← Return to website
Smart Lock Buyer's Guide← Back to Guide Index
Chapter 11 — What the Certifications Actually Mean

Australian Smart Lock
Standards Explained

AS4145.2 mechanical lock grading (SL, D, C, K), AS1905.1 fire door certification, AS1428.1 DDA compliance, asbestos regulations for Queensland fire doors, the 2026 smart device cyber security law, IP ratings, and the RCM mark — explained plainly by qualified locksmiths.

AS4145.2 Grades AS1905.1 Fire Door AS1428.1 DDA Asbestos Regs Cyber Security Rules IP Ratings • RCM

Compliance markings on smart lock specifications are frequently cited in marketing material but rarely explained. This chapter covers the main Australian standards you'll encounter: AS4145.2 (the four-part mechanical grading system), AS1905.1 (fire door hardware certification), AS1428.1 (DDA accessibility), asbestos regulations for Queensland fire doors, IP ingress ratings, the RCM mark, and — since 4 March 2026 — the mandatory cyber security standard that now applies to connected smart locks. Understanding what they actually mean, and what they don't cover, helps you evaluate products honestly and avoid misplaced confidence in a rating that doesn't address your actual concern.

AS4145.2:2008 — Mechanical Lock Grading

AS4145.2:2008 is the Australian Standard for mechanical locksets and latchsets. It defines performance requirements and testing procedures across four independent dimensions — physical security, durability, corrosion resistance, and key security. Each dimension is graded separately, so a lock can be rated on all four simultaneously. When you see a rating string like SL8 D8 on a product spec sheet, that's the AS4145.2 shorthand for the lock's grade in each category.

This standard applies to the mechanical bolt and lock body — not the electronic components. A smart lock can carry a strong AS4145.2 rating on its deadbolt mechanism while having no electronic certification at all. The two are independent, and since March 2026 the electronic side has its own mandatory standard — see the cyber security section below.

SL
1 – 8
Physical Security
Resistance to forced entry, sawing, drilling, and picking. SL8 is the highest grade.
D
1 – 8
Durability
Cycle life under mechanical testing. D8 = 500,000 cycles. Highest grade.
C
C7 · C10
Corrosion
Neutral salt spray hours. C7 High = 240hr; C10 Extreme = 1,000hr.
K
1 – 5
Key Security
Key combination count and duplication protection. K5 = restricted, legally protected keying system.
SL — Physical Security
Resistance to physical attack
Grades SL1 through SL8 • SL8 is highest

The SL grade measures how resistant the lock mechanism is to forced entry, including sawing of the deadbolt, cylinder drilling, picking, and brute-force attack. Tests simulate real-world break-in methods with increasing force and sophistication at higher grades. The standard specifically identifies deadbolt resistance to sawing as a required test for products designated SL4 or SL8.

GradeTypical applicationWhat it means
SL1 – SL2Interior doors, low-security storageMeets basic structural requirements. Minimal attack resistance beyond normal use.
SL3 – SL4Residential entry doorsStandard residential deadbolt performance. Resistance to common forced entry methods.
SL5 – SL6Commercial, light industrialHigher resistance to attack. Anti-pick and anti-drill features typically required.
SL7 – SL8Commercial, high-security residentialMaximum grade. Hardened bolt resistant to sawing, anti-drill cylinder, high pick resistance. The dormakaba MS2602 primary mortice lock is rated SL8 D8 — see the full dormakaba range.
D — Durability
Mechanical cycle life
Grades D1 through D8 • D8 = 500,000 cycles confirmed

The D grade measures how many complete lock/unlock cycles the mechanism withstands before failure. Testing involves mechanically operating the lock on a test door under load until the required cycle count is reached, then re-verifying full operational compliance. D8 is independently confirmed at 500,000 cycles by manufacturers including Iver (door levers) and Lockwood, whose Paradigm series publishes the grade.

D8 in real-world terms — a lifetime mechanical spec
A residential front door used 10 times per day would take approximately 137 years to reach 500,000 cycles. A busy commercial office door used 50 times per day would reach it in about 27 years. D8 is not a spec that will matter in most real-world applications — but it tells you the manufacturer has built the mechanism to a serious quality standard rather than simply passing minimum requirements. For the commercial cycle ratings that mechanical digital locks publish, see Chapter 16 — Commercial & Heavy Duty.
C — Corrosion Resistance
Salt spray and environmental resistance
Graded by neutral salt spray hours • C7 High and C10 Extreme are the categories you'll see published

Corrosion testing is conducted using a neutral salt spray (NSS test per AS2332.3.1). The lock is exposed to a controlled salt-air environment for a specified duration, then assessed for surface degradation, functional impairment, and finish deterioration. The AS4145.2 corrosion category is derived from the number of hours survived — the more hours, the higher the category.

