Australia Cyber Security Act Smart Device Applicability Workflow
Use this workflow to decide whether a connected product is a consumer-grade relevant connectable product covered by Australia's smart-device security standard.
The workflow separates commencement, connectivity, consumer-grade scope, six exclusions, Australian consumer acquisition, manufacturer and supplier roles, and the Schedule 1 controls in force from 4 March 2026.
Australia's Cyber Security Act 2024 authorises mandatory security standards for connected products, but the first product-level decision is whether the item is a . The Cyber Security (Security Standards for Smart Devices) Rules 2025 then prescribe a standard for -grade products that will be acquired in Australia by a consumer, subject to six exclusions. The standard, statement requirements, and five-year retention rule commenced on 4 March 2026. Manufacturers, suppliers, importers, distributors, product counsel, security engineering, and compliance teams can use this workflow to record the scope decision and the evidence behind it.
1
Section 1
Step 1: confirm the commencement and supply dates
Start the workflow when a team plans to manufacture, import, distribute, list, relabel, materially redesign, or continue supplying a connected product for the Australian market. Part 2 of the Act applies to a manufactured on or after 29 November 2025, or supplied other than as second-hand goods on or after that date. The prescribed smart-device standard and statement requirements commenced on 4 March 2026.
Record both manufacture and Australian supply dates before testing product scope. A product manufactured before Part 2 commenced can still enter the workflow when it is supplied other than as second-hand goods after commencement and the prescribed class and acquisition conditions are met.
Inputs: product name, model, batch or stock-keeping-unit identifier, manufacture date, first Australian supply date, whether the supply is second-hand, manufacture path, and Australian supply channel.
Owner: product compliance opens the record; supply-chain operations confirms dates and second-hand status; product counsel records whether Part 2 and the Rules are in force for the transaction.
Output: continue to the connectivity test, outside Part 2 because the only relevant manufacture or supply occurred before commencement, outside Part 2 because the supply is second-hand and there is no post-commencement manufacture, or needs case-specific review.
Step 2: test connectivity, consumer use, and the six exclusions
First decide whether the item is a . The Act covers an internet-connectable product and defined network-connectable products. The network test includes products that connect directly to an internet-connectable product using an internet-protocol communication, and certain products that can connect directly to two or more products at the same time and to an internet-connectable product using a non-internet-protocol communication. Wires or cables used merely to connect products do not meet that latter test.
If the product is a , apply the class prescribed by the Smart Devices Rules. The covered class is intended by the to be used, or is of a kind likely to be used, for personal, domestic, or household use or consumption. The specified circumstance is acquisition in Australia by a , using the Australian Consumer Law meaning of consumer. Record the from labels, instructions, promotional material, sales material, and statements.
The Australian Law test can include a business buyer. The current monetary limb covers goods priced at no more than $100,000, while goods ordinarily acquired for personal, domestic, or household use can qualify regardless of price. Specified acquisitions for resupply or for use up or transformation in production, manufacture, repair, or treatment are excluded. Apply the transaction facts as well as the product's market.
Product names do not determine scope. A product that looks -facing can still fall outside the standard if it belongs to an excluded group. The explanatory statement discusses smart TVs, smart watches, home assistants, baby monitors, and consumer energy resources as examples considered for the standard.
In-scope answer: , -grade personal/domestic/household use or likely use, will be acquired in Australia by a consumer, and no exclusion applies.
Exclusion checks: desktop computer or laptop, tablet computer, smartphone, therapeutic good, road vehicle, and road vehicle component.
Evidence: connectivity specification, protocols, system architecture, companion-app and gateway dependencies, intended-purpose statements, labels and instructions, sales material, target-customer notes, channel plan, and the reason an exclusion does or does not apply.
Output: covered product, excluded product, not a , not within the , or needs classification review.
Step 3: assign manufacturer, supplier, and statement-of-compliance work
When the product is in scope, split the workflow by statutory role. A must manufacture the product in compliance with the standard when it is aware, or could reasonably be expected to be aware, that the product will be acquired in Australia by a . The manufacturer must also comply with the standard's other manufacturer requirements. A must not supply a non-compliant covered product in Australia when the same awareness test is met.
