Artifact GuideAustraliaCyber Security Act vs UK PSTI Act
Australia Cyber Security Act vs UK PSTI Act
Australia's Cyber Security Act 2024 covers connected-product security as well as ransomware payment reports, significant cyber incident coordination, and review-board powers. The UK PSTI comparison on this page concerns connected-product security.
This comparison helps separate reusable connected-product evidence from Australia-only reporting, notice, and critical-infrastructure workstreams.
Use this comparison when a connected product, ransomware payment decision, or Australian critical-infrastructure dependency could be affected by Australia's Cyber Security Act 2024 while the same product program is already tracking the UK's Product Security and Telecommunications Infrastructure Act 2022 () and 2023 security requirements regulations. Australia's ransomware provisions have applied since 29 May 2025. Cyber Security Act Part 2 commenced on 29 November 2025, while the Smart Devices Rules' consumer-grade standard and statement requirements commenced on 4 March 2026. The UK consumer connectable product regime has applied since 29 April 2024. Australia's separate Security of Critical Infrastructure Act 2018 () governs critical-infrastructure assets and incident reporting.
Side-by-side comparison
Australia Cyber Security Act 2024 vs UK PSTI Act: concrete compliance differences
Compare the Australian Cyber Security Act 2024 and UK only where the cited sources support it: connected-product security has overlap; ransomware reporting, incident coordination, review-board powers, and SOCI analysis remain Australia-specific.
Covers smart-device security standards where the product, consumer-acquisition circumstance, and manufacturer or supplier knowledge tests are met, plus separate ransomware payment reporting, significant incident coordination, Cyber Incident Review Board, and regulatory-powers workstreams.
Second framework
UK PSTI Act
Comparator regime for UK product security and telecommunications infrastructure, with this page limited to connected-product security facts supported by the existing UK sources and Australian explanatory statement.
Australia Cyber Security Act 2024 vs UK PSTI Act: concrete compliance differences
Australia: the Smart Devices Rules apply when a manufacturer or supplier knows, or could reasonably be expected to know, that a consumer will acquire in Australia a relevant connectable product intended, or likely, to be used for personal, domestic, or household use. The Rules exclude listed categories including desktop and laptop computers, tablets, smartphones, therapeutic goods, road vehicles, and road-vehicle components.
UK PSTI: the regime covers consumer connectable products made available to UK consumers. Official guidance lists exclusions and exceptions, including certain Northern Ireland products, EV charge points, medical devices, smart meters, specified computers without cellular connectivity, and vehicle categories covered by the 2025 amendment.
A product can reuse part of the product-security analysis only after the Australian consumer-grade and acquisition-in-Australia tests are documented separately from the UK PSTI scope decision.
Australia: manufacturers and suppliers need to keep the smart-device standard, statement-of-compliance fields, and retention obligations aligned with Australian requirements, while the Act separately reaches reporting businesses for ransomware payment reporting and the entities involved in Cyber Incident Review Board and SOCI matters.
UK PSTI: manufacturers, importers, and distributors have duties under the Act and 2023 Regulations, including statement-of-compliance duties. Authorised representatives also have duties when a manufacturer's compliance failure arises.
Do not assume the same controlled party list across Australia and the UK; first identify whether the task is product compliance, ransomware reporting, or critical-infrastructure reporting.
Australia: the statement must be prepared by or on behalf of the manufacturer and include product type and batch identifier, manufacturer and authorised-representative details, compliance declarations, , signatory details, and place and date of issue; statements must be retained for five years.
UK PSTI: Australian source support says UK-market products can provide the same statement-of-compliance information for Australia only if all Australian section 9 requirements are met; the UK source in this file should not be treated as proving Australian retention or field requirements.
Reuse the same document only after adding an Australian field-by-field check and retention owner; otherwise keep a UK PSTI statement and an Australian statement as separate records.
Australia: Part 3 has applied since 29 May 2025. A must report when all ransomware-payment conditions apply; the rules set a $3 million previous-financial-year turnover threshold for non-SOCI businesses, subject to the Act's exclusions and the pro-rated rule for a business carried on for only part of that year. The report is due within 72 hours after payment or awareness of an on-behalf payment.
UK PSTI: the consumer connectable product regime has applied since 29 April 2024. It is a product-security regime, not a ransomware-payment reporting regime.
Do not merge ransomware-payment playbooks with UK product-security evidence; route these cases to Australian incident response, legal, and executive approval owners.
Australia: the Cyber Security Act includes voluntary information sharing with the National Cyber Security Coordinator for significant cyber security incidents and creates a Cyber Incident Review Board process; SOCI separately covers critical infrastructure asset registration, risk management programs, cyber-incident notification, and enhanced cyber obligations.
UK PSTI: the provided UK PSTI sources support connected-product security comparison, not Australian-style review-board referrals or SOCI critical-infrastructure asset obligations.