Two categories account for almost everything published in the Australian market, and both appear on locks we stock:

C7 — High · 240 hours
Most exposed installations A genuinely capable rating, adequate for the large majority of exposed installations including most external doors and gates away from direct beachfront. Published across the Carbine mechanical digital range, and set out in Carbine's own salt spray testing information sheet (PDF), which explains the AS4145.2 method and the exposure categories the result maps to. Browse the Carbine range →
C10 — Extreme · 1,000 hours
Highest published figure The strongest published figure in the mechanical digital category. Achieved by Borg's Marine Grade Pro (MG Pro) range, which pairs the coating with marine-grade stainless internals. See what MG Pro actually means. Browse the Borg range →
Laboratory hours are not calendar years
A 1,000-hour salt spray result does not mean the lock survives 1,000 hours by the beach and then fails. Neutral salt spray is a deliberately severe accelerated test run under continuous controlled conditions — it exists to compare products against each other, not to predict service life at a specific address. Treat the number as a ranking tool. A C7 lock installed under a covered entry may well outlast a C10 lock bolted to an unshaded beachfront gate. For the full side-by-side with both test certificates, see Chapter 16 — the three mechanical digital ranges compared.
A corrosion rating is a test result — not a coastal warranty
A high corrosion category tells you the lock passed an extended salt spray test in a controlled laboratory environment. It does not mean the manufacturer will honour a warranty claim for salt air damage on a coastal property. Several major brands — including Yale — explicitly exclude salt spray and coastal air exposure from their warranty regardless of the lock's corrosion rating. Always confirm warranty terms specifically for your location before purchasing for any property within 2km of the coast.
K — Key Security
Key combination count and duplication protection
Grades K1 through K5 • K5 is highest

The K grade measures the security of the cylinder and key system. It is determined by: the number of effective key combinations (differs) the cylinder provides; resistance to picking and impressioning; and the level of protection against unauthorised key duplication. Higher grades require more sophisticated key systems with greater numbers of effective combinations and legal protection for the key profile.

GradeWhat it meansTypical use
K1 – K2Basic key security. Limited key combinations. Keys can generally be duplicated without restriction at any key cutter.Interior doors, low-security storage
K3 – K4Moderate key security. Higher number of effective combinations. Some duplication controls.Standard residential, commercial
K5Highest grade. Restricted, legally protected key system. Keys cannot be duplicated without proof of authorisation (typically a card issued to the lock owner). High effective combination count. K5 requires that the cylinder body or lock construction also prevents drilling, at the highest security grades.High-security residential, commercial, any application where key control is critical
Smart locks eliminate the K grade problem entirely
The K rating only matters for the physical key. Smart locks replace key entry with PIN, fingerprint, RFID, Bluetooth, or facial recognition — methods that have no key duplication vulnerability. A lost PIN is changed in seconds via the app. A compromised RFID card is deactivated immediately. You don't need to know what K grade your lock is rated to if your primary access method doesn't use a key.
Reading an AS4145.2 grade string
A grade string lists each dimension the lock has been tested against, in the form SL[n] D[n] C[n] K[n]. Not every product publishes all four — a lock with no keyed cylinder has no meaningful K grade, and many manufacturers publish only the dimensions they have had tested. The dormakaba MS2602 publishes SL8 D8 — the highest physical security grade and a 500,000-cycle mechanical lifespan. Read the string as a list of what has been verified, not as a single overall score, and note that AS4145.2 covers the mechanical lock body only. The electronic components of a smart lock are assessed separately under RCM, any applicable electrical safety standards, and the cyber security Rules covered later in this chapter.
AS1905.1 — Fire Door Hardware Certification

AS1905.1-2015 is the Australian Standard for fire-resistant doorsets — "Components for the Protection of Openings in Fire-Resistant Walls." It is mandatory under the National Construction Code (NCC/BCA) Deemed-to-Satisfy pathway and governs the design, construction, installation, and maintenance of fire doors and all associated hardware. Compliance is also tested to AS1530.4 (the fire resistance test standard). For the detailed companion guide covering which specific smart locks are certified for each door core type in Australia, see Chapter 05 — Fire Door Smart Lock Certification by Core Type.

