WorkflowAustraliaSmart Device Applicability

Australia Cyber Security Act Smart Device Applicability Workflow

Use this workflow to decide whether a connected product is a consumer-grade relevant connectable product covered by Australia's smart-device security standard.

The workflow separates commencement, connectivity, consumer-grade scope, six exclusions, Australian consumer acquisition, manufacturer and supplier roles, and the Schedule 1 controls in force from 4 March 2026.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 25, 2026
Sections
5

Structured answer sets in this page tree.

Primary sources
5

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 25, 2026
Overview

Australia's Cyber Security Act 2024 authorises mandatory security standards for connected products, but the first product-level decision is whether the item is a . The Cyber Security (Security Standards for Smart Devices) Rules 2025 then prescribe a standard for -grade products that will be acquired in Australia by a consumer, subject to six exclusions. The standard, statement requirements, and five-year retention rule commenced on 4 March 2026. Manufacturers, suppliers, importers, distributors, product counsel, security engineering, and compliance teams can use this workflow to record the scope decision and the evidence behind it.

Section 1

Step 1: confirm the commencement and supply dates

Start the workflow when a team plans to manufacture, import, distribute, list, relabel, materially redesign, or continue supplying a connected product for the Australian market. Part 2 of the Act applies to a manufactured on or after 29 November 2025, or supplied other than as second-hand goods on or after that date. The prescribed smart-device standard and statement requirements commenced on 4 March 2026.

Record both manufacture and Australian supply dates before testing product scope. A product manufactured before Part 2 commenced can still enter the workflow when it is supplied other than as second-hand goods after commencement and the prescribed class and acquisition conditions are met.

  • Inputs: product name, model, batch or stock-keeping-unit identifier, manufacture date, first Australian supply date, whether the supply is second-hand, manufacture path, and Australian supply channel.
  • Owner: product compliance opens the record; supply-chain operations confirms dates and second-hand status; product counsel records whether Part 2 and the Rules are in force for the transaction.
  • Output: continue to the connectivity test, outside Part 2 because the only relevant manufacture or supply occurred before commencement, outside Part 2 because the supply is second-hand and there is no post-commencement manufacture, or needs case-specific review.
Section 2

Step 2: test connectivity, consumer use, and the six exclusions

First decide whether the item is a . The Act covers an internet-connectable product and defined network-connectable products. The network test includes products that connect directly to an internet-connectable product using an internet-protocol communication, and certain products that can connect directly to two or more products at the same time and to an internet-connectable product using a non-internet-protocol communication. Wires or cables used merely to connect products do not meet that latter test.

If the product is a , apply the class prescribed by the Smart Devices Rules. The covered class is intended by the to be used, or is of a kind likely to be used, for personal, domestic, or household use or consumption. The specified circumstance is acquisition in Australia by a , using the Australian Consumer Law meaning of consumer. Record the from labels, instructions, promotional material, sales material, and statements.

The Australian Law test can include a business buyer. The current monetary limb covers goods priced at no more than $100,000, while goods ordinarily acquired for personal, domestic, or household use can qualify regardless of price. Specified acquisitions for resupply or for use up or transformation in production, manufacture, repair, or treatment are excluded. Apply the transaction facts as well as the product's market.

Product names do not determine scope. A product that looks -facing can still fall outside the standard if it belongs to an excluded group. The explanatory statement discusses smart TVs, smart watches, home assistants, baby monitors, and consumer energy resources as examples considered for the standard.

  • In-scope answer: , -grade personal/domestic/household use or likely use, will be acquired in Australia by a consumer, and no exclusion applies.
  • Exclusion checks: desktop computer or laptop, tablet computer, smartphone, therapeutic good, road vehicle, and road vehicle component.
  • Evidence: connectivity specification, protocols, system architecture, companion-app and gateway dependencies, intended-purpose statements, labels and instructions, sales material, target-customer notes, channel plan, and the reason an exclusion does or does not apply.
  • Output: covered product, excluded product, not a , not within the , or needs classification review.
Section 3

Step 3: assign manufacturer, supplier, and statement-of-compliance work

When the product is in scope, split the workflow by statutory role. A must manufacture the product in compliance with the standard when it is aware, or could reasonably be expected to be aware, that the product will be acquired in Australia by a . The manufacturer must also comply with the standard's other manufacturer requirements. A must not supply a non-compliant covered product in Australia when the same awareness test is met.

Section 15 contains a limited constitutional exception for requirements outside internet or like-service connection, use, or protection where the entity is neither a constitutional corporation nor acting in interstate, Territory, or international trade or commerce. Record case-specific advice before using this exception; entity size or an unincorporated structure alone does not establish it.

Keep statement-of-compliance work in the same applicability record. A must supply the product in Australia with a statement that meets the Rules. The statement must be prepared by, or on behalf of, the and include the product type and batch identifier, manufacturer and authorised-representative details, compliance declarations, , signatory details, and place and date of issue.

