.png)
.png)

Cyber Security Act of 2024 (Australia)
Framework Name
Cyber Security Act 2024 (Australia)
Type
Mandatory
Region / Jurisdiction
Australia (the smart device provisions reach overseas manufacturers and suppliers whose products are sold into the Australian market)
Enforcing Body / Certifying Party
Department of Home Affairs, through its Technology Assessment and Regulation Office for smart device standards and the National Cyber Security Coordinator for incident-related matters. A separate Cyber Incident Review Board reviews major incidents after the fact
Penalty / Consequence of Non-Compliance
Civil penalties calculated in Australian "penalty units" (currently $330 AUD each, multiplied five times for corporations), compliance, stop, and recall notices for non-compliant smart devices, and civil penalties specifically for failing to report a ransomware payment within the required window
What It Is & Why It Matters
The Cyber Security Act 2024 is Australia's first standalone national cybersecurity law, built around four distinct pillars. It sets mandatory minimum security standards for smart, internet-connectable devices sold in Australia, requiring a formal statement of compliance from manufacturers. It requires certain businesses, those with AUD 3 million or more in annual turnover, and critical infrastructure entities regardless of size, to report ransomware payments within 72 hours. It gives limited-use legal protection to information voluntarily shared with the National Cyber Security Coordinator during a significant incident, so a company reporting an incident isn't handing regulators evidence to use against it. And it establishes a no-fault Cyber Incident Review Board, modeled on aviation accident investigation boards, that reviews major incidents afterward to improve national resilience without publicly assigning blame.
It matters because Australia previously had no single, dedicated cybersecurity law, obligations were scattered across sector-specific rules like the Security of Critical Infrastructure Act. The mandatory ransomware reporting requirement closes a real gap: Australia had no general legal duty to disclose ransom payments before this. It's also part of a broader global pattern, arriving around the same time as the EU's own Cyber Resilience Act, both governments moving to regulate the security of everyday connected devices directly rather than leaving it to the market.
Who Needs It
- You manufacture or supply smart, internet-connectable devices sold into the Australian market, even as an overseas company
- Your business has AUD 3 million or more in annual turnover, or you operate critical infrastructure, and need to understand ransomware payment reporting obligations
- You want to understand what legal protection applies if you voluntarily report a cyber incident to the government
- You're preparing for the possibility of a no-fault review by the Cyber Incident Review Board following a significant incident