A fire doorset is a system — every component must be certified
A fire door is not just the door leaf. It is a certified system comprising the door leaf, frame, hinges, seals, closer, and locking hardware — all tested together. Changing any component to a non-certified alternative can void the entire fire certification of the doorset. This is why you cannot simply fit any smart lock to a fire door — the lock must be tested and certified as part of that specific door assembly. All hardware must be tested and approved by a registered testing authority.

Fire Resistance Level (FRL) is expressed as three numbers separated by forward slashes, for example -/60/30:

First number
Structural Adequacy. Not applicable to door sets — always shown as a dash.
Second number
60
Integrity — how long (minutes) the door resists the passage of flames and hot gases.
Third number
30
Insulation — how long (minutes) the door limits temperature rise on the unexposed face.

So a door rated -/60/30 resists flames for 60 minutes and limits heat transmission for 30 minutes. A -/120/30 door provides 2-hour flame integrity. Most Queensland apartment fire doors are rated to at least -/60/30.

AS1905.1 RuleWhat It Means for Smart Locks
All hardware must be tested on the specific door type A lock certified for an E-Core door is not automatically certified for a Firecore or Pyropanel door. Always confirm the lock's certification matches your specific door core type. Read: Fire Door Types & Smart Lock Certification →
Lock must be self-latching Fire door locks must latch automatically — a lock that holds the door open or fails to latch is non-compliant. No hold-open feature is permitted.
Fire-rated automatic door closer required Every fire door must have a fire-rated automatic closer. Smart lock installation does not remove this requirement.
One penetration principle You cannot add a secondary deadbolt to a fire door. The standard effectively limits you to the single certified locking device. A second lock penetration voids the fire door certification. Read: The One-Penetration Principle Explained →
Lock height: 900mm–1100mm from floor Standardised with DDA requirements. Combined fire door and DDA compliance requires the lock to be within this range.
No hold-open feature It is illegal to prop or wedge a fire door open. Smart locks with auto-unlock proximity detection must be configured to re-latch the door — consult us before fitting to a fire door.

Common fire door core types in Australia: E-Core (engineered composite, most common in apartments), Firecore (high-density, high-risk environments), and Pyropanel (specialist brand, premium applications). Most fire-rated smart locks are tested on E-Core and Firecore. Pyropanel requires specific certification — fewer locks qualify. Full compliance summary by door type →

Fire door tags: Under the Building Act 1975, all buildings approved after 1 April 1976 must have certification tags fitted to fire doors. Tags are required under AS/NZS 1905.1 and include the component standard, fire resistant level (e.g., -/60/30), manufacturer name, certifier name, door tag number, and year of manufacturing. The year of manufacture on the tag is important — it helps identify asbestos risk (see below).

Certified smart locks for fire doors in Australia. Only a small number of smart locks carry AS1905.1 certification. These are the two primary options currently available:

Hamilton Disabled Fire Rated
AS1905.1 + AS1428.1 AS1905.1-2015 certified and DDA lever compliant, in Black and Satin Nickel. See the full fire assessment detail for the door core types it is assessed against. Browse the McGrath range →
Unity Entrance Fire Rated with DDA Lever
2-hour AS1905.1 Tested for 2 hours on AS1905.1-2015 assemblies, with an AS1428.1 accessible lever. See the fire rating detail and note that Secure mode is disabled on the fire-rated variant. Browse the Yale range →

Certification documentation including test certificates is available at Fire Rating Certificates → Shop all certified fire door smart locks →

Queensland maintenance obligations — fire doors are a prescribed fire safety installation
Under Section 104D of the Fire and Emergency Services Act 1990, the occupier of a building must maintain every prescribed fire safety installation to a standard of safety and reliability. Fire doors are prescribed installations. Maintenance must comply with the Queensland Development Code (QDC) MP 6.1 and AS1851 (routine service of fire protection systems) — typically at 3-monthly intervals for fire doors. Penalties apply for failure to maintain. Only a person holding a QBCC Passive Fire Protection — Fire Doors and Fire Shutters licence can certify, inspect, or test fire doors. Locksmith work on fire door components (locks, closers, seals, hinges) is exempt from the definition of building work and requires no additional licence — but the fire certification must not be compromised by any changes made. Read: What Locks Are Actually Compliant on Gold Coast Apartment Fire Doors? →
Fire Door Types & Smart Lock Certification
E-Core, Firecore and Pyropanel door types — which locks are certified for each.
Fire Rating Certificates
Certification documentation for fire-rated smart locks sold on this site.
Secondary Locks & the One-Penetration Principle
What you can — and can't — add to an apartment fire door in Queensland.
Apartment Fire Doors on the Gold Coast: What's Actually Compliant?
A practical guide to fire door tags and compliant smart lock upgrades in Queensland.
AS1428.1 — Disability Access & DDA Compliance

