Artifact GuideAustraliaTimeline and Commencement

Australia Cyber Security Act Timeline and Commencement

The Act and its three 2025 rule instruments started on different dates. Track framework commencement and the operative dates for ransomware, CIRB, and smart-device obligations separately.

Match each workflow to the relevant Part and instrument; consultation, registration, commencement, and event deadlines are different legal events.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 23, 2026
Sections
4

Structured answer sets in this page tree.

Primary sources
8

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 23, 2026
Overview

The Cyber Security Act 2024 commenced in stages: Parts 1, 4, 6, and 7 on 30 November 2024; Parts 3 and 5 on 29 May 2025; and Part 2 on 29 November 2025. Home Affairs guidance incorrectly gives 30 May 2025 for the Part 3 and Part 5 regimes. The prescribed smart-device standard and statement duties became operative on 4 March 2026. Match each ransomware, smart-device, and Cyber Incident Review Board workflow to its governing Part and Rules.

Section 1

Which Cyber Security Act commencement dates matter?

Parts 1, 4, 6, and 7 commenced on 30 November 2024, and Part 2 commenced on 29 November 2025. Parts 3 and 5 commenced on 29 May 2025 under the binding column 2 mechanism in section 2: no earlier day was proclaimed, so they commenced on the day after the six-month fallback period ended. The Federal Register also displays 29 May 2025 in column 3. Home Affairs guidance incorrectly says the ransomware reporting regime and Rules started on 30 May 2025.

The subordinate instruments have separate tables. The ransomware and Rules commence with Parts 3 and 5. Part 1 of the Smart Devices Rules commenced on registration on 4 March 2025, but Part 2 and Schedule 1 - including the prescribed class, security standard, statement requirements, and five-year retention rule - commenced on 4 March 2026.

  • 29 November 2024: the Act received Royal Assent.
  • 30 November 2024: Parts 1, 4, 6, and 7 commenced.
  • 3 March 2025: the Ransomware Payment Reporting Rules and Rules were registered. Registration did not by itself activate either instrument because each provision also ties operation to the relevant Part of the Act.
  • 4 March 2025: the Smart Devices Rules were registered and Part 1 commenced. Part 2 and Schedule 1 remained deferred for 12 months.
  • 29 May 2025: Parts 3 and 5 commenced under section 2 of the Act. Home Affairs guidance incorrectly gives 30 May 2025 for the linked ransomware and regimes.
  • 29 November 2025: Part 2 of the Act commenced, establishing the smart-device statutory framework.
  • 4 March 2026: Part 2 and Schedule 1 of the Smart Devices Rules commenced, making the prescribed consumer-grade product controls and statement requirements operative.
Section 2

Which date belongs in each operating workflow?

Ransomware teams should track the payment event or awareness event for each incident. A is either a qualifying non-government business carried on in Australia whose previous-financial-year turnover exceeds the prescribed $3 million threshold, or a responsible entity for a critical infrastructure asset to which SOCI Part 2B applies. The incident, demand, payment, and statutory exclusion conditions must also be met. If the reporting business entity made the payment, the report is due within 72 hours after payment. If another entity paid on its behalf, the report is due within 72 hours after the reporting business entity became aware of the payment.

Product teams need both 29 November 2025 and 4 March 2026. Section 13 brings a into Part 2 if it was manufactured on or after 29 November 2025 or supplied in Australia, other than as second-hand goods, on or after that date. The prescribed consumer-grade security standard and provisions became operative on 4 March 2026. The official explanatory statement gives smart TVs, smart watches, home assistants, baby monitors, and consumer energy resources as examples of the consumer-grade class, but product teams must still apply the binding connectivity, intended-use, acquisition, awareness, date, and exclusion tests to each product.

The date establishes the review framework; it does not create a periodic filing. A published review notification does not itself require an organisation to respond. A written request under section 48 is voluntary, but a later notice under section 49 may require an involved non-government entity to produce relevant documents, with at least 14 days allowed for production.

  • Incident response: retain payment and awareness timestamps, the reporting-business-entity decision, the 72-hour deadline, and submission proof.
  • Product release: retain manufacture and supply dates, whether a supply was second hand, product-scope and exclusion decisions, technical control evidence, the issued statement, and its five-year retention owner.
  • response: distinguish a public review notification, a voluntary section 48 request, and a compulsory section 49 notice; record the notice date, the production deadline of at least 14 days, the legal and disclosure review, the response, and submission proof.
  • Legal or compliance: monitor rule amendments and the Act's provision permitting a Parliamentary Joint Committee on Intelligence and Security () review, subject to the Committee beginning it as soon as practicable after 1 December 2027.
Section 3

Which dates are commonly confused?

