xmodoxmodo

Frameworks · Middle East

ADGM GEN 3.5 Cyber Risk

GEN 3.5 Cyber Risk Management is the ADGM Financial Services Regulatory Authority's binding cyber risk framework for Authorised Persons and Recognised Bodies. It was announced in July 2025, with a transition period ending 31 January 2026. It requires board-approved cyber risk governance and classification of ICT assets. Firms must also protect, monitor and test their systems, detect, respond to and recover from incidents, and notify the FSRA of cyber incidents.

Who it applies to

It applies to Authorised Persons and Recognised Bodies regulated by the FSRA in Abu Dhabi Global Market, other than representative offices. Banks, insurers and certain investment account managers have enhanced governance expectations.

Main requirements

Governance

The board approves a cyber risk management framework that forms part of the firm's wider risk framework and defines roles.

Identification & assessment

Firms classify their ICT assets and assess the cyber risk to each of them.

Protection, monitoring & testing

Controls match each asset's classification, and firms monitor and test them regularly.

Detection, response, recovery & notification

Firms maintain incident detection, response and recovery plans, and notify the FSRA of cyber incidents within the period set in the rulebook.

How xmodo supports it

  • 1

    Each part of the framework is set up as a control with an owner, evidence and a calculated compliance status, which the board can review before approval.

  • 2

    ICT asset classifications are held in the asset register and determine which controls apply to each system.

  • 3

    FSRA notification runs in the incident workflow, with the reporting deadline, the submission and the timestamps on one record.

  • 4

    Mapping to DFSA GEN 5.5 supports groups with entities in both centres. Mapping to ISO/IEC 27001 and NIST CSF 2.0 covers the underlying controls.

Related frameworks

ADGM GEN 3.5 Cyber Risk shares requirements with the frameworks below. Controls you already run for any of them count towards ADGM GEN 3.5 Cyber Risk as well.

Frequently asked questions

When did GEN 3.5 become binding?

The FSRA announced the framework on 29 July 2025 and gave firms a transition period to reach full compliance by 31 January 2026. xmodo stores the in-force date on the framework and checks it against the current rulebook.

We are also in the DIFC. Is this the same as DFSA GEN 5.5?

The two sets of rules are similar in structure but are separate laws. xmodo sets up each centre's rules on their own terms. The mapping lets a group implement shared controls once and provide evidence to both regulators.

See how xmodo works for your organisation

Get a demo on the frameworks that apply to you.

Get a demo