08.07.2026

Do the new LEGO Smart Bricks have to comply with the Cyber Resilience Act?

LEGO is currently attracting a lot of attention: its new Smart Bricks combine classic building bricks with digital technology. But what at first glance looks like fun raises an interesting regulatory question on closer inspection: do the Smart Bricks fall within the scope of the Cyber Resilience Act (CRA)?

Arrange a no-obligation initial consultation
Your ISiCO-Expert:
Dr Jan Scharfenberg
Partner Information Security, Managing Director

What is behind the new LEGO Smart Bricks?

LEGO has announced a new generation of interactive building blocks known as Smart Bricks. Visually, they remain true to the familiar LEGO bricks, but inside they contain modern technology: sensors, LEDs, speakers and their own control unit. The Smart Bricks react to movement, position or neighbouring bricks and figures and generate light or sound effects without visible cables or external control.

The aim: to combine classic, tactile building with digital functions and thereby create new play experiences. It is precisely this connection between a physical product and digital logic that makes the Smart Bricks particularly interesting from a regulatory perspective.

Do LEGO Smart Bricks fall within the scope of the Cyber Resilience Act?

Whether the LEGO Smart Bricks actually fall under the Cyber Resilience Act (CRA) cannot be answered in general terms. In principle, however, classification within the scope is entirely conceivable.

The CRA is an EU regulation that, for the first time, creates uniform and binding cybersecurity requirements for so-called products with digital elements. This does not only mean classic IT products, but also hardware that has digital functions, contains software or processes data. The aim is to ensure cybersecurity throughout the entire product lifecycle from development until well after market launch.

The Smart Bricks are likely to meet the definition of a “product with digital elements” under the CRA. Although they have firmware and sensors, the decisive factor for applicability is the ability to establish a data connection: if the bricks have interfaces, such as Bluetooth, USB or Wi-Fi, to communicate with an app, a controller or the internet, they fall directly within the scope of the regulation.

By contrast, the mere existence of electronics without connectivity would not be sufficient.

If the Smart Bricks are placed on the market in the EU, they would therefore not only be considered toys, but also digital products within the meaning of the CRA. Since they neither fall under specific special regimes, such as medical devices or vehicle technology, nor are obviously covered by statutory exemptions, they could theoretically fall within the scope of the CRA. Whether and to what extent this is the case would have to be clarified as part of a specific relevance and risk assessment.

Which requirements would LEGO have to meet?

If the Smart Bricks were to fall under the CRA, this would entail a number of specific obligations for the manufacturer. These relate not only to the technology itself, but to the entire product lifecycle:

  • Security by design: security aspects would have to be taken into account already during the development of hardware and firmware — for example through security by default, meaning secure default settings, and a deliberate reduction of the attack surface.
  • Risk assessment and documentation: potential cyber risks would have to be systematically analysed and documented, including the software components used, meaning a software bill of materials, or SBOM, with third-party libraries also recorded.
  • Update and patch management: security updates would have to be provided for a defined period, based on the expected product lifetime, in order to remedy known vulnerabilities.
  • Vulnerability and incident management: actively exploited vulnerabilities or relevant security incidents would have to be reported to the competent authorities, CSIRTs/ENISA, within short deadlines — early warning within 24 hours, notification within 72 hours.
  • CE marking and declaration of conformity: compliance with the CRA requirements would be a prerequisite for lawful distribution in the EU.

Smart Bricks would likely be classified as a standard product, meaning that self-assessment by the manufacturer, Module A, internal production control, would be sufficient. Nevertheless, the organisational effort should not be underestimated.

Which obligations does the CRA generally impose on companies?

The Cyber Resilience Act makes clear that cybersecurity is no longer an optional add-on, but a fundamental product characteristic. Companies that develop, manufacture or distribute products with digital elements must systematically integrate security into their processes.

This includes, among other things, regular risk analyses, robust technical documentation, security updates planned for the long term and clear processes for handling vulnerabilities and security incidents. Breaches may lead to severe sanctions — including sales bans, recalls from the market or fines of up to EUR 15 million or 2.5% of worldwide annual turnover.

Conclusion

The LEGO Smart Bricks vividly demonstrate that the Cyber Resilience Act is no longer limited to classic IT products. Innovative consumer and toy products with digital functions can also fall under the new cybersecurity requirements — and show how important it is to address the CRA at an early stage.

Your next step towards CRA conformity.

You decide how deeply you want to engage. If you want to implement the CRA with support from start to finish, we will advise you on your situation in a free initial consultation. If you first want to know where your product stands, the CRA Initial Assessment Workshop will provide your assessment in four hours.

Our services relating to the Cyber Resilience Act

At ISiCO, we support companies in implementing the Cyber Resilience Act pragmatically and in a legally secure manner. We assess whether and to what extent products fall under the CRA and conduct detailed gap analyses to identify open action items, as well as comprehensive relevance and risk analyses. We also support our clients in conformity assessment and in preparing the required technical documentation.

In addition, we advise on secure development processes, security by design, sustainable update strategies and legal protection along the entire supply chain.

Holistic advisory: data protection, IT security and AI

However, our approach does not end with the CRA. As a specialised consultancy, we seamlessly connect these new requirements with our comprehensive portfolio in data protection and IT security law in order to use synergies and avoid duplicate work:

  • IT security and compliance: we support the implementation of the NIS2 Directive, assist with certifications under ISO 27001 or TISAX® and, on request, provide external information security officers.
  • Data protection (GDPR): our core business includes the establishment of data protection management systems, audits and the provision of external data protection officers.
  • Artificial intelligence: we advise on the legally compliant introduction of AI systems under the new AI Act and support certification under ISO 42001.
  • Crisis management: in an emergency, we support you with proven processes for managing data breaches and security incidents.

This ensures that your compliance strategy does not consist of isolated individual measures, but functions as an integrated overall system.

Information security that protects and thinks ahead

We don't just secure your systems; we also strengthen your structures. We provide well-thought-out IT security solutions that are tailored to your company and evolve alongside it.

Book your appointment now