Section 15 contains a limited constitutional exception for requirements outside internet or like-service connection, use, or protection where the entity is neither a constitutional corporation nor acting in interstate, Territory, or international trade or commerce. Record case-specific advice before using this exception; entity size or an unincorporated structure alone does not establish it.
Keep statement-of-compliance work in the same applicability record. A must supply the product in Australia with a statement that meets the Rules. The statement must be prepared by, or on behalf of, the and include the product type and batch identifier, manufacturer and authorised-representative details, compliance declarations, , signatory details, and place and date of issue.
owner: product engineering and security engineering prepare evidence for password, security-issue reporting, and support-period requirements; product counsel or compliance approves the statement package.
owner: procurement, import, distribution, marketplace, or retail channel owner confirms the product will not be supplied without the statement and blocks a non-compliant product when the Act's product-class, acquisition-awareness, and supply conditions are met.
Evidence: signed statement of compliance, product type and batch identifier, name and address, the name and address of an , each other authorised representative in Australia if any, compliance declarations, support period at issue date, signatory function, place and date of issue.
Recordkeeping: retain statements of compliance for the five-year period specified by the Smart Devices Rules, with the retention owner named in the workflow record.
Step 4: verify the Schedule 1 controls before shipment or listing
After classifying a -grade as covered, security engineering and product operations must check the three Schedule 1 control areas: passwords, security-issue reporting, and defined support periods for security updates.
For website listings controlled by the , the support-period check should be linked to the publication workflow. The explanatory statement says a should not need to navigate unnecessarily or know about the Act, Rules, or Schedule to discover the .
Password gate: test covered credentials after the product leaves the and after a later factory reset. Passwords used with covered hardware, pre-installed software, or required installable software must be unique per product or defined by the user. A unique-per-product password must not use incremental counters or public information. It may be derived from a unique product identifier only through an encryption method or keyed hashing algorithm accepted as , and it must not otherwise be unacceptably guessable.
Security-issue reporting gate: the must publish at least one contact point and say when a reporter will receive acknowledgement and status updates until resolution. The information must be accessible, clear, transparent, available without prior request, in English, free of charge, and available without requiring personal information.
Support-period gate: the must publish the for security updates, expressed as a period of time with an end date. The information must meet the same access conditions and be understandable without prior technical knowledge. Once published, the period must not be shortened; an extension must be published as soon as practicable.
Website gate: if the offers the product on a website it controls, the support period must appear prominently with information intended to inform acquisition decisions and alongside, or with equal prominence to, every publication of the product's main characteristics.
Publication evidence: public reporting-contact page, acknowledgement/status-update language, support-period publication location, each relevant product-listing capture, archived page records, and release approval from security engineering and product compliance.
Step 5: escalate unclear or changed products before relying on an old answer
Re-run the workflow when a product line changes enough to affect connectivity, intended purpose, acquisition, exclusions, identity, channel, statement contents, password design, vulnerability reporting, or support-period publication. A prior answer for one batch or model should not be reused where the facts that support the statement of compliance have changed.
Escalation should be concrete. Product counsel should resolve statutory scope issues, security engineering should resolve control evidence, channel operations should resolve supply facts, and compliance should block release where the statement or publication evidence is missing for an in-scope product.
Escalate to product counsel: mixed-use products, accessories that may be connectable products in their own right, therapeutic-good or road-vehicle classification questions, or unclear acquisition facts.
Escalate to security engineering: default-password design, companion-app dependency, update mechanism, vulnerability-reporting process, or security-update support-period evidence is incomplete.
Escalate to compliance or release governance: an in-scope product lacks a compliant statement, the statement owner cannot confirm the five-year retention plan, or evidence shows the product does not comply with the standard before Australian supply.
Closeout record: final scope result, role owners, source citations, evidence locations, unresolved assumptions, reviewer approval, and the product event that will trigger the next review.
Current official explanation of the Australian Consumer Law consumer test, including business acquisitions, the $100,000 threshold, and acquisition exclusions.