KMO Achieves ETSI EN 303 645 Cybersecurity Accreditation – , Enabling IoT Products to Enter the Australian Market

From: | Testing & Certification | kmolab.com  Date:2026-05-22  Belong to:Company News

Ke Mei Ou Lab Achieves ETSI EN 303 645 Cybersecurity Accreditation – Full Compliance with Australia‘s Mandatory Smart Device Security Rules, Enabling IoT Products to Enter the Australian Market

(Shenzhen, China) – As of 4 March 2026, Australia’s Cyber Security (Security Standards for Smart Devices) Rules 2025 have become fully mandatory. All consumer-grade smart connected devices sold in the Australian market are now required to meet mandatory cybersecurity compliance requirements, or face market access restrictions and regulatory penalties.

ETSI EN 303 645 (Version 3.1.3) serves as the core technical reference for Australia‘s new rules, with the two frameworks fully aligned across all three mandatory requirements – password management, vulnerability disclosure policy, and defined security update support period. KE MEI OU LAB CO., LTD. (“Ke Mei Ou Lab”) has officially added ETSI EN 303 645 (Version 3.1.3) to its ISO/IEC 17025:2017 accreditation scope (ANAB Certificate No. AT-1532), becoming one of the few testing laboratories in China accredited to perform testing to both ETSI EN 303 645 and the EN 18031 series.

With this unique advantage, Ke Mei Ou Lab offers one‑stop cybersecurity compliance testing services for consumer IoT device manufacturers exporting to Australia and global markets, helping products meet Australian regulatory requirements and efficiently gain access to the Australian market.

1. Regulatory Background – Australia‘s Smart Device Cybersecurity Rules Now Fully Mandatory

Since 4 March 2026, the Cyber Security (Security Standards for Smart Devices) Rules 2025 – a core instrument under Australia’s Cyber Security Act 2024 – has been in full enforcement. The rules apply to all consumer-grade smart devices sold in Australia that can directly or indirectly connect to the internet, including smart cameras, smart locks, smart routers, smart TVs, smart speakers, smart lighting devices, wearables, and home security alarms. Desktop computers, laptops, tablets, and smartphones are explicitly exempt.

The Australian rules are directly aligned with the first three principles of ETSI EN 303 645, forming the mandatory cybersecurity baseline for compliance:

Core RequirementEN 303 645 ClauseAustralia Rule Detail
No Universal Default Passwords5.1Devices must have a unique password or require user‑set passwords on first activation
Vulnerability Disclosure Policy5.2Manufacturers must maintain a 24/7 reporting channel for vulnerabilities
Defined Security Support Period5.3Security updates must be provided for at least 5 years after the last product sale

From March 2027, the Australian Government will also launch a voluntary Security Labelling Scheme for Smart Devices. The label is expected to display security ratings (A–D) at the point of sale, helping consumers easily compare security protections and encouraging manufacturers to further enhance product security. Once fully implemented, the labelling scheme is likely to further increase market demand for third‑party cybersecurity testing and certification services.

2. Standard Overview – ETSI EN 303 645: The Global Baseline for Consumer IoT Cybersecurity

ETSI EN 303 645 (Version 3.1.3) is globally recognized as the baseline cybersecurity standard for consumer IoT devices. Its 13 mandatory security provisions cover the full product lifecycle – from design and development to operation and maintenance:

ClauseRequirement
5-1No universal default passwords (unique per device or mandatory change on first activation)
5-2Implement a vulnerability disclosure policy
5-3Keep software updated (security update mechanism)
5-4Securely store sensitive data (credentials, cryptographic keys)
5-5Ensure secure communication (use TLS, etc.)
5-6Minimize exposed attack surfaces (disable unused ports, etc.)
5-7Ensure software integrity (secure boot, etc.)
5-8Protect personal data (privacy‑by‑design)
5-9Make devices resilient to offline brute‑force attacks (limit failed attempts)
5-10Monitor security anomalies (log security events)
5-11Provide a mechanism for data cleanup (factory reset)
5-12Consider physical security (tamper resistance)
5-13Validate input data (prevent injection attacks)

Dual Bridge – Best Choice for Australia & Global Market Compliance

According to industry reports, “A device already compliant with EN 303 645 will meet most Australian requirements” . Accredited testing bodies have confirmed that uating products against EN 303 645 can effectively demonstrate compliance with Australian rules . At the same time, products that meet Australian requirements are more easily accepted for EU market recognition, enabling manufacturers to reduce certification costs through standard alignment.