Three instruments work together to create Australian disability access requirements for door hardware:

The core requirement for door hardware on accessible routes: operable without tight grasping, pinching, or twisting of the wrist. In practical terms, this means:

RequirementDetailSmart Lock Relevance
Lever handle — not knob Lever handles operable with one hand and a closed fist. Round knobs require gripping and twisting — non-compliant on any accessible route. Smart locks with lever handles — the McGrath Albion and Hamilton, and the Yale Unity DDA — satisfy this. Keypads and fingerprint sensors eliminate the handle requirement entirely for entry action.
D-type lever preferred Horizontally aligned, minimum return at end to prevent the hand slipping off. Clearance 35–45mm from inside of lever to door face. The McGrath Albion range uses an L1 / D-type lever configuration, independently tested for AS1428.1 compliance. Download compliance cert →
20mm return on lever end Prevents hand slipping off when pulling door open — important for people with grip limitations. Confirm this on any lever selected for DDA applications. Standard residential levers may not have the correct return dimension.
Fitted height: 900–1100mm from floor Same height range as required by BCA for exit and fire door locks. This alignment means a correctly specified lock satisfies both requirements simultaneously. All smart locks should be installed at this height. For fire door applications this is additionally mandated under BCA D2.21.
Minimum operating force AS1428.1 sets maximum force requirements for opening doors — too-heavy door closers can make a technically compliant lever non-functional for many users. Fire-rated door closers must be fire-rated but also within the force limits AS1428.1 specifies. Combined compliance requires careful hardware selection.
Smart locks are frequently the DDA-compliant choice for commercial entry points
A traditional key deadbolt on an accessible route is non-compliant — key operation requires twisting. Smart lock access methods (PIN keypad, fingerprint, RFID tap, facial recognition) all satisfy the no-twisting requirement for the entry action itself. This means smart locks are often the required upgrade, not just an option, when replacing non-compliant hardware on accessible routes in commercial premises. Mechanical digital locks also have accessible lever options — see Chapter 16 — Commercial & Heavy Duty. For the full accessibility guide including NDIS and SDA funding pathways, see Chapter 09 — DDA Compliance Requirements.
Asbestos Regulations — Queensland Fire Doors

This is one of the most misunderstood and rapidly evolving issues in Australian fire door compliance. There are now three distinct risk windows — including one covering fire doors installed as recently as mid-2025. If your building has fire doors and any work is planned on them, read this section carefully.

Risk Window 1 — Pre-1990 construction: thermal insulation core
Fire doors in buildings constructed before January 1990 may contain asbestos-containing material (ACM) in the door core as thermal insulation. Fire door core asbestos is classified as friable — it can crumble to powder when disturbed. Drilling, boring, routing, or cutting into such a door can release asbestos fibres. When a locksmith says "I need to check this before I drill," that is a risk control decision, not an inconvenience. Read the full three-risk-window explanation →
Risk Window 2 — Korab/Pyrokor recall: 1 January 1993 to 3 September 1998
In June 1999, the federal government ordered an urgent compulsory recall of up to 4,500 fire doors made using a Pyrokor core and supplied between 1 January 1993 and 3 September 1998. These doors — manufactured by Theo Holdings Pty Ltd and Barok Industries Pty Ltd (trading as Korab & Co Pty Ltd and Korab Industries Pty Ltd) — failed to achieve their claimed fire resistance level ratings and were found to contain asbestos. They were supplied primarily in southern Queensland and northern New South Wales. This recall does not apply to doors supplied after 3 September 1998 by the new owner of the Korab company name. If your building's fire door tags show manufacture dates in this window, consult your building manager immediately.
⚠ Risk Window 3 — Pyropanel FRB contamination: 2021 to May 2025 (ACTIVE ALERT)
This is a current and active safety alert issued by the Australian Border Force, WorkSafe QLD, WorkSafe Victoria, WorkSafe WA, and the Heads of Workplace Safety Authorities (HWSA).

The Australian Border Force detected chrysotile asbestos in Fire Rated Boards (FRBs) branded Pyropanel, imported by ASSA ABLOY Australia from China between 2021 and May 2025 (and on-supplied to New Zealand up to August 2025). These FRBs were used as internal core material in fire door construction. The asbestos was not present by design — it was a contamination event involving the overseas raw material supplier. Some overseas manufacturers classify materials with low asbestos levels as "asbestos-free" under standards that do not meet Australian requirements.

