We are exhibiting at GISEC Global 2026 · 16-18 Sept · Expo City DubaiBook a booth session with our CEO
AccuSights
Products
Assess
Comply
Protect
Free Tools
Email Breach Checker
Cyber Hygiene Test
Regulator directory
Regulatory calendar
ADHICS
ADGM
CBUAE
CSC
DFSA
DHA
DHCC
DIFC
DOH
FSRA
NIAF
Malaffi
MOHAP
NABIDH
NCAP
SCA
VARA
Healthcare
Finance
AI & Machine Learning
Defence & Military
Government Contractor
Professional Services
Technology & SaaS
Retail & Hospitality
Real Estate & Construction
Architecture, Design & Construction
Cybersecurity in Dubai
Cybersecurity in Abu Dhabi
Cybersecurity in Sharjah
All emirates
Chambers of Commerce
MSP
Partner Program
About Us
Why AccuSights
Compliance Center
Blog
Threat Dashboard
Threat Headlines
Contact

NCAP · National Cyber Accreditation Program · UAE Cyber Security Council

NCAP in the UAE: what the National Cyber Accreditation Program is, who it touches, and how to be ready.

The Cyber Security Council’s National Cyber Accreditation Program sets one framework for evaluating, accrediting and certifying entities against baseline cybersecurity requirements, so that government bodies and critical operators work only with providers who meet them. It rides on the UAE Information Assurance Standard and the National Cybersecurity Strategy 2025 to 2031. If you serve government or critical infrastructure, or you sell cybersecurity services and training in the Emirates, 2026 is the year to be ready.

Built on the UAE IA Standard v2 (2025)Named in the National Cyber Security Strategy 2025 to 2031Rolling out through 2026

The facts, verified 2 September 2026

What NCAP is, and what it is not.

What it is

A framework for consistent evaluation, accreditation and certification of entities against baseline cybersecurity requirements, run by the UAE Cyber Security Council.

Who it covers

Government entities, cybersecurity service providers, and cybersecurity training organizations. Businesses that serve government or critical infrastructure are affected as buyers: they will work with accredited providers.

What it builds on

The UAE Information Assurance Standard v2, issued by the Council in 2025 (15 families, 134 controls, 449 sub-controls, with "always applicable" and risk-based tiers), integrated with the National Cyber Risk Management Framework.

Status

A Council program under the National Cyber Security Strategy 2025 to 2031, approved by Cabinet in February 2025. Consultancies report rollout during 2026 that begins to restrict the use of unaccredited providers for critical information infrastructure. Deadlines, phases, assessor lists and fees are not yet public; we say so rather than guess.

Not to be confused with

NIAP, the Council’s National Information Assurance Platform (a monitoring and scoring platform, not an accreditation); DESC Cyber Force, Dubai’s provider certification for Dubai government work; ADHICS, the Abu Dhabi healthcare standard; and the several other things called NCAP online, from car safety to aerial photography.

Who needs to be ready

Two groups, two readiness paths, one evidence set.

Government entities and critical operators

You will be expected to demonstrate baseline conformance and to work with accredited providers.

  • Know which of your vendors provide cybersecurity services and which will need accreditation
  • Hold your own IA Standard v2 baseline evidence, current and provable
  • Have the supply-chain clauses ready for contracts renewing in 2026 and 2027
Audit my providers and my baseline

Cybersecurity service providers, MSPs, testers, trainers

Accreditation becomes the ticket to government and critical-infrastructure work.

  • Map your controls and delivery practices to the IA Standard v2 families
  • Close the gaps with evidence an assessor would accept
  • Keep the evidence continuous so re-accreditation is a report, not a project
Get my provider readiness plan

The readiness path

Scope, baseline, evidence, continuous. Four steps, no surprises at the review.

1Scope

Which category you fall into, which services and systems are in scope, and which customers will ask first.

2Baseline

Your position against the IA Standard v2 families, with the always-applicable controls first.

3Evidence

One evidence set, collected once, mapped to NCAP, the IA Standard and any sector rulebook you already answer to.

4Continuous

The read-only compliance agent keeps every control proven, so the accreditation review finds nothing new.

Questions people ask about NCAP

Is NCAP mandatory?
It is a Council program rather than a federal law. Its effect is practical: government entities and critical operators are expected to work with accredited providers, so for providers it becomes the condition of doing that business. Public deadlines have not been published; we update this page when they are.
Does every company in the UAE need NCAP accreditation?
No. NCAP accredits government entities, cybersecurity providers and training organizations. Other businesses are affected through their suppliers and, if they serve government or critical sectors, through the baseline they are asked to demonstrate.
How does NCAP relate to the UAE IA Standard?
The IA Standard v2 is the control set; NCAP is the accreditation layer that certifies entities against baseline requirements drawn from it. Readiness for one is readiness for the other.
Is my MSSP or penetration tester NCAP-accredited?
No public register has been published yet. Ask the provider for their IA Standard v2 evidence now; accreditation will follow the same baseline.
We already hold ISO 27001. Does that help?
It helps with the management-system discipline and much of the evidence. The IA Standard adds UAE-specific families and always-applicable controls; a mapping closes the difference without repeating the work.
What does AccuSights do here?
We map you to the IA Standard v2 baseline, build your custom critical control framework so one evidence set answers NCAP and every sector rulebook you carry, host it in the platform, and keep it proven with telemetry and the read-only compliance agent. Up to 80% less manual work, and no surprises at the review.

Sources: u.ae: National Cyber Security Accreditation Program · UAE Cyber Security Council · UAE Cabinet: National Cybersecurity Strategy approval. We describe what is published; we do not speculate about enforcement.

A note on authority: the regulator, auditor or certifying body has the final say on whether you comply. Much regulator language is still being clarified, and we say so rather than guess. We help interpret the requirements, scope what applies to you, gap-assess against what is published today, and keep you compliance-ready and secure as the guidance evolves. We hold no regulatory authority and do not certify; where a regulator has its own process, that process governs.

Get your NCAP readiness plan.

Tell us which group you are in and we will send the readiness checklist for it, then offer thirty minutes with an engineer to turn it into a plan with a fixed fee.