Who is in scope
Virtual-asset service providers licensed in Dubai outside the DIFC.
VARA
Regulates Dubai virtual-asset service providers. Its Technology & Information Rulebook requires independent security audits, penetration tests, tested incident response, and key-management controls.
Virtual-asset service providers licensed in Dubai outside the DIFC.
Incident notification to VARA as the rulebook prescribes.
VARA Technology and Information Rulebook: independent security audits, penetration tests, tested incident response, key-management and wallet controls, and technology governance.
Yes. The two rulebooks differ in wording and cadence but converge on the same controls. One mapped set with two calendars is the normal shape for a group like that.
Summary for orientation, with attribution to the regulator, last checked September 2026. The regulator's own publications govern; consult them and your advisers for decisions. Where this page and the instrument differ, follow the instrument and tell us, so we can fix it.
A note on authority: the regulator, auditor or certifying body has the final say on whether you comply. Much regulator language is still being clarified, and we say so rather than guess. We help interpret the requirements, scope what applies to you, gap-assess against what is published today, and keep you compliance-ready and secure as the guidance evolves. We hold no regulatory authority and do not certify; where a regulator has its own process, that process governs.
Book a demo
Tell us your sector and we will show you which UAE regulations apply to you, where the gaps are, and how one control set covers them all.