We are exhibiting at GISEC Global 2026 · 16-18 Sept · Expo City DubaiBook a booth session with our CEO
AccuSights
Products
Assess
Comply
Protect
Free Tools
Email Breach Checker
Cyber Hygiene Test
Regulator directory
Regulatory calendar
ADHICS
ADGM
CBUAE
CSC
DFSA
DHA
DHCC
DIFC
DOH
FSRA
NIAF
Malaffi
MOHAP
NABIDH
NCAP
SCA
VARA
Healthcare
Finance
AI & Machine Learning
Defence & Military
Government Contractor
Professional Services
Technology & SaaS
Retail & Hospitality
Real Estate & Construction
Architecture, Design & Construction
Cybersecurity in Dubai
Cybersecurity in Abu Dhabi
Cybersecurity in Sharjah
All emirates
Chambers of Commerce
MSP
Partner Program
About Us
Why AccuSights
Compliance Center
Blog
Threat Dashboard
Threat Headlines
Contact

UAE regulator directory

Every UAE cybersecurity and data regulator, on one page, kept current.

Who is in scope, the current rulebook, the notification window, the duties in plain language and the official link. Verified monthly. The page compliance officers keep open beside the regulator.

Federal law reaches everyone. An emirate authority may reach you on top of it. A free zone may replace parts of both. That stacking is why this is grouped by jurisdiction rather than listed A to Z.

Federal

Applies across all seven emirates, whatever else applies to you.

CSC

UAE Cybersecurity Council

Sets national cybersecurity strategy and issues public threat guidance for every organization in the Emirates.

TDRA / aeCERT

Telecommunications & Digital Government Regulatory Authority

Regulates telecom and digital government; operates aeCERT, the national computer emergency response team, and the UAE Information Assurance standard for critical sectors.

UAE Data Office

UAE Data Office (PDPL)

Federal personal data protection under the PDPL (Federal Decree-Law 45 of 2021): consent, processing, breach duties, and cross-border transfer for nearly every business.

MoHAP

Ministry of Health and Prevention

Federal health ministry; licenses providers in Sharjah and the Northern Emirates and runs the Riayati health information platform.

CBUAE

Central Bank of the UAE

Regulates banks, finance companies, exchange houses, payment providers, stored-value facilities, and insurers, with information security and consumer data duties throughout.

SCA

Securities & Commodities Authority

Regulates onshore capital markets: brokers, fund and asset managers, advisers, listed companies, onshore virtual-asset providers, and robo-advisers, whose rules mandate independent IT audits.

MoET

Ministry of Economy & Tourism (AML supervision)

Supervises designated non-financial businesses for anti-money-laundering: accountants, auditors, corporate service providers, real estate brokers, and dealers, including goAML registration and annual risk assessments.

Official site

FTA

Federal Tax Authority

Registers and supervises tax agents, whose duties include taxpayer-data confidentiality and portal credential security.

Official site

Abu Dhabi

The emirate's own authorities, on top of federal law.

DIFC

A financial free zone with its own laws and its own regulator.

DFSA

Dubai Financial Services Authority (DIFC)

Regulates financial firms in the DIFC free zone. Its GEN 5.5 rules require a written cyber risk framework, an incident response plan reviewed at least annually, and 72-hour incident notification.

DIFC DP

DIFC Commissioner of Data Protection

Administers the DIFC Data Protection Law (DPL 2020), including annual registration renewal for every DIFC entity that processes personal data.

Official site

ADGM

A financial free zone with its own laws and its own regulator.

New in 2026

NCAP: the National Cyber Accreditation Program

Accreditation of government entities, cybersecurity providers and training organizations against the UAE IA Standard. What is public, who it touches, and the four-step readiness path.

NCAP readiness

A note on authority: the regulator, auditor or certifying body has the final say on whether you comply. Much regulator language is still being clarified, and we say so rather than guess. We help interpret the requirements, scope what applies to you, gap-assess against what is published today, and keep you compliance-ready and secure as the guidance evolves. We hold no regulatory authority and do not certify; where a regulator has its own process, that process governs.

Questions we get

The standards, the clocks and the difference between them.

What is the UAE IA Standard v2?

The UAE Information Assurance Standard Version 2, published by the Cyber Security Council in September 2025, replaces the older NESA IAS. It reorganises controls into 15 families, 134 controls and 449 sub-controls, aligned to ISO 27001:2022 and adding cloud, IoT, AI and post-quantum topics. It is mandatory for government entities and critical infrastructure and is the reference for NCAP and the sector regulators.

What is ADHICS?

The Abu Dhabi Healthcare Information and Cyber Security Standard is the Department of Health Abu Dhabi’s mandatory cybersecurity standard for every hospital, clinic, pharmacy, insurer and health service provider handling patient data in the emirate. Version 2.0 took effect in August 2024. It runs across eleven control domains and three tiers (Basic, Transitional, Advanced), and compliance is tied to facility licensing.

What is NABIDH?

NABIDH (National Backbone for Integrated Dubai Health) is the Dubai Health Authority’s unified electronic health record exchange. Every DHA-licensed facility must connect to it to obtain or renew its licence, using an approved EMR that meets the NABIDH minimum data set and HL7/FHIR messaging standards. Connection brings security duties: access control, audit logs, consent handling and secure integration.

What is the 72-hour rule in ADGM?

Under Article 32 of the ADGM Data Protection Regulations 2021, a controller must notify the ADGM Office of Data Protection of a personal data breach without undue delay and, where feasible, within 72 hours of becoming aware of it, or explain the delay. Affected individuals must also be told when the breach is likely to cause high risk to them. Processors notify controllers without undue delay.

How does DIFC breach notification differ?

DIFC Law No. 5 of 2020 does not use a fixed 72-hour clock. Article 41 requires notification to the Commissioner as soon as practicable when a breach compromises confidentiality, security or privacy, and Article 42 requires telling affected individuals when the risk to them is high. The practical answer is the same in both zones: decide in advance who makes the call and how the clock is evidenced.

How fast do financial firms have to report a cyber incident?

VARA’s Technology and Information Rulebook and the FSRA cyber rules effective January 31, 2026 require notification of material incidents within 24 hours, weekends included. DFSA’s Cyber Risk Management rules, mandatory since January 1, 2024, allow up to 72 hours. CBUAE requires prompt reporting under its Information Assurance framework. A firm under more than one regulator meets the shortest clock.

Is NCAP the same as IA compliance?

No. The IA Standard is the control framework an organisation implements. NCAP, the National Cyber Accreditation Program, accredits the service providers that help them do it. An organisation complies with IA; a provider is accredited under NCAP.

Book a demo

See your obligations as one program.

Tell us your sector and we will show you which UAE regulations apply to you, where the gaps are, and how one control set covers them all.

The team replies within one business day, in English or Arabic.