When a connected product is also part of an Australian critical-infrastructure service, run product-security, SOCI, and incident-review checks as separate tracks with separate owners and evidence.
UK PSTI: enforces the product-security regime on behalf of DSIT and says it carries out regulatory activity on a risk-based basis. Businesses must also investigate potential compliance failures, keep records, and act on compliance failures as required by the legislation.
Keep jurisdiction-specific response files. Australian remediation may involve compliance, stop, or recall notices and examinations; UK remediation should record contact, the suspected failure, the investigation, required notifications, and corrective action.
Australia: the Act also treats product non-compliance as a matter that can escalate through notices, infringement action, enforceable undertakings, and injunctions, so the Australian response can move beyond a single product-label or statement fix.
UK PSTI: UK enforcement remains a separate process under the and Regulations; Australian notices and review-board powers do not govern the UK response.
Assign separate Australian and UK response owners and preserve the regulator correspondence, investigation, corrective action, and legal basis for each jurisdiction.
Australia: Schedule 1 requires unique-per-product or user-defined passwords, published security-issue reporting information with acknowledgement and status-update processes, and publication of a defined security-update support period. Australian statement and five-year retention requirements remain separate.
UK PSTI: the 2023 Regulations cover the comparable password, security-issue reporting, and minimum security-update-period topics, together with UK statement-of-compliance duties.
Map the three shared control topics once, then check the exact Australian and UK clauses and keep each market's statement, actor, scope, and retention records separate.
Australia: run the smart-device workstream when the product, specified consumer-acquisition circumstance, and manufacturer or supplier knowledge tests are met. Run ransomware, incident-coordination, review-board, and SOCI workstreams only when their separate triggers apply.
UK PSTI: run the UK workstream when an in-scope relevant connectable product is made available to UK consumers. Confirm the UK actor role, security requirements, statement, exclusions, and any compliance-failure action.
Run both product assessments for products entering both markets. Reuse technical evidence where it proves each rule, but keep the Australian and UK legal artifacts, dates, actor findings, and incident-only records separate.
Australia: the Smart Devices Rules apply when a manufacturer or supplier knows, or could reasonably be expected to know, that a consumer will acquire in Australia a relevant connectable product intended, or likely, to be used for personal, domestic, or household use. The Rules exclude listed categories including desktop and laptop computers, tablets, smartphones, therapeutic goods, road vehicles, and road-vehicle components.
UK PSTI: the regime covers consumer connectable products made available to UK consumers. Official guidance lists exclusions and exceptions, including certain Northern Ireland products, EV charge points, medical devices, smart meters, specified computers without cellular connectivity, and vehicle categories covered by the 2025 amendment.
A product can reuse part of the product-security analysis only after the Australian consumer-grade and acquisition-in-Australia tests are documented separately from the UK PSTI scope decision.
Australia: manufacturers and suppliers need to keep the smart-device standard, statement-of-compliance fields, and retention obligations aligned with Australian requirements, while the Act separately reaches reporting businesses for ransomware payment reporting and the entities involved in Cyber Incident Review Board and SOCI matters.
UK PSTI: manufacturers, importers, and distributors have duties under the Act and 2023 Regulations, including statement-of-compliance duties. Authorised representatives also have duties when a manufacturer's compliance failure arises.
Do not assume the same controlled party list across Australia and the UK; first identify whether the task is product compliance, ransomware reporting, or critical-infrastructure reporting.
Australia: the statement must be prepared by or on behalf of the manufacturer and include product type and batch identifier, manufacturer and authorised-representative details, compliance declarations, , signatory details, and place and date of issue; statements must be retained for five years.
UK PSTI: Australian source support says UK-market products can provide the same statement-of-compliance information for Australia only if all Australian section 9 requirements are met; the UK source in this file should not be treated as proving Australian retention or field requirements.
Reuse the same document only after adding an Australian field-by-field check and retention owner; otherwise keep a UK PSTI statement and an Australian statement as separate records.
Australia: Part 3 has applied since 29 May 2025. A must report when all ransomware-payment conditions apply; the rules set a $3 million previous-financial-year turnover threshold for non-SOCI businesses, subject to the Act's exclusions and the pro-rated rule for a business carried on for only part of that year. The report is due within 72 hours after payment or awareness of an on-behalf payment.
UK PSTI: the consumer connectable product regime has applied since 29 April 2024. It is a product-security regime, not a ransomware-payment reporting regime.
Do not merge ransomware-payment playbooks with UK product-security evidence; route these cases to Australian incident response, legal, and executive approval owners.
Australia: the Cyber Security Act includes voluntary information sharing with the National Cyber Security Coordinator for significant cyber security incidents and creates a Cyber Incident Review Board process; SOCI separately covers critical infrastructure asset registration, risk management programs, cyber-incident notification, and enhanced cyber obligations.
UK PSTI: the provided UK PSTI sources support connected-product security comparison, not Australian-style review-board referrals or SOCI critical-infrastructure asset obligations.
