Smart Locks and Cyber Security: Australia's New Law
Posted by Jim Noort on 31st Jul 2026
What Australia’s new smart device law actually requires, and how Yale’s and Lockwood’s published declarations across their Australian ranges measure up to it.
A smart lock is a small computer bolted to your door. Like any connected device, it depends on a manufacturer keeping its firmware patched and being honest about how long that support will last. Since 4 March 2026, Australia has had its first mandatory law addressing exactly that — and it changes what you should expect from any smart lock manufacturer or retailer, including us.
This post looks at what the law actually requires, then at what compliant paperwork looks like in practice — using Yale’s and Lockwood’s published compliance hubs (both ASSA ABLOY) as the worked examples, because together they are the most complete declaration set we’ve found for any smart lock brand on the Australian market.
This guide covers:
- What changed under Australia’s Cyber Security (Security Standards for Smart Devices) Rules 2025, and who administers them
- Which products are captured, what the Rules deliberately leave alone, and where our own obligation as a supplier sits
- How Australia’s approach compares with the UK, EU, US and Singapore
- How Yale and Lockwood are approaching compliance, with every declared product we stock linked to its own signed declaration
- What to actually ask for when you’re buying a connected lock
For the full legal detail — scope, exclusions, enforcement, and what a Statement of Compliance must contain — see Chapter 11 — Cyber Security: Australia’s Smart Device Law. This post is about compliance paperwork; where a platform physically stores your access data is a separate question, covered in our platform-by-platform data hosting guide.
Australia’s New Smart Device Security Law
What Changed on 4 March 2026
The Cyber Security (Security Standards for Smart Devices) Rules 2025 commenced on 4 March 2026, made under the Cyber Security Act 2024 (Cth) and registered on the Federal Register of Legislation as F2025L00276. They followed a twelve-month transition period, they form part of the 2023–2030 Australian Cyber Security Strategy, and they replace the old voluntary code-of-practice era with enforceable obligations. It is Australia’s first mandatory consumer IoT security standard, and it requires three things: no universal default passwords, a published channel to report security issues, and published, honest information about how long the device will keep receiving security updates.
The three requirements are deliberately narrow. They mirror the first three provisions of ETSI EN 303 645, the international baseline standard for consumer IoT security, which is the common ancestor of the Australian, UK and Singaporean regimes:
| Requirement | What it means in practice |
|---|---|
| No universal default passwords | For any product that uses a password, once it is set up that password must be unique to the unit or set by the user — a single factory code shared across every unit can no longer remain the working credential. A default may still exist in the out-of-the-box state, and a product is not required to use passwords at all. |
| A published means to report security issues | The manufacturer must operate a vulnerability disclosure channel — a published route for researchers and users to report a security problem, available free, in English, without demanding personal information, with status updates on resolution. If you cannot find one for a brand, that is informative. |
| Published support-period transparency | The manufacturer must publish how long the device will receive security updates. The guidance’s preferred form is a fixed end date (for example, “until 30 June 2029”) rather than a bare duration such as “three years”. It must cover the lock’s firmware and its companion app, be shown prominently where purchase information appears, and once published it cannot be shortened. It is the requirement with the most practical value to a buyer — it converts an open-ended assumption into a stated commitment you can check before purchase. |
Who the Rules Cover, and What They Don’t Do
The Rules apply to “relevant connectable products” — consumer products that are internet-connectable or network-connectable, intended for personal, domestic or household use, and acquired (or reasonably expected to be acquired) in Australia. Smart locks qualify in both directions. A Bluetooth lock that pairs with a phone is network-connectable; a lock reachable through a Wi-Fi gateway is internet-connectable. There is no Bluetooth-only escape hatch.
Scope attaches to a whole class of device rather than to how an individual unit was sold, so a lock a consumer could reasonably buy for a home is captured even where it is also marketed commercially. The obligations have extraterritorial reach, which means an overseas manufacturer supplying the Australian market is captured whether or not it has an Australian entity. Desktop computers, laptops, smartphones and tablets are specifically excluded, along with therapeutic goods and road vehicles — which is why compliance declarations often recite that odd-looking exclusion list. They are quoting the Rules’ own carve-outs, not describing the product.