Ke Mei Ou Lab‘s dual accreditation for both ETSI EN 303 645 and the EN 18031 series (mandatory cybersecurity standards under the EU RED Directive) offers manufacturers a “test once, access multiple markets” solution – significantly improving export certification efficiency and reducing compliance costs for global market access.

1779526473.png   1779526743.png

3. Uniquely Positioned – One‑Stop Cybersecurity Compliance for Australia

Ke Mei Ou Lab is one of the few testing laboratories in China accredited to perform full-scope testing to ETSI EN 303 645. This capability delivers significant value to Chinese IoT manufacturers:

  • Professional Compliance Documentation: The laboratory can assist clients in preparing the officially required Statement of Compliance, addressing all 12 required elements to ensure smooth market entry into Australia.

  • Market Access Assurance: Devices already conforming to EN 303 645 are reasonably deemed to meet the vast majority of Australia‘s new cybersecurity rules, unblocking Australian market access and greatly reducing compliance time and cost.

  • True One‑Stop Certification: In addition to cybersecurity testing, the laboratory offers EMC, RF, safety (LVD), energy efficiency (ErP), and other testing capabilities under one roof – enabling comprehensive multi‑market certification for IoT devices.

  • Full EN 18031 Series Capability: As a core component of Ke Mei Ou Lab’s cybersecurity service portfolio, EN 303 645 complements the laboratory‘s existing EN 18031-1/-2/-3 series accreditation (the mandatory cybersecurity standards under the EU RED Directive for radio equipment). This combination simultaneously satisfies Australian market cybersecurity requirements and European mandatory compliance standards, offering a true “test once, access global markets” solution for manufacturers.

4. Product Scope and Services

Devices subject to Australia‘s new cybersecurity rules include:

  • Smart cameras, smart locks, smart routers

  • Smart TVs, smart speakers, smart lighting devices

  • Wearables, home security alarms

  • VoIP phones, smart switches, wireless headsets

Testing Services:

ServiceDescription
Full EN 303 645 TestingAll 13 mandatory security provisions
Gap AnalysisIdentify security weaknesses, provide recommendations
Statement of CompliancePrepare official Australia compliance documentation
Integrated CertificationCybersecurity + EMC + RF + Safety + Energy Efficiency

Exempt Products (not subject to Australia‘s cybersecurity testing requirements under the Rules, but may still be subject to other regulations – please consult Ke Mei Ou Lab for case‑by‑case compliance strategies):

  • Desktop computers, laptops, tablets, smartphones

  • Therapeutic goods and road vehicles and their core components

For specific details and requirements, please contact our KMO!  ->> kmo@kmolab.com 

About Us
Follow us for the latest newsFollow us for the latest news
Contact Us
+86 755-8364 2690

Working hours: 9:00-18:30, Monday to Friday

Contact:Lisa Liu

Mobile:18028790769

Email: kmo@kmolab.com

Address:Room 2013, 20th Floor, Business Center, Jiahui Xin Cheng, No 3027, Shen Nan Road, Fu Tian, Shen Zhen, Guang Dong, China

Navigation
Ke Mei Ou Laboratory Co., Ltd. (KMO) is located in Shenzhen, China. KMO is an independent third-party testing Laboratory authorized by many international organizations. Since its establishment, KMO has focused on providing the most professional and efficient wireless & communication & voice product testing and certification services for international export enterprises. It is authorized by ILAC-MRA and ANAB, under the supervision and guidance of ANAB. KMO is a well-known ISO/IEC laboratory accreditation organization accredited laboratory in the United States. It is also authorized and recognized by national or regional agencies such as FCC of the United States, ISED of Canada, ACMA of Australia, Telepermit of New Zealand, OFCA of Hong Kong, IMDA of Singapore, etc.
Ke Mei Ou Laboratory Co., Ltd. Copyright ICP 10094765  Technical Support:KMOLAB