Artifact GuideUK and AustraliaPSTI vs Australia

UK PSTI vs Australia Smart Device Rules

The two regimes use a similar three-control baseline, but their scope tests, responsible actors, statement rules, publication details, retention periods, and enforcement systems are not identical.

A shared statement and technical evidence can be reused only when it contains every field and supports every duty required in both jurisdictions.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Sections
2

Structured answer sets in this page tree.

Primary sources
7

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

Use this comparison for consumer smart devices supplied under the UK's Product Security and Telecommunications Infrastructure (PSTI) Act 2022 and Australia's Cyber Security Act 2024. Australia's rules call the prescribed class . Assess each market separately, then reuse password, vulnerability-reporting, security-update, and product-identification evidence where the product version and legal requirement align.

Side-by-side comparison

UK PSTI vs Australia's smart-device regime

Compare the binding product-security parts of each framework. Other parts of Australia's Cyber Security Act have different triggers.

Review all sources
First framework
UK PSTI

UK security and statement duties for relevant connectable products made available to consumers.

Second framework
Australia

Part 2 of the Cyber Security Act 2024 and the 2025 Rules for .

Comparison row 1

Scope test

UK PSTI

Relevant internet-connectable or network-connectable products made available to UK consumers, subject to the Act, Regulations, exceptions, and the actor's intention or awareness.

Australia

Relevant connectable products intended or likely to be used for personal, domestic, or household consumption and acquired in Australia by a consumer under the Rules' Australian Consumer Law test.

Operational implication

Do not use a consumer-product conclusion from one jurisdiction as the conclusion for the other.

Comparison row 2

Responsible actors

UK PSTI

Manufacturers, importers, and distributors have distinct duties. An authorised representative may perform specified manufacturer functions but does not erase the manufacturer's obligations.

Australia

Manufacturers must manufacture to the standard and meet its other obligations. Suppliers must not supply a product they know or could reasonably be expected to know is non-compliant and must meet statement duties.

Operational implication

Map the actual manufacturer and each supply-chain role; the labels and duties are not identical across the two Acts.

Comparison row 3

Security baseline

UK PSTI

Passwords must meet the Schedule 1 conditions; manufacturers publish a security-issue reporting route and response-time information; manufacturers publish the minimum security-update period.

Australia

Passwords must be user-defined or unique per product and not guessable by prohibited methods; manufacturers publish a reporting contact and provide acknowledgements and status updates; manufacturers publish and honour a defined support end date subject to the Rules.

Operational implication

Build to the stricter applicable detail, then keep clause-level evidence showing how each product version meets both texts.

Comparison row 4

Statement and retention

UK PSTI

The statement accompanies the product. Manufacturers and importers generally keep a copy for the longer of 10 years from issue or the defined support period.

Australia

The manufacturer prepares the statement and suppliers supply the product accompanied by it. Manufacturers and suppliers keep it for five years; the Rules specify Australian content fields.

Operational implication

A single document is possible, but only after a field-by-field and supply-path check for both regimes.

Comparison row 5

Enforcement

UK PSTI

OPSS can investigate and use compliance, stop, recall, forfeiture, monetary-penalty, and related statutory powers.

Australia

The Australian Secretary can use compliance, stop, and recall notices; the Minister can publish failures to comply with recall notices. The Act also provides examinations and internal review mechanisms.

Operational implication

Keep regulator-ready product, statement, test, publication, supply, and corrective-action records for each jurisdiction.

Comparison row 6

Dates and reassessment

UK PSTI

The UK security, statement, and supply-chain duties have applied since 29 April 2024. Reassess when the product, actor, consumer-market facts, security controls, support period, or deemed-compliance basis changes.

Australia

The Australian smart-device standard commenced on 4 March 2026. Reassess when the product class, acquisition circumstances, manufacturer or supplier awareness, statement fields, published support period, or product version changes.

Operational implication

Use release and market-entry gates, not a one-time global approval. Record the date, facts, owner, and evidence for each reassessment.

Practical decision rule

How should a dual-market team proceed?

