xmodoxmodo

Frameworks · Middle East

UAE CIIP Policy 2.0

The Critical Information Infrastructure Protection Policy is issued by the UAE Cyber Security Council and approved by the Cabinet. It sets the baseline for the security and cyber resilience of the nation's critical information infrastructure. It defines one approach to identifying and assessing CII and building the national risk profile across CII sectors. Entities are categorised into groups by how they operate. xmodo sets up the current edition, Version 2.0 of September 2025, as a policy pack alongside the UAE IA Standard.

Who it applies to

It applies to designated critical information infrastructure entities and their sector regulators. The sectors are digital infrastructure, financial services, transport, energy, healthcare, electricity and water, government services, education, space and food, plus any sector the Council determines.

Main requirements

Identification

Entities identify their CII assets and services and confirm their category.

Risk profile

Entities complete an assessment that contributes to the sector and national risk profile.

Baseline security

Entities meet the security and resilience baseline through UAE IA Standard 2.1 controls.

Reporting

Entities report to their sector regulator and the Council as the policy requires.

How xmodo supports it

  • 1

    The policy's baseline requirements link to UAE IA Standard 2.1 controls, so CII designation does not add a second set of controls.

  • 2

    CII assets are flagged in the asset register, which sets the scope for the controls that apply to them.

  • 3

    Reporting duties run through the incident and reporting workflows, and each submission is filed as evidence.

Related frameworks

UAE CIIP Policy 2.0 shares requirements with the frameworks below. Controls you already run for any of them count towards UAE CIIP Policy 2.0 as well.

Frequently asked questions

Is the CIIP Policy a control framework?

It is a policy that sets the approach and the baseline. The controls come from the UAE Information Assurance Standard 2.1, so xmodo sets up the two together and each control appears only once.

See how xmodo works for your organisation

Get a demo on the frameworks that apply to you.

Get a demo