Blog / UAE compliance

UAE compliance

The 2027 UAE Regulatory Calendar: Four Real Dates, Several Renewals, and the Deadline Nobody Has Published

A UAE regulatory calendar for 2027: which cybersecurity and data dates are published, which are renewals you set yourself, and what NCAP has not announced.

Sam KhanSam Khan The Cyber ExpertFounder and CEO24 September 2026 · 6 min read

The board asks for the dates

The group compliance manager of a Dubai family holding company gets the request on the first working Sunday of January. The board meets on the 21st, and the chairman would like one slide: what are we obliged to do this year, and when.

The group is three businesses that share an office floor and nothing else. A twelve-chair medical centre in Al Barsha connected to NABIDH. A freight and customs arm with a warehouse in Jebel Ali and forty drivers whose licences, visas and medical files sit in an HR system nobody has looked inside since it was installed. And a small advisory entity licensed in the DIFC, four people, mostly laptops and a shared drive.

She opens a spreadsheet and starts a column called "Deadline". By Tuesday most of the cells say the same thing, which is nothing. Not because the obligations are unclear, but because they are continuous. The PDPL does not have a filing season. NABIDH does not send a reminder in March.

She finds four dates she can defend, a dozen renewals that exist only because somebody set them, and one programme everybody is talking about that has published no deadline at all.

The slide she takes to the board on the 21st is better than the one she was asked for. It has fewer dates and more owners.

What the heck does this mean

A UAE compliance calendar is mostly not a list of government deadlines. It is a list of renewals, reviews and connection requirements that you schedule yourself, plus a small number of published dates.

The federal Personal Data Protection Law covers personal data across the country, continuously. ADHICS v2 governs health information security in Abu Dhabi, and NABIDH governs the Dubai health information exchange and the connection requirements that come with it. DESC ISR v3 applies to Dubai government entities and their suppliers. The DIFC Data Protection Law, with Regulation 10 in place since September 2023, applies to DIFC entities; ADGM runs its own regime.

The National Cybersecurity Assurance Programme, run by the UAE Cybersecurity Council and built on the UAE Information Assurance Standard v2 of 2025, has been rolling out through 2026. There is no public register and no published deadline for private companies.

So the calendar you build is mostly one you own. That is not a loophole. It is a longer to-do list than a deadline would give you.

The numbers that matter

Third parties were involved in 48 percent of breaches in the Verizon 2026 Data Breach Investigations Report, up 60 percent year over year, which is why the vendor review dates you set yourself matter more than the ones anyone publishes.

The human element was present in 62 percent of breaches in the Verizon 2026 report. A group of three businesses sharing an office floor shares its people, its habits and its inboxes.

Credential abuse accounted for 13 percent of initial access in the Verizon 2026 report, and stolen credentials do not check which emirate the entity is registered in before they are used.

What to do this week

  1. Write the entity map before the date list. One row per legal entity: where it is licensed, which regulator follows from that, what personal or health data it holds, and who owns it by name. The Dubai clinic, the mainland freight arm and the DIFC advisory entity are three different rows and three different answers. (CIS 1 Inventory and Control of Enterprise Assets)
  2. Set your own renewal dates and put them in the calendar with a person attached: PDPL processing records reviewed each March, health information access reviews each quarter for the clinic, DIFC records reviewed each June. A self-set date you keep beats a published date you did not know about. (CIS 3 Data Protection)
  3. Build the vendor list and give each contract a review month. The HR system, the practice management software, the customs broker's portal, the cloud accounting package, the IT support company. Ask each one where the data is stored and get the answer in writing. (CIS 15 Service Provider Management)
  4. Book the connection and standards work as a project, not a date. NABIDH connection requirements for the clinic and ADHICS v2 controls for anyone operating in Abu Dhabi are checklists with sequences, and both take longer than a quarter if the systems are old. (CIS 3 Data Protection)
  5. Patch on a cycle you can prove, monthly for servers and endpoints and immediately for anything reachable from the internet, and write the cycle down. When a regulator or a customer asks how you manage vulnerabilities, the answer is a schedule and a record, not a product name. (CIS 7 Continuous Vulnerability Management)
  6. Leave one line on the calendar blank on purpose, labelled NCAP, with a named person who checks the Cybersecurity Council's announcements each month. Blank is the honest entry. Inventing a date and planning around it is worse than admitting the date is not published. (CIS 1 Inventory and Control of Enterprise Assets)

