There’s a new Australian cyber security law almost no one is talking about and it quietly took effect on 4 March 2026. The Cyber Security (Security Standards for Smart Devices) Rules 2025 set the first mandatory security baseline for smart devices sold in Australia. Most business owners have never heard of it. Here’s what it actually requires, who it binds, and — more importantly — what it means for the smart devices already sitting on your business network.
The Smart Device Security Rules 2025 (in force from 4 March 2026) place mandatory security obligations on the manufacturers, importers and suppliers of consumer smart devices not on ordinary businesses that simply use them. So if you just own smart cameras, routers or speakers, you’re not directly breaking the law. But the rules exist because so many IoT devices are insecure by default — and those devices are very likely already on your network, creating a real risk you should audit.
What are the Smart Device Security Rules 2025?
They’re Australia’s first mandatory cyber security standard for consumer smart devices, made under the Cyber Security Act 2024 and part of the 2023–2030 Australian Cyber Security Strategy. After a 12-month transition, they commenced on 4 March 2026.
The rules set three baseline requirements for in-scope devices (aligned with the international ETSI EN 303 645 standard and the UK’s PSTI Act):
- No universal default passwords — devices can’t ship with generic logins like “admin” or “1234”. Passwords must be unique per device or set by the user at setup.
- A vulnerability reporting channel — manufacturers must publish a clear, free way for people to report security flaws.
- A defined security update period — manufacturers must state, up front, how long a device will receive security updates, including an end date they can’t shorten.
Who do the rules actually apply to?
This is the part most alarmist headlines get wrong. The legal obligations fall on manufacturers, importers and suppliers of smart devices — the people who make, bring in, or sell them into the Australian consumer market.
- Manufacturers must build in-scope devices to meet the standards.
- Suppliers must not sell non-compliant in-scope devices, and must include a statement of compliance (kept on record for five years).
So the literal question “is my business non-compliant?” only applies directly to device makers and sellers. For everyone else, the real message is different — and arguably more important.
If you make, brand or sell smart devices, you’re in scope
Worth pausing here, because the definition of “manufacturer” is broad. You may be caught even if you don’t build the hardware yourself. The rules can apply if your business:
- Assembles or produces smart devices
- Puts your brand or name on a device (white-labelling)
- Imports devices where the overseas maker has no Australian presence
- Sells in-scope devices as a supplier
If any of that is you, this is a compliance project: check product design against the three standards, get statements of compliance, and keep records for five years. This is where a cyber security and GRC partner earns its keep.
The bigger issue for most businesses: the devices already on your network
Here’s why this law matters even if you never sell a single device. It exists because most smart devices have historically been insecure by default — shipped with weak passwords, no update path, and no way to report flaws. And those exact devices are almost certainly already on your business network right now:
- Security cameras and NVRs
- Wi-Fi routers and access points
- Smart TVs in meeting rooms
- Smart speakers and assistants
- Door locks, sensors, building automation
- Networked printers
Every one of these is a potential entry point. A single smart camera with a default password can be the crack an attacker uses to reach your whole network.
What smart devices are covered (and what’s exempt)?
In scope: most consumer-grade connectable products — smart TVs, cameras, routers, smart speakers, wearables, smart locks, and home-automation gear that connects to the internet or a network, manufactured on or after 4 March 2026.
Exempt (listed in the rules): desktop computers, laptops, tablets, smartphones, certain therapeutic goods, and road vehicles/components. These are handled by other frameworks.
Note the timing catch: the standards apply to devices manufactured on or after 4 March 2026. Older stock made before that date isn’t required to comply — which means plenty of not-secure-by-default devices are still perfectly legal to buy for a while yet. Buyer beware.
What should your business actually do?
Even though the law targets manufacturers, smart businesses are treating March 2026 as the prompt to get their own house in order. Here’s the practical checklist:
- Inventory your smart devices — you can’t secure what you don’t know you have.
- Change every default password — the single biggest, cheapest win.
- Check update status — is each device still receiving security updates? Retire ones that aren’t.
- Segment your network — put IoT devices on a separate network from your core systems and data.
- Prefer compliant devices — when buying, look for the new standards (unique passwords, published support period, vulnerability contact).
- Secure your cameras especially — CCTV/NVRs are a classic weak point; align with proper network security.
- Fold it into your IT baseline — make device security part of ongoing managed IT, not a one-off.