Affected products include:
— FRB MAXI SI (48mm single leaf — up to 2400×920 / 2100×1120)
— FRB M14 Sliding Fire Door (PSFD120-80 / PSFD240-80)
— FRB M13 Sliding Fire Door (PSFD120-65)

Important distinctions: Only the FRB product is affected. The separate FR Board product (also Pyropanel) has not been found to contain asbestos. Not all doors in the affected supply window are confirmed contaminated — the contamination was non-uniform — but because there is no reliable way to identify affected doors without laboratory testing, the official guidance is: treat as asbestos until confirmed otherwise by a NATA-accredited laboratory.

Risk if intact and undisturbed: Very low to negligible — the FRB is encased within the door. Risk increases significantly if hardware work disturbs the core — exactly the situation when a lock is being installed or replaced.

This alert was investigated and confirmed by FVS Fire Doors (who have taken over Advanced Fire Doors). Their advice: treat any Pyropanel fire door (2021–2025) as asbestos until confirmed otherwise.

The regulatory framework for asbestos at workplaces (which includes residential premises when work is carried out by a contractor):

Legislation / StandardKey Requirement
Work Health and Safety Act 2011 (WHS Act) Primary legislation governing asbestos at workplaces. A residence becomes a "workplace" when a contractor carries out work on it — meaning these obligations apply to any lock installation job on an apartment fire door.
WHS Regulation 2011, Chapter 8 (Asbestos) Detailed framework for managing, controlling, and removing asbestos. Requires risk assessment before disturbing potential ACM. Sets out licensing requirements for asbestos assessors and removalists.
Code of Practice: How to Manage and Control Asbestos in the Workplace 2021 Practical guidance for identifying asbestos and implementing controls. Identifies fire door core as a known ACM location. Requires NATA-accredited laboratory testing to confirm or rule out asbestos presence.
Asbestos register requirements Queensland buildings built before 1990 require an asbestos register. Following the 2021–2025 Pyropanel FRB alert, any installed door from that supply period must also be recorded on the asbestos register and included in an asbestos management plan until removed.
National asbestos import ban (31 December 2003) The ban prohibits manufacture, import, supply, sale, storage, and use of asbestos-containing products. The Pyropanel FRB contamination event demonstrates this ban can be circumvented by overseas suppliers misclassifying materials — which is why the 2021–2025 window is a confirmed risk despite the ban being in force.

What a locksmith checks before drilling any fire door:

If asbestos is confirmed or cannot be ruled out before drilling: (1) engage a QBCC-licensed asbestos assessor to assess the door before any work; (2) for Pyropanel FRB doors, contact your supplier (ASSA ABLOY or their distributor) to confirm whether the specific door is affected; (3) if friable asbestos is confirmed, removal must be by a WorkCover Queensland-certified asbestos removalist; (4) bonded/enclosed asbestos that is undisturbed must be entered onto the building's asbestos register and managed through an asbestos management plan. Affected FRBs prohibited from new installation must be disposed of as asbestos waste once replacement doors are available. Full guide to the asbestos assessment and action process →

IP Ratings — Ingress Protection

IP ratings indicate protection against solid particles (first digit) and liquids (second digit). For smart locks, the relevant range is IP52 through IP67.

RatingDustWaterPractical Meaning for Smart Locks
IP52Dust protectedDrip-proof at 15° angleIndoor use only, or a protected awning installation with no direct rain contact. Not suitable for any exposed position.
IP54Dust protectedSplashing from any directionSheltered entry with occasional splash exposure. Minimum for covered outdoor use in still conditions.
IP65Dust tight — zero ingressLow-pressure water jets (6.3mm nozzle, any direction)Suitable for sheltered outdoor installations — undercover front door, rain-protected entry. The most common outdoor residential rating.
IP66Dust tightHigh-pressure water jets (12.5mm nozzle)Suitable for fully exposed outdoor gates and unsheltered entry points. Recommended for any lock exposed to direct rain.
IP67Dust tightTemporary immersion up to 1m / 30 minutesFlood-risk applications. Rare in smart locks but available on select heavy-duty models.
IP rating does not cover UV, salt air, or Queensland heat
IP ratings test water and dust ingress only. They do not cover: UV degradation of plastic components and touchscreen coatings (significant in Queensland's UV index), salt air corrosion of metal components and circuit boards (significant within 1–2km of the coast), or performance in sustained high temperatures above 40°C. Salt air resistance is measured separately under the AS4145.2 corrosion category, and several manufacturers — including Yale — explicitly exclude coastal air, salt spray, and high humidity from their warranty. For coastal Queensland properties, contact us before purchasing to confirm suitability for your location.
RCM — Regulatory Compliance Mark

The RCM (Regulatory Compliance Mark) is a combined electrical safety and electromagnetic compatibility mark for the Australian and New Zealand market. Any smart lock sold legally in Australia must carry RCM marking, demonstrating it has been tested against relevant electrical safety and EMC standards.