  • owner: product engineering and security engineering prepare evidence for password, security-issue reporting, and support-period requirements; product counsel or compliance approves the statement package.
  • owner: procurement, import, distribution, marketplace, or retail channel owner confirms the product will not be supplied without the statement and blocks a non-compliant product when the Act's product-class, acquisition-awareness, and supply conditions are met.
  • Evidence: signed statement of compliance, product type and batch identifier, name and address, the name and address of an , each other authorised representative in Australia if any, compliance declarations, support period at issue date, signatory function, place and date of issue.
  • Recordkeeping: retain statements of compliance for the five-year period specified by the Smart Devices Rules, with the retention owner named in the workflow record.
Section 4

Step 4: verify the Schedule 1 controls before shipment or listing

After classifying a -grade as covered, security engineering and product operations must check the three Schedule 1 control areas: passwords, security-issue reporting, and defined support periods for security updates.

For website listings controlled by the , the support-period check should be linked to the publication workflow. The explanatory statement says a should not need to navigate unnecessarily or know about the Act, Rules, or Schedule to discover the .

  • Password gate: test covered credentials after the product leaves the and after a later factory reset. Passwords used with covered hardware, pre-installed software, or required installable software must be unique per product or defined by the user. A unique-per-product password must not use incremental counters or public information. It may be derived from a unique product identifier only through an encryption method or keyed hashing algorithm accepted as , and it must not otherwise be unacceptably guessable.
  • Security-issue reporting gate: the must publish at least one contact point and say when a reporter will receive acknowledgement and status updates until resolution. The information must be accessible, clear, transparent, available without prior request, in English, free of charge, and available without requiring personal information.
  • Support-period gate: the must publish the for security updates, expressed as a period of time with an end date. The information must meet the same access conditions and be understandable without prior technical knowledge. Once published, the period must not be shortened; an extension must be published as soon as practicable.
  • Website gate: if the offers the product on a website it controls, the support period must appear prominently with information intended to inform acquisition decisions and alongside, or with equal prominence to, every publication of the product's main characteristics.
  • Publication evidence: public reporting-contact page, acknowledgement/status-update language, support-period publication location, each relevant product-listing capture, archived page records, and release approval from security engineering and product compliance.
Section 5

Step 5: escalate unclear or changed products before relying on an old answer

Re-run the workflow when a product line changes enough to affect connectivity, intended purpose, acquisition, exclusions, identity, channel, statement contents, password design, vulnerability reporting, or support-period publication. A prior answer for one batch or model should not be reused where the facts that support the statement of compliance have changed.

Escalation should be concrete. Product counsel should resolve statutory scope issues, security engineering should resolve control evidence, channel operations should resolve supply facts, and compliance should block release where the statement or publication evidence is missing for an in-scope product.

  • Escalate to product counsel: mixed-use products, accessories that may be connectable products in their own right, therapeutic-good or road-vehicle classification questions, or unclear acquisition facts.
  • Escalate to security engineering: default-password design, companion-app dependency, update mechanism, vulnerability-reporting process, or security-update support-period evidence is incomplete.
  • Escalate to compliance or release governance: an in-scope product lacks a compliant statement, the statement owner cannot confirm the five-year retention plan, or evidence shows the product does not comply with the standard before Australian supply.
  • Closeout record: final scope result, role owners, source citations, evidence locations, unresolved assumptions, reviewer approval, and the product event that will trigger the next review.
Primary sources

References and citations

accc.gov.au
Referenced sections
  • Current official explanation of the Australian Consumer Law consumer test, including business acquisitions, the $100,000 threshold, and acquisition exclusions.
legislation.gov.au
Referenced sections
  • Supports treating compliance, stop, recall, and examination powers as escalation context when covered smart-device evidence is missing or disputed.
"Compliance with security standard for a relevant connectable product"
legislation.gov.au
Referenced sections
  • Supports rechecking product webpages and accessories because some accessories may be consumer-grade relevant connectable products in their own right.
"some accessories will amount to consumer grade relevant connectable products"
Related guides

