AS4145.2 mechanical lock grading (SL, D, C, K), AS1905.1 fire door certification, AS1428.1 DDA compliance, asbestos regulations for Queensland fire doors, the 2026 smart device cyber security law, IP ratings, and the RCM mark — explained plainly by qualified locksmiths.
Compliance markings on smart lock specifications are frequently cited in marketing material but rarely explained. This chapter covers the main Australian standards you'll encounter: AS4145.2 (the four-part mechanical grading system), AS1905.1 (fire door hardware certification), AS1428.1 (DDA accessibility), asbestos regulations for Queensland fire doors, IP ingress ratings, the RCM mark, and — since 4 March 2026 — the mandatory cyber security standard that now applies to connected smart locks. Understanding what they actually mean, and what they don't cover, helps you evaluate products honestly and avoid misplaced confidence in a rating that doesn't address your actual concern.
AS4145.2:2008 is the Australian Standard for mechanical locksets and latchsets. It defines performance requirements and testing procedures across four independent dimensions — physical security, durability, corrosion resistance, and key security. Each dimension is graded separately, so a lock can be rated on all four simultaneously. When you see a rating string like SL8 D8 on a product spec sheet, that's the AS4145.2 shorthand for the lock's grade in each category.
This standard applies to the mechanical bolt and lock body — not the electronic components. A smart lock can carry a strong AS4145.2 rating on its deadbolt mechanism while having no electronic certification at all. The two are independent, and since March 2026 the electronic side has its own mandatory standard — see the cyber security section below.
The SL grade measures how resistant the lock mechanism is to forced entry, including sawing of the deadbolt, cylinder drilling, picking, and brute-force attack. Tests simulate real-world break-in methods with increasing force and sophistication at higher grades. The standard specifically identifies deadbolt resistance to sawing as a required test for products designated SL4 or SL8.
| Grade | Typical application | What it means |
|---|---|---|
| SL1 – SL2 | Interior doors, low-security storage | Meets basic structural requirements. Minimal attack resistance beyond normal use. |
| SL3 – SL4 | Residential entry doors | Standard residential deadbolt performance. Resistance to common forced entry methods. |
| SL5 – SL6 | Commercial, light industrial | Higher resistance to attack. Anti-pick and anti-drill features typically required. |
| SL7 – SL8 | Commercial, high-security residential | Maximum grade. Hardened bolt resistant to sawing, anti-drill cylinder, high pick resistance. The dormakaba MS2602 primary mortice lock is rated SL8 D8 — see the full dormakaba range. |
The D grade measures how many complete lock/unlock cycles the mechanism withstands before failure. Testing involves mechanically operating the lock on a test door under load until the required cycle count is reached, then re-verifying full operational compliance. D8 is independently confirmed at 500,000 cycles by manufacturers including Iver (door levers) and Lockwood, whose Paradigm series publishes the grade.
Corrosion testing is conducted using a neutral salt spray (NSS test per AS2332.3.1). The lock is exposed to a controlled salt-air environment for a specified duration, then assessed for surface degradation, functional impairment, and finish deterioration. The AS4145.2 corrosion category is derived from the number of hours survived — the more hours, the higher the category.
Two categories account for almost everything published in the Australian market, and both appear on locks we stock:
The K grade measures the security of the cylinder and key system. It is determined by: the number of effective key combinations (differs) the cylinder provides; resistance to picking and impressioning; and the level of protection against unauthorised key duplication. Higher grades require more sophisticated key systems with greater numbers of effective combinations and legal protection for the key profile.
| Grade | What it means | Typical use |
|---|---|---|
| K1 – K2 | Basic key security. Limited key combinations. Keys can generally be duplicated without restriction at any key cutter. | Interior doors, low-security storage |
| K3 – K4 | Moderate key security. Higher number of effective combinations. Some duplication controls. | Standard residential, commercial |
| K5 | Highest grade. Restricted, legally protected key system. Keys cannot be duplicated without proof of authorisation (typically a card issued to the lock owner). High effective combination count. K5 requires that the cylinder body or lock construction also prevents drilling, at the highest security grades. | High-security residential, commercial, any application where key control is critical |
AS1905.1-2015 is the Australian Standard for fire-resistant doorsets — "Components for the Protection of Openings in Fire-Resistant Walls." It is mandatory under the National Construction Code (NCC/BCA) Deemed-to-Satisfy pathway and governs the design, construction, installation, and maintenance of fire doors and all associated hardware. Compliance is also tested to AS1530.4 (the fire resistance test standard). For the detailed companion guide covering which specific smart locks are certified for each door core type in Australia, see Chapter 05 — Fire Door Smart Lock Certification by Core Type.
