NCAP · National Cyber Accreditation Program · UAE Cyber Security Council
NCAP in the UAE: what the National Cyber Accreditation Program is, who it touches, and how to be ready.
The Cyber Security Council’s National Cyber Accreditation Program sets one framework for evaluating, accrediting and certifying entities against baseline cybersecurity requirements, so that government bodies and critical operators work only with providers who meet them. It rides on the UAE Information Assurance Standard and the National Cybersecurity Strategy 2025 to 2031. If you serve government or critical infrastructure, or you sell cybersecurity services and training in the Emirates, 2026 is the year to be ready.
The facts, verified 2 September 2026
What NCAP is, and what it is not.
What it is
A framework for consistent evaluation, accreditation and certification of entities against baseline cybersecurity requirements, run by the UAE Cyber Security Council.
Who it covers
Government entities, cybersecurity service providers, and cybersecurity training organizations. Businesses that serve government or critical infrastructure are affected as buyers: they will work with accredited providers.
What it builds on
The UAE Information Assurance Standard v2, issued by the Council in 2025 (15 families, 134 controls, 449 sub-controls, with "always applicable" and risk-based tiers), integrated with the National Cyber Risk Management Framework.
Status
A Council program under the National Cyber Security Strategy 2025 to 2031, approved by Cabinet in February 2025. Consultancies report rollout during 2026 that begins to restrict the use of unaccredited providers for critical information infrastructure. Deadlines, phases, assessor lists and fees are not yet public; we say so rather than guess.
Not to be confused with
NIAP, the Council’s National Information Assurance Platform (a monitoring and scoring platform, not an accreditation); DESC Cyber Force, Dubai’s provider certification for Dubai government work; ADHICS, the Abu Dhabi healthcare standard; and the several other things called NCAP online, from car safety to aerial photography.
Who needs to be ready
Two groups, two readiness paths, one evidence set.
Government entities and critical operators
You will be expected to demonstrate baseline conformance and to work with accredited providers.
- Know which of your vendors provide cybersecurity services and which will need accreditation
- Hold your own IA Standard v2 baseline evidence, current and provable
- Have the supply-chain clauses ready for contracts renewing in 2026 and 2027
Cybersecurity service providers, MSPs, testers, trainers
Accreditation becomes the ticket to government and critical-infrastructure work.
- Map your controls and delivery practices to the IA Standard v2 families
- Close the gaps with evidence an assessor would accept
- Keep the evidence continuous so re-accreditation is a report, not a project
The readiness path
Scope, baseline, evidence, continuous. Four steps, no surprises at the review.
Which category you fall into, which services and systems are in scope, and which customers will ask first.
Your position against the IA Standard v2 families, with the always-applicable controls first.
One evidence set, collected once, mapped to NCAP, the IA Standard and any sector rulebook you already answer to.
The read-only compliance agent keeps every control proven, so the accreditation review finds nothing new.
Questions people ask about NCAP
Is NCAP mandatory?
Does every company in the UAE need NCAP accreditation?
How does NCAP relate to the UAE IA Standard?
Is my MSSP or penetration tester NCAP-accredited?
We already hold ISO 27001. Does that help?
What does AccuSights do here?
Sources: u.ae: National Cyber Security Accreditation Program · UAE Cyber Security Council · UAE Cabinet: National Cybersecurity Strategy approval. We describe what is published; we do not speculate about enforcement.
A note on authority: the regulator, auditor or certifying body has the final say on whether you comply. Much regulator language is still being clarified, and we say so rather than guess. We help interpret the requirements, scope what applies to you, gap-assess against what is published today, and keep you compliance-ready and secure as the guidance evolves. We hold no regulatory authority and do not certify; where a regulator has its own process, that process governs.
Get your NCAP readiness plan.
Tell us which group you are in and we will send the readiness checklist for it, then offer thirty minutes with an engineer to turn it into a plan with a fixed fee.