Why it matters: A significant volume of smart locks are imported directly from overseas platforms (AliExpress, Alibaba) without RCM certification. These products are not legally compliant for sale in Australia, may not meet Australian electrical safety standards, are not covered by Australian consumer law warranty protections, and may be refused warranty claims by the manufacturer. All products stocked by Terry's carry RCM certification.

RCM covers electrical safety and interference — whether the device is safe to power and won't disrupt other equipment. It says nothing about the security of the software inside it. Since March 2026, that gap has been closed by a separate mandatory standard.

Cyber Security — Australia's Smart Device Law

On 4 March 2026, connected smart locks sold in Australia came under a mandatory security standard for the first time. The Cyber Security (Security Standards for Smart Devices) Rules 2025 — made under the Cyber Security Act 2024 (Cth) and registered on the Federal Register as F2025L00276 — commenced after a twelve-month transition period, replacing the previous voluntary code-of-practice era with enforceable obligations. The Rules form part of the 2023–2030 Australian Cyber Security Strategy.

They are administered by the Technology Assessment and Regulation Office (TARO) within the Department of Home Affairs, supporting the Secretary's enforcement powers. There are no civil penalties; the regulator has stated an education-first, uplift-focused approach, and the enforcement toolkit is compliance notices, stop notices, and recall notices — with the details of a product and entity potentially published if a recall notice is ignored. Home Affairs publishes guidance, a factsheet and a decision flow chart for the regime.

Smart locks are squarely in scope. The Rules apply to "relevant connectable products" — consumer products that are internet-connectable or network-connectable, intended for personal, domestic or household use, and acquired (or reasonably expected to be acquired) in Australia. Locks qualify in both directions: a Bluetooth lock that pairs with a phone is network-connectable, and a lock reachable through a WiFi gateway is internet-connectable. Scope attaches to a whole class of device, not to how any one unit is sold — so a lock that could reasonably be bought by a consumer for a home is captured even where it is also marketed commercially. The obligations have extraterritorial reach, so overseas manufacturers supplying the Australian market are captured. Desktop computers, laptops, smartphones and tablets are specifically excluded — which is why compliance declarations often recite that odd-looking exclusion list. They are quoting the Rules' own carve-outs.

The date that actually matters is the manufacture date
The standards apply to in-scope products manufactured on and from 4 March 2026. Stock manufactured before that date is not required to comply, because the standard was not in force when the product was made. In practice this means a lock sitting on a shelf in 2026 may legitimately have no declaration behind it, and that asking for one is a reasonable question about newer stock rather than a universal expectation of everything in the market. It also means the picture will change steadily as older inventory clears.

The three requirements are deliberately narrow. They mirror the first three provisions of ETSI EN 303 645, the international baseline standard for consumer IoT security, which is the common ancestor of the Australian, UK and Singaporean regimes:

RequirementWhat it means in practice
No universal default passwords For any product that uses a password, once it is set up that password must be unique to the unit or set by the user — a single factory code shared across every unit can no longer remain the working credential. A default may still exist in the out-of-the-box state, and a product is not required to use passwords at all.
A published means to report security issues The manufacturer must operate a vulnerability disclosure channel — a published route for researchers and users to report a security problem, available free, in English, without demanding personal information, with status updates on resolution. If you cannot find one for a brand, that is informative.
Published support-period transparency The manufacturer must publish how long the device will receive security updates, as a fixed end date (for example, "until 30 June 2029") rather than a bare duration. This must cover the lock's firmware and its companion app, be shown prominently where purchase information appears, and once published it cannot be shortened. It is the requirement with the most practical value to a buyer — it converts an open-ended assumption into a stated commitment you can check before purchase.
What the law does not do — read a declaration as disclosure, not as a quality rating
The Rules are a transparency-and-hygiene floor, not a security certification. They do not set a minimum support period — only that the period must be disclosed. They do not require independent testing, mandate encryption standards, or impose any data residency requirement. A product can be entirely compliant and still be a modest piece of engineering with a short support life. The value of a declaration is that it forces the manufacturer to state things in writing that were previously unstated — it is not a badge of security quality, and it should not be read as one.
The obligation follows the brand on the box, not the platform underneath it
A large share of the world's connected locks do not run their own software stack. They are built on shared IoT platforms, and two dominate globally — TTLock (operated by Sciener) and Tuya. Several brands sold in Australia are TTLock-based under their own badge. The Rules place their duties on the manufacturer and the supplier of the finished product, not on the platform operator, so a shared cloud does not produce a shared declaration: each lock model needs its own, naming its own firmware and its own support end date. Two locks running the identical platform can therefore have quite different answers on support period and disclosure. For what each platform actually is and how they differ, see Chapter 14 — What TTLock is and Chapter 15 — the Tuya platform.
TTLock Tuya
The two largest consumer smart lock platforms worldwide. Neither is the entity that issues a statement of compliance — ask the brand whose name is on the lock.
Statements of Compliance — What to Ask For

