The two regimes use a similar three-control baseline, but their scope tests, responsible actors, statement rules, publication details, retention periods, and enforcement systems are not identical.
A shared statement and technical evidence can be reused only when it contains every field and supports every duty required in both jurisdictions.
Use this comparison for consumer smart devices supplied under the UK's Product Security and Telecommunications Infrastructure (PSTI) Act 2022 and Australia's Cyber Security Act 2024. Australia's rules call the prescribed class . Assess each market separately, then reuse password, vulnerability-reporting, security-update, and product-identification evidence where the product version and legal requirement align.
Side-by-side comparison
UK PSTI vs Australia's smart-device regime
Compare the binding product-security parts of each framework. Other parts of Australia's Cyber Security Act have different triggers.
Relevant internet-connectable or network-connectable products made available to UK consumers, subject to the Act, Regulations, exceptions, and the actor's intention or awareness.
Relevant connectable products intended or likely to be used for personal, domestic, or household consumption and acquired in Australia by a consumer under the Rules' Australian Consumer Law test.
Manufacturers, importers, and distributors have distinct duties. An authorised representative may perform specified manufacturer functions but does not erase the manufacturer's obligations.
Manufacturers must manufacture to the standard and meet its other obligations. Suppliers must not supply a product they know or could reasonably be expected to know is non-compliant and must meet statement duties.
Passwords must meet the Schedule 1 conditions; manufacturers publish a security-issue reporting route and response-time information; manufacturers publish the minimum security-update period.
Passwords must be user-defined or unique per product and not guessable by prohibited methods; manufacturers publish a reporting contact and provide acknowledgements and status updates; manufacturers publish and honour a defined support end date subject to the Rules.
The statement accompanies the product. Manufacturers and importers generally keep a copy for the longer of 10 years from issue or the defined support period.
The manufacturer prepares the statement and suppliers supply the product accompanied by it. Manufacturers and suppliers keep it for five years; the Rules specify Australian content fields.
The Australian Secretary can use compliance, stop, and recall notices; the Minister can publish failures to comply with recall notices. The Act also provides examinations and internal review mechanisms.
The UK security, statement, and supply-chain duties have applied since 29 April 2024. Reassess when the product, actor, consumer-market facts, security controls, support period, or deemed-compliance basis changes.
The Australian smart-device standard commenced on 4 March 2026. Reassess when the product class, acquisition circumstances, manufacturer or supplier awareness, statement fields, published support period, or product version changes.
Relevant internet-connectable or network-connectable products made available to UK consumers, subject to the Act, Regulations, exceptions, and the actor's intention or awareness.
Relevant connectable products intended or likely to be used for personal, domestic, or household consumption and acquired in Australia by a consumer under the Rules' Australian Consumer Law test.
Manufacturers, importers, and distributors have distinct duties. An authorised representative may perform specified manufacturer functions but does not erase the manufacturer's obligations.
Manufacturers must manufacture to the standard and meet its other obligations. Suppliers must not supply a product they know or could reasonably be expected to know is non-compliant and must meet statement duties.
Passwords must meet the Schedule 1 conditions; manufacturers publish a security-issue reporting route and response-time information; manufacturers publish the minimum security-update period.
Passwords must be user-defined or unique per product and not guessable by prohibited methods; manufacturers publish a reporting contact and provide acknowledgements and status updates; manufacturers publish and honour a defined support end date subject to the Rules.
The statement accompanies the product. Manufacturers and importers generally keep a copy for the longer of 10 years from issue or the defined support period.
The manufacturer prepares the statement and suppliers supply the product accompanied by it. Manufacturers and suppliers keep it for five years; the Rules specify Australian content fields.
The Australian Secretary can use compliance, stop, and recall notices; the Minister can publish failures to comply with recall notices. The Act also provides examinations and internal review mechanisms.
The UK security, statement, and supply-chain duties have applied since 29 April 2024. Reassess when the product, actor, consumer-market facts, security controls, support period, or deemed-compliance basis changes.
The Australian smart-device standard commenced on 4 March 2026. Reassess when the product class, acquisition circumstances, manufacturer or supplier awareness, statement fields, published support period, or product version changes.
UK PSTI applies to relevant connectable products made available to UK consumers, subject to statutory exceptions and actor-specific tests. Its security requirements have applied since 29 April 2024.