Enforcement sits with the Technology Assessment and Regulation Office (TARO) within the Department of Home Affairs, supporting the Secretary’s powers. There are no civil penalties; the regulator has signalled an education-first, uplift-focused approach, and the toolkit is compliance notices, stop notices and recall notices — with the product and entity details potentially published if a recall notice is ignored. The regime is self-certified: no third-party laboratory gate and no government pre-approval. Its real teeth are the record-keeping duty, those enforcement powers, and ordinary Australian Consumer Law exposure if a declaration turns out to be false.
One practical note for imported product: a manufacturer’s UK statement of compliance can be used in Australia, provided it meets the requirements of the UK Act and section 9 of Australia’s Rules. A brand already selling compliantly into the UK is usually most of the way to meeting ours.
We’re a Regulated Supplier Too
Here’s the part that doesn’t get said often enough: this law doesn’t just regulate manufacturers. The Rules place obligations on two roles only — the manufacturer and the supplier, each as defined under Australian Consumer Law. There is no separate importer category, so an importer or a retailer sits inside “supplier”. That includes us. From 4 March 2026 a supplier is not meant to be supplying an in-scope smart lock manufactured after that date without a valid statement of compliance behind it, and both the manufacturer and the supplier must retain that statement for a minimum of five years.
We’re not writing about this law as a spectator. We’re one of the businesses it applies to, which is exactly why we’ve started asking every brand we stock to show us their paperwork — and why we’re happy to show you what a brand doing it well actually looks like.
The Global Picture
Australia didn’t invent this from scratch. Most of the world’s consumer IoT security rules trace back to the same source — ETSI EN 303 645, a European baseline standard published in 2020 — and the pattern below shows how far each region has taken it.
| Region | Status | Key detail |
|---|---|---|
| United Kingdom | In force since 29 April 2024 | The PSTI Act 2022 — the same three requirements, and the template Australia followed. Substantial financial penalties apply, and a UK statement of compliance can be used here |
| European Union | In force 10 Dec 2024 · reporting duties bite 11 September 2026 · full application 11 Dec 2027 | The Cyber Resilience Act (Reg. 2024/2847) — the most demanding of the group. Actively exploited vulnerabilities must be reported to ENISA on a 24-hour early warning and 72-hour notification clock; fines reach €15m or 2.5% of worldwide turnover. A separate RED delegated act has already placed Bluetooth and Wi-Fi locks in scope in the EU since 1 August 2025 |
| United States | Voluntary | The Cyber Trust Mark — an FCC consumer label built on NIST criteria, not a mandatory standard. The US took the labelling route instead of the legislative one |
| Singapore | Voluntary, tiered | The Cybersecurity Labelling Scheme — four levels, each indicating progressively more rigorous assessment. This is the model Australia’s planned label follows |
| Australia | Mandatory since 4 March 2026 | A voluntary labelling scheme is planned from March 2027, developed with IoT Alliance Australia and following the Singaporean and German models — visible at the point of sale, and designed to reward manufacturers who go past the minimum |
The direction of travel is consistent: password hygiene and disclosure transparency are becoming baseline expectations everywhere, and the EU is going furthest by tying it to real financial penalties — with its reporting clock starting in September 2026. For the country-by-country detail behind this table, see Chapter 11’s international picture.

None of these regimes say anything about where a platform physically keeps your access logs, guest codes and unlock history. That is a separate question from compliance paperwork, and it is the one most often asked about the two largest global smart lock platforms, TTLock and Tuya — both Chinese-headquartered, and between them the software behind a large share of the budget and mid-market locks sold in Australia.
TTLock and Tuya are the two dominant third-party smart lock platforms worldwide; neither is a brand Terry’s stocks under its own name.
We treat that as its own subject: see where each smart lock platform hosts its data for the platform-by-platform breakdown, or TTLock and Tuya compared directly. This post stays on the compliance paperwork.
How Yale and Lockwood Are Approaching Compliance

Of every smart lock brand we stock, the two publishing the most complete, most specific compliance paperwork we’ve found on the Australian market are Yale and Lockwood — both part of ASSA ABLOY, and both approaching the new law the same way. That’s worth showing in detail, because it’s a useful benchmark for what “doing this properly” actually looks like.
Yale and Lockwood are sibling brands under ASSA ABLOY Australia, and share a single declaration template and support programme.