Royal Assent, registration, framework , operative rule commencement, and event-triggered deadlines describe different legal events. Registration of the Smart Devices Rules on 4 March 2025 did not activate Part 2 and Schedule 1; they commenced on 4 March 2026.

The five-year statement period is a retention duration, not a common destruction date. The Rules specify a five-year period but do not state its starting event, so the manufacturer and supplier should record the interpretation used and obtain case-specific advice before disposing of a statement.

The 72-hour reporting period starts from the payment or awareness trigger in section 27, not from initial detection of the cyber incident. If no payment or benefit directly related to the extorting demand was provided, Part 3 does not create a ransomware payment report deadline, although other incident-reporting duties may still apply.

  • Do not label the 2024-2025 Rules consultation window as a compliance deadline; it preceded the final instruments.
  • Do not use 29 November 2025 alone as the smart-device control date; the prescribed standard and statement provisions sit in Rules provisions that commenced on 4 March 2026.
  • Do not treat the framework as a substitute for reporting under the Security of Critical Infrastructure Act 2018 (SOCI Act), the Privacy Act 1988, Australian Prudential Regulation Authority (APRA) standards, law-enforcement processes, insurance terms, or contracts.
  • For stock around , record whether the product was manufactured or supplied on or after Part 2 commenced and whether the supply was second hand.
Section 4

How should teams maintain the commencement record?

Keep one dated legal-status register that links each Act Part and rule instrument to its provision, affected workflow, owner, and evidence location. Keep event-triggered deadlines in the operational system where the trigger occurs.

Recheck the latest authorised Act and rule versions after an amendment or new instrument. Preserve the version relied on for an earlier decision so the organisation can explain what was in force at that time.

  • Record Act Part, instrument, provision, event, operative date, source version, and last verification date.
  • Connect Part 3 to the ransomware payment-reporting workflow and Part 5 to the response owner.
  • Connect Part 2 and the Smart Devices Rules to product intake, release approval, statement issuance, and retention controls.
  • Log an unresolved question rather than substituting a consultation date, registration date, or planning target for the legal provision.
Primary sources

References and citations

legislation.gov.au
Referenced sections
  • Primary Act source for the commencement mechanism and the Federal Register's dates for Parts 2, 3, 5, and the other provisions.
"2 Commencement"
legislation.gov.au
Referenced sections
  • Current Act sections 27, 48, 49, and 88 support the 72-hour trigger, the distinction between voluntary CIRB requests and compulsory document notices, the minimum 14-day production period, and the statutory-review timing.
"Chair may require certain entities to produce documents"
Related guides