Explore more topics

Australia Compliance Statement Evidence Workflow
Evidence workflow for preparing, supplying, and retaining statements of compliance under Australia's Cyber Security Act 2024 and Smart Devices Rules.
Australia Cyber Security Act 2024 scope and definitions
Official source scope guide for Australia's Cyber Security Act 2024: relevant connectable products, consumer-grade smart devices, reporting business entities, ransomware payment reports, and SOCI overlap.
Australia Cyber Security Act and SOCI Act overlap
How the Australia Cyber Security Act overlaps with the Security of Critical Infrastructure Act for responsible entities, ransomware payment reporting, smart devices, and evidence records.
Australia Cyber Security Act Applicability Test
Decide whether the Australia Cyber Security Act 2024 applies to a smart-device product, supplier, manufacturer, or ransomware payment reporting scenario.
Australia Cyber Security Act Commencement Timeline
Cyber Security Act 2024 commencement timeline for ransomware reporting, CIRB reviews, smart-device duties, statement retention, and statutory review.
Australia Cyber Security Act Compliance Checklist
Concrete checklist items for Australian Cyber Security Act smart-device and ransomware duties, with SOCI and APRA CPS 234 evidence checks.
Australia Cyber Security Act Compliance Guide
A cited compliance guide for Australia Cyber Security Act smart-device statements, ransomware payment reporting, incident coordination, and review-board readiness.
Australia Cyber Security Act Deadlines and Calendar
Cyber Security Act 2024 dates and event-driven deadlines for ransomware payment reports, smart-device duties, records, notices, and statutory review.
Australia Cyber Security Act FAQ
Answers to Australia Cyber Security Act questions on smart device scope, statements of compliance, ransomware reports, enforcement notices, and incident review.
Australia Cyber Security Act penalties and fines
Cyber Security Act 2024 civil penalties explained by section, including ransomware reports, protected information, CIRB notices, and smart-device enforcement.
Australia Cyber Security Act recordkeeping FAQ
What records to keep for Cyber Security Act 2024 smart-device statements, ransomware payment reports, and supported SOCI or APRA overlap checks.
Australia Cyber Security Act Requirements
Australia Cyber Security Act requirements for smart-device security standards, statements of compliance, ransomware payment reports, notices, and evidence records.
Australia Cyber Security Act Statement of Compliance Evidence
Evidence guide for Australia Cyber Security Act smart-device statements of compliance: required fields, manufacturer and supplier records, five-year retention, and examination readiness.
Australia Cyber Security Act templates
Source-backed field lists for Australia Cyber Security Act smart-device scope, statements of compliance, ransomware reports, notices, SOCI overlap, and records.
Australia Cyber Security Act vs EU Cyber Resilience Act
Compare Australia's Cyber Security Act 2024 with the EU Cyber Resilience Act across smart-device duties, ransomware reporting, product-with-digital-elements scope, actors, records, and enforcement routes.
Australia Cyber Security Act vs UK PSTI Act Guide
Compare Australia's Cyber Security Act 2024 smart-device, ransomware, and SOCI-adjacent obligations with the UK's PSTI connected-product regime.
Australia ransomware payment reporting 72-hour duty
Explain when Australia's Cyber Security Act 2024 requires a ransomware payment report, when the 72-hour clock starts, and what information the report must contain.
Australia Ransomware Payment Reporting Workflow
Operational workflow for Australia Cyber Security Act 2024 ransomware payment reports: scope, 72-hour trigger, report fields, owners, evidence, and cited Act and Rules sources.
Australia Ransomware Payment Reporting: Threshold and Report Content
FAQ answer on Australia's Cyber Security Act ransomware payment reporting scope, $3 million turnover threshold, 72-hour trigger, report fields, and evidence.
Australia Smart Device Compliance Statement
What a smart-device statement of compliance must contain under Australia's Cyber Security Act 2024 and Smart Devices Rules, who prepares and supplies it, how long to retain it, and how to prepare for examination.
Australia Smart Device Security Standards under the Cyber Security Act
Plain-English guide to Australia's Cyber Security (Security Standards for Smart Devices) Rules 2025: scope, passwords, vulnerability reporting, support periods, statements of compliance, and evidence records.
CSA 2024 Smart Device Applicability Test
Check whether a smart device is a consumer-grade relevant connectable product under Australia's Cyber Security Act and Smart Devices Rules.
Cyber Security Act 2024 Smart Device Compliance Checklist
Checklist for Australia Cyber Security Act 2024 smart-device scope, password controls, vulnerability reporting, security-update support periods, statements of compliance, retention, and evidence.
Cyber Security Act 2024 Statements of Compliance FAQ
Australian smart-device statements of compliance: covered products, responsible actors, required contents, supporting evidence, and five-year retention.
Cyber Security Act vs EU CRA: scope and obligations comparison
Compare Australia's Cyber Security Act 2024 with the EU Cyber Resilience Act across smart-device duties, ransomware reporting, product-with-digital-elements scope, actors, records, and enforcement routes.
Cyber Security Act vs UK PSTI Act: device security obligations compared
Compare Australia's Cyber Security Act 2024 smart-device, ransomware, and SOCI-adjacent obligations with the UK's PSTI connected-product regime.
How do notices and recalls work under the Australia Cyber Security Act?
FAQ on Australia Cyber Security Act compliance notices, stop notices, recall notices, public notifications, owners, evidence fields, and cited timing.
How does the Australia Cyber Security Act overlap with the SOCI Act?
FAQ on when Australia Cyber Security Act ransomware reporting overlaps with SOCI critical infrastructure assets, responsible entities, and smart-device duties.
Manufacturer, Importer, and Supplier Duties under Australia's Cyber Security Act 2024
Cyber Security Act 2024 smart-device duties for manufacturers, importers, and suppliers, including role tests, scope, statements, and records.
SOCI overlap triage workflow for Australia Cyber Security Act
Triage SOCI Act overlap with Australia Cyber Security Act ransomware reporting and smart-device standards using separate owners, evidence, and cited scope checks.
Which smart devices are in scope under Australia's Cyber Security Act 2024?
FAQ on Cyber Security Act 2024 smart-device scope: relevant connectable products, consumer-grade criteria, exclusions, Australian consumer acquisition, and records to keep.