Fire Resistance Level (FRL) is expressed as three numbers separated by forward slashes, for example -/60/30:
So a door rated -/60/30 resists flames for 60 minutes and limits heat transmission for 30 minutes. A -/120/30 door provides 2-hour flame integrity. Most Queensland apartment fire doors are rated to at least -/60/30.
| AS1905.1 Rule | What It Means for Smart Locks |
|---|---|
| All hardware must be tested on the specific door type | A lock certified for an E-Core door is not automatically certified for a Firecore or Pyropanel door. Always confirm the lock's certification matches your specific door core type. Read: Fire Door Types & Smart Lock Certification → |
| Lock must be self-latching | Fire door locks must latch automatically — a lock that holds the door open or fails to latch is non-compliant. No hold-open feature is permitted. |
| Fire-rated automatic door closer required | Every fire door must have a fire-rated automatic closer. Smart lock installation does not remove this requirement. |
| One penetration principle | You cannot add a secondary deadbolt to a fire door. The standard effectively limits you to the single certified locking device. A second lock penetration voids the fire door certification. Read: The One-Penetration Principle Explained → |
| Lock height: 900mm–1100mm from floor | Standardised with DDA requirements. Combined fire door and DDA compliance requires the lock to be within this range. |
| No hold-open feature | It is illegal to prop or wedge a fire door open. Smart locks with auto-unlock proximity detection must be configured to re-latch the door — consult us before fitting to a fire door. |
Common fire door core types in Australia: E-Core (engineered composite, most common in apartments), Firecore (high-density, high-risk environments), and Pyropanel (specialist brand, premium applications). Most fire-rated smart locks are tested on E-Core and Firecore. Pyropanel requires specific certification — fewer locks qualify. Full compliance summary by door type →
Fire door tags: Under the Building Act 1975, all buildings approved after 1 April 1976 must have certification tags fitted to fire doors. Tags are required under AS/NZS 1905.1 and include the component standard, fire resistant level (e.g., -/60/30), manufacturer name, certifier name, door tag number, and year of manufacturing. The year of manufacture on the tag is important — it helps identify asbestos risk (see below).
Certified smart locks for fire doors in Australia. Only a small number of smart locks carry AS1905.1 certification. These are the two primary options currently available:
Certification documentation including test certificates is available at Fire Rating Certificates → Shop all certified fire door smart locks →
Three instruments work together to create Australian disability access requirements for door hardware:
The core requirement for door hardware on accessible routes: operable without tight grasping, pinching, or twisting of the wrist. In practical terms, this means:
| Requirement | Detail | Smart Lock Relevance |
|---|---|---|
| Lever handle — not knob | Lever handles operable with one hand and a closed fist. Round knobs require gripping and twisting — non-compliant on any accessible route. | Smart locks with lever handles — the McGrath Albion and Hamilton, and the Yale Unity DDA — satisfy this. Keypads and fingerprint sensors eliminate the handle requirement entirely for entry action. |
| D-type lever preferred | Horizontally aligned, minimum return at end to prevent the hand slipping off. Clearance 35–45mm from inside of lever to door face. | The McGrath Albion range uses an L1 / D-type lever configuration, independently tested for AS1428.1 compliance. Download compliance cert → |
| 20mm return on lever end | Prevents hand slipping off when pulling door open — important for people with grip limitations. | Confirm this on any lever selected for DDA applications. Standard residential levers may not have the correct return dimension. |
| Fitted height: 900–1100mm from floor | Same height range as required by BCA for exit and fire door locks. This alignment means a correctly specified lock satisfies both requirements simultaneously. | All smart locks should be installed at this height. For fire door applications this is additionally mandated under BCA D2.21. |
| Minimum operating force | AS1428.1 sets maximum force requirements for opening doors — too-heavy door closers can make a technically compliant lever non-functional for many users. | Fire-rated door closers must be fire-rated but also within the force limits AS1428.1 specifies. Combined compliance requires careful hardware selection. |
This is one of the most misunderstood and rapidly evolving issues in Australian fire door compliance. There are now three distinct risk windows — including one covering fire doors installed as recently as mid-2025. If your building has fire doors and any work is planned on them, read this section carefully.