  • Write separate UK and Australian scope findings, including each jurisdiction's excluded-product analysis.
  • Use one technical control set for passwords, vulnerability intake, and updates, but cite and test both legal texts.
  • Prepare a field matrix before deciding whether one statement can serve both markets.
  • Record accompaniment, supplier checks, publication locations, retention dates, and responsible owners for each market.
Section 1

Which regime applies?

UK PSTI applies to relevant connectable products made available to UK consumers, subject to statutory exceptions and actor-specific tests. Its security requirements have applied since 29 April 2024.

Australia's comparison point is Part 2 of the Cyber Security Act 2024 and the Cyber Security (Security Standards for Smart Devices) Rules 2025, not every part of the Act. The Rules cover intended or likely to be used for personal, domestic, or household consumption when acquired in Australia by a consumer. Part 2 of the Rules and Schedule 1 commenced 12 months after the Rules were registered on 4 March 2025, so the smart-device standard commenced on 4 March 2026.

Australia expressly exempts desktop and laptop computers, tablets, smartphones, therapeutic goods, road vehicles, and road-vehicle components from this standard. UK exceptions differ. For example, a connected home camera or smart speaker can be a representative in-scope product in both markets, while an Australian-exempt smartphone still needs a separate UK assessment. The specific design, intended use, supply path, and exception conditions control the result.

The actor tests also differ. An Australian manufacturer must comply when it is aware, or could reasonably be expected to be aware, that the product will be acquired in Australia in the specified consumer circumstances. An Australian supplier must not supply a non-compliant product when the supplier has the same form of awareness and must meet the statement duty. UK manufacturers, importers, and distributors follow the PSTI Act's separate intention, knowledge, and reasonable-belief tests.

Section 2

Where the controls align and where they split

Both regimes address passwords, a public channel for security reports, and publication of a security-update support period. That makes shared engineering evidence practical. The detailed wording still matters. For example, Australia's Rules require acknowledgements and status updates for reported security issues, set accessibility conditions for the published reporting information, require an end date for the defined support period, and regulate how prominently a manufacturer publishes that period on websites under its control.

The statement rules are materially different. Under UK PSTI, a must accompany the product unless a current statutory deemed-compliance condition applies, and manufacturers and importers generally retain a required statement for the longer of 10 years from issue or the defined support period. Under the Australian Rules, the manufacturer prepares the statement, suppliers must supply the product accompanied by it, and manufacturers and suppliers retain it for five years. The Australian statement identifies the product and batch, the manufacturer, an authorised representative, any of the manufacturer's other authorised representatives in Australia, the manufacturer's declarations, the defined support period at issue, the signatory and function, and the place and date of issue.

The Australian Act requires a supplier to supply the covered product accompanied by the statement. The explanatory statement adds that the statement need not be handed to the buyer at the point of sale and is intended for regulator use; a responsible entity may provide or publish it with the product if it chooses. Information used for another jurisdiction may be reused only if every Australian content requirement is met. The UK accompaniment and content analysis remains separate.

Can the same cover the UK and Australia?

It can be the same controlled document only if it satisfies both regimes in full. The Australian explanatory statement expressly allows information used for a UK PSTI product to be reused when every Australian requirement is met. Check product and batch identification, details of the manufacturer, an authorised representative, and any of the manufacturer's other authorised representatives in Australia, declarations, defined support period, signature, signatory function, and place and date of issue, as well as the separate UK Schedule 4 fields and accompaniment rule.

Do Australia's ransomware-reporting rules apply to every smart-device manufacturer?

Not merely because a manufacturer sells a smart device. Ransomware payment reporting sits in Part 3 of the Cyber Security Act and has its own application and threshold tests. This page compares the smart-device security regime in Part 2 and the 2025 Smart Device Rules. Assess ransomware reporting separately if a payment is made after a qualifying cyber security incident.

Are smartphones covered by both regimes?

Australia's 2025 Smart Device Rules expressly exempt smartphones from the consumer-grade security standard. UK PSTI does not use the same blanket smartphone exception, so a smartphone or related product still needs a separate UK scope assessment. Companion products such as a connected accessory can also require their own assessment.

