On this page
The short version
- 01The Cyber Security (Security Standards for Smart Devices) Rules 2025 took effect on 4 March 2026.
- 02Covered devices can’t ship with universal or predictable default passwords, must offer a way to report vulnerabilities, and must state how long they’ll get security updates.
- 03It targets consumer-grade devices and excludes computers, tablets and phones — but the same three checks are a smart buying rule for any office device.
Small offices are full of devices nobody thinks of as computers: the security camera by the door, the smart TV in the meeting room, the Wi-Fi router in the cupboard. They’re also some of the easiest things on a network to break into. Since 4 March 2026, Australia has a minimum security standard for many of them.
What the standard requires#
The Cyber Security (Security Standards for Smart Devices) Rules 2025, made under the Cyber Security Act 2024, set three requirements for covered devices:
| Requirement | What it means |
|---|---|
| No universal default passwords | Devices can’t ship with universal, sequential or otherwise predictable passwords. |
| A way to report vulnerabilities | Manufacturers must provide a free, accessible way for people to report security problems. |
| A stated support period | Manufacturers must say how long the device will receive security updates, with a clear end date. |
What it covers — and what it doesn’t#
The standard applies to consumer-grade smart devices intended for personal, domestic or household use and manufactured from 4 March 2026 — products such as smart TVs, IP cameras, routers and smart home gear.
Desktop computers, laptops, tablets and smartphones are excluded, along with therapeutic goods and road vehicles. Devices made before 4 March 2026 don’t have to comply.
Why it matters for a small office#
Plenty of small businesses buy consumer-grade gear because it’s affordable and easy to find. The new rules raise the floor for those products — but only for newer stock, and only on the three basics.
Consumer devices also tend to get fewer years of updates than business equipment, and an unpatched camera or router can become the way into everything else on the network.
Getting the devices you already have under control#
- 01Change every default password on cameras, printers, routers and smart TVs.
- 02Update the firmware, and switch on automatic updates where they’re offered.
- 03Keep them apart from staff computers on a separate guest or device network, so a compromised camera can’t reach your files.
- 04Check support end dates and plan to replace devices that no longer get updates.
- 05Remove what you don’t use. Every connected device is one more thing to maintain.
Network separation and device inventories are part of how we set up office networks and support for clients — the unglamorous work that stops a cheap camera becoming an expensive problem.
Common questions
When did Australia’s smart device security standard start?
The Cyber Security (Security Standards for Smart Devices) Rules 2025 took effect on 4 March 2026, after a 12-month transition period.
Does the smart device standard apply to laptops and phones?
No. Desktop computers, laptops, tablets and smartphones are excluded. The standard targets consumer smart devices such as smart TVs, IP cameras and routers.
Do I need to replace smart devices bought before March 2026?
Not because of the standard — devices made before 4 March 2026 don’t have to comply. You should still change default passwords, keep firmware updated and replace devices that no longer receive security updates.