The paperwork mechanism of the regime is the statement of compliance (sometimes published as a "cyber security declaration"). The Rules place obligations on two roles only — the manufacturer and the supplier, each as defined under Australian Consumer Law; there is no separate importer category, so an importer or retailer sits within "supplier." The manufacturer prepares and issues the statement, and the supplier must not supply a relevant connectable product without one. Both the manufacturer and the supplier must retain the statement for a minimum of five years under the Rules — some manufacturers, including ASSA ABLOY, state a longer ten-year retention on their own declarations, which is a voluntary step beyond the legal floor.

The regime operates on self-certification. There is no third-party testing gate and no government pre-approval — the manufacturer attests to compliance itself. This is the same model the United Kingdom adopted, and it is worth understanding plainly: the statement's force comes from the record-keeping duty, the Secretary's enforcement powers, and exposure under Australian Consumer Law for false representations, not from an independent laboratory having checked the claim.

A well-formed declaration contains a predictable set of fields. Knowing them lets you tell a real one from a marketing page:

FieldWhat it tells you
Product and model identifierThe exact SKU (and batch identifier, where one exists) covered. A declaration for a different model in the same range does not cover yours.
Hardware and firmware revisionVersion-specific accountability. Compliance is claimed against a stated build, not the brand in general.
Support period and end dateThe transparency requirement, answered. This is the field to read first — and the guidance calls for a fixed end date rather than a bare duration.
Associated softwareThe companion app and its version — confirming the app is inside the compliance scope, not just the hardware.
Issuing entity and named signatoryA named, accountable person at a real corporate entity, ideally one with an Australian presence you could actually contact.
Date of statementWhen compliance was attested. Useful context against the 4 March 2026 commencement.
Retention noteConfirmation the issuer understands the retention duty (five years under the Rules; some issuers state longer) — a small but telling sign of a systematic programme rather than a one-off document.
A worked example — what a compliance programme looks like in practice
ASSA ABLOY publishes a public compliance hub carrying individual cyber security declarations for each SKU across the Australian Yale and Lockwood smart ranges — the Assure, Unity and Screen Door series, ByYou Pro, Luna Pro+, Kyra Pro, the Home Module and Connect Plus Hub 2, plus Lockwood's Home Hub and Latitude Slim. The declarations are dated in late January and early February 2026, ahead of the 4 March commencement, are signed by a named product manager at ASSA ABLOY Australia, and each states a defined three-year security-update support period. We reference it here because it is a clear, inspectable example of the format described above — a per-model document rather than a general assurance. One honest note: the guidance's preferred form for the support period is a fixed end date rather than a duration such as "three years," so a duration-based figure, while informative, is the softer version of that requirement. Ask any supplier for the equivalent on the product you are considering.
ASSA ABLOY Yale
A worked example you can read for yourself: the declaration for the Yale Unity Entrance Fire Rated (PDF) — declaration number Cyber-AU-00009, a named model, a stated hardware revision and firmware version, and a defined support period. Compare it against the field list above. Browse Yale and ASSA ABLOY.

What to actually ask before you buy a connected lock:

The International Picture

Australia's Rules did not appear in isolation. Most of the world's consumer IoT security regimes trace back to the same baseline document, and they have converged on the same three-part floor. This matters when you are buying an imported lock: a manufacturer already meeting the UK or European requirements is usually most of the way to meeting Australia's — and a UK statement of compliance can, in fact, be used here.

