FAQ item index

Search every question across sub-FAQs

Find the exact question, open the source answer card, and copy a direct link to the anchored sub-FAQ response.

Indexed coverage
25of25items
Across 7 modules • Updated Jul 24, 2026
Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
How do notices and recalls work under the Australia Cyber Security Act?

Can the Secretary request a product or statement for independent examination?

Yes. If an entity has a section 15 or 16 obligation for a relevant connectable product, the Secretary may engage an appropriately qualified and experienced expert to examine whether the product complies with the security standard, whether its statement of compliance meets section 16, or both.

For that examination, the Secretary may request the product, the statement, or both in writing. The request must identify the product, identify the manufacturer if known when the recipient is not the manufacturer, set a reasonable response period, describe the retention period and testing requirements for the product, explain the kind of testing or analysis, and explain possible consequences of non-compliance. The Commonwealth must pay reasonable compensation for complying with the request.

  • Keep a retrievable copy of the statement and a product or representative unit tied to the relevant type and batch.
  • Route the written request separately from a compliance, stop, or recall notice; section 23 examination can assess compliance but is not another step in the three-notice escalation sequence.
  • Record the requested product, response deadline, expected retention period, tests described, item transfer, chain of custody, and compensation costs.
Citations
Cyber Security Act 2024

Section 23 authorises independent examination, lists the required contents of a written product or statement request, and provides reasonable compensation for compliance.

How does the Australia Cyber Security Act overlap with the SOCI Act?

How does the Australia Cyber Security Act overlap with the Security of Critical Infrastructure Act?

The Cyber Security Act does not supersede the Security of Critical Infrastructure Act 2018 (SOCI Act). It imports SOCI concepts for a critical infrastructure asset and a responsible entity, and its ransomware payment reporting regime expressly covers a responsible entity for a critical infrastructure asset to which SOCI Act Part 2B applies.

The same event can therefore require a Cyber Security Act ransomware payment report and a SOCI Act Part 2B cyber security incident report. The triggers differ: the Cyber Security Act report follows a payment or benefit tied to an extortion demand, while SOCI reporting turns on the incident's impact on a covered asset. One report does not replace the other. For SOCI, a significant impact on availability uses the test in section 30BEA; other reportable incidents use the broader relevant impact concept, which includes availability, integrity, reliability, and specified confidentiality impacts.

  • Confirm whether the affected system is a critical infrastructure asset under SOCI Act materials.
  • Identify whether the organisation is the responsible entity for that asset.
  • If a ransomware payment was made by, or on behalf of, that entity, assess the Cyber Security Act ransomware report obligation alongside SOCI Part 2B incident notification.
  • Run the clocks separately: the ransomware payment report is due within 72 hours of payment or awareness of payment; a critical SOCI incident must be reported as soon as practicable and within 12 hours of awareness, while another reportable SOCI incident must be reported as soon as practicable and within 72 hours of awareness. If a critical-incident report is oral, provide the approved-form written record within 84 hours after the oral report. If another reportable-incident report is oral, provide its approved-form written record within 48 hours after the oral report. A written-record exemption may be given under the SOCI Act.
Citations
Cyber Security Act 2024

Defines critical infrastructure asset and responsible entity by reference to the SOCI Act and sets when responsible entities for Part 2B assets are reporting business entities.

Security of Critical Infrastructure Act 2018

Sections 30BB to 30BEA support Part 2B application, the 12-hour and 72-hour incident-notification duties, the 84-hour written record after an oral critical-incident report, the 48-hour written record after another oral reportable-incident report, the possible written-record exemptions, and the significant-impact test.

How does the Australia Cyber Security Act overlap with the SOCI Act?

What should be separated from SOCI overlap?

Keep the smart-device product regime outside the SOCI overlap analysis. Cyber Security Act Part 2 applies to relevant connectable products and product supply obligations. The SOCI overlap concerns critical infrastructure assets, responsible entities, SOCI Part 2B incident notification, and Cyber Security Act ransomware payment reporting.

A manufacturer or supplier may have smart-device duties for a relevant connectable product even when it is not the responsible entity for a SOCI asset. Conversely, a SOCI responsible entity can have ransomware reporting exposure even when the incident is not about placing a smart device on the Australian market.