  • Use a product-and-batch identifier that can connect both statements to the tested hardware, firmware, companion software, and release.
  • Check every password path, including factory reset, preinstalled software, and software needed for all manufacturer-intended purposes.
  • Publish one security-reporting page that meets the stricter applicable content and accessibility conditions, while recording which clauses it satisfies.
  • State a fixed support end date where Australia applies. Do not shorten Australia's published defined support period; record any extension and update the required product pages.
  • Approve a jurisdiction-specific statement checklist before supply. Similar titles do not make the statements legally interchangeable.
  • Reassess both files when a firmware or service release changes credentials, reporting contacts, update delivery, the support end date, product identifiers, manufacturer details, consumer positioning, or the supply route.
Primary sources

References and citations

legislation.gov.au
Referenced sections
  • Part 2 Divisions 3 and 4 establish notices, publication, examination, review, and related enforcement mechanisms.
Related guides

Explore more topics

UK PSTI Act statement of compliance: what must the SoC contain?
Understand when a UK PSTI statement is required, the Schedule 4 fields, supply-chain checks, retention, digital accompaniment, and the December 2025 label route.
UK PSTI Act: vulnerability disclosure policy requirements and template
Publish a free, clear, accessible English reporting route plus expected acknowledgement and status-update times, and retain evidence that the information remained available.
UK PSTI applicability test: product, market, and actor scope
Apply the UK PSTI tests in order: connectivity, current exceptions, UK consumer availability, supply facts, and the manufacturer, importer, or distributor trigger.
UK PSTI compliance checklist for product release
Use a release checklist with scope, role, security-control, statement, records, and compliance-failure evidence for UK consumer connectable products.
UK PSTI compliance: duties, evidence, and response
Build a UK PSTI compliance process covering product scope, supply-chain roles, the three security requirements, statements, records, and post-market failures.
UK PSTI default password requirements
Apply the UK PSTI password rule to each relevant password, test unique-per-product generation, and keep reset and release evidence for the shipped model.
UK PSTI Default Password Rules
PSTI requires each covered password to be user-defined or unique per product. Unique credentials must not use prohibited predictable generation methods.
UK PSTI ETSI Evidence and Deemed Compliance
ETSI EN 303 645 and TS 103 701 can structure technical evidence, but the standards-based PSTI route depends on the exact mapped provisions and additional Schedule 2 conditions.
UK PSTI Excepted Products and Boundaries
An internet- or network-connectable product is outside the relevant-product definition only when a current Schedule 3 exception applies; record the exact category and facts rather than relying on a broad sector label.
UK PSTI Importer and Distributor Duties
Importers and distributors have their own statement, stop-supply, remediation, and notification duties; importers also have statutory investigation and 10-year investigation-record duties.
UK PSTI Manufacturer, Importer and Distributor Roles
Distinguish manufacturer, importer, distributor, and authorised-representative duties per product and supply route, including rebranding, imports, statement checks, stop-supply decisions, and compliance failures.
UK PSTI OPSS Notices: Compliance, Stop, Recall, and Penalties
OPSS can use compliance, stop, and recall notices alongside monetary and other measures; notice recipients should preserve the notice, product scope, supply records, corrective actions, representations, and appeal dates.
UK PSTI password and security update policy requirements
Implement the UK PSTI password rule and publish a defined security support period with the required end date, access conditions, and change controls.
UK PSTI Product Security Deadlines and Compliance Calendar Guide
Track the UK PSTI regime's commencement and amendment dates, product-specific support periods, record retention, and OPSS response and appeal windows.
UK PSTI Product Security FAQ
Get direct, sourced answers on product scope, exceptions, roles, passwords, vulnerability reporting, update-period information, statements, records, and OPSS enforcement.
UK PSTI Product Security Importer and Distributor Duties Guide
Identify the pre-supply checks, statement or deemed-compliance evidence, stop-supply decisions, notification and remediation duties required of UK importers and distributors, plus importer-specific investigation and record duties.
UK PSTI Product Security Minimum Support Period and Update Transparency Guide
