Skip to content
Legislation
Skip to legislation

Cyber Security Act 2024 · Version 2024-11-29

Division 4—Miscellaneous

Register source version C2024A00098 · Source observation:

Reading presentation · Verification limits and dated status · No live currency check

Part 2—Security standards for smart devices

Read this container only

Division 4—Miscellaneous

Read this container only

21 Revocation and variation of notices given under this Part

Variation

  • (1) The Secretary may, by notice in writing given to an entity, vary a compliance notice, stop notice or recall notice given under this Part to the entity if the Secretary is reasonably satisfied that the variation is required:
  • (a) in order to rectify an error, defect or ambiguity in the notice; or
  • (b) to adequately rectify the non‑compliance, or possible non‑compliance, to which the notice relates.
  • (2) Before giving the notice to the entity under subsection (1), the Secretary must:
  • (a) notify the entity that the Secretary intends to give the notice to the entity; and
  • (b) give the entity a specified period (which must not be shorter than 10 days) to make representations about the giving of the notice.
  • (3) A varied compliance notice, stop notice or recall notice has the same effect as the original notice for the purposes of this Part.

Revocation

  • (4) The Secretary may, by notice in writing given to an entity, revoke a compliance notice, stop notice or recall notice given under this Part to the entity if the Secretary is no longer satisfied that the grounds for issuing the notice were met.
  • (5) If a compliance notice, stop notice or recall notice, relating to non‑compliance or possible non‑compliance by an entity with an obligation, is revoked under subsection (4), no further notices may be issued under this Part in relation to that non‑compliance.

22 Internal review of decision to give compliance, stop or recall notice

  • (1) An entity may apply, in writing, to the Secretary for review (an internal review) of a decision:
  • (a) to give the entity a compliance notice under section 17; or
  • (b) to give the entity a stop notice under section 18; or
  • (c) to give the entity a recall notice under section 19; or
  • (d) to vary, under section 21, a notice given to the entity.
  • (2) An application for an internal review must be made within 30 days after the day on which the notice was given to the entity.
  • (3) The decision‑maker for the internal review is:
  • (a) the Secretary; or
  • (b) if the Secretary made the decision personally—a person:
    • (i) to whom the power to issue a notice of that kind has been delegated under section 86; and
    • (ii) that was not involved in the making of the Secretary’s decision.
  • (4) Within 30 days after the application is received, the decision‑maker must:
  • (a) review the decision; and
  • (b) affirm, vary or revoke the decision; and
  • (c) if the decision is revoked—make such other decision (if any) that the decision‑maker thinks appropriate.
  • (5) The decision‑maker for the reviewable decision must, as soon as practicable after making a decision under subsection (4), give the applicant a written statement of the decision‑maker’s reasons for the decision.

23 Examination to assess compliance with security standard and statement of compliance

  • (1) If an entity must comply with an obligation in section 15 or 16 in relation to a relevant connectable product, the Secretary may engage an appropriately qualified and experienced expert to carry out an independent examination of the product to determine either or both of the following:
  • (a) whether the product complies with the security standard for the class of relevant connectable product;
  • (b) whether the statement of compliance for the product complies with the requirements of section 16.
  • (2) The expert may examine the product, for example, by doing any of the following:
  • (a) opening any package in which the product is contained;
  • (b) operating the product;
  • (c) testing or analysing the product, including through the use of electronic equipment;
  • (d) if the product contains a record or document—reading the record or document either directly or with the use of an electronic device;
  • (e) taking photographs or video recordings of the product.

Request for product and statement of compliance

  • (3) For the purposes of the examination, the Secretary may request, by notice in writing, the entity to provide the product, or the statement of compliance for the product, or both.
  • (4) The notice must:
  • (a) specify the product; and
  • (b) if the entity is not the manufacturer—specify the manufacturer of the product (if known); and
  • (c) specify a reasonable period within which the entity must provide the notice; and
  • (d) specify the period for which the product will be retained for testing; and
  • (e) specify the requirements of the security standard that the product will be tested against; and
  • (f) explain the kind of testing or analysis that will be done; and
  • (g) explain what may happen if:
    • (i) the entity does not comply with the notice; or
    • (ii) the entity does not comply with its obligations in section 15 or 16 in relation to the product; and
  • (h) set out any other matters prescribed by the rules.

Compensation

  • (5) An entity is entitled to be paid by the Commonwealth reasonable compensation for complying with a request under subsection (3).

24 Acquisition of property

This Part has no effect to the extent (if any) that its operation would result in an acquisition of property (within the meaning of paragraph 51(xxxi) of the Constitution) from a person otherwise than on just terms (within the meaning of that paragraph).