This Practice Note provides an overview of the key aspects of Regulation (EU) 2024/2847, the EU Cyber Resilience Act (CRA), its background, timeline, objectives and how it interacts with other EU laws. For more information on the scope of the CRA or key obligations for economic operators, see Practice Notes: • The EU Cyber Resilience Act—scope and classification of products • The EU Cyber Resilience Act—obligations, compliance and enforcement Regulation (EU) 2024/2847, the EU Cyber Resilience Act (CRA) is a first of its kind EU legislation that imposes mandatory cybersecurity standards on ‘products with digital elements’ throughout the EU. Products that do not meet these standards will not be eligible for sale on the EU market as of December 2027. Compliance with the CRA will therefore become essential to gain access to the EU market for hardware and software products. Manufacturers, importers and distributors of such products will be subject to extensive cybersecurity obligations and face substantial fines if they fail to comply. The CRA has