Where AccuSights fits

We build the entity map and assess each part of a group against the regulators that actually apply, PDPL, ADHICS, NABIDH, DESC or DIFC, and hand back one calendar with owners rather than five overlapping ones. Our read-only compliance agent gives continuous insight across your cloud and infrastructure, so the reviews you scheduled are informed by what is really running. We have no access and we do not remediate. You or your IT partner fix; we show you where. A falcon singles out one thing and holds it. Our regulatory calendar tracks what is published.

Questions people ask

When does NCAP compliance become mandatory for a private company? No deadline has been published, and there is no public register to check. The National Cybersecurity Assurance Programme sits with the UAE Cybersecurity Council, is built on the UAE Information Assurance Standard v2 of 2025, and has been rolling out through 2026. The sensible reading is to build against the IA Standard controls now, because they are published and stable, and treat the programme's timing as an announcement you will act on when it arrives.

Does the DIFC Data Protection Law apply to my company if the office is in Business Bay? No. The DIFC law applies to entities established in the DIFC and to processing carried out there, and ADGM has its own regime on Al Maryah Island. A Business Bay company falls under the federal PDPL, plus whatever sector rules follow from what it does. Groups with entities in more than one place end up with two or three regimes at once, which is a mapping exercise before it is a technology one.

When is GISEC Global 2027? The 2027 dates have not been published as this is written. GISEC Global 2026 ran from 16 to 18 September 2026 in Dubai, and the show has been the practical place to meet regulators, sector bodies and assessors in one week. Keep a placeholder in the calendar and confirm the dates from the organiser rather than from a vendor email.

The best compliance calendar in this country is short, honest about what is not published, and has a name next to every line. Build that one.

Questions people ask

When does NCAP compliance become mandatory for a private company?

No deadline has been published, and there is no public register to check. The National Cybersecurity Assurance Programme sits with the UAE Cybersecurity Council, is built on the UAE Information Assurance Standard v2 of 2025, and has been rolling out through 2026. The sensible reading is to build against the IA Standard controls now, because they are published and stable, and treat the programme's timing as an announcement you will act on when it arrives.

Does the DIFC Data Protection Law apply to my company if the office is in Business Bay?

No. The DIFC law applies to entities established in the DIFC and to processing carried out there, and ADGM has its own regime on Al Maryah Island. A Business Bay company falls under the federal PDPL, plus whatever sector rules follow from what it does. Groups with entities in more than one place end up with two or three regimes at once, which is a mapping exercise before it is a technology one.

When is GISEC Global 2027?

The 2027 dates have not been published as this is written. GISEC Global 2026 ran from 16 to 18 September 2026 in Dubai, and the show has been the practical place to meet regulators, sector bodies and assessors in one week. Keep a placeholder in the calendar and confirm the dates from the organiser rather than from a vendor email.

Controls this post maps to

CIS 1 Inventory and Control of Enterprise AssetsCIS 3 Data ProtectionCIS 15 Service Provider Management

CIS Controls v8.1, the baseline the UAE IA Standard and ADHICS build on. These are the same controls our assessment scores.

Sam Khan, Founder and CEO. CISA and CRISC. More than two decades in financial services security and risk, from the Federal Reserve System to Guggenheim. Reads the week in threats so an owner does not have to. About the team →

Where AccuSights fits

Check, then repeat. We provide read-only insight so you prioritize the right things and keep an eye on them.

We have no access and do not remediate. You or your IT partner fix; we show you where, mapped to your regulators. Thirty minutes with your Risk Assessor draws the map for your organization.

Compliance is not security. The audit is not the exam; the attacker is.