We are exhibiting at GISEC Global 2026 · 16-18 Sept · Expo City DubaiBook a booth session with our CEO
AccuSights
Products
Assess
Comply
Protect
Free Tools
Email Breach Checker
Cyber Hygiene Test
Regulator directory
Regulatory calendar
ADHICS
ADGM
CBUAE
CSC
DFSA
DHA
DHCC
DIFC
DOH
FSRA
NIAF
Malaffi
MOHAP
NABIDH
NCAP
SCA
VARA
Healthcare
Finance
AI & Machine Learning
Defence & Military
Government Contractor
Professional Services
Technology & SaaS
Retail & Hospitality
Real Estate & Construction
Architecture, Design & Construction
Cybersecurity in Dubai
Cybersecurity in Abu Dhabi
Cybersecurity in Sharjah
All emirates
Chambers of Commerce
MSP
Partner Program
About Us
Why AccuSights
Compliance Center
Blog
Threat Dashboard
Threat Headlines
Contact

DFSA

Dubai Financial Services Authority (DIFC)

Regulates financial firms in the DIFC free zone. Its GEN 5.5 rules require a written cyber risk framework, an incident response plan reviewed at least annually, and 72-hour incident notification.

Last verified: September 2026Official site

Who is in scope

Every authorised firm in the DIFC, from boutique advisers to global banks’ DIFC branches.

Notification window

72 hours for cyber incidents under GEN 5.5; data breaches to the DIFC Commissioner without undue delay.

Current instrument

DFSA Rulebook GEN 5.5 cyber risk management: a written cyber risk framework, an incident response plan reviewed at least annually, threat-intelligence participation, and 72-hour incident notification. The DIFC Data Protection Law 2020 applies in parallel with annual registration.

The duties, in plain language

  • A cyber risk framework the board owns and reviews.
  • An incident response plan tested before the 72-hour clock ever starts.
  • Annual data protection renewal and rights handling under the DIFC DPL.

Questions we get

Is GEN 5.5 prescriptive about which framework we use?

No. ISO, NIST or CIS are all accepted; what matters is that the framework is written, owned and operated. We run it on the same control set as your group’s other regimes.

Summary for orientation, with attribution to the regulator, last checked September 2026. The regulator's own publications govern; consult them and your advisers for decisions. Where this page and the instrument differ, follow the instrument and tell us, so we can fix it.

A note on authority: the regulator, auditor or certifying body has the final say on whether you comply. Much regulator language is still being clarified, and we say so rather than guess. We help interpret the requirements, scope what applies to you, gap-assess against what is published today, and keep you compliance-ready and secure as the guidance evolves. We hold no regulatory authority and do not certify; where a regulator has its own process, that process governs.

Book a demo

See your obligations as one program.

Tell us your sector and we will show you which UAE regulations apply to you, where the gaps are, and how one control set covers them all.

The team replies within one business day, in English or Arabic.