
The Australian Government adopted Cyber Security (Security Standards for Smart Devices) Rules 2025, which were approved on March 4, 2025. The document became fully effective on March 4, 2026. It applies to so called relevant connectable products — products that can connect to the internet directly or indirectly.
The security standards cover relevant connectable products intended for personal, domestic, or household use that were manufactured on or after March 4, 2026. The following types of products are outside the scope of the Rules:
The Rules contain the following three baseline requirements that relates to cyber security and personal data protection:
Please note, that manufacturers should prepare and maintain a statement of compliance showing that the product meets the Rules. The retention period for the statement of compliance is 5 years.
The full text of the Rules is availble via the link.

The information has been prepared by the GMA Consult Group team.
If you want to get regular updates and insights from the industry, subscribe to our newsletter.
GMA Consult Group provides a full cycle of international type approval and global market access services for IT, Telecom, and industrial electrical products in all countries throughout the world. With proven expertise in worldwide regulations, compliance, certification, and conformity assessment, GMA Consult Group can help your company speed up access to any market with almost zero efforts from your side.
Need your own guide to the world of certification and approvals? Don't hesitate to contact us via info@gma.trade.

Join our mailing list to stay
up-to-date with the latest global markets insights and regulatory news

Join our mailing list to stay
up-to-date with the latest global markets insights and regulatory news