Ready to Map Your UAE Compliance Obligations?
Get clarity on which federal, emirate-level and sector requirements actually apply to your organization, then a roadmap to close the gaps.
UAE organizations navigate a layered regulatory environment: federal Information Assurance Standards, Dubai-specific requirements, sector regulators, and a federal data protection law with separate free-zone regimes. Cyberox helps map which requirements apply to you and builds a program that satisfies them together.
Last reviewed: September 2026. Verify current requirements against the official regulator before acting — sources linked below.
The federal baseline cybersecurity standard sets Information Assurance Standards (IAS) applicable to critical national infrastructure and government entities across the UAE's emirates. Historically issued under the National Electronic Security Authority (NESA) function, now operating under the UAE's federal security apparatus.
DESC enforces the Dubai Information Security Regulation (ISR) for Dubai government departments and their suppliers, plus a Cloud Service Provider security standard for providers serving Dubai government entities.
CBUAE imposes cybersecurity and technology-risk requirements on licensed banks, finance companies, insurers and payment providers, layered on top of the federal baseline standard.
The UAE's federal Personal Data Protection Law applies across the mainland and free zones without their own regime. 2026 marks a period of full enforcement emphasis, with accountability — documented policies, processing records, and technical/organizational measures — central to demonstrating compliance.
The Dubai International Financial Centre operates under its own Data Protection Law (No. 5 of 2020), and Abu Dhabi Global Market under its 2021 Data Protection Regulations — separate regimes for entities registered in these financial free zones, distinct from the federal PDPL.
UAE data protection implementing regulations remain under development. Confirm current obligations directly with the relevant regulator (federal authority, DESC, CBUAE, DIFC or ADGM as applicable) or legal counsel before finalizing a compliance program.
Whether you're a Dubai government supplier navigating DESC, a CBUAE-licensed institution, or a mainland/free-zone company mapping PDPL obligations — we scope the requirements that actually apply to you first.
Cybersecurity and compliance consulting overview for organizations operating in the UAE.
Learn moreISMS certification that aligns with UAE Information Assurance Standards and CBUAE expectations.
Learn moreDedicated service page for UAE information-security regulation compliance work.
Learn moreGet clarity on which federal, emirate-level and sector requirements actually apply to your organization, then a roadmap to close the gaps.