Explore more topics

Australia Compliance Statement Evidence Workflow
Evidence workflow for preparing, supplying, and retaining statements of compliance under Australia's Cyber Security Act 2024 and Smart Devices Rules.
Australia Cyber Security Act 2024 scope and definitions
Official source scope guide for Australia's Cyber Security Act 2024: relevant connectable products, consumer-grade smart devices, reporting business entities, ransomware payment reports, and SOCI overlap.
Australia Cyber Security Act and SOCI Act overlap
How the Australia Cyber Security Act overlaps with the Security of Critical Infrastructure Act for responsible entities, ransomware payment reporting, smart devices, and evidence records.
Australia Cyber Security Act Applicability Test
Decide whether the Australia Cyber Security Act 2024 applies to a smart-device product, supplier, manufacturer, or ransomware payment reporting scenario.
Australia Cyber Security Act Compliance Checklist
Concrete checklist items for Australian Cyber Security Act smart-device and ransomware duties, with SOCI and APRA CPS 234 evidence checks.
Australia Cyber Security Act Compliance Guide
A cited compliance guide for Australia Cyber Security Act smart-device statements, ransomware payment reporting, incident coordination, and review-board readiness.
Australia Cyber Security Act Deadlines and Calendar
Cyber Security Act 2024 dates and event-driven deadlines for ransomware payment reports, smart-device duties, records, notices, and statutory review.
Australia Cyber Security Act FAQ
Answers to Australia Cyber Security Act questions on smart device scope, statements of compliance, ransomware reports, enforcement notices, and incident review.
Australia Cyber Security Act penalties and fines
Cyber Security Act 2024 civil penalties explained by section, including ransomware reports, protected information, CIRB notices, and smart-device enforcement.
Australia Cyber Security Act recordkeeping FAQ
What records to keep for Cyber Security Act 2024 smart-device statements, ransomware payment reports, and supported SOCI or APRA overlap checks.
Australia Cyber Security Act Requirements
Australia Cyber Security Act requirements for smart-device security standards, statements of compliance, ransomware payment reports, notices, and evidence records.
Australia Cyber Security Act Statement of Compliance Evidence
Evidence guide for Australia Cyber Security Act smart-device statements of compliance: required fields, manufacturer and supplier records, five-year retention, and examination readiness.
Australia Cyber Security Act templates
Source-backed field lists for Australia Cyber Security Act smart-device scope, statements of compliance, ransomware reports, notices, SOCI overlap, and records.
Australia Cyber Security Act vs EU Cyber Resilience Act
Compare Australia's Cyber Security Act 2024 with the EU Cyber Resilience Act across smart-device duties, ransomware reporting, product-with-digital-elements scope, actors, records, and enforcement routes.
Australia Cyber Security Act vs UK PSTI Act Guide
Compare Australia's Cyber Security Act 2024 smart-device, ransomware, and SOCI-adjacent obligations with the UK's PSTI connected-product regime.
Australia ransomware payment reporting 72-hour duty
Explain when Australia's Cyber Security Act 2024 requires a ransomware payment report, when the 72-hour clock starts, and what information the report must contain.
Australia Ransomware Payment Reporting Workflow
Operational workflow for Australia Cyber Security Act 2024 ransomware payment reports: scope, 72-hour trigger, report fields, owners, evidence, and cited Act and Rules sources.
Australia Ransomware Payment Reporting: Threshold and Report Content
FAQ answer on Australia's Cyber Security Act ransomware payment reporting scope, $3 million turnover threshold, 72-hour trigger, report fields, and evidence.
Australia Smart Device Applicability Workflow
Decide whether Australia's mandatory smart-device security standard applies, including commencement, connectivity, consumer use, exclusions, roles, and evidence.
Australia Smart Device Compliance Statement
What a smart-device statement of compliance must contain under Australia's Cyber Security Act 2024 and Smart Devices Rules, who prepares and supplies it, how long to retain it, and how to prepare for examination.
Australia Smart Device Security Standards under the Cyber Security Act
Plain-English guide to Australia's Cyber Security (Security Standards for Smart Devices) Rules 2025: scope, passwords, vulnerability reporting, support periods, statements of compliance, and evidence records.
CSA 2024 Smart Device Applicability Test
Check whether a smart device is a consumer-grade relevant connectable product under Australia's Cyber Security Act and Smart Devices Rules.
Cyber Security Act 2024 Smart Device Compliance Checklist
Checklist for Australia Cyber Security Act 2024 smart-device scope, password controls, vulnerability reporting, security-update support periods, statements of compliance, retention, and evidence.
Cyber Security Act 2024 Statements of Compliance FAQ
Australian smart-device statements of compliance: covered products, responsible actors, required contents, supporting evidence, and five-year retention.
Cyber Security Act vs EU CRA: scope and obligations comparison
Compare Australia's Cyber Security Act 2024 with the EU Cyber Resilience Act across smart-device duties, ransomware reporting, product-with-digital-elements scope, actors, records, and enforcement routes.
Cyber Security Act vs UK PSTI Act: device security obligations compared
Compare Australia's Cyber Security Act 2024 smart-device, ransomware, and SOCI-adjacent obligations with the UK's PSTI connected-product regime.
How do notices and recalls work under the Australia Cyber Security Act?
FAQ on Australia Cyber Security Act compliance notices, stop notices, recall notices, public notifications, owners, evidence fields, and cited timing.
How does the Australia Cyber Security Act overlap with the SOCI Act?
FAQ on when Australia Cyber Security Act ransomware reporting overlaps with SOCI critical infrastructure assets, responsible entities, and smart-device duties.
Manufacturer, Importer, and Supplier Duties under Australia's Cyber Security Act 2024
Cyber Security Act 2024 smart-device duties for manufacturers, importers, and suppliers, including role tests, scope, statements, and records.
SOCI overlap triage workflow for Australia Cyber Security Act
Triage SOCI Act overlap with Australia Cyber Security Act ransomware reporting and smart-device standards using separate owners, evidence, and cited scope checks.
Which smart devices are in scope under Australia's Cyber Security Act 2024?
FAQ on Cyber Security Act 2024 smart-device scope: relevant connectable products, consumer-grade criteria, exclusions, Australian consumer acquisition, and records to keep.