Who is in scope
Every organization in the Emirates, with specific expectations for government entities, critical information infrastructure and their suppliers.
CSC
Sets national cybersecurity strategy and issues public threat guidance for every organization in the Emirates.
Every organization in the Emirates, with specific expectations for government entities, critical information infrastructure and their suppliers.
Sector-specific; the Council coordinates national incident response and publishes daily threat bulletins.
National Cybersecurity Strategy 2025 to 2031 (five pillars: governance, protection, innovation, capacity building, partnership); UAE Information Assurance Standard v2; Critical Information Infrastructure Protection Policy; National Cyber Security Policy for AI.
The Council reported countering about 200,000 attacks a day in 2025 and around 600,000 a day in 2026, and the UAE sits in Tier 1 of the ITU Global Cybersecurity Index 2024. Its National Cyber Accreditation Program (NCAP) is rolling out through 2026 for government entities, cybersecurity providers and training organizations; see the NCAP readiness page.
Feb 2025 · in force
Five pillars: governance, protection, innovation, capacity building and partnership. The national direction every sector regulator now builds on.
Source: UAE Cabinet; World Governments Summit 2025
31 Oct 2025 · in force
Certificates on the 2013 edition are no longer valid; surveillance audits now run against the 2022 controls.
Source: ISO / IAF
16 to 18 Sep 2026 · upcoming
The region’s largest cybersecurity gathering, hosted with the Cyber Security Council. AccuSights exhibits; booth sessions can be reserved on the home page.
Source: gisec.ae
It sets national policy and standards and coordinates response; sector regulators apply them to licensed firms. Critical infrastructure entities and their suppliers answer to the Council most directly.
The National Cyber Accreditation Program accredits government entities, cybersecurity service providers and training organizations against baseline requirements drawn from the UAE IA Standard v2. Other businesses meet it through their suppliers and, if they serve government or critical sectors, through the baseline they are asked to show. Our NCAP readiness page explains what is public and how to prepare.
With the essential controls the UAE IA standard and the Council’s guidance both describe: identity and access, patching, backups, email protection and logging. Our free assessment scores you against exactly that baseline.
Summary for orientation, with attribution to the regulator, last checked September 2026. The regulator's own publications govern; consult them and your advisers for decisions. Where this page and the instrument differ, follow the instrument and tell us, so we can fix it.
A note on authority: the regulator, auditor or certifying body has the final say on whether you comply. Much regulator language is still being clarified, and we say so rather than guess. We help interpret the requirements, scope what applies to you, gap-assess against what is published today, and keep you compliance-ready and secure as the guidance evolves. We hold no regulatory authority and do not certify; where a regulator has its own process, that process governs.
Book a demo
Tell us your sector and we will show you which UAE regulations apply to you, where the gaps are, and how one control set covers them all.