In short: Australia's smart device security rules apply to in-scope consumer devices manufactured on and from 4 March 2026, not to everything currently on sale. They require a manufacturer to publish three things: no universal default passwords, a route for reporting security issues, and a security update support period with an end date. You can check two of those yourself before you buy. The statement of compliance, which is the actual proof of compliance, does not have to be published at all.
You are comparing two similar smart home devices. Both promise the same features, both work with your preferred platform, and neither box makes it obvious whether the product will still receive security updates in three years.
Australia's new smart device security rules are meant to make part of that decision less opaque. They establish three mandatory requirements, but they do not certify that every device on a shop shelf is secure or guarantee a long useful life.
The date on which the device was manufactured matters, too. A newly purchased product may lawfully fall outside the standards if it was manufactured before the rules took effect.
What changed in Australia
Australia's security standards for smart devices are mandatory requirements covering passwords, security issue reporting and published security update periods for certain consumer connectable products manufactured on and from 4 March 2026.
The legal framework comes from the Cyber Security Act 2024, with the detailed standard prescribed by the Cyber Security (Security Standards for Smart Devices) Rules 2025. The security standards took effect on 4 March 2026, following a lead-in period after the Rules were made in 2025.
In this context, Internet of Things, or IoT, simply means physical products that connect to the internet or to other networked products. The Act uses the more precise term relevant connectable product for a product capable of connecting directly or indirectly to the internet, subject to the statutory definition and exemptions.
The standards are a baseline for manufacturers and suppliers, not a consumer security rating. They address three specific weaknesses that have made it difficult to judge connected products, while leaving many other security and privacy questions outside their scope.
Which devices are covered
The Australian smart device security standards cover a relevant connectable product that will be acquired, or could reasonably be expected to be acquired, by an Australian consumer and is intended or likely to be used for personal, domestic or household purposes.
Home Affairs gives smart TVs, smart watches, home assistants, baby monitors and consumer energy resources as examples. Inclusion depends on the legal tests, however, not simply on whether a retailer calls something smart.
The Rules exempt desktop computers, laptops, tablet computers, smartphones, therapeutic goods, road vehicles and road vehicle components as those terms are defined in the relevant legislation. An exempt product does not become covered merely because it has an internet connection.
A product marketed mainly to businesses is not automatically outside the standard. Home Affairs says the standard applies to classes of product, so a product can be covered if there is a circumstance in which it could reasonably be acquired by an Australian consumer for personal, domestic or household use.
This article provides general information, not legal advice. Manufacturers, importers and suppliers deciding whether a particular product is in scope should work from the Act and Rules and obtain advice for their circumstances.
The manufacture date is the critical date
The smart device security standards came into force for in-scope products manufactured on and from 4 March 2026.
They do not apply merely because a product was sold or purchased after that date. According to Home Affairs guidance, products manufactured before 4 March 2026 are not required to comply because the standards were not in effect on their date of manufacture.
That creates a transition period on real shop shelves. Older stock can continue to appear beside newer units, even where the products share a model name and look identical.
A purchase date, product launch date or retailer listing date therefore does not establish that a device is covered. If the distinction matters to your decision, ask the retailer for the manufacture date or a batch-specific statement of compliance before paying, although that information may not be available on the public product page.
The three requirements
The three requirements manufacturers must meet are restrictions on universal default passwords, a published process for reporting security issues, and a published security update support period that includes an end date.
1. No universal default passwords
Where an in-scope product uses the passwords addressed by the standard, they must be unique to each product or defined by the user once the product is outside its factory default state. The detailed requirement covers relevant device hardware, pre-installed software and software that must be installed for the product's intended use.
This does not mean every covered product must use a password. Home Affairs says the password requirement applies where the relevant password functionality exists, and a default password may be used while the product remains in its factory default state.
2. A published route for reporting security issues
Manufacturers must publish at least one point of contact through which people can report security issues. They must also publish when a reporter will receive an acknowledgement and status updates through to resolution.
The information must be accessible, clear and transparent. Under the Rules, it must also be available in English, free of charge, without a prior request and without requiring personal information about the reporter.
3. A published security support period
Manufacturers must publish the period during which applicable device hardware and software will receive security updates, including an end date. The obligation can also extend to required software and manufacturer-developed companion software associated with the product's intended use where those components can receive security updates.
Think of the support end date as a best-before date for one part of the product's security, not an expiry date for the hardware. The device may continue working after that date, but the published commitment to provide security updates will have ended unless the manufacturer extends it.
The Rules do not prescribe a minimum support duration. A clearly published short period may satisfy the disclosure requirement, so buyers still need to decide whether the offered period suits how long they expect to keep the device.
What to check before buying
Two of the three security obligations create information that a buyer can usually check directly in about a minute. The third obligation, concerning passwords, is harder to test before setup, while the formal statement of compliance presents a separate visibility gap.
