The Cyber Security Act smart-device regime is a product compliance track. Cyber Security Act Part 2 commenced on 29 November 2025. Part 2 and Schedule 1 of the Smart Devices Rules, which contain the consumer-grade standard and statement requirements, commenced on 4 March 2026. The Rules cover consumer grade relevant connectable products intended, or likely, to be used for personal, domestic, or household use or consumption when the manufacturer or supplier is aware, or could reasonably be expected to be aware, that a consumer will acquire the product in Australia. Listed exclusions include desktop and laptop computers, tablets, smartphones, therapeutic goods, road vehicles, and road vehicle components.
That product track can sit beside, but should not be blended with, SOCI obligations. A consumer energy product or connected device may need product-scope, security-standard, statement-of-compliance, support-period, and security-issue-reporting evidence. A critical-infrastructure operator may separately need SOCI asset, responsible-entity, incident-reporting, and risk-management evidence. The same incident can touch both tracks, but each track needs its own source, owner, trigger, and record.