What the Cyber Resilience Act Means for IoT Device Security
The average Australian home now contains dozens of connected devices, from smart TVs and fridges to doorbell cameras and voice assistants. Many of these products ship with default passwords, outdated software, and minimal security oversight, creating soft targets for cyber criminals. With the rapid expansion of the National Broadband Network and falling prices for smart home gadgets, the attack surface in suburban Sydney apartments and Brisbane family homes has grown faster than the regulations designed to protect them.
The European Union's Cyber Resilience Act, which entered into force in late 2024 and applies from 2027, represents the most comprehensive attempt yet to fix this broken ecosystem. It imposes security obligations on manufacturers, importers, and distributors of virtually any product with digital elements, from routers and baby monitors to industrial sensors. The legislation mandates that connected devices be designed with security built in, that vulnerabilities be reported promptly, and that software updates be provided throughout a product's supported lifetime.
Although the law is geographically European, its impact will be global. The so-called Brussels effect means that multinational manufacturers rarely build different versions of a product for different markets, so compliance with the strictest standard becomes the baseline for everyone. When the EU mandates that a smart lightbulb must receive security patches for at least five years, Australian consumers buying that same bulb at their local Harvey Norman or JB Hi-Fi benefit from that requirement without ever reading a single line of the regulation.
For Australian readers concerned about the intersection of privacy, technology, and consumer rights, the analysis on Twenty of Time explores many of these themes in depth. Understanding the Cyber Resilience Act is essential for anyone who has ever wondered whether their smart speaker is listening, or whether their router will be supported in three years.
Security by Design and by Default
At the heart of the Cyber Resilience Act lies a simple but radical idea: security cannot be an afterthought. The regulation requires manufacturers to embed security features during the design phase rather than bolting them on after a breach. This includes secure authentication mechanisms, encrypted communications where appropriate, and the elimination of hard-coded passwords that have plagued the industry for years.
The Act also introduces a tiered system of conformity assessments. Most products can self-assess their compliance, but those deemed critical, such as industrial control systems, identity management software, and certain network devices, must undergo third-party assessment by notified bodies. This shift forces manufacturers to document their security claims and subjects them to market surveillance authorities who can demand evidence.
Another core requirement is vulnerability handling. Manufacturers must establish processes to identify, document, and remediate security flaws throughout the supported lifetime of a product. They are required to report actively exploited vulnerabilities to the European Union Agency for Cybersecurity within 24 hours of discovery, creating a rapid response mechanism that has been largely absent in the consumer IoT space.
Manufacturer and Importer Obligations
The supply chain provisions of the Cyber Resilience Act extend far beyond the companies that design products. Importers and distributors carry explicit responsibilities to verify that products placed on the market bear the CE marking and are accompanied by proper documentation. A retailer in Melbourne importing a batch of security cameras from Shenzhen cannot simply claim ignorance if those cameras contain known vulnerabilities.
Documentation requirements are substantial. Manufacturers must prepare technical documentation describing the security features of their products, the supported lifetime, and the measures in place to handle vulnerabilities. This documentation must be retained for ten years and made available to market surveillance authorities on request. The goal is to create a paper trail that makes accountability possible long after a product has been sold.
Non-compliance carries serious financial consequences. Penalties can reach up to €15 million or 2.5 percent of global annual turnover, whichever is higher. For a major manufacturer like Tuya or Aqara, which supply products to the Australian market through local distributors, these figures represent a meaningful deterrent. The Act essentially makes insecure products a corporate liability rather than a calculated business risk.
Implications for the Australian Market
Australia does not currently have a single, comprehensive law equivalent to the Cyber Resilience Act. The Australian Cyber Security Centre promotes the Essential Eight maturity model and the IoT Code of Practice, but these are voluntary frameworks. The Privacy Act 1988 includes the Notifiable Data Breaches scheme, which requires organisations to notify affected individuals when serious harm is likely, but it does not regulate the security of the devices themselves.
Australian Consumer Law does provide some protection. Products must be of acceptable quality and fit for purpose, which arguably includes basic cybersecurity. The Australian Competition and Consumer Commission has pursued cases against companies for misleading representations about data handling, but the legal basis for mandating security-by-design remains underdeveloped compared to the EU approach.
For consumers, this regulatory gap means that buying an IoT device in Australia is somewhat akin to buying a car without safety standards. The market is flooded with cheap, unbranded devices that may stop receiving updates within months of purchase. Even reputable brands sometimes abandon product lines, leaving customers with expensive paperweights that pose ongoing security risks. The conversations about consumer data practices in the retail sector offer a parallel perspective on how personal information is treated across different industries.
Practical Steps for Australian Households
While regulators and manufacturers work through the long process of compliance, Australian households are not powerless. The first and most effective step is to change default passwords on every connected device, from the router supplied by your internet provider to the baby monitor in the nursery. The Australian Signals Directorate publishes guidance on securing consumer devices, and the basics remain the same: unique passwords, two-factor authentication where available, and regular firmware updates.
Network segmentation offers another layer of protection. Most modern routers allow users to create a separate network for IoT devices, isolating them from laptops and phones where sensitive data is stored. This way, a compromised smart bulb cannot be used as a stepping stone to access banking credentials or personal email. It is a technical step, but many Australian internet service providers now offer this feature in their default router settings.
When shopping for new devices, Australian consumers should look for products that explicitly state a supported lifetime for security updates. A three-year commitment is reasonable; a one-year commitment should be a red flag. Buying from established retailers who have relationships with manufacturers, rather than random overseas sellers on marketplace platforms, also provides some recourse if a product turns out to be fundamentally insecure.
The Convergence of IoT and Public Surveillance
The security of individual devices is only part of the picture. The same networks that connect our homes also connect public spaces, creating a surveillance infrastructure that extends well beyond the front door. The recent review on AI surveillance in public parks examines how sensors, cameras, and analytics are being deployed in ways that often outpace public awareness and legislative oversight.
This is where the Cyber Resilience Act intersects with broader debates about technology and society. A secure device that collects excessive data is not necessarily a victory for privacy. Conversely, a device with strong security but unclear data handling practices can be just as problematic. The Australian approach to these issues remains fragmented, with different agencies handling different aspects of the problem and no overarching framework that treats device security, data protection, and surveillance oversight as a single challenge.
The following comparison summarises the key differences between the two regimes.
| Security Aspect | EU Cyber Resilience Act | Australian Approach |
|---|---|---|
| Security by design | Mandatory for all connected products | Voluntary via IoT Code of Practice |
| Vulnerability reporting | 24-hour disclosure to ENISA | No mandatory equivalent |
| Software update support | Minimum 5 years or product lifetime | Recommended, not enforced |
| Penalties for non-compliance | Up to €15 million or 2.5% of turnover | ACL penalties and ACCC action |
| Conformity assessment | CE marking required for critical products | No equivalent marking scheme |
The practical takeaway is that Australian consumers cannot wait for local legislation to catch up. Review the connected devices in your home this week, change the default passwords, and check whether the manufacturer has a published end-of-life policy for security updates. If a device cannot answer those basic questions, it might be time to replace it with something more trustworthy.