Smart devices in the workplace: what Australia's new Cyber Security Act means for IT and facilities teams
09 July 2026
TechnologySHARE
Australia's mandatory security standards for smart devices came into force on 4 March 2026 under the Cyber Security Act 2024. The direct obligations fall on manufacturers and suppliers — but for IT and facilities teams, the rules change what compliant products look like and raise the bar on how connected devices should be managed. This article covers what the new standards require, what to check when procuring devices, and how to get existing workplace devices under control.
What the Cyber Security Act 2024 Requires — And Where Your Organisation Fits In
The Cyber Security (Security Standards for Smart Devices) Rules 2025 came into force on 4 March 2026 under the Cyber Security Act 2024. The rules introduce mandatory baseline security requirements for most consumer-grade smart devices supplied in Australia.
The direct obligations sit with manufacturers, importers and suppliers — not with businesses that purchase and use these devices. However, the rules change what compliant products look like, which has practical implications for how organisations procure and manage connected devices.
The three baseline requirements
Under the new rules, manufacturers and suppliers of in-scope devices must meet three core requirements:
1. No universal default passwords
Each device must ship with a unique password, or require the user to set their own during initial setup. Generic defaults such as "admin" or "1234" are no longer permitted. This requirement addresses one of the most common attack vectors for IoT devices.
2. A published vulnerability disclosure mechanism
Manufacturers must make available a clear, accessible channel through which security researchers and users can report potential vulnerabilities. This channel must be free to use and available in English, without requiring personal information to submit a report.
3. A defined security update support period
Manufacturers must publicly disclose the minimum period for which a device will receive security updates. This period cannot be shortened after the device is sold. For organisations procuring devices, this means the support timeline is now a piece of information that must be provided — making it easier to assess a device's long-term security viability before purchase.
What counts as a smart device — and what doesn't
The rules apply to relevant connectable products — devices that can directly or indirectly connect to the internet or other devices over a network, intended for personal, domestic or household use.
Device Category | In-Scope (Must Comply) | Excluded (Out of Scope) |
|---|---|---|
Workplace & Facilities | IP cameras, Security systems, Wi-Fi routers, Smart TVs, Access control devices, Environmental sensors | Desktop computers, Laptops, Tablets, Smartphones |
Specialised Equipment | Smart speakers, Voice assistants | Medical devices / Therapeutic goods, Road vehicles & components |
Smart Device Procurement: Checking the Statement of Compliance
For IT and procurement teams, the most immediate practical change is at the point of purchase. From 4 March 2026, in-scope devices must be accompanied by a Statement of Compliance — a formal declaration by the manufacturer or supplier confirming that the device meets the three mandatory security requirements. Building this check into your procurement process is the most straightforward way to ensure devices your organisation acquires meet the new baseline.
In practice, this means:
When purchasing from a manufacturer or authorised distributor, request the Statement of Compliance as part of the procurement process
For bulk orders or platform purchases, confirm the statement is available before finalising
Retain a copy as part of your asset records for each device
The declared support period is worth noting at the time of purchase — it gives you a baseline for planning firmware updates and eventual device replacement, and feeds directly into the inventory management steps covered in the next section.
The parallel import risk
Devices purchased through overseas e-commerce platforms or grey-market channels may not carry a valid Statement of Compliance under Australian rules, even if they appear identical to locally supplied versions.
For organisations, this is a procurement policy question as much as a technical one. Purchasing through authorised Australian distributors is the most reliable way to ensure devices entering your network meet the mandatory baseline. If direct overseas purchasing is part of your current procurement model, it is worth reviewing in light of the new rules.
Managing smart devices already in your workplace
Devices manufactured before 4 March 2026 are not required to comply with the new standards — but the security risks they carry do not disappear because of an exemption date. For most organisations, the larger immediate task is getting a clear picture of what is already connected to the network, and putting basic management practices in place.
1. Inventory first — know what's connected
Before anything else, establish a complete list of network-connected devices in your workplace. This includes devices that may have been installed and forgotten — older IP cameras, routers running on default settings, or smart displays added for meeting rooms without being formally registered as IT assets.
For each device, record:
Device type, make and model
Location and responsible team or contact
Date of installation or purchase
Whether it is still within the manufacturer's support period
This inventory is the foundation for everything that follows. Without it, there is no reliable way to assess exposure or prioritise action.
2. Check and change default credentials
Default usernames and passwords remain one of the most common entry points for attackers targeting connected devices. Identify any devices still running factory-default credentials and update them to unique, device-specific passwords.
Where possible:
Assign responsibility for each device's credentials to a named team or individual
Store credentials securely — a password manager or IT asset management system rather than a shared spreadsheet
Document when credentials were last reviewed or changed
3. Check firmware status and manufacturer support periods
For each device in your inventory, confirm:
Whether the current firmware is up to date
When the manufacturer's security support period ends
Devices that are out of support — meaning the manufacturer no longer issues security updates — present an ongoing risk that will not be resolved by software updates alone. Where end-of-life devices are identified, assess whether they can be replaced in the next procurement cycle or whether interim controls are needed in the meantime.
For older devices, you may need to check the manufacturer's website directly.
4. Establish a reporting and response flow
Ensure your team knows what to do if a device behaves unexpectedly or a security concern is identified. At a minimum, this means:
A clear internal escalation path to your IT team or managed service provider
Awareness that serious cyber incidents can be reported to the Australian Cyber Security Centre via ReportCyber at cyber.gov.au/report
Having this process documented in advance is more useful than trying to work it out when something goes wrong.
5. Set a regular review cycle
Device inventories go out of date quickly. New devices are added, old ones are retired, and support periods expire. A review cycle — at minimum annually — keeps your records current and ensures that end-of-life devices are identified before they become a liability.
Build device additions and retirements into your existing asset management workflow so that the inventory stays accurate between formal reviews.
The Cyber Security Act's smart device standards are primarily a manufacturer obligation — but they create a practical opportunity for organisations to lift the baseline of how connected devices are procured and managed. Confirming a Statement of Compliance at the point of purchase and maintaining an up-to-date device inventory are straightforward steps that meaningfully reduce exposure.
For complex network security assessments or advice on specific devices and configurations, consult a qualified IT security professional.
Official sources:
Department of Home Affairs — Security standards for smart devices
Cyber Security (Security Standards for Smart Devices) Rules 2025
Last updated: July 2026
SHARE
