A new Australian labelling scheme for smart home devices will help consumers identify products that meet a number of mandatory security standards, Cybersecurity Minister Tony Burke has said in launching a pilot of the scheme after several years in development.

Led by the Connected Technology Alliance (CTA) and funded by the Department of Home Affairs (DHA), the new Security Labelling Scheme for Smart Devices (SLSSD) will badge smart home Internet of Things (IoT) products with an information sticker and security rating out of 4.

It applies to products including smart TVs, doorbells and surveillance cameras, baby monitors, robot vacuum cleaners and solar inverters – all of which have been compromised by cybercriminals in recent years – but not to connected cars or medical devices.

Set to kick off next month with the support of device makers NetComm, Telstra, ASSA ABLOY / Lockwood and Electrolux it will rate products according to rules set out by testing labs Viden, Securus Consulting Group, Teron Labs, DEKRA and TÜV SÜD.

The tech giants are notably absent for now.

“Australians need to be able to trust that the devices they bring into their homes won’t compromise their safety,” Burke said.

Ratings for consumers

The scheme debuted within Australia’s 2023-2030 Australian Cyber Security Strategy and, similar to how food makers use the Health Star Rating System to gauge product nutrition, helps consumers evaluate products’ compliance with smart home security standards.

Those standards were formally codified by the Cyber Security (Security Standards for Smart Devices) Rules 2025, which commenced on 4 March and enforce a range of security requirements on smart devices sold in Australia.

Under those rules eligible devices must, for example, avoid use of default passwords and use unique random passwords for each product; provide ways for users to report security issues; and clarify policies such as how long security updates will be provided.

Meeting those criteria will earn a product Level 1 status, while Level 2 adds robust authentication, secure communications and secure data storage; Level 3 confirms the use of security by design practices; and Level 4 validates penetration testing against common attacks.

The rules do not apply to desktop or laptop computers, smartphones or tablets but require manufacturers of other smart devices to bundle a statement of compliance with the product – a requirement that the new SLSSD badge will fufil.

“Raising consumer awareness about smart device security is an important first step in reducing cyber risk,” CTA chair Judy Anderson said, calling the ratings scheme “a great opportunity for manufacturers to take the lead in raising security for all of us.”

Cybercriminals have long taken advantage of insecure home devices to take over home networks, with Mirai inspired malware like Kimwolf, Eleven11 and Aisuru letting them seize control of home routers, IP cameras and other devices and turn them on other targets.

Estimates suggest there will be 29.7 billion IoT devices installed by 2027, with over 820,000 daily attacks on such devices.

The tide of IoT security raises all boats

As the SLSSD pilot program rolls on, advocates hope it will both educate consumers and save them from potentially catastrophic buying decisions when choosing smart home products that are already pervasive and quickly becoming even more so.

The average Australian home already has 25 connected devices and this number is expected to increase to 44 by 2030, NBN Co has predicted – with faster overall broadband speeds meaning that infected devices can launch ever more powerful DDoS and other attacks.

It’s a global problem, and the new cybersecurity standards and labelling scheme reflect the Department of Home Affairs’ participation in the Global Cybersecurity Labelling Initiative (GCLI), also adopted by 11 other countries including Singapore, the UK, UAE, and Canada.

While most major consumer brands are not involved with the pilot, authorities hope the increasing presence of cybersecurity labels – both here and abroad, particularly in countries where the devices are made – will ramp up manufacturers’ secure by design practices.

Failure to comply will increasingly attract the scrutiny of DHA’s Technology Assessment and Regulation Office (TARO), which has enforcement powers under the new regulations and can punish noncompliance with warnings, formal stop notices, or a formal recall notice.

The enforcement framework “is designed to encourage engagement with manufacturers and suppliers of in-scope smart devices and uplift industry best practice,” TARO explains, promising to “ensure Australian end-users are kept at the centre of our activities.”