The Compliance Hub and Per-SKU Declarations

ASSA ABLOY publishes a dedicated compliance hub for each brand — Yale’s and Lockwood’s — each listing a signed Cyber Security Declaration for every current smart product in its Australian range. Not one blanket statement covering the whole brand, but a separate, dated PDF for each individual SKU: the Lockwood Latitude Slim alone has eleven, one per item code, each with its own declaration number and firmware version.
ASSA ABLOY is the parent group behind both brands, and the issuing entity named on every declaration.
The declarations we’ve reviewed carry Certificate Confirmed Dates in late January and early February 2026 — a month or more before the law took effect on 4 March. Each names the model and variant, the hardware revision, the firmware version, the bar code, and the companion app with its version date, so the compliance claim is anchored to a specific build rather than to the brand in general. Each states a security-update support period of three years from the date of the statement, and each notes that it must be retained for a minimum of ten years — double the five years the Rules require, which is a voluntary step past the legal floor.
The Yale declarations are issued by Andrew Williams, Product Management Manager at ASSA ABLOY Australia Pty Limited, based at 235 Huntingdale Road, Oakleigh, Victoria; the Lockwood declarations come from the same entity on the same template. Either way it is a named, local, accountable source rather than an anonymous corporate statement.
The Vulnerability Reporting Channel
The second of the three legal requirements is the one buyers rarely check, and it takes about thirty seconds. Both brands operate a published security centre with reporting guidelines and a route to a product security response team — Yale’s reporting guidelines and Lockwood’s reporting guidelines. Free to use, in English, no personal information demanded to file a report. That is the requirement, satisfied and visible.
It is worth knowing what to look for because the absence is the useful signal. If you cannot find a published security contact or disclosure page for a brand at all, the manufacturer either has not met that requirement or has not made meeting it findable — and for a device on your front door, either answer tells you something.
The Yale and Lockwood Range We Stock, With Declarations
Here is every Yale and Lockwood product family carrying a current cyber security declaration that we stock. Each product link goes straight to that product’s own cyber security section where the page has one, and the final column links the signed declaration itself — the actual PDF, not a summary of it.
| Product family | Available at Terry’s | What it is | Signed declaration |
|---|---|---|---|
| Yale Assure Lever | Satin Chrome · Matt Black | Touchscreen leverset with key override, Yale Home Module included | YRL226HKSC · YRL226HKMBK |
| Yale Assure SL | Satin Chrome · Matt Black | Key-free touchscreen deadbolt, no mechanical override | YRD256HKSC · YRD256HKMBK |
| Yale Assure Keyed | Satin Chrome · Matt Black | Touchscreen deadbolt with mechanical key override | YRD226HKSC · YRD226HKMBK |
| Yale Unity Slim | Unity Slim | Narrow-stile multipoint lock for aluminium doors | YURSSL |
| Yale Unity Entrance | Matt Black · Silver | Standard hinged-door entrance lever lock | YUR/DEL/1/MBK · YUR/DEL/1/SIL |
| Yale Unity Entrance Fire Rated | Silver · with DDA Lever | 2hr AS1905.1 fire-door rated; DDA variant is AS1428.1 accessible | YUR/DEL/FR/SIL |
| Yale Unity Screen Door Lock | Silver · Matt Black | Security screen door lock, DualDoor-compatible with a Unity entrance lock | YUR/SSDL/1/SIL · YUR/SSDL/1/MBK |
| Yale ByYou Pro | Matt Black | Grab-and-Go fingerprint mortice lock with Apple Home Key | YBYM/60/HK |
| Yale Luna Pro+ | Nova Graphite · Champagne Gold | 3D facial recognition push-pull mortice lock | YLN/60/HK/NG · YLN/60/HK/CG |
| Yale Kyra Pro | Matt Black | Push-pull multi-credential mortice lock | YKR/60/HK/MBK |
| Yale Connect Plus Hub 2 | Connect Plus Hub 2 | Wi-Fi gateway accessory for remote access and voice control | YAR/SWAA/HUB |
| Yale Home Module | Home Module with Door Sensor | Bluetooth and DoorSense upgrade fitted inside Assure series locks | YD-MD01 |
| Yale Aeron Window Actuator | Aeron Wireless Actuator (at Gold Coast Hardware) | Zigbee mesh window actuator on the same Yale Home ecosystem | Black · White · Special |
| Lockwood (ASSA ABLOY) — the same compliance approach, the same hub structure | |||