1. Find the security support end date. Search the manufacturer's product page and support documentation for security updates, defined support period or support end date. Check that the statement names an actual end date and applies to the precise model, relevant software and companion app you are considering.
2. Find the security reporting channel. Look for a security, vulnerability disclosure or product security page. It should identify a reporting contact and explain when reports will be acknowledged and when status updates will be provided.
3. Check whether the date rule can be established. A product bought today is not necessarily a product manufactured on or after 4 March 2026. Ask the retailer or manufacturer about the manufacture date, batch and applicable compliance statement when older stock may be involved.
If you cannot find a support date or reporting channel, do not immediately label the product non-compliant. It may predate the standard, fall outside its scope or publish the information somewhere you have not found. Treat the missing information as an unresolved buying risk and ask the manufacturer or retailer for a direct answer.
The support date is the strongest comparison tool. If two devices otherwise meet your needs, compare how much supported life remains from the date of purchase, not how many years the manufacturer originally announced.
The statement of compliance gap
A statement of compliance is a manufacturer-prepared declaration identifying the product and stating that, in the manufacturer's opinion, it and the manufacturer meet the applicable security standard.
Manufacturers must provide statements for in-scope products when the statutory awareness test is met, and suppliers must supply those products with a statement. Manufacturers and suppliers must retain the statement for five years.
Consumers should not assume they can inspect this evidence on a website before buying. Publishing the statement online is not mandatory, although Home Affairs suggests manufacturers may choose to do so for transparency.
The statement must accompany the supply in the manner chosen by the entity, but Home Affairs notes that the Act does not define accompanied or specify exactly what supplying a product with the statement requires. This means the support date and reporting channel may be easier to verify before purchase than the formal declaration itself.
A statement is also not an independent security certification. It records the manufacturer's declaration and required product details, while the regulator retains powers to examine products and statements.
What these rules do not guarantee
The standards do not tell you whether a product collects more data than necessary, whether its cloud service will remain commercially available or whether it is well protected against every attack. They also do not prescribe a minimum number of years for security support.
Compliance should therefore be treated as a floor, not the complete buying decision. Your intended workload still matters: a remotely accessible camera, lock or energy system creates different consequences from a low-impact device isolated on a home network.
Remote access deserves separate attention because exposing a service can increase the ways it may be reached. Readers running home servers alongside smart devices can use our practical guides to security and ransomware protection, reducing remote access exposure with a VPN and remote access through Tailscale or Cloudflare Tunnels as workload-specific examples.
How enforcement works
The Technology Assessment and Regulation Office, or TARO, within the Department of Home Affairs regulates Australia's smart device security rules and supports the Department's Secretary in exercising enforcement powers.
Home Affairs describes its approach as education-first and uplift-focused. The available escalation includes engagement, a compliance notice, a stop notice and a recall notice, while products and statements may be examined to assess compliance.
If an entity fails to comply with a recall notice, the Act permits publication of its identity, product details, the non-compliance and the product's risks on the Home Affairs website. Need to Know IT has not verified how TARO has used these powers since commencement.
Do the rules apply to a smart device I bought before March 2026?
No. A device bought before 4 March 2026 necessarily predates the manufacture-date threshold, so the new security standard does not apply to it.
Do all smart devices sold in Australia now have to comply?
No. Coverage depends on the product's manufacture date, connectability, expected Australian consumer acquisition and intended or likely household use, as well as the exemptions in the Rules.
Does a support end date guarantee years of updates?
The published date identifies the period for which security updates will be provided, but the Rules do not set a minimum duration. Compare the remaining support period with how long you expect to use the device.
Can I see a statement of compliance before buying?
A supplier must supply a covered product with a statement of compliance, but neither the Act nor the Rules requires that statement to be published online for pre-purchase inspection. You can ask the retailer or manufacturer for it, but Need to Know IT has not verified how individual vendors respond in practice.
Does a statement of compliance mean the government certified the product?
No. The statement contains a declaration made by or on behalf of the manufacturer, rather than an independent government certification or product score.
Who enforces Australia's smart device security rules?
The Technology Assessment and Regulation Office within the Department of Home Affairs regulates the rules and supports the Secretary of Home Affairs in using the Act's enforcement powers.
Use the disclosures as part of the decision
Before buying a connected household product, record its security support end date and find its vulnerability-reporting process. Then judge those disclosures against the device's expected life, the sensitivity of its workload and the consequences if its account, app or remote connection is compromised.
The new standard makes two useful facts more visible, but it does not choose the right device for you. That still requires comparing the product with a defined household, workload and risk tolerance.
This article is part of NTKIT's smart home coverage, which explains the wider stack these rules apply to: hubs, protocols, cameras, local processing and the network underneath.
Once a smart device is in your home, the next question is how you reach it from outside without exposing it to the open internet. This guide compares the two approaches most people end up choosing between.