  • Smart-device check: relevant connectable product, manufacture or supply in Australia, security standard, and statement of compliance.
  • SOCI overlap check: critical infrastructure asset, responsible entity, whether SOCI Part 2B applies, incident impact, awareness time, and the applicable 12-hour or 72-hour clock.
  • Ransomware check: cyber security incident, extortion demand, payment or benefit, reporting business entity status, and report content.
Citations
Cyber Security Act 2024

Separates Part 2 smart-device obligations from Part 3 ransomware payment reporting, cross-references SOCI concepts, and lists the ransomware report-content categories.

How does the Australia Cyber Security Act overlap with the SOCI Act?

What evidence should support the SOCI overlap answer?

Keep a short overlap record covering the asset, entity, incident, and payment analysis. Record which asset was affected, why SOCI Part 2B did or did not apply, who the responsible entity was, whether a ransomware payment was made, when each reporting clock started, and which report fields could be completed within each window.

If the same event also touches a connected product, keep that product compliance file separate so SOCI incident triage is not confused with smart-device security-standard evidence.

  • Asset and role evidence: SOCI asset classification, responsible-entity reasoning, and any application-rule note used.
  • Incident evidence: incident timing, awareness time, impact on the entity and the asset's availability, integrity, reliability, or confidentiality, SOCI classification as a critical or other reportable incident, oral or written submission method, the 84-hour written follow-up for an oral critical-incident report or the 48-hour written follow-up for an oral other-incident report, any written-record exemption, and the information available when each report is made.
  • Payment evidence: demand, amount or non-monetary benefit, method of provision, communications, and whether another entity paid on the reporting business entity's behalf.
Citations
Cyber Security Act 2024

Primary legislation for the ransomware payment trigger, reporting-business-entity test, 72-hour deadline, and report-content categories.

Manufacturer, Importer, and Supplier Duties under Australia's Cyber Security Act 2024

What do manufacturers, importers, and suppliers have to do under Australia's Cyber Security Act 2024?

Manufacturers must make an in-scope relevant connectable product in line with the applicable security standard when the product is in the covered class and the manufacturer is aware, or could reasonably be expected to be aware, that it will be acquired in Australia in the specified circumstances. The Smart Devices Rules target consumer-grade relevant connectable products, with listed exclusions for desktops and laptops, tablets, smartphones, therapeutic goods, road vehicles, and road vehicle components.

Suppliers must not supply a non-compliant covered product in Australia when they are aware, or could reasonably be expected to be aware, that it will be acquired in Australia in the specified circumstances. Suppliers must also supply the product with a statement of compliance and retain a copy for the period set by the Rules.

Importers are not given a separate importer-specific duty in the Act or Rules. The Act adopts the Australian Consumer Law meanings of manufacturer and supply, with supplied and supplier taking corresponding meanings. Under that manufacturer definition, a person who imports goods into Australia is a manufacturer where the goods were made outside Australia and the maker does not have a place of business in Australia. An importer may also be a supplier if its conduct meets the adopted supply definition. Record each role separately; an overseas purchase or logistics movement alone does not settle the answer.

The timing boundary also matters. Part 2 applies to relevant connectable products manufactured on or after 29 November 2025 or supplied in Australia on or after that date, except second-hand goods. Part 2 and Schedule 1 of the Smart Devices Rules commenced on 4 March 2026.

  • Manufacturer duty: confirm the product class, build against the password, vulnerability-reporting, and defined-support-period requirements, and provide a compliant statement of compliance for Australian supply.
  • Supplier duty: do not supply a known non-compliant covered product in Australia, supply it with the statement of compliance, and keep the retained statement record.
  • Importer triage: check whether the goods were made outside Australia, whether the maker has a place of business in Australia, whether the importer brought the goods into Australia, and whether the importer also sells, leases, exchanges, or otherwise supplies them.
  • Constitutional-reach check: section 15(5) contains a limited exception for an entity that is neither a constitutional corporation nor acting in relevant interstate, territory, or overseas trade, but only to the extent a security-standard requirement does not relate to the connectivity, use, or protection matters listed in section 15(6). Do not treat it as a general small-business or importer exemption.
  • Exception check: confirm whether the product is outside the Rules because it is not consumer-grade, will not be acquired by a consumer in Australia, or is one of the product exclusions listed in section 8 of the Smart Device Rules.
Citations
Cyber Security Act 2024

Official Act source for the manufacturer and supplier duties in sections 15 and 16, including compliance, non-supply, statement-of-compliance, retention, and the limited constitutional-reach exception in sections 15(5) and 15(6).