| Lockwood Latitude Slim | Matt Black | Narrow-stile multipoint smart lock for aluminium and timber doors — the Lockwood-badged Unity Slim | Eleven, one per item code — e.g. 2-Point 30mm · Induro 4-Point 30mm. Ask us for the one matching your item code |
| Lockwood 001Touch Plus | Chrome | Retrofit smart deadlatch on the Yale Home / Lockwood Home platform | LWL-001TDDL-CPDP |
| Lockwood Lume | Matt Black | Interior smart lever (fingerprint plus app), for interior doors only | LWL-LUM-ICR-MBK |
| Lockwood Home Hub | Home Hub | Wi-Fi gateway for remote access and voice control — the Lockwood equivalent of the Connect Plus Hub 2 | LWA/HUB |
A Worked Example: Yale ByYou Pro
Take one document and read it properly. The Yale ByYou Pro declaration covers model YBYM/60/HK. It carries declaration number Cyber-AU-00003, hardware revision 1, firmware version V4.0.8, a bar code, a three-year support period, and a Certificate Confirmed Date of 3 February 2026 — a month before the law took effect. It names the Yale Home app and its version as the associated software, so the app sits inside the compliance scope rather than outside it, and it is signed by a named product manager at an Australian entity you could actually contact.
That is what a real one looks like: dated, tied to a specific firmware build, model-specific rather than brand-wide, and signed by someone accountable. Lockwood’s declarations use the identical template — its Home Hub, for example, is declared under Cyber-AU-00035 at firmware V2.3.7 — so the same benchmark applies across both brands. You can also see the same declaration surfaced on the Yale ByYou Pro product page.
What This Means When You’re Buying
None of this means avoid other brands, or assume a lock without a declaration is unsafe — plenty of legitimately compliant products haven’t needed one yet under the manufacture-date trigger. It means asking better questions before you buy.
Ask for the Statement of Compliance
Any smart lock manufactured from 4 March 2026 onward should have one, for the exact model — not the brand, not the range. Check that the model identifier on the document matches the one on the box. It won’t tell you where the servers are, but it will tell you the support period and the date it was issued, the firmware version it was written against, whether the companion app is inside scope, and who signed it. A retailer that can’t produce one for a product manufactured after that date is a retailer who hasn’t done the paperwork — worth asking about.
Two things are worth checking yourself, and both take under a minute: that the brand has a published vulnerability reporting page at all, and that you can work out the actual calendar date the security updates stop. If the declaration gives a duration rather than an end date, do the arithmetic from the statement date. See Chapter 11’s guide to Statements of Compliance for the full field-by-field breakdown of what a well-formed document contains.
Frequently Asked Questions
Does the new law mean my existing smart lock is now illegal?
No. The Rules apply to products manufactured on and from 4 March 2026. A lock you already own, or one built before that date, isn’t retrospectively affected, and there is nothing you need to do about it.
Does every Yale and Lockwood smart lock have a cyber security declaration?
Every current product family in both Australian smart ranges does, per the published compliance hubs — and each declaration is linked in the table above. Discontinued predecessors like the YDM 3109 and YDM 7220 have been superseded rather than re-declared, which is expected: the obligation applies to what is actually being manufactured and sold today.
What should I actually ask a retailer before buying a smart lock?
Ask for the statement of compliance for your specific model if the unit was manufactured after 4 March 2026, ask what the support end date works out to, ask whether the companion app is named on the declaration, and ask whether the lock keeps working locally — PIN, fingerprint, or Bluetooth — if the app or cloud service ever goes offline.
Who enforces the Rules, and what are the penalties?
They are administered by the Technology Assessment and Regulation Office within the Department of Home Affairs, supporting the Secretary’s enforcement powers. There are no civil penalties attached to the Rules themselves. The regulator has signalled an education-first approach, and its toolkit is compliance notices, stop notices and recall notices — with product and entity details potentially published if a recall notice is ignored. Separately, a false compliance claim carries ordinary Australian Consumer Law exposure.
Is a compliance declaration the same as a security certification?
