Who is in scope
Every authorised firm in the DIFC, from boutique advisers to global banks’ DIFC branches.
DFSA
Regulates financial firms in the DIFC free zone. Its GEN 5.5 rules require a written cyber risk framework, an incident response plan reviewed at least annually, and 72-hour incident notification.
Every authorised firm in the DIFC, from boutique advisers to global banks’ DIFC branches.
72 hours for cyber incidents under GEN 5.5; data breaches to the DIFC Commissioner without undue delay.
DFSA Rulebook GEN 5.5 cyber risk management: a written cyber risk framework, an incident response plan reviewed at least annually, threat-intelligence participation, and 72-hour incident notification. The DIFC Data Protection Law 2020 applies in parallel with annual registration.
No. ISO, NIST or CIS are all accepted; what matters is that the framework is written, owned and operated. We run it on the same control set as your group’s other regimes.
Summary for orientation, with attribution to the regulator, last checked September 2026. The regulator's own publications govern; consult them and your advisers for decisions. Where this page and the instrument differ, follow the instrument and tell us, so we can fix it.
A note on authority: the regulator, auditor or certifying body has the final say on whether you comply. Much regulator language is still being clarified, and we say so rather than guess. We help interpret the requirements, scope what applies to you, gap-assess against what is published today, and keep you compliance-ready and secure as the guidance evolves. We hold no regulatory authority and do not certify; where a regulator has its own process, that process governs.
Book a demo
Tell us your sector and we will show you which UAE regulations apply to you, where the gaps are, and how one control set covers them all.