We are exhibiting at GISEC Global 2026 · 16-18 Sept · Expo City DubaiBook a booth session with our CEO
AccuSights
Products
Assess
Comply
Protect
Free Tools
Email Breach Checker
Cyber Hygiene Test
Regulator directory
Regulatory calendar
ADHICS
ADGM
CBUAE
CSC
DFSA
DHA
DHCC
DIFC
DOH
FSRA
NIAF
Malaffi
MOHAP
NABIDH
NCAP
SCA
VARA
Healthcare
Finance
AI & Machine Learning
Defence & Military
Government Contractor
Professional Services
Technology & SaaS
Retail & Hospitality
Real Estate & Construction
Architecture, Design & Construction
Cybersecurity in Dubai
Cybersecurity in Abu Dhabi
Cybersecurity in Sharjah
All emirates
Chambers of Commerce
MSP
Partner Program
About Us
Why AccuSights
Compliance Center
Blog
Threat Dashboard
Threat Headlines
Contact

CSC

UAE Cybersecurity Council

Sets national cybersecurity strategy and issues public threat guidance for every organization in the Emirates.

Last verified: September 2026Official site

Who is in scope

Every organization in the Emirates, with specific expectations for government entities, critical information infrastructure and their suppliers.

Notification window

Sector-specific; the Council coordinates national incident response and publishes daily threat bulletins.

Current instrument

National Cybersecurity Strategy 2025 to 2031 (five pillars: governance, protection, innovation, capacity building, partnership); UAE Information Assurance Standard v2; Critical Information Infrastructure Protection Policy; National Cyber Security Policy for AI.

The duties, in plain language

  • Operate a control baseline aligned to the UAE IA standard, scaled to your criticality.
  • Participate in sector drills and threat-intelligence sharing where designated.
  • Report significant incidents through the national channels and cooperate with aeCERT.

Where this stands

The Council reported countering about 200,000 attacks a day in 2025 and around 600,000 a day in 2026, and the UAE sits in Tier 1 of the ITU Global Cybersecurity Index 2024. Its National Cyber Accreditation Program (NCAP) is rolling out through 2026 for government entities, cybersecurity providers and training organizations; see the NCAP readiness page.

Dates on this regulator's calendar

Feb 2025 · in force

National Cybersecurity Strategy 2025 to 2031 announced

Five pillars: governance, protection, innovation, capacity building and partnership. The national direction every sector regulator now builds on.

Source: UAE Cabinet; World Governments Summit 2025

31 Oct 2025 · in force

ISO/IEC 27001:2013 to 2022 transition closed

Certificates on the 2013 edition are no longer valid; surveillance audits now run against the 2022 controls.

Source: ISO / IAF

16 to 18 Sep 2026 · upcoming

GISEC Global 2026, Dubai Exhibition Centre

The region’s largest cybersecurity gathering, hosted with the Cyber Security Council. AccuSights exhibits; booth sessions can be reserved on the home page.

Source: gisec.ae

Questions we get

Does the Cyber Security Council regulate private companies directly?

It sets national policy and standards and coordinates response; sector regulators apply them to licensed firms. Critical infrastructure entities and their suppliers answer to the Council most directly.

What is NCAP and does it apply to us?

The National Cyber Accreditation Program accredits government entities, cybersecurity service providers and training organizations against baseline requirements drawn from the UAE IA Standard v2. Other businesses meet it through their suppliers and, if they serve government or critical sectors, through the baseline they are asked to show. Our NCAP readiness page explains what is public and how to prepare.

Where does a business start?

With the essential controls the UAE IA standard and the Council’s guidance both describe: identity and access, patching, backups, email protection and logging. Our free assessment scores you against exactly that baseline.

Summary for orientation, with attribution to the regulator, last checked September 2026. The regulator's own publications govern; consult them and your advisers for decisions. Where this page and the instrument differ, follow the instrument and tell us, so we can fix it.

A note on authority: the regulator, auditor or certifying body has the final say on whether you comply. Much regulator language is still being clarified, and we say so rather than guess. We help interpret the requirements, scope what applies to you, gap-assess against what is published today, and keep you compliance-ready and secure as the guidance evolves. We hold no regulatory authority and do not certify; where a regulator has its own process, that process governs.

Book a demo

See your obligations as one program.

Tell us your sector and we will show you which UAE regulations apply to you, where the gaps are, and how one control set covers them all.

The team replies within one business day, in English or Arabic.