UAE regulator directory
Every UAE cybersecurity and data regulator, on one page, kept current.
Who is in scope, the current rulebook, the notification window, the duties in plain language and the official link. Verified monthly. The page compliance officers keep open beside the regulator.
Federal law reaches everyone. An emirate authority may reach you on top of it. A free zone may replace parts of both. That stacking is why this is grouped by jurisdiction rather than listed A to Z.
Federal
Applies across all seven emirates, whatever else applies to you.
CSC
UAE Cybersecurity Council
Sets national cybersecurity strategy and issues public threat guidance for every organization in the Emirates.
TDRA / aeCERT
Telecommunications & Digital Government Regulatory Authority
Regulates telecom and digital government; operates aeCERT, the national computer emergency response team, and the UAE Information Assurance standard for critical sectors.
UAE Data Office
UAE Data Office (PDPL)
Federal personal data protection under the PDPL (Federal Decree-Law 45 of 2021): consent, processing, breach duties, and cross-border transfer for nearly every business.
MoHAP
Ministry of Health and Prevention
Federal health ministry; licenses providers in Sharjah and the Northern Emirates and runs the Riayati health information platform.
CBUAE
Central Bank of the UAE
Regulates banks, finance companies, exchange houses, payment providers, stored-value facilities, and insurers, with information security and consumer data duties throughout.
SCA
Securities & Commodities Authority
Regulates onshore capital markets: brokers, fund and asset managers, advisers, listed companies, onshore virtual-asset providers, and robo-advisers, whose rules mandate independent IT audits.
MoET
Ministry of Economy & Tourism (AML supervision)
Supervises designated non-financial businesses for anti-money-laundering: accountants, auditors, corporate service providers, real estate brokers, and dealers, including goAML registration and annual risk assessments.
Official siteFTA
Federal Tax Authority
Registers and supervises tax agents, whose duties include taxpayer-data confidentiality and portal credential security.
Official siteAbu Dhabi
The emirate's own authorities, on top of federal law.
DoH
Department of Health, Abu Dhabi
Licenses Abu Dhabi healthcare and mandates ADHICS, the emirate’s healthcare information and cyber security standard, with Malaffi HIE participation.
ADREC
Abu Dhabi Real Estate Centre
Regulates Abu Dhabi real-estate licensing and conduct.
Official siteDubai
The emirate's own authorities, on top of federal law.
DHA
Dubai Health Authority
Licenses Dubai healthcare, runs the NABIDH health information exchange, and sets standards including ST-14 for telehealth and health data.
DHCC / DHCA
Dubai Healthcare City Authority
Free-zone regulator for providers inside Dubai Healthcare City, with its own licensing and data rules layered on Dubai requirements.
Official siteVARA
Virtual Assets Regulatory Authority (Dubai)
Regulates Dubai virtual-asset service providers. Its Technology & Information Rulebook requires independent security audits, penetration tests, tested incident response, and key-management controls.
DESC
Dubai Electronic Security Center
Dubai’s cyber authority. Its ISR v3 standard and CSP certification are mandatory for cloud and service providers that serve Dubai government, with data-residency requirements.
DLD / RERA
Dubai Land Department / RERA
Licenses Dubai real-estate activity: broker registration, project and escrow rules, Mollak for owners’ associations, and transaction reporting duties.
Official siteDIFC
A financial free zone with its own laws and its own regulator.
DFSA
Dubai Financial Services Authority (DIFC)
Regulates financial firms in the DIFC free zone. Its GEN 5.5 rules require a written cyber risk framework, an incident response plan reviewed at least annually, and 72-hour incident notification.
DIFC DP
DIFC Commissioner of Data Protection
Administers the DIFC Data Protection Law (DPL 2020), including annual registration renewal for every DIFC entity that processes personal data.
Official siteADGM
A financial free zone with its own laws and its own regulator.
FSRA
Financial Services Regulatory Authority (ADGM)
Regulates ADGM financial firms. Its Cyber Risk Management Framework, live since 31 January 2026, requires a board-approved program reviewed annually and 24-hour incident notification.
ADGM DP
ADGM Office of Data Protection
Administers ADGM Data Protection Regulations 2021, including annual renewal for registered establishments.
Official siteNew in 2026
NCAP: the National Cyber Accreditation Program
Accreditation of government entities, cybersecurity providers and training organizations against the UAE IA Standard. What is public, who it touches, and the four-step readiness path.
NCAP readiness →A note on authority: the regulator, auditor or certifying body has the final say on whether you comply. Much regulator language is still being clarified, and we say so rather than guess. We help interpret the requirements, scope what applies to you, gap-assess against what is published today, and keep you compliance-ready and secure as the guidance evolves. We hold no regulatory authority and do not certify; where a regulator has its own process, that process governs.
Questions we get
The standards, the clocks and the difference between them.
What is the UAE IA Standard v2?
The UAE Information Assurance Standard Version 2, published by the Cyber Security Council in September 2025, replaces the older NESA IAS. It reorganises controls into 15 families, 134 controls and 449 sub-controls, aligned to ISO 27001:2022 and adding cloud, IoT, AI and post-quantum topics. It is mandatory for government entities and critical infrastructure and is the reference for NCAP and the sector regulators.
What is ADHICS?
The Abu Dhabi Healthcare Information and Cyber Security Standard is the Department of Health Abu Dhabi’s mandatory cybersecurity standard for every hospital, clinic, pharmacy, insurer and health service provider handling patient data in the emirate. Version 2.0 took effect in August 2024. It runs across eleven control domains and three tiers (Basic, Transitional, Advanced), and compliance is tied to facility licensing.
What is NABIDH?
NABIDH (National Backbone for Integrated Dubai Health) is the Dubai Health Authority’s unified electronic health record exchange. Every DHA-licensed facility must connect to it to obtain or renew its licence, using an approved EMR that meets the NABIDH minimum data set and HL7/FHIR messaging standards. Connection brings security duties: access control, audit logs, consent handling and secure integration.
What is the 72-hour rule in ADGM?
Under Article 32 of the ADGM Data Protection Regulations 2021, a controller must notify the ADGM Office of Data Protection of a personal data breach without undue delay and, where feasible, within 72 hours of becoming aware of it, or explain the delay. Affected individuals must also be told when the breach is likely to cause high risk to them. Processors notify controllers without undue delay.
How does DIFC breach notification differ?
DIFC Law No. 5 of 2020 does not use a fixed 72-hour clock. Article 41 requires notification to the Commissioner as soon as practicable when a breach compromises confidentiality, security or privacy, and Article 42 requires telling affected individuals when the risk to them is high. The practical answer is the same in both zones: decide in advance who makes the call and how the clock is evidenced.
How fast do financial firms have to report a cyber incident?
VARA’s Technology and Information Rulebook and the FSRA cyber rules effective January 31, 2026 require notification of material incidents within 24 hours, weekends included. DFSA’s Cyber Risk Management rules, mandatory since January 1, 2024, allow up to 72 hours. CBUAE requires prompt reporting under its Information Assurance framework. A firm under more than one regulator meets the shortest clock.
Is NCAP the same as IA compliance?
No. The IA Standard is the control framework an organisation implements. NCAP, the National Cyber Accreditation Program, accredits the service providers that help them do it. An organisation complies with IA; a provider is accredited under NCAP.
Book a demo
See your obligations as one program.
Tell us your sector and we will show you which UAE regulations apply to you, where the gaps are, and how one control set covers them all.