Your smart devices now have to be secure by law: what Australia's IoT rules (live since March 2026) change for buyers
Your smart devices now have to be secure by law — what changed on 4 March 2026
Australia has had plenty of advice about IoT security and almost no obligations. That changed on 4 March 2026, when the Cyber Security (Security Standards for Smart Devices) Rules 2025 commenced under the Cyber Security Act 2024, after a twelve-month transition. It is the country's first mandatory, enforceable security baseline for consumer smart devices — the legal replacement for a voluntary code of practice manufacturers were free to ignore.
The requirements are deliberately modest, and that's the point: they target the three failures behind the largest botnets and the ugliest consumer-device breaches of the past decade. Everything is aligned with the UK's PSTI regime (in force there since April 2024) and the opening provisions of the international standard ETSI EN 303 645, so manufacturers get one compliance story for multiple markets.
The three requirements
No universal default passwords. Every in-scope device must ship with a password unique to that individual unit, or require the user to set their own during setup. The Rules close the obvious loopholes: a "unique" password can't come from an incremental counter (the instrument's own examples are "password1", "password2"), can't be derived from publicly available information, and can't be derived from the serial number or another product identifier unless that's done with proper cryptographic hashing. A catch-all bans anything "otherwise guessable" by good industry practice. The end of "admin/admin" on ten million identical cameras is the single biggest practical change here — default credentials are the raw material of botnet recruitment and of unauthorised access to the cameras, mics and sensors people install in their own bedrooms.
A published way to report security flaws. Manufacturers must operate a vulnerability disclosure channel: a clearly published contact point where researchers and users can report security issues free of charge, with acknowledgement and status updates on resolution. Until now, plenty of researchers who found serious holes in consumer devices simply had nowhere to send the report except a press release. As analysis of the new rules notes, if you can't find a disclosure channel for a brand, that absence is itself information about how the company treats security.
Honest statements about security updates. Manufacturers must publish the minimum period during which the device will receive security updates, including an end date — the guidance prefers a fixed date ("until 30 June 2029") over a vague duration — covering both firmware and companion app, displayed prominently where purchase information appears. Once published, the support period cannot be quietly shortened. This converts the open-ended assumption "of course it'll keep working" into a written commitment you can check before you buy, which is arguably the requirement with the most day-to-day value.
Manufacturers and suppliers must also produce a statement of compliance for each product, retained for five years, and suppliers — including importers and retailers — are prohibited from supplying in-scope products that were required to comply and don't. Enforcement runs through escalating notices from the Department of Home Affairs: compliance, stop, recall, and public naming.
What's covered — and what's quietly excluded
The Act's definition of a "relevant connectable product" is broad: anything that talks IP to the internet, plus "network-connectable" products that can't reach the internet themselves but plug into something that does — a Zigbee sensor talking to a hub is captured. The Rules then narrow this to devices of a kind likely to be acquired by a consumer for personal, domestic or household use. In practice that sweeps in smart appliances, home robotics, connected sensors, smart locks, cameras, speakers and the rest of the household ecosystem — and, notably, devices manufactured on or after 4 March 2026 or supplied new on or after that date, so old-stock manufacturing in 2025 and sold new in July 2026 is still in scope; only genuinely second-hand supply is exempt.
But read the exclusions before you assume your gadgets are protected. Smartphones, tablets, laptops and desktops are out of scope, as are road vehicles and therapeutic goods — regulated (or not) elsewhere. Enterprise-grade equipment is excluded too, even though identical hardware frequently ends up in small-business racks; the government has flagged enterprise standards as under consideration, but they don't exist yet. And, critically, the grandfathering rule means everything manufactured before commencement — including every device already installed on your network — complies with nothing. The camera you bought in 2023 is exactly as insecure today as it was in February.
The privacy layer the security rules don't touch
Compliance with the standard is a floor, not a privacy guarantee. A smart device can satisfy all three requirements and still collect room-scale data: mapping data, photos, video feeds, behavioural patterns, real-time location. A camera-compliant robot vacuum that stores floor plans in a foreign cloud meets the letter of the Rules while learning the geometry of your home. Security standards stop unauthorised access; they say little about authorised collection. Two habits close the gap. First, read what a device collects before you invite it in, and prefer local-control models where they exist — a device that works without a cloud account can't leak what it never uploads. Second, physically block what you can: a webcam cover 3-pack on every camera you don't actively use, and for devices you only need intermittently, a faraday phone pouch or a faraday keyfob guard keeps radios dark when the hardware is idle. None of this is paranoid; it's just declining to leave channels open that the law doesn't force closed.
How to vet a device under the new regime
The rules give buyers three concrete checks that take about ten minutes:
- Look for the statement of compliance and the support end date on the product page or packaging. From March 2026, an in-scope device manufactured after commencement that shows neither is a red flag — and the retailer supplying it is on the hook too.
- Check the manufacturer's site for a security.txt or vulnerability disclosure page. Its existence, and how specific the promised acknowledgement timeframes are, is a fast proxy for security maturity.
- Ask the setup question: does onboarding force a unique password, or does it hand you a shared default and leave the change optional? A forced unique credential at setup is the clearest visible compliance signal an ordinary buyer can check in the store.
For the older gear already on your network — the grandfathered population the Rules will never reach — the checklist is unglamorous but effective: change every default credential today, disable cloud features and microphones you don't use, segment IoT devices onto a separate network or VLAN so a compromised bulb can't see your laptop, and put the household's DNS behind a filtering resolver — a home DNS appliance kit does this without per-device fiddling and gives you a log of exactly which devices phone home, and to whom. That log is often the first place you learn a "dumb" appliance has been contacting an analytics endpoint every hour since install day.
What happens next
The regime is young — five months old as of October 2026 — and two follow-ons are worth watching. A voluntary security labelling scheme is planned from March 2027, developed with IoT Alliance Australia along the lines of the Singapore and German models, designed to reward manufacturers who go beyond the minimum and give shoppers something visible at the point of sale. And the Act itself faces parliamentary committee review timelines set years out; the smart-device rules will be judged on enforcement, and the first public naming of a non-compliant product will do more to change retailer behaviour than any factsheet.
Until then, the honest summary is this: the law has moved the floor for new devices, moved it nowhere for the ones you own, and left the data-collection question largely to the Privacy Act and to you. Check the labels on what you buy next; check the passwords on what you bought last year.
This article is general information, not legal advice.