Every internet-connected consumer device manufactured for the Australian market since 4 March this year has had to meet three security requirements by law. It cannot ship with a universal default password. It has to publish a way for someone to report a security flaw. It has to state how long it will receive security updates.

The label that would tell a shopper which products on the shelf actually do those things is still a pilot. It enters trial next month and is scheduled for full rollout in 2027.

The requirements come from the Cyber Security (Security Standards for Smart Devices) Rules 2025, registered on the Federal Register of Legislation in March 2025 and commenced twelve months later after a transition period. They are made under the Cyber Security Act 2024 and administered by the Department of Home Affairs. Manufacturers have to prepare a statement of compliance and keep it. Where a manufacturer does not comply, the Rules provide for recall notices, and for the details of a failure to follow one to be published.

The Rules apply to products manufactured on and from 4 March 2026. Anything made before that date is outside them. A router or a camera assembled in February is not required to meet any of the three requirements, and it can sit on the same shelf as one that does, at the same price, with nothing on either box to separate them.

That gap is what the label is for, and the Commonwealth has paid an industry body to build it. The Labelling Scheme for Smart Devices grant, listed on business.gov.au, is a single grant of up to $1.7 million to an Internet of Things peak body. The money funds two things: co-designing and implementing an industry-led voluntary labelling scheme, and raising consumer awareness of the mandatory minimum standard. The grant runs across 2024-25 to 2026-27 and is closed to applications.

The recipient was IoT Alliance Australia, which has since rebranded as the Connected Technology Alliance. The scheme is one of the deliverables of the 2023-2030 Australian Cyber Security Strategy, and its design was completed in December 2025.

The result is a Commonwealth-funded, industry-run mark that certifies, in part, compliance with a standard that is already compulsory. No manufacturer is obliged to join it, and the body designing it is the industry's own peak association.

The pilot is due to open at the Connecting Technology Summit in Sydney from 1 to 3 September, where Tony Burke, the Minister for Home Affairs, Immigration and Citizenship, Cyber Security and the Arts, is giving the opening keynote. Reported early participants are NetComm, ASSA ABLOY and Telstra, with registration open to other vendors. That detail comes from the trade press rather than from a departmental release, and Home Affairs has not published the pilot terms.

A voluntary label can still do useful work. Singapore's Cybersecurity Labelling Scheme and the United States Cyber Trust Mark both run on the same model, and Australia is a participant in the Global Cybersecurity Labelling Initiative. A label that grades a device above the legal floor, on update duration or on how long a vendor commits to support, tells a buyer something the law does not.

A label that certifies only the floor tells them what the law already requires.

What is not yet public is the enforcement record. The Rules have been in force for five months and the department has not published how many statements of compliance have been assessed, how many products have been found non-compliant, or whether a recall notice has been issued. Those are the numbers that would show whether the mandatory standard is doing anything, and they matter more than the label. The pilot terms and the enforcement figures are both outstanding.