Ledger IT

Smart cameras, TVs and routers in the office? The new security standard explained

Since 4 March 2026, many consumer smart devices in Australia must meet minimum security rules. What changed, what isn’t covered, and how to buy safely for the office.

Published
Reading time
3 minutes
Written by
The Ledger IT team
A glass office tower lit up at night
On this page
  1. What the standard requires
  2. What it covers — and what it doesn’t
  3. Why it matters for a small office
  4. Getting the devices you already have under control
  5. Common questions
  6. Sources

The short version

  1. 01The Cyber Security (Security Standards for Smart Devices) Rules 2025 took effect on 4 March 2026.
  2. 02Covered devices can’t ship with universal or predictable default passwords, must offer a way to report vulnerabilities, and must state how long they’ll get security updates.
  3. 03It targets consumer-grade devices and excludes computers, tablets and phones — but the same three checks are a smart buying rule for any office device.

Small offices are full of devices nobody thinks of as computers: the security camera by the door, the smart TV in the meeting room, the Wi-Fi router in the cupboard. They’re also some of the easiest things on a network to break into. Since 4 March 2026, Australia has a minimum security standard for many of them.

What the standard requires#

The Cyber Security (Security Standards for Smart Devices) Rules 2025, made under the Cyber Security Act 2024, set three requirements for covered devices:

RequirementWhat it means
No universal default passwordsDevices can’t ship with universal, sequential or otherwise predictable passwords.
A way to report vulnerabilitiesManufacturers must provide a free, accessible way for people to report security problems.
A stated support periodManufacturers must say how long the device will receive security updates, with a clear end date.

What it covers — and what it doesn’t#

The standard applies to consumer-grade smart devices intended for personal, domestic or household use and manufactured from 4 March 2026 — products such as smart TVs, IP cameras, routers and smart home gear.

Desktop computers, laptops, tablets and smartphones are excluded, along with therapeutic goods and road vehicles. Devices made before 4 March 2026 don’t have to comply.

Why it matters for a small office#

Plenty of small businesses buy consumer-grade gear because it’s affordable and easy to find. The new rules raise the floor for those products — but only for newer stock, and only on the three basics.

Consumer devices also tend to get fewer years of updates than business equipment, and an unpatched camera or router can become the way into everything else on the network.

Getting the devices you already have under control#

  1. 01Change every default password on cameras, printers, routers and smart TVs.
  2. 02Update the firmware, and switch on automatic updates where they’re offered.
  3. 03Keep them apart from staff computers on a separate guest or device network, so a compromised camera can’t reach your files.
  4. 04Check support end dates and plan to replace devices that no longer get updates.
  5. 05Remove what you don’t use. Every connected device is one more thing to maintain.

Network separation and device inventories are part of how we set up office networks and support for clients — the unglamorous work that stops a cheap camera becoming an expensive problem.

Common questions

When did Australia’s smart device security standard start?

The Cyber Security (Security Standards for Smart Devices) Rules 2025 took effect on 4 March 2026, after a 12-month transition period.

Does the smart device standard apply to laptops and phones?

No. Desktop computers, laptops, tablets and smartphones are excluded. The standard targets consumer smart devices such as smart TVs, IP cameras and routers.

Do I need to replace smart devices bought before March 2026?

Not because of the standard — devices made before 4 March 2026 don’t have to comply. You should still change default passwords, keep firmware updated and replace devices that no longer receive security updates.

Sources

  1. 01Department of Home Affairs — Security standards for smart devices
  2. 02Digital Policy Alert — Cyber Security (Security Standards for Smart Devices) Rules 2025
  3. 03Nemko — Mandatory cybersecurity: Australia’s new regulations from 4 March 2026

Written by the Ledger IT team

The same Melbourne engineers who answer our support line and look after client environments day to day. About us

Share

Keep reading

All insights

Free discovery and quote

No cost, no obligation; we’ll tell you what you need before we tell you what it costs.