When a connected product is also part of an Australian critical-infrastructure service, run product-security, SOCI, and incident-review checks as separate tracks with separate owners and evidence.
UK PSTI: enforces the product-security regime on behalf of DSIT and says it carries out regulatory activity on a risk-based basis. Businesses must also investigate potential compliance failures, keep records, and act on compliance failures as required by the legislation.
Keep jurisdiction-specific response files. Australian remediation may involve compliance, stop, or recall notices and examinations; UK remediation should record contact, the suspected failure, the investigation, required notifications, and corrective action.
Australia: the Act also treats product non-compliance as a matter that can escalate through notices, infringement action, enforceable undertakings, and injunctions, so the Australian response can move beyond a single product-label or statement fix.
UK PSTI: UK enforcement remains a separate process under the and Regulations; Australian notices and review-board powers do not govern the UK response.
Assign separate Australian and UK response owners and preserve the regulator correspondence, investigation, corrective action, and legal basis for each jurisdiction.
Australia: Schedule 1 requires unique-per-product or user-defined passwords, published security-issue reporting information with acknowledgement and status-update processes, and publication of a defined security-update support period. Australian statement and five-year retention requirements remain separate.
UK PSTI: the 2023 Regulations cover the comparable password, security-issue reporting, and minimum security-update-period topics, together with UK statement-of-compliance duties.
Map the three shared control topics once, then check the exact Australian and UK clauses and keep each market's statement, actor, scope, and retention records separate.
Australia: run the smart-device workstream when the product, specified consumer-acquisition circumstance, and manufacturer or supplier knowledge tests are met. Run ransomware, incident-coordination, review-board, and SOCI workstreams only when their separate triggers apply.
UK PSTI: run the UK workstream when an in-scope relevant connectable product is made available to UK consumers. Confirm the UK actor role, security requirements, statement, exclusions, and any compliance-failure action.
Run both product assessments for products entering both markets. Reuse technical evidence where it proves each rule, but keep the Australian and UK legal artifacts, dates, actor findings, and incident-only records separate.
Start with the Australian scope split: smart-device standard, ransomware payment report, significant incident coordination, Cyber Incident Review Board, or SOCI overlap.
Reuse UK PSTI evidence only for connected-product security where Australian statement, support-period, retention, and consumer-acquisition requirements are independently satisfied.
Use official UK guidance for commencement, actor, scope, exclusion, and facts; check the Act, current Regulations, and enforcement policy before stating penalty amounts or case-specific enforcement consequences.
What is comparable between the Australian and UK regimes?
The closest overlap is connected-product security. Australia's Smart Devices Rules establish a security standard for that manufacturers or suppliers know, or could reasonably be expected to know, will be acquired in Australia by a consumer. The Australian explanatory statement says those standards closely follow the UK's 2023 relevant-connectable-product security requirements regulations.
Australia's Cyber Security Act 2024 also contains ransomware payment reporting, significant cyber incident coordination, and Cyber Incident Review Board provisions. The remains a separate Australian critical-infrastructure regime. UK PSTI evidence does not cover those Australian workstreams. In the UK, the Office for Product Safety and Standards () enforces the product-security regime on behalf of the Department for Science, Innovation and Technology.
Use product-security evidence across both regimes only for password requirements, vulnerability-reporting publication, support-period publication, and statement-of-compliance content where the Australian rules are met.
Create separate Australian records for ransomware payment reporting, including the test, payment trigger, 72-hour report clock, and required report fields.
Keep SOCI asset scoping separate from UK PSTI product scope because SOCI is about Australian critical infrastructure assets, reporting, risk management, and enhanced cyber obligations.
Treat Cyber Incident Review Board requests and significant incident coordination as Australia-only governance matters unless another source creates a separate UK duty.
Which evidence can be reused, and which must stay Australia-specific?
For connected products, the Australian explanatory statement allows responsible entities operating across similar consumer-grade smart-device frameworks to use the same information for Australia, including UK-market products, if every Australian section 9 requirement is met. The Australian Rules use details as statement fields but do not define that role.
That reuse is conditional. Australian records still need the Australian product class and consumer-acquisition analysis, manufacturer-prepared statement fields, , five-year retention, and any Australian supply decision. A also needs a separate ransomware payment report when every Part 3 trigger is met. Ransomware payment reports and SOCI records are not PSTI artifacts.
Product owner: maintain product type, batch identifier, manufacturer and authorised-representative details, support-period text, and compliance declaration for Australian statement-of-compliance use.
Security engineering: prove unique or user-defined passwords, security-issue reporting details, acknowledgement and status-update process, and security-update support period publication.
Incident response and legal: keep Australian ransomware payment report facts separate, including ABN/address details where applicable, incident impact, demand, payment, and communications fields.
Critical infrastructure owner: document whether SOCI asset obligations apply separately from product-security duties before reusing any control or audit evidence.