We are exhibiting at GISEC Global 2026 · 16-18 Sept · Expo City DubaiBook a booth session with our CEO
AccuSights
Products
Assess
Comply
Protect
Free Tools
Email Breach Checker
Cyber Hygiene Test
Regulator directory
Regulatory calendar
ADHICS
ADGM
CBUAE
CSC
DFSA
DHA
DHCC
DIFC
DOH
FSRA
NIAF
Malaffi
MOHAP
NABIDH
NCAP
SCA
VARA
Healthcare
Finance
AI & Machine Learning
Defence & Military
Government Contractor
Professional Services
Technology & SaaS
Retail & Hospitality
Real Estate & Construction
Architecture, Design & Construction
Cybersecurity in Dubai
Cybersecurity in Abu Dhabi
Cybersecurity in Sharjah
All emirates
Chambers of Commerce
MSP
Partner Program
About Us
Why AccuSights
Compliance Center
Blog
Threat Dashboard
Threat Headlines
Contact

CBUAE

Central Bank of the UAE

Regulates banks, finance companies, exchange houses, payment providers, stored-value facilities, and insurers, with information security and consumer data duties throughout.

Last verified: September 2026Official site

Who is in scope

Banks, payment service providers, stored-value facilities, exchange houses, finance companies and insurers licensed by the Central Bank.

Notification window

Prompt incident reporting to the Central Bank as the rulebook prescribes for the licence category.

Current instrument

CBUAE Rulebook, including information security and technology risk requirements (Article 13 for relevant licensees), consumer protection standards, and business continuity expectations. Federal Decree-Law 6 of 2025 consolidated the Central Bank’s financial-sector legislation, effective 16 September 2025.

The duties, in plain language

  • Board-level cyber governance and an information security program with independent assurance.
  • Technology risk controls, penetration testing and continuity testing on the prescribed rhythm.
  • Outsourcing and cloud arrangements governed and reported.

Frameworks that satisfy it

Dates on this regulator's calendar

16 Sep 2025 · in force

Federal Decree-Law 6 of 2025 in force

Consolidated the Central Bank’s financial-sector legislation; licensees should confirm their obligations map to the consolidated text.

Source: Central Bank of the UAE

Questions we get

Does the Central Bank accept ISO 27001 as our framework?

ISO 27001 is the common backbone licensees use to meet the rulebook, with PCI DSS where cards flow and SWIFT CSP where connected. The rulebook sets the outcomes; the framework is how you organize the evidence.

Summary for orientation, with attribution to the regulator, last checked September 2026. The regulator's own publications govern; consult them and your advisers for decisions. Where this page and the instrument differ, follow the instrument and tell us, so we can fix it.

A note on authority: the regulator, auditor or certifying body has the final say on whether you comply. Much regulator language is still being clarified, and we say so rather than guess. We help interpret the requirements, scope what applies to you, gap-assess against what is published today, and keep you compliance-ready and secure as the guidance evolves. We hold no regulatory authority and do not certify; where a regulator has its own process, that process governs.

Book a demo

See your obligations as one program.

Tell us your sector and we will show you which UAE regulations apply to you, where the gaps are, and how one control set covers them all.

The team replies within one business day, in English or Arabic.