The regulatory framework for asbestos at workplaces (which includes residential premises when work is carried out by a contractor):
| Legislation / Standard | Key Requirement |
|---|---|
| Work Health and Safety Act 2011 (WHS Act) | Primary legislation governing asbestos at workplaces. A residence becomes a "workplace" when a contractor carries out work on it — meaning these obligations apply to any lock installation job on an apartment fire door. |
| WHS Regulation 2011, Chapter 8 (Asbestos) | Detailed framework for managing, controlling, and removing asbestos. Requires risk assessment before disturbing potential ACM. Sets out licensing requirements for asbestos assessors and removalists. |
| Code of Practice: How to Manage and Control Asbestos in the Workplace 2021 | Practical guidance for identifying asbestos and implementing controls. Identifies fire door core as a known ACM location. Requires NATA-accredited laboratory testing to confirm or rule out asbestos presence. |
| Asbestos register requirements | Queensland buildings built before 1990 require an asbestos register. Following the 2021–2025 Pyropanel FRB alert, any installed door from that supply period must also be recorded on the asbestos register and included in an asbestos management plan until removed. |
| National asbestos import ban (31 December 2003) | The ban prohibits manufacture, import, supply, sale, storage, and use of asbestos-containing products. The Pyropanel FRB contamination event demonstrates this ban can be circumvented by overseas suppliers misclassifying materials — which is why the 2021–2025 window is a confirmed risk despite the ban being in force. |
What a locksmith checks before drilling any fire door:
If asbestos is confirmed or cannot be ruled out before drilling: (1) engage a QBCC-licensed asbestos assessor to assess the door before any work; (2) for Pyropanel FRB doors, contact your supplier (ASSA ABLOY or their distributor) to confirm whether the specific door is affected; (3) if friable asbestos is confirmed, removal must be by a WorkCover Queensland-certified asbestos removalist; (4) bonded/enclosed asbestos that is undisturbed must be entered onto the building's asbestos register and managed through an asbestos management plan. Affected FRBs prohibited from new installation must be disposed of as asbestos waste once replacement doors are available. Full guide to the asbestos assessment and action process →
IP ratings indicate protection against solid particles (first digit) and liquids (second digit). For smart locks, the relevant range is IP52 through IP67.
| Rating | Dust | Water | Practical Meaning for Smart Locks |
|---|---|---|---|
| IP52 | Dust protected | Drip-proof at 15° angle | Indoor use only, or a protected awning installation with no direct rain contact. Not suitable for any exposed position. |
| IP54 | Dust protected | Splashing from any direction | Sheltered entry with occasional splash exposure. Minimum for covered outdoor use in still conditions. |
| IP65 | Dust tight — zero ingress | Low-pressure water jets (6.3mm nozzle, any direction) | Suitable for sheltered outdoor installations — undercover front door, rain-protected entry. The most common outdoor residential rating. |
| IP66 | Dust tight | High-pressure water jets (12.5mm nozzle) | Suitable for fully exposed outdoor gates and unsheltered entry points. Recommended for any lock exposed to direct rain. |
| IP67 | Dust tight | Temporary immersion up to 1m / 30 minutes | Flood-risk applications. Rare in smart locks but available on select heavy-duty models. |
The RCM (Regulatory Compliance Mark) is a combined electrical safety and electromagnetic compatibility mark for the Australian and New Zealand market. Any smart lock sold legally in Australia must carry RCM marking, demonstrating it has been tested against relevant electrical safety and EMC standards.
Why it matters: A significant volume of smart locks are imported directly from overseas platforms (AliExpress, Alibaba) without RCM certification. These products are not legally compliant for sale in Australia, may not meet Australian electrical safety standards, are not covered by Australian consumer law warranty protections, and may be refused warranty claims by the manufacturer. All products stocked by Terry's carry RCM certification.
