Published Sep 10, 2026 by Xiph
From March 2026, smart devices sold in Australia must meet mandatory minimum security standards under the Cyber Security Act 2024 — starting with a ban on the universal default passwords behind countless botnet takeovers. Here’s what the standard requires, what it doesn’t cover, and how to vet the connected gear already on your network.
Take a moment to count the things in your home or office that are quietly connected to the internet. Not the laptops and phones — the other things. The doorbell. The security cameras. The TV in the boardroom. The printer, the smart speaker, the robot vacuum mapping your floor plan.
Until this year, not one of them had to meet any cyber security standard to be sold in Australia. A manufacturer could ship a camera with the password admin printed on the side, no way to report a security flaw, and no commitment to ever fix one — and nothing in Australian law stopped them. There was a voluntary code of practice, published in 2020, and it did what voluntary codes usually do: it sat politely on a website while the market ignored it.
On 4 March 2026, that changed. The Cyber Security (Security Standards for Smart Devices) Rules 2025 — made under the Cyber Security Act 2024, Australia’s first standalone cyber security law — came into force after a twelve-month transition period. For the first time, most consumer-grade smart devices supplied in Australia must meet legally enforceable minimum security standards.
It is a genuinely local, genuinely new development. And judging by how little attention it has received outside legal circles, most of the people it protects haven’t registered that it exists.
The passwords that built a weapon
To understand why regulators started here, go back to 2016. A piece of malware called Mirai began scanning the internet for connected devices — cameras, video recorders, home routers — and trying to log in with a short list of factory default credentials: combinations like admin/admin and root/12345. It didn’t exploit any clever flaw. It simply knocked on millions of doors and found a staggering number unlocked, because the same default password had been stamped into every unit on the production line and almost nobody had changed it.
The result was a botnet of hundreds of thousands of hijacked devices, aimed like a firehose at targets including the DNS provider Dyn — knocking major platforms offline across large parts of the internet. The owners never knew. Their cameras kept recording the driveway while moonlighting in one of the largest attacks the internet had seen.
Nearly a decade on, the model hasn’t retired — it has professionalised. This year, researchers exposed the Masjesu botnet, a DDoS-for-hire operation built the same way: hijacking everyday routers and IP cameras through unchanged default passwords, outdated firmware and the absence of any channel to report the flaws being exploited — then renting the hijacked fleet out to attack businesses and critical infrastructure.
That is the specific, well-documented failure mode Australia’s new rules are aimed at. Not sophisticated espionage — the industrial-scale harvesting of devices that were never given even a basic lock.
What the law actually requires
The rules apply to “relevant connectable products” — consumer-grade devices that can connect to the internet directly or indirectly — manufactured from 4 March 2026 and acquired by consumers in Australia. They impose three core obligations, deliberately aligned with the UK’s Product Security and Telecommunications Infrastructure regime (in force since April 2024) and the first three provisions of the international standard ETSI EN 303 645:
-
No universal default passwords. Every device must ship with a password unique to that unit, or require the user to set their own during setup. Passwords cannot be predictable, sequential or derivable from public information — no more admin on ten million cameras.
-
A published way to report security flaws. Manufacturers must provide a vulnerability disclosure channel: a clearly published contact point where researchers and users can report security issues, free of charge, with acknowledgement and status updates. Until now, plenty of researchers who found gaping holes in consumer devices had nowhere to send the report.
-
Transparency about security updates. Manufacturers must state the minimum period during which the device will receive security updates — including an end date — and publish it prominently. Once published, the support period cannot be quietly shortened.
Each device must also be accompanied by a statement of compliance, retained for five years, and suppliers — including importers and retailers — are prohibited from supplying products that were required to comply and don’t.
Enforcement sits with the Department of Home Affairs, whose Secretary can issue escalating notices: compliance notices, stop notices halting supply, and recall notices. An entity that ignores a recall notice can be publicly named, with the product and its risks published on the department’s website.

What it doesn’t cover
This is where the honest assessment matters, because the new regime is a floor — a deliberately low one — and it would be a mistake to read “secure by law” as “secure.”
Significant categories are excluded. Smartphones, laptops, tablets and desktop computers are out of scope, as are road vehicles and therapeutic goods — all regulated (or not) elsewhere. So is enterprise-grade equipment: the rules cover consumer devices, even though identical hardware frequently ends up racked in small business networks. The government has flagged enterprise standards are under consideration, but they don’t exist yet.