RegimeStatusWhat it requires
ETSI EN 303 645 (international baseline) Published 2020 — voluntary standard The common ancestor. Its first three provisions — no default passwords, vulnerability disclosure, support transparency — are the ones Australia, the UK and Singapore each adopted. Compliance with EN 303 645 substantially evidences compliance with the Australian requirements.
United Kingdom — PSTI Act 2022 In force since 29 April 2024 The same three requirements, and the template Australia followed. Substantial financial penalties apply for non-compliance. A manufacturer's UK statement of compliance can be used in Australia, provided it meets the requirements of the Act and section 9 of Australia's Rules — a practical shortcut for imported product already sold into the UK.
European Union — Cyber Resilience Act (Reg. 2024/2847) In force 10 December 2024 · reporting obligations from 11 September 2026 · full application 11 December 2027 The most demanding regime of the group. Manufacturers must report actively exploited vulnerabilities and severe incidents to ENISA (24-hour early warning, 72-hour notification), and products carry CE marking for cyber requirements. Fines reach €15 million or 2.5% of worldwide turnover. See the European Commission's CRA guidance.
European Union — RED delegated act Applies from 1 August 2025 Cyber security requirements for radio-connected devices, which places Bluetooth and WiFi locks in scope within the EU.
United States — Cyber Trust Mark Voluntary labelling scheme (FCC) A consumer-facing label based on NIST criteria rather than a mandatory standard — the US has taken the labelling route instead of the legislative one.
Singapore — Cybersecurity Labelling Scheme (CLS) Voluntary label, four levels A tiered label where higher levels indicate progressively more rigorous assessment. This is the model Australia's own planned label follows.
What's coming next in Australia — a voluntary security label from 2027
A voluntary cyber security labelling scheme for Internet of Things products is planned from March 2027, developed by the Australian Government with IoT Alliance Australia and following the Singaporean and German label models. Where the current Rules are a pass/fail floor that produces a document, a label is designed to be visible at the point of sale and to reward manufacturers who go beyond the minimum. If it works as intended, it will make the comparison this chapter describes considerably easier to do at a glance.

For how the underlying app platforms differ on security architecture and where your access data is actually held, see Chapter 15 — Security & Data Sovereignty. For the TTLock platform specifically, including its published vulnerability history, see Chapter 14 — TTLock Security.

Queensland-Specific Considerations

Queensland's climate creates specific challenges for smart lock durability that standards-based ratings don't fully capture:

ConcernEffectWhat to Do
UV exposure Queensland UV index is among the highest globally. Plastic fascias, touchscreen coatings, and rubber seals degrade faster than in southern states. Full-sun lifespan of plastic components can be 3–5 years vs 8–12 years in shade. Install in shade where possible. Inspect annually for cracking or discolouration of plastic components.
Salt air (coastal) Properties within approximately 1–2km of the coast experience salt aerosol that accelerates corrosion of metal components, circuit boards, and contact surfaces. Multiple manufacturers explicitly void warranty for coastal installations. How salt air affects smart lock lifespan in Queensland → Contact us before purchasing for any coastal property. Check the specific product's warranty exclusions — "salt spray" is the key phrase to look for. Compare published AS4145.2 corrosion categories where the manufacturer publishes one.
Heat and humidity Sustained temperatures above 40°C accelerate battery self-discharge and stress electronic components. High humidity increases corrosion risk in non-sealed enclosures. Use quality alkaline batteries only — no lithium. Choose locks with IP65+ sealed enclosures. Avoid west-facing full-afternoon-sun positions where alternatives exist.
Further Reading
Chapter 05 — Fire Door Smart Locks
Which smart locks are AS1905.1 certified, core type matching, and the complete fire door compliance checklist.
Chapter 09 — DDA & NDIS Accessibility
AS1428.1 compliance in depth, NDIS funding pathways, SDA requirements, and the certified DDA smart lock range.
Chapter 15 — Smart Lock App Platforms
Platform security architecture, where your access data is held, and how the major app ecosystems compare on data sovereignty.
Chapter 16 — Mechanical Digital Locks
The battery-free, network-free category — published salt spray figures, commercial cycle ratings, and where mech-digi outperforms.
Asbestos in Gold Coast Apartment Fire Doors
The three risk windows, how to identify your door's risk category, and the correct process before drilling.
Apartment Fire Doors: What Locks Are Actually Compliant?
Practical compliance guide for Queensland strata and apartment fire door lock upgrades.
Lockwood vs Borg vs Carbine — Corrosion Compared
Both brands' published salt spray certificates side by side, with the AS4145.2 categories and honest test-versus-installed framing.
How Long Do Digital Door Locks Last?
Realistic lifespan expectations, the coastal environment effect, and what actually determines how long a lock survives in Queensland.

Unsure about compliance for your application?

Our team can confirm which standards apply to your door type and location — and which products meet them. Fire door, DDA, asbestos risk, coastal, cyber security declarations — we've seen all of it. No charge for the conversation.