RCM covers electrical safety and interference — whether the device is safe to power and won't disrupt other equipment. It says nothing about the security of the software inside it. Since March 2026, that gap has been closed by a separate mandatory standard.
On 4 March 2026, connected smart locks sold in Australia came under a mandatory security standard for the first time. The Cyber Security (Security Standards for Smart Devices) Rules 2025 — made under the Cyber Security Act 2024 (Cth) and registered on the Federal Register as F2025L00276 — commenced after a twelve-month transition period, replacing the previous voluntary code-of-practice era with enforceable obligations. The Rules form part of the 2023–2030 Australian Cyber Security Strategy.
They are administered by the Technology Assessment and Regulation Office (TARO) within the Department of Home Affairs, supporting the Secretary's enforcement powers. There are no civil penalties; the regulator has stated an education-first, uplift-focused approach, and the enforcement toolkit is compliance notices, stop notices, and recall notices — with the details of a product and entity potentially published if a recall notice is ignored. Home Affairs publishes guidance, a factsheet and a decision flow chart for the regime.
Smart locks are squarely in scope. The Rules apply to "relevant connectable products" — consumer products that are internet-connectable or network-connectable, intended for personal, domestic or household use, and acquired (or reasonably expected to be acquired) in Australia. Locks qualify in both directions: a Bluetooth lock that pairs with a phone is network-connectable, and a lock reachable through a WiFi gateway is internet-connectable. Scope attaches to a whole class of device, not to how any one unit is sold — so a lock that could reasonably be bought by a consumer for a home is captured even where it is also marketed commercially. The obligations have extraterritorial reach, so overseas manufacturers supplying the Australian market are captured. Desktop computers, laptops, smartphones and tablets are specifically excluded — which is why compliance declarations often recite that odd-looking exclusion list. They are quoting the Rules' own carve-outs.
The three requirements are deliberately narrow. They mirror the first three provisions of ETSI EN 303 645, the international baseline standard for consumer IoT security, which is the common ancestor of the Australian, UK and Singaporean regimes:
| Requirement | What it means in practice |
|---|---|
| No universal default passwords | For any product that uses a password, once it is set up that password must be unique to the unit or set by the user — a single factory code shared across every unit can no longer remain the working credential. A default may still exist in the out-of-the-box state, and a product is not required to use passwords at all. |
| A published means to report security issues | The manufacturer must operate a vulnerability disclosure channel — a published route for researchers and users to report a security problem, available free, in English, without demanding personal information, with status updates on resolution. If you cannot find one for a brand, that is informative. |
| Published support-period transparency | The manufacturer must publish how long the device will receive security updates, as a fixed end date (for example, "until 30 June 2029") rather than a bare duration. This must cover the lock's firmware and its companion app, be shown prominently where purchase information appears, and once published it cannot be shortened. It is the requirement with the most practical value to a buyer — it converts an open-ended assumption into a stated commitment you can check before purchase. |
The paperwork mechanism of the regime is the statement of compliance (sometimes published as a "cyber security declaration"). The Rules place obligations on two roles only — the manufacturer and the supplier, each as defined under Australian Consumer Law; there is no separate importer category, so an importer or retailer sits within "supplier." The manufacturer prepares and issues the statement, and the supplier must not supply a relevant connectable product without one. Both the manufacturer and the supplier must retain the statement for a minimum of five years under the Rules — some manufacturers, including ASSA ABLOY, state a longer ten-year retention on their own declarations, which is a voluntary step beyond the legal floor.
The regime operates on self-certification. There is no third-party testing gate and no government pre-approval — the manufacturer attests to compliance itself. This is the same model the United Kingdom adopted, and it is worth understanding plainly: the statement's force comes from the record-keeping duty, the Secretary's enforcement powers, and exposure under Australian Consumer Law for false representations, not from an independent laboratory having checked the claim.