Manufacturer, Importer, and Supplier Duties under Australia's Cyber Security Act 2024

What records should prove the manufacturer, importer, or supplier role?

Keep records that show why the product and actor were placed inside or outside the smart-device obligations. Use a product-scope file, a role file, a security-standard file, and a statement-of-compliance file. A generic compliance memo does not capture those separate decisions.

The statement of compliance must be prepared by, or on behalf of, the manufacturer and include the product type and batch identifier, manufacturer and authorised representative details, compliance declarations, defined support period, signatory details, and place and date of issue. Both manufacturers and suppliers must retain a copy for the Rules' five-year period.

  • Product-scope evidence: product type, batch identifier, intended use, consumer acquisition analysis, connection capability, and any section 8 exclusion relied on.
  • Role evidence: manufacturer identity, authorised representative details, Australian supplier or importer entity, contracts or purchase orders showing who supplies the product in Australia, and the basis for any out-of-scope conclusion.
  • Security-standard evidence: password design proof, security-issue reporting contact and acknowledgement/update process, published defined support period, and security-update publication records.
  • Statement evidence: issued statement of compliance, signatory name and function, issue date and place, defined support period at issue, retention owner, and retrieval path for regulator requests or independent examination.
Citations
Cyber Security Act 2024

Official Act source for statement-of-compliance duties, retention by manufacturers and suppliers, and the Secretary's power to request a product or statement for examination.

Manufacturer, Importer, and Supplier Duties under Australia's Cyber Security Act 2024

Which edge cases should be escalated before supply in Australia?

Escalate cases where the supply-chain label does not answer the legal-role test. An offshore OEM, Australian distributor, online marketplace seller, local importer, and reseller may each need a separate manufacturer-or-supplier assessment based on who meets the adopted statutory definition, who supplies in Australia, and who knows or should know the product will be acquired in Australia by a consumer.

Also escalate products near the Rules' scope boundary: bundled products, accessories with their own connection capability, consumer energy resources, business devices that may still be consumer acquisitions, and excluded product categories. Do not use ransomware reporting or Security of Critical Infrastructure Act workflows as substitutes for the smart-device product duties; those are separate regimes unless the same facts independently trigger them.

  • Do not call a product exempt just because it is sold to a business; the Rules use the Australian Consumer Law consumer concept and the specified circumstance of acquisition by a consumer.
  • Do not rely on a support-period statement hidden only in a regulatory page if product information or main characteristics are published elsewhere on a manufacturer-controlled website.
  • Do not ship without a statement record simply because the manufacturer is overseas; the supplier duty still turns on supply in Australia of a covered product with the required statement.
  • Do not shorten a published defined support period; if it is extended, publish the new period as soon as practicable.
Citations
Cyber Security Act 2024

Official Act source for the awareness standard attached to manufacturer and supplier duties when products will be acquired in Australia in specified circumstances.

Which smart devices are in scope under Australia's Cyber Security Act 2024?

Which smart devices are in scope under Australia's Cyber Security Act 2024?

First, classify the product. Under the Act, a relevant connectable product is an internet-connectable product or a network-connectable product that is not exempted under the rules. Internet-connectable means capable of connecting to the internet using a communication protocol in the internet protocol suite to send and receive data. Network-connectable covers products that can both send and receive data by electrical or electromagnetic transmission, are not internet-connectable, and meet one of the Act's direct-connection tests. A non-internet-protocol connection must satisfy the detailed multi-product test in section 13(7), subject to the cable and computer-input-product rules in sections 13(8) and 13(9).