Australia's comparison point is Part 2 of the Cyber Security Act 2024 and the Cyber Security (Security Standards for Smart Devices) Rules 2025, not every part of the Act. The Rules cover intended or likely to be used for personal, domestic, or household consumption when acquired in Australia by a consumer. Part 2 of the Rules and Schedule 1 commenced 12 months after the Rules were registered on 4 March 2025, so the smart-device standard commenced on 4 March 2026.
Australia expressly exempts desktop and laptop computers, tablets, smartphones, therapeutic goods, road vehicles, and road-vehicle components from this standard. UK exceptions differ. For example, a connected home camera or smart speaker can be a representative in-scope product in both markets, while an Australian-exempt smartphone still needs a separate UK assessment. The specific design, intended use, supply path, and exception conditions control the result.
The actor tests also differ. An Australian manufacturer must comply when it is aware, or could reasonably be expected to be aware, that the product will be acquired in Australia in the specified consumer circumstances. An Australian supplier must not supply a non-compliant product when the supplier has the same form of awareness and must meet the statement duty. UK manufacturers, importers, and distributors follow the PSTI Act's separate intention, knowledge, and reasonable-belief tests.
Both regimes address passwords, a public channel for security reports, and publication of a security-update support period. That makes shared engineering evidence practical. The detailed wording still matters. For example, Australia's Rules require acknowledgements and status updates for reported security issues, set accessibility conditions for the published reporting information, require an end date for the defined support period, and regulate how prominently a manufacturer publishes that period on websites under its control.
The statement rules are materially different. Under UK PSTI, a must accompany the product unless a current statutory deemed-compliance condition applies, and manufacturers and importers generally retain a required statement for the longer of 10 years from issue or the defined support period. Under the Australian Rules, the manufacturer prepares the statement, suppliers must supply the product accompanied by it, and manufacturers and suppliers retain it for five years. The Australian statement identifies the product and batch, the manufacturer, an authorised representative, any of the manufacturer's other authorised representatives in Australia, the manufacturer's declarations, the defined support period at issue, the signatory and function, and the place and date of issue.
The Australian Act requires a supplier to supply the covered product accompanied by the statement. The explanatory statement adds that the statement need not be handed to the buyer at the point of sale and is intended for regulator use; a responsible entity may provide or publish it with the product if it chooses. Information used for another jurisdiction may be reused only if every Australian content requirement is met. The UK accompaniment and content analysis remains separate.
Can the same cover the UK and Australia?
It can be the same controlled document only if it satisfies both regimes in full. The Australian explanatory statement expressly allows information used for a UK PSTI product to be reused when every Australian requirement is met. Check product and batch identification, details of the manufacturer, an authorised representative, and any of the manufacturer's other authorised representatives in Australia, declarations, defined support period, signature, signatory function, and place and date of issue, as well as the separate UK Schedule 4 fields and accompaniment rule.
Do Australia's ransomware-reporting rules apply to every smart-device manufacturer?
Not merely because a manufacturer sells a smart device. Ransomware payment reporting sits in Part 3 of the Cyber Security Act and has its own application and threshold tests. This page compares the smart-device security regime in Part 2 and the 2025 Smart Device Rules. Assess ransomware reporting separately if a payment is made after a qualifying cyber security incident.
Are smartphones covered by both regimes?
Australia's 2025 Smart Device Rules expressly exempt smartphones from the consumer-grade security standard. UK PSTI does not use the same blanket smartphone exception, so a smartphone or related product still needs a separate UK scope assessment. Companion products such as a connected accessory can also require their own assessment.
Use a product-and-batch identifier that can connect both statements to the tested hardware, firmware, companion software, and release.
Check every password path, including factory reset, preinstalled software, and software needed for all manufacturer-intended purposes.
Publish one security-reporting page that meets the stricter applicable content and accessibility conditions, while recording which clauses it satisfies.
State a fixed support end date where Australia applies. Do not shorten Australia's published defined support period; record any extension and update the required product pages.
Approve a jurisdiction-specific statement checklist before supply. Similar titles do not make the statements legally interchangeable.
Reassess both files when a firmware or service release changes credentials, reporting contacts, update delivery, the support end date, product identifiers, manufacturer details, consumer positioning, or the supply route.
Keep one technical evidence set, but sign off the UK and Australian scope, statement, supply, publication, retention, and enforcement requirements separately.