Who is in scope
Every FSRA-authorised firm in ADGM, including fintechs and virtual-asset firms licensed there.
FSRA
Regulates ADGM financial firms. Its Cyber Risk Management Framework, live since 31 January 2026, requires a board-approved program reviewed annually and 24-hour incident notification.
Every FSRA-authorised firm in ADGM, including fintechs and virtual-asset firms licensed there.
24 hours for cyber incidents; data breaches under the ADGM regime within 72 hours.
FSRA Cyber Risk Management Framework, in force since 31 January 2026: a board-approved program reviewed annually, incident notification within 24 hours, and related digital-impersonation risk expectations. ADGM Data Protection Regulations 2021 apply in parallel with annual renewal.
31 Jan 2026 · in force
Board-approved program reviewed annually and 24-hour incident notification for every FSRA-authorised firm in ADGM.
Source: ADGM FSRA
The framework is proportionate to your size and activities, but the board-approval, annual review and 24-hour notification duties apply to everyone. Scoping it correctly is the first thing we do.
Summary for orientation, with attribution to the regulator, last checked September 2026. The regulator's own publications govern; consult them and your advisers for decisions. Where this page and the instrument differ, follow the instrument and tell us, so we can fix it.
A note on authority: the regulator, auditor or certifying body has the final say on whether you comply. Much regulator language is still being clarified, and we say so rather than guess. We help interpret the requirements, scope what applies to you, gap-assess against what is published today, and keep you compliance-ready and secure as the guidance evolves. We hold no regulatory authority and do not certify; where a regulator has its own process, that process governs.
Book a demo
Tell us your sector and we will show you which UAE regulations apply to you, where the gaps are, and how one control set covers them all.