Next, apply the Smart Devices Rules. The current security standard covers relevant connectable products intended by the manufacturer to be used, or of a kind likely to be used, for personal, domestic, or household use or consumption. The specified circumstance is that the product will be acquired in Australia by a consumer. The Rules use section 3 of the Australian Consumer Law: goods costing no more than the current $100,000 threshold can qualify, as can higher-priced goods ordinarily acquired for personal, domestic, or household use and certain vehicles or trailers. The test excludes goods acquired for re-supply and goods acquired to be used up or transformed in trade or commerce during production, manufacture, repair, or treatment of other goods or fixtures. A business purchase is not automatically outside scope. The vehicle-or-trailer consumer limb does not override the Smart Devices Rules' separate exclusion for road vehicles and road vehicle components.

Check timing separately. Part 2 applies to a relevant connectable product manufactured on or after 29 November 2025, or supplied in Australia on or after that date other than as second-hand goods. The operative product class and security standard in Part 2 and Schedule 1 of the Smart Devices Rules commenced on 4 March 2026.

  • In scope: an internet-connectable or network-connectable product, not exempted by rules, that fits the consumer-grade personal, domestic, or household class and will be acquired in Australia by a consumer.
  • Examples identified in the explanatory statement include smart TVs, smart watches, home assistants, baby monitors, and consumer energy resources.
  • Keep the two exclusions separate: an exemption under section 13 would prevent the item from being a relevant connectable product, while the six exclusions in section 8 of the Smart Devices Rules remove products from the current consumer-grade class without changing the Act's connectivity definition.
  • Do not rely only on the product name or whether the buyer is an individual. Record connectivity, the manufacturer's intended purpose, likely household use, sales channel, and the Australian Consumer Law basis for treating the acquisition as a consumer acquisition.
  • If the product is connectable but not consumer-grade, or the acquisition circumstance is missing, record that the current Smart Devices Rules scope has not been met rather than forcing the product into scope.
Citations
Cyber Security Act 2024

Supports the relevant connectable product definition and the internet-connectable and network-connectable product tests.

Which smart devices are in scope under Australia's Cyber Security Act 2024?

Which products are excluded from the current Australian smart-device security standard?

The Smart Devices Rules do not prescribe the current security standard for every connected product. Even when a product is a relevant connectable product and looks consumer-facing, section 8 excludes six product groups from the consumer-grade class.

The excluded groups are desktop computers or laptops, tablet computers, smartphones, therapeutic goods within the meaning of the Therapeutic Goods Act 1989, road vehicles within the meaning of the Road Vehicle Standards Act 2018, and road vehicle components within the meaning of that Act.

  • Keep a separate exclusion field for each of the six carved-out product groups.
  • Do not treat a product as excluded merely because it has a screen, app, battery, or wireless module; tie the exclusion to one of the named categories in the Rules.
  • For mixed products, keep the bill of materials, marketing claims, user instructions, regulatory classification, and product-line rationale used to decide whether an exclusion applies.
Citations
Which smart devices are in scope under Australia's Cyber Security Act 2024?

What records should teams keep for a Cyber Security Act 2024 smart-device scope answer?

Keep enough evidence to re-run the answer without relying on memory. The record should show why the product is, or is not, a relevant connectable product; why it is, or is not, consumer-grade; whether an exclusion was checked; and whether the Australian consumer acquisition circumstance is present.

For products that are in scope, keep the downstream compliance records with the scope file. The Act and Rules tie covered products to manufacturer and supplier duties, statement-of-compliance records, password requirements, security-issue reporting information, and defined support-period publication. Only the five-year statement retention period is prescribed here; the broader scope file is a practical record rather than a separately prescribed retention duty.

  • Scope evidence: product name, model or batch, hardware and software connectivity, protocols, companion app or gateway dependency, and whether the product can directly or indirectly connect to the internet.
  • Consumer-grade evidence: manufacturer's intended purpose, label, instructions for use, promotional or sales materials, likely personal, domestic, or household use, and intended Australian acquisition channel.
  • Exclusion evidence: desktop or laptop, tablet, smartphone, therapeutic good, road vehicle, and road-vehicle-component checks, including the source document or product classification used for each answer.
  • In-scope product evidence: statement of compliance, defined support period at issue date, password-control evidence, published security-issue reporting contact and acknowledgement/status-update information, and the five-year statement retention owner.
Citations
Cyber Security Act 2024

Supports manufacturer and supplier duties for covered relevant connectable products and the statement-of-compliance obligation.

Page 2 of 2