What do manufacturers, importers, and suppliers have to do under Australia's Cyber Security Act 2024?
Manufacturers must make an in-scope relevant connectable product in line with the applicable security standard when the product is in the covered class and the manufacturer is aware, or could reasonably be expected to be aware, that it will be acquired in Australia in the specified circumstances. The Smart Device Rules target consumer-grade relevant connectable products, with listed exclusions for desktops and laptops, tablets, smartphones, therapeutic goods, road vehicles, and road vehicle components.
Suppliers must not supply a non-compliant covered product in Australia when they are aware, or could reasonably be expected to be aware, that it will be acquired in Australia in the specified circumstances. Suppliers must also supply the product with a statement of compliance and retain a copy for the period set by the Rules.
Importers are not given a separate importer-specific duty label in the cited Act and Rules. Treat an importer as in scope when its facts also make it a manufacturer or a supplier, such as importing a covered consumer-grade smart device for supply in Australia. Keep the role analysis explicit instead of assuming that every overseas purchase, distributor, or logistics movement is automatically covered.
- Manufacturer duty: confirm the product class, build against the password, vulnerability-reporting, and defined-support-period requirements, and provide a compliant statement of compliance for Australian supply.
- Supplier duty: do not supply a known non-compliant covered product in Australia, supply it with the statement of compliance, and keep the retained statement record.
- Importer triage: record whether the importer manufactures, supplies, or only handles logistics; apply the manufacturer or supplier duties only when the facts support that role.
- Exception check: confirm whether the product is outside the Rules because it is not consumer-grade, will not be acquired by a consumer in Australia, or is one of the product exclusions listed in section 8 of the Smart Device Rules.
Official Act source for the manufacturer and supplier duties in sections 15 and 16, including compliance, non-supply, statement-of-compliance, and retention obligations.
Official Rules source for consumer-grade relevant connectable product scope, listed product exclusions, statement contents, and the five-year statement retention period.