A well-formed declaration contains a predictable set of fields. Knowing them lets you tell a real one from a marketing page:
| Field | What it tells you |
|---|---|
| Product and model identifier | The exact SKU (and batch identifier, where one exists) covered. A declaration for a different model in the same range does not cover yours. |
| Hardware and firmware revision | Version-specific accountability. Compliance is claimed against a stated build, not the brand in general. |
| Support period and end date | The transparency requirement, answered. This is the field to read first — and the guidance calls for a fixed end date rather than a bare duration. |
| Associated software | The companion app and its version — confirming the app is inside the compliance scope, not just the hardware. |
| Issuing entity and named signatory | A named, accountable person at a real corporate entity, ideally one with an Australian presence you could actually contact. |
| Date of statement | When compliance was attested. Useful context against the 4 March 2026 commencement. |
| Retention note | Confirmation the issuer understands the retention duty (five years under the Rules; some issuers state longer) — a small but telling sign of a systematic programme rather than a one-off document. |
What to actually ask before you buy a connected lock:
Australia's Rules did not appear in isolation. Most of the world's consumer IoT security regimes trace back to the same baseline document, and they have converged on the same three-part floor. This matters when you are buying an imported lock: a manufacturer already meeting the UK or European requirements is usually most of the way to meeting Australia's — and a UK statement of compliance can, in fact, be used here.
| Regime | Status | What it requires |
|---|---|---|
| ETSI EN 303 645 (international baseline) | Published 2020 — voluntary standard | The common ancestor. Its first three provisions — no default passwords, vulnerability disclosure, support transparency — are the ones Australia, the UK and Singapore each adopted. Compliance with EN 303 645 substantially evidences compliance with the Australian requirements. |
| United Kingdom — PSTI Act 2022 | In force since 29 April 2024 | The same three requirements, and the template Australia followed. Substantial financial penalties apply for non-compliance. A manufacturer's UK statement of compliance can be used in Australia, provided it meets the requirements of the Act and section 9 of Australia's Rules — a practical shortcut for imported product already sold into the UK. |
| European Union — Cyber Resilience Act (Reg. 2024/2847) | In force 10 December 2024 · reporting obligations from 11 September 2026 · full application 11 December 2027 | The most demanding regime of the group. Manufacturers must report actively exploited vulnerabilities and severe incidents to ENISA (24-hour early warning, 72-hour notification), and products carry CE marking for cyber requirements. Fines reach €15 million or 2.5% of worldwide turnover. See the European Commission's CRA guidance. |
| European Union — RED delegated act | Applies from 1 August 2025 | Cyber security requirements for radio-connected devices, which places Bluetooth and WiFi locks in scope within the EU. |
| United States — Cyber Trust Mark | Voluntary labelling scheme (FCC) | A consumer-facing label based on NIST criteria rather than a mandatory standard — the US has taken the labelling route instead of the legislative one. |
| Singapore — Cybersecurity Labelling Scheme (CLS) | Voluntary label, four levels | A tiered label where higher levels indicate progressively more rigorous assessment. This is the model Australia's own planned label follows. |
For how the underlying app platforms differ on security architecture and where your access data is actually held, see Chapter 15 — Security & Data Sovereignty. For the TTLock platform specifically, including its published vulnerability history, see Chapter 14 — TTLock Security.
Queensland's climate creates specific challenges for smart lock durability that standards-based ratings don't fully capture:
| Concern | Effect | What to Do |
|---|---|---|
| UV exposure | Queensland UV index is among the highest globally. Plastic fascias, touchscreen coatings, and rubber seals degrade faster than in southern states. Full-sun lifespan of plastic components can be 3–5 years vs 8–12 years in shade. | Install in shade where possible. Inspect annually for cracking or discolouration of plastic components. |
| Salt air (coastal) | Properties within approximately 1–2km of the coast experience salt aerosol that accelerates corrosion of metal components, circuit boards, and contact surfaces. Multiple manufacturers explicitly void warranty for coastal installations. How salt air affects smart lock lifespan in Queensland → | Contact us before purchasing for any coastal property. Check the specific product's warranty exclusions — "salt spray" is the key phrase to look for. Compare published AS4145.2 corrosion categories where the manufacturer publishes one. |
| Heat and humidity | Sustained temperatures above 40°C accelerate battery self-discharge and stress electronic components. High humidity increases corrosion risk in non-sealed enclosures. | Use quality alkaline batteries only — no lithium. Choose locks with IP65+ sealed enclosures. Avoid west-facing full-afternoon-sun positions where alternatives exist. |
Our team can confirm which standards apply to your door type and location — and which products meet them. Fire door, DDA, asbestos risk, coastal, cyber security declarations — we've seen all of it. No charge for the conversation.