for ransomware reporting, CIRB reviews, smart-device duties, statement retention, and statutory review.
Australia Cyber Security Act Compliance Checklist
Concrete checklist items for Australian Cyber Security Act smart-device and ransomware duties, with SOCI and APRA CPS 234 evidence checks.
Australia Cyber Security Act Compliance Guide
A cited compliance guide for Australia Cyber Security Act smart-device statements, ransomware payment reporting, incident coordination, and review-board readiness.
Australia Cyber Security Act Deadlines and Calendar
Cyber Security Act 2024 dates and event-driven deadlines for ransomware payment reports, smart-device duties, records, notices, and statutory review.
Australia Cyber Security Act FAQ
Answers to Australia Cyber Security Act questions on smart device scope, statements of compliance, ransomware reports, enforcement notices, and incident review.
Australia Cyber Security Act penalties and fines
Cyber Security Act 2024 civil penalties explained by section, including ransomware reports, protected information, CIRB notices, and smart-device enforcement.
Australia Cyber Security Act recordkeeping FAQ
What records to keep for Cyber Security Act 2024 smart-device statements, ransomware payment reports, and supported SOCI or APRA overlap checks.
Australia Cyber Security Act Requirements
Australia Cyber Security Act requirements for smart-device security standards, statements of compliance, ransomware payment reports, notices, and evidence records.
Australia Cyber Security Act Statement of Compliance Evidence
Evidence guide for Australia Cyber Security Act smart-device statements of compliance: required fields, manufacturer and supplier records, five-year retention, and examination readiness.
Australia Cyber Security Act templates
Source-backed field lists for Australia Cyber Security Act smart-device scope, statements of compliance, ransomware reports, notices, SOCI overlap, and records.
Australia Cyber Security Act vs EU Cyber Resilience Act
Compare Australia's Cyber Security Act 2024 with the EU Cyber Resilience Act across smart-device duties, ransomware reporting, product-with-digital-elements scope, actors, records, and enforcement routes.
Australia Cyber Security Act vs UK PSTI Act Guide
Compare Australia's Cyber Security Act 2024 smart-device, ransomware, and SOCI-adjacent obligations with the UK's PSTI connected-product regime.
Australia ransomware payment reporting 72-hour duty
Explain when Australia's Cyber Security Act 2024 requires a ransomware payment report, when the 72-hour clock starts, and what information the report must contain.
Australia Ransomware Payment Reporting Workflow
Operational workflow for Australia Cyber Security Act 2024 ransomware payment reports: scope, 72-hour trigger, report fields, owners, evidence, and cited Act and Rules sources.
Australia Ransomware Payment Reporting: Threshold and Report Content
FAQ answer on Australia's Cyber Security Act ransomware payment reporting scope, $3 million turnover threshold, 72-hour trigger, report fields, and evidence.
Australia Smart Device Applicability Workflow
Decide whether Australia's mandatory smart-device security standard applies, including commencement, connectivity, consumer use, exclusions, roles, and evidence.
Australia Smart Device Compliance Statement
What a smart-device statement of compliance must contain under Australia's Cyber Security Act 2024 and Smart Devices Rules, who prepares and supplies it, how long to retain it, and how to prepare for examination.
Australia Smart Device Security Standards under the Cyber Security Act
Plain-English guide to Australia's Cyber Security (Security Standards for Smart Devices) Rules 2025: scope, passwords, vulnerability reporting, support periods, statements of compliance, and evidence records.
CSA 2024 Smart Device Applicability Test
Check whether a smart device is a consumer-grade relevant connectable product under Australia's Cyber Security Act and Smart Devices Rules.
Cyber Security Act 2024 Smart Device Compliance Checklist
Checklist for Australia Cyber Security Act 2024 smart-device scope, password controls, vulnerability reporting, security-update support periods, statements of compliance, retention, and evidence.
Cyber Security Act 2024 Statements of Compliance FAQ
Australian smart-device statements of compliance: covered products, responsible actors, required contents, supporting evidence, and five-year retention.
Cyber Security Act vs EU CRA: scope and obligations comparison
Compare Australia's Cyber Security Act 2024 with the EU Cyber Resilience Act across smart-device duties, ransomware reporting, product-with-digital-elements scope, actors, records, and enforcement routes.
How do notices and recalls work under the Australia Cyber Security Act?
FAQ on Australia Cyber Security Act compliance notices, stop notices, recall notices, public notifications, owners, evidence fields, and cited timing.
How does the Australia Cyber Security Act overlap with the SOCI Act?
FAQ on when Australia Cyber Security Act ransomware reporting overlaps with SOCI critical infrastructure assets, responsible entities, and smart-device duties.
Manufacturer, Importer, and Supplier Duties under Australia's Cyber Security Act 2024
Cyber Security Act 2024 smart-device duties for manufacturers, importers, and suppliers, including role tests, scope, statements, and records.
SOCI overlap triage workflow for Australia Cyber Security Act
Triage SOCI Act overlap with Australia Cyber Security Act ransomware reporting and smart-device standards using separate owners, evidence, and cited scope checks.
Which smart devices are in scope under Australia's Cyber Security Act 2024?
FAQ on Cyber Security Act 2024 smart-device scope: relevant connectable products, consumer-grade criteria, exclusions, Australian consumer acquisition, and records to keep.