No, and this is the most common misreading. The Rules are self-certified — the manufacturer attests to compliance itself, with no third-party laboratory testing and no government pre-approval. A declaration tells you the manufacturer has stated certain things in writing and is accountable for them. It does not tell you the product was independently tested, that its encryption is strong, or that its support period is generous. Read it as disclosure, not as a quality rating.
My lock is Bluetooth only, with no Wi-Fi. Is it still covered?
Yes. The Rules cover products that are internet-connectable or network-connectable, and a Bluetooth lock that pairs with a phone is network-connectable. There is no Bluetooth-only exemption. It is a common assumption and it is wrong.
What is a vulnerability reporting channel, and why does it matter to me?
It is a published route for a security researcher or a customer to privately tell the manufacturer about a security flaw, free of charge and without handing over personal details. It matters because it is how flaws in your lock get found and patched before they are exploited — and because its absence is the easiest thing in the whole regime for a buyer to check. Yale and Lockwood both publish reporting guidelines under their security centres, linked earlier in this post.
What happens when the support period ends?
The lock keeps working. What stops is the manufacturer’s commitment to issue security updates for its firmware and app. In practice that matters most for locks that depend on a cloud service and an app; a lock you operate by PIN or fingerprint at the door is far less exposed. It is a good reason to know the end date before you buy rather than after, and a good reason to weigh a connected lock against a battery-free mechanical alternative if the door doesn’t genuinely need remote access.
Can a manufacturer shorten the support period after publishing it?
No. Once the support period has been published it cannot be reduced. It can be extended, and some manufacturers indicate extended support may become available, but the published figure is a floor the manufacturer is held to rather than a moving estimate.
Does the law say where my lock’s data has to be stored?
No. The Rules impose no data residency requirement at all — a fully compliant lock can host your access logs and guest codes anywhere in the world. Hosting location is a genuinely separate question, and we cover it platform by platform in where your smart lock’s data actually lives.
Does an overseas manufacturer have to comply if it ships direct to Australia?
Yes. The obligations have extraterritorial reach, so a manufacturer supplying the Australian market is captured whether or not it has an Australian entity. In practice this is hardest to enforce against direct-from-overseas marketplace sellers, which is one more reason those purchases carry risk — alongside the separate problem that many of them arrive without RCM electrical compliance and without Australian Consumer Law warranty cover.
Is a UK compliance statement valid in Australia?
It can be. A manufacturer’s UK statement of compliance may be used here provided it meets the requirements of the UK Act and section 9 of Australia’s Rules. Because the UK’s PSTI Act is the template Australia followed, a brand already selling compliantly into Britain is usually most of the way to meeting the Australian requirements.
Does Terry’s have an obligation under this law as well?
Yes. The Rules place obligations on manufacturers and suppliers, and a retailer sits within “supplier” — there is no separate importer category. From 4 March 2026 we should not be supplying an in-scope smart lock manufactured after that date without a valid statement of compliance behind it, and we must retain that statement for a minimum of five years. It is why we ask every brand we stock for its paperwork.
Related Guides
The full legal detail behind the Rules 2025, Statements of Compliance, and the international regulatory picture.
The companion piece to this one — where each smart lock platform physically hosts your access data, and what that means.
Cross-platform comparison of TTLock, Tuya, Yale Home, Carbine Connect and Igloohome, including data hosting.
Why each brand we stock is worth considering — including Yale’s HomeKit integration and coastal warranty notes.
What Yale locks do well, what to be aware of, and honest coastal installation guidance.
A direct comparison of two other major smart lock platforms — architecture, security record and data sovereignty.
Want to See the Compliant Range in Person?
We check the paperwork so you don’t have to guess — talk to a real person about which Yale or Lockwood model actually suits your door.
Ask an ExpertVisit Australia’s leading Smart Lock showroom and workshop:
Gold Coast Smart Locks
9/2 Prosper Crescent
Burleigh Heads, QLD
See working models, compare gateways, and get real advice before you commit.

Disclaimer: This post reflects the regulatory situation and the published compliance hub content of Yale and Lockwood as understood at the time of writing. Legislation, manufacturer documentation and declaration versions can change. It is not legal advice; for a specific compliance question, consult the statement of compliance issued for the exact product, or a qualified professional.