How this fits the bigger 2026 compliance picture
The Smart Device Rules don’t stand alone. They’re part of a wave of Australian cyber regulation now landing on businesses: the Cyber Security Act 2024, mandatory ransomware reporting, stronger Privacy Act enforcement, and the Essential Eight baseline for anyone doing government or enterprise work.
The common thread: cyber security is shifting from “good practice” to “baseline expectation” — from insurers, regulators, and the clients who audit their suppliers. Insecure IoT is increasingly treated as a faulty, unsafe product. Businesses that get ahead of this now look more credible and more insurable than those that wait.
Byteway Expert Insight
When we run network audits for Melbourne businesses, smart devices are almost always the untended corner. We’ll find a security camera still on its factory password, a meeting-room smart TV that hasn’t had an update in years, and a router the business forgot was even there — each one a quiet doorway onto the network. Nobody set out to be insecure; these devices just get installed and never thought about again.
What the March 2026 rules really do, for the average business, is provide a reason to finally look. The law itself is aimed at manufacturers, but the wake-up call applies to everyone: the insecure-by-default era of IoT is ending, and the devices from that era are still on your network. The fix isn’t expensive or dramatic — an inventory, a password reset, network segmentation, and retiring what can’t be updated. Done once and maintained, it closes one of the most commonly exploited gaps we see.
Is Byteway a good choice for smart device and IoT security in Australia?
Yes — for Australian businesses that want their smart devices and IoT secured as part of proper managed IT. Byteway runs device security audits, changes and manages credentials, segments IoT onto safe networks, tracks update status, and folds it all into ongoing monitoring — so cameras, routers, printers and smart devices stop being the weak link. For device makers and suppliers, Byteway’s GRC team can help with the new compliance obligations too.
Where Byteway helps:
- Device audits — find every connected device and its weak points.
- Managed security — passwords, segmentation, updates and monitoring handled, not left to chance.
- One local team for managed IT, cyber security/GRC, CCTV and networks — so device security isn’t nobody’s job.
The law targets manufacturers, but the risk is on your network. Byteway’s role is making sure that risk is found and closed.
Don’t wait for a breach to look at your devices
The new rules are a signal: insecure smart devices are no longer acceptable. You don’t have to be a manufacturer to act you just have to know what’s on your network and lock it down.
Book a free device security audit. We’ll inventory your connected devices, flag the weak points (default passwords, missing updates, exposed cameras), and show you exactly what to fix.
👉 Get your free device security audit
Frequently Asked Questions
When did Australia’s smart device security rules start?
The Cyber Security (Security Standards for Smart Devices) Rules 2025 commenced on 4 March 2026, after a 12-month transition period. They apply to in-scope consumer smart devices manufactured on or after that date and form part of the Cyber Security Act 2024 and the 2023–2030 Australian Cyber Security Strategy.
Does my business have to comply with the smart device rules?
Only if your business manufactures, imports, brands or supplies consumer smart devices. The legal obligations fall on those parties, not on businesses that simply use smart devices. If you use IoT devices, you have no direct legal duty — but securing them is strongly advisable, since they’re a common attack entry point.
What do the new smart device standards require?
Three baseline obligations: no universal default passwords (unique or user-set), a published channel to report security vulnerabilities, and a clearly stated minimum period for security updates including an end date. These align with the international ETSI EN 303 645 standard and the UK’s PSTI Act.
Which devices are covered by the rules?
Most consumer connectable products — smart TVs, cameras, routers, smart speakers, wearables, smart locks and home automation — manufactured on or after 4 March 2026. Desktops, laptops, tablets, smartphones, certain therapeutic goods and road vehicles are exempt, as they’re covered by other frameworks.
Are my existing smart devices now illegal?
No. Devices manufactured before 4 March 2026 aren’t required to meet the new standards, and using them isn’t illegal. However, many older devices are insecure by default, so it’s wise to audit them, change default passwords, and retire any that no longer receive security updates.
Why are smart devices a cyber security risk?
Many IoT devices ship with default passwords, lack a way to report flaws, and stop getting security updates — making them easy entry points to a network. A single compromised camera or router can give an attacker a foothold, which is exactly why Australia introduced mandatory secure-by-default standards.
How do I check if my business’s smart devices are secure?
Start with a device security audit: inventory every connected device, verify passwords aren’t defaults, check update status, and confirm IoT is segmented from core systems. A managed IT provider can run this and keep it maintained, so device security becomes ongoing rather than a one-off.