العربية

Market · United Arab Emirates

Know which of the five UAE registers binds you

The UAE does not have a cyber security regime. It has five, and which of them binds you depends on where you are incorporated and who your customers are — not on where your office is.

Start with the question that actually decides it

Most UAE readiness work goes wrong at the first step, because the firm doing it assumes a federal baseline and then layers emirate rules on top. That is the wrong shape. A DIFC-incorporated fund and an Abu Dhabi hospital share almost no obligations, and neither of them is primarily governed by the federal law.

The question that decides your register is where you are incorporated, and which sector you serve. Everything else follows from that.

The five registers

Reference numbers below are as published by the issuing authority. Where an authority publishes no version number, we say so rather than inventing one.

Federal

Information Assurance Regulation and the federal data law

UAE IAR v1.1Decree-Law 45/2021

The IAR binds government entities and any entity identified as critical under the CIIP Policy — six management and nine technical control families across four priority tiers. The federal data protection law has been in force since January 2022 and reaches processors outside the UAE handling residents' data, but its Executive Regulations still have not been issued, so the penalty regime is not operable.

Who signsRegulator monitors and audits mandated entities; periodic reporting, no fixed cadence in the document.
Dubai

DESC Information Security Regulation and the provider standards

DESC ISRCSP / DC / SOC standards

The ISR binds Dubai government and semi-government entities and extends to their contractors and consultants. Separately, any provider wanting to sell cloud, data centre or SOC services into Dubai government must hold the matching DESC certification. An existing ISO/IEC 27001 certificate — with 27017 evidenced as a cloud extension to it — is widely reported to be recognised without re-audit, but we have not been able to confirm that mechanism against a DESC document, because DESC releases the ISR on email request rather than publishing it. Treat it as likely rather than settled until you have asked DESC directly. ISO/IEC 27002 is the control guidance behind 27001 rather than a standard an organisation can be certified against, so there is no 27002 certificate to present.

Who signsAccredited certification body. Annual surveillance audit, three-yearly recertification.
Abu Dhabi

ADHICS, and the Responsible AI Standard

DOH/SD/ICSO/ADHICS/V2/2024DOH/ST/DDGO/RAI/V1/2025

ADHICS V2 has been effective since August 2024 and binds any entity that generates, accesses, stores, uses, processes or transmits health information in the emirate — facilities, payers, and technology and service providers alike. It is tied to DoH licensing and Malaffi integration, and it mandates an Information Security Governance Committee, a HIIP workgroup and a CISO. The Responsible AI Standard sits alongside it and is the most operationally demanding AI instrument in the country.

Who signsIndependent audits shall be performed at least annually. Compliance due within six months of programme induction.
DIFC

Data Protection Law and Regulation 10

DIFC Law 5/2020 (am. 1/2025)Regulation 10

The July 2025 amendment created a private right of action — data subjects may sue directly in the DIFC Courts for financial loss and for distress, without going through the Commissioner. Regulation 10 governs personal data processed by autonomous and semi-autonomous systems: designated Deployer and Operator roles, registers of use cases, and an Autonomous Systems Officer for high-risk systems. It is the only AI-specific rule in the UAE that binds across sectors rather than inside one — the Abu Dhabi Responsible AI Standard is mandatory too, but only in healthcare.

Who signsSelf-assessed, but the annual assessment of whether a DPO is required is itself an obligation — failing to perform it attracts a fine of up to USD 25,000.
ADGM

Data Protection Regulations

ADGM DPR 2021

Every ADGM-registered entity processing personal data must register as a data controller with the Office of Data Protection and renew annually. Supplementary rules issued in September 2025 clarify the lawful bases for special-category data in insurance and vulnerable-person contexts. Maximum fine USD 28 million.

Who signsAnnual controller registration with the Office of Data Protection.

Health data cannot leave the country

Federal Law 2/2019 prohibits processing or storing health data outside the UAE where the health service is provided in the UAE, reinforced by the Abu Dhabi patient data privacy standard. This is a delivery constraint, not a paperwork one: patient data cannot go onto a foreign consultant's laptop or a foreign-hosted collaboration tool. Any healthcare engagement we take is delivered on client systems, in country. If a firm proposes otherwise, that is the question to ask them.

Where we will tell you to use someone else

Penetration testing and incident response for Dubai government, semi-government and critical infrastructure entities may only be procured from Dubai Cyber Force certified companies — which requires a UAE trade licence covering cyber security, CREST accreditation, and Dubai Police clearance for named consultants. We do not hold that, and we will say so on the first call rather than after the engagement letter. Advisory and GRC work is not caught by it.

What we are engaged to do here

Assessment only. We do not resell products, take vendor commission, or bid for the remediation work arising from our own findings.

01

Register scoping

Establish which of the five registers actually binds you, and stop the work you do not owe. Usually the highest-value half-day of the engagement.

Half day
02

ADHICS readiness

Gap assessment against ADHICS V2 ahead of the annual independent audit, plus the governance structures the standard mandates.

ADHICS V2Malaffi
03

DIFC Regulation 10 readiness

Deployer and Operator designation, use-case registers, and the high-risk route — ahead of the certification requirements anticipated for the regime.

Reg. 10ISO/IEC 42001
04

Outsourced DPO

A named, qualified officer where the role is required and cannot be filled internally, in DIFC, ADGM or under the federal law.

Accredited DPO

Before you brief anyone

Four questions worth asking any UAE adviser

  • Which of the five registers binds us, and on what basis?
  • Who is legally permitted to sign our audit — you, or an accredited body?
  • Where will our data sit during the engagement, and is that lawful for our sector?
  • Do you also sell the remediation you are about to recommend?

Three things commonly got wrong

  • Treating the federal data law as operable. It is in force, but its Executive Regulations have not been issued.
  • Quoting NESA IAS control counts. The verifiable instrument is the IAR v1.1; the widely circulated figures do not appear in any official source.
  • Quoting a DESC ISR version number. DESC publishes the ISR without one and releases documents only on request.

Start with a scoping call

Tell us the entity, the emirate or free zone, and the instrument you are being measured against. If an accredited local assessor is required, you will hear it on the call.