Everything made before 4 March 2026 is grandfathered. Devices manufactured before commencement don’t have to comply — including stock still moving through retail channels and, more importantly for you, every device already installed on your network. The camera you bought in 2023 is exactly as insecure today as it was in February.
Three requirements is not a security program. The rules say nothing about encryption of data in transit or at rest, secure cloud back-ends, the data the device collects and where it sends it, or secure development practices. The UK’s equivalent regime shares the same gap, and the EU’s far more demanding Cyber Resilience Act — with obligations phasing in from 2026 and full application in 2027 — shows how much further “secure by design” can go.
The support period only has to be disclosed, not long. A manufacturer can lawfully sell you a device with a twelve-month update commitment, as long as it says so. The obligation is transparency, not longevity — which makes the published support period something you now need to actually read.
Enforcement is light-touch by design. There are no automatic civil penalties for shipping a non-compliant device; the regime works through escalating notices, and the regulator has described its approach as “uplift-focused.” Compliance is self-declared, and with millions of product lines in scope, enforcement will realistically be complaint-driven. The law raises the floor; it does not inspect every device crossing the border.
Why this lands on your business
If you run a business, the phrase “consumer smart devices” should not lull you. Walk any Australian office, clinic, warehouse or shopfront and you’ll find consumer gear everywhere: the smart TV in reception, the doorbell on the side entrance, cameras from a big-box retailer, a speaker in the lunchroom. Each one is a computer on your network — often unpatched, unmonitored, and invisible to your IT processes.
That matters because attackers increasingly enter through exactly these devices. On the flat networks most small businesses run, a foothold on the doorbell is a short hop from the server holding your customer records. At that point it stops being an IT curiosity: under the Notifiable Data Breaches scheme, the resulting leak is a reportable breach with your name on it, regardless of which gadget opened the door. And as we covered in our piece on living-off-the-land attacks, compromised edge devices are precisely how patient intruders make their traffic look local and ordinary.
How to vet the connected gear already on your network
The law will slowly improve what’s on the shelf. What’s already on your network is your problem, and the fix is unglamorous work:
-
Inventory every connected device. You cannot secure what you don’t know you own. Scan your network and list everything — including the things nobody thinks of as computers.
-
Kill every default credential. Change default passwords on every device, today. This single step removes you from the population that botnets harvest.
-
Check the support status. Find each manufacturer’s published support period. If updates have ended — or were never committed to — plan the device’s replacement. An unsupported internet-facing device is a permanent open window.
-
Patch the firmware, then keep patching. Enable automatic updates where they exist. IoT devices deserve the same patching discipline as servers.
-
Segment your network. Put cameras, TVs and smart devices on a separate network or VLAN from the systems that hold your data. If a device is compromised, segmentation turns a breach into a nuisance.
-
Disable what you don’t use. Remote access features, UPnP, cloud connectivity you never asked for — every unused service is attack surface.
-
Buy deliberately from now on. Look for the statement of compliance, a unique-password design, a named vulnerability disclosure channel and a support period that outlasts your intended use of the device. The rules have made this information available; use it.
A floor, not a ceiling
Australia has joined a clear international direction of travel: insecure connected products are being reclassified from a buyer-beware inconvenience into a product safety failure, the way electrical goods once were — and the government has signalled that further requirements will follow.
But a floor is all this is. The rules make the worst products harder to sell; they do not make your network secure, and they do nothing for the fleet you installed before March. The gap between “legal to sell” and “safe to run” is still yours to close.
Xiph Cyber helps Australian businesses find and fix the weak points in their networks — from vulnerability assessments and network security penetration testing that uncover the forgotten devices on your network, to cyber security risk audits and vCISO support that build device security into policy rather than luck. Get in touch and you’ll speak to a real person within 24 hours.
Further reading
-
Department of Home Affairs, Security standards for smart devices — https://www.homeaffairs.gov.au/about-us/our-portfolios/cyber-security/security-standards-for-smart-devices
-
Cyber Security (Security Standards for Smart Devices) Rules 2025, Federal Register of Legislation — https://www.legislation.gov.au/F2025L00276/asmade/text
-
Department of Home Affairs, Factsheet: Security standards for smart devices — https://www.homeaffairs.gov.au/cyber-security-subsite/files/factsheet-security-standards-for-smart-devices-and-consumer-grade-rules.pdf
-
ETSI EN 303 645, Cyber Security for Consumer Internet of Things — https://www.etsi.org/technologies/consumer-iot-security
-
ASD’s ACSC, Internet of Things devices guidance — https://www.cyber.gov.au/protect-yourself/securing-your-devices/how-secure-your-devices/internet-things-devices
Posted in: Security