Publish the minimum security-update period and end date in English, free of charge, without prior request, and in clear language, without implying that PSTI sets one duration for every product.
UK PSTI Product Security OPSS Enforcement and Penalties Guide
Understand OPSS investigations, compliance, stop and recall notices, monetary penalties, forfeiture, court orders, representations, appeals, and evidence needed to respond.
UK PSTI Product Security OPSS Notices Guide
Prepare for compliance, stop, and recall notices by understanding their effects, representation and appeal routes, product records, and corrective-action evidence.
UK PSTI Product Security Penalties and Fines Guide
Understand the maximum fixed and daily PSTI penalties, how OPSS sets an amount, representation and appeal rights, and separate court-ordered sanctions.
UK PSTI product security requirements
Read the three Schedule 1 security requirements and the surrounding manufacturer, importer, distributor, statement, record, and failure-response duties.
UK PSTI Relevant Connectable Product Scope
A product is relevant when it is internet-connectable or network-connectable and not excepted, then the UK consumer-use and supply facts determine whether the Part 1 duties engage.
UK PSTI relevant connectable product scope test
Decide whether one product meets the UK PSTI connectivity definition, falls within a current exception, and reaches the separate UK-consumer duty tests.
UK PSTI relevant connectable products: categories and exceptions
Understand which connected product categories can enter UK PSTI scope, how the statutory tests work, and why examples never replace the current exception schedule.
UK PSTI Scope Classifier Workflow
Decide whether a product falls within the UK PSTI product-security regime by checking connectivity, consumer supply, exceptions, actor roles, and product-specific evidence.
UK PSTI security requirements in practice
Implement the three UK PSTI security requirements through product specifications, release tests, public information, approvals, and post-release evidence.
UK PSTI Security Update Support Periods
PSTI does not prescribe a universal minimum number of support years. The manufacturer sets and publishes a product-specific minimum period and end date; preserve the published commitment and assess any later change against the current Regulations.
UK PSTI Security Update Transparency
Publish the minimum security-update period and end date in English, free of charge, without prior request, and in language understandable without technical knowledge.
UK PSTI Statement of Compliance Evidence Pack
Join the prescribed statement fields to product identifiers, control evidence, publication records, supply-chain checks, accompaniment evidence, retention, and change management.
UK PSTI Statement of Compliance Template
Build a statement record with the prescribed Schedule 4 information and evidence that it accompanied the product, while checking whether a current Schedule 2A deemed-compliance route applies.
UK PSTI Statement of Compliance Workflow
Prepare, approve, provide, verify, retain, and update statement evidence before a relevant connectable product is made available in the UK.
UK PSTI Statement of Compliance: Contents, Delivery, and Records
A statement must contain the prescribed information and accompany the product unless a current deemed-compliance route applies; a digital method is possible, but each business must ensure that it meets the Act.
UK PSTI Support Period Evidence Workflow
Set, publish, approve, and preserve the product-specific minimum security-update period and end date, then control changes and customer information against the shipped product.
UK PSTI to ETSI Evidence Mapping
Map ETSI EN 303 645 and TS 103 701 evidence to the three UK legal requirements without treating the wider voluntary ETSI baseline as if every provision were mandatory under PSTI.
UK PSTI vs ETSI EN 303 645
See how binding UK PSTI duties relate to ETSI EN 303 645, which edition the UK Regulations name, what the standard adds, and what evidence to retain.
UK PSTI vs EU Cyber Resilience Act
Decide whether UK PSTI, the EU Cyber Resilience Act, or both apply, then compare actors, exclusions, security work, documents, reporting, and dates.
UK PSTI vs EU Cyber Resilience Act (CRA)
Compare UK PSTI and the EU Cyber Resilience Act by scope, security duties, support periods, conformity assessment, reporting, evidence, and application dates.
UK PSTI Vulnerability Disclosure Requirements
Publish a clear reporting route plus expected acknowledgement and status-update times. PSTI requires the information and timescales to be available; it does not prescribe one universal response deadline for every report.
UK PSTI Vulnerability Disclosure Workflow
Operate intake, acknowledgement, status updates, investigation, remediation, disclosure, and evidence while keeping the legal publication duty distinct from broader good-practice response targets.