Frameworks · United Arab Emirates
UAE frameworks by issuer and entity type
Federal, emirate, free-zone and central bank regulations differ in issuer, scope and reporting deadline. xmodo sets up each one under its official title and edition, and one control can serve all of them.
Four layers
The regulations that apply depend on where you are established
A mainland bank, a DIFC fund, an ADGM firm, a Dubai Government entity and an Abu Dhabi hospital answer to different issuers. The four layers below show who issues each regulation. The selector further down lists the frameworks for your entity.
Federal
This layer covers the national information-assurance baseline and the federal data-protection law. The PDPL does not apply in free zones that have their own data-protection law, or to government entities.
Emirate
Dubai has an information-security regulation for government entities and a cloud-provider standard for their suppliers. Abu Dhabi has a standard for anyone handling health information.
Financial free zones
Each financial centre has its own data-protection law and cyber-risk rulebook. Each also has its own commissioner and regulator to administer them.
Central bank and sector regulators
This layer covers the Central Bank's parent risk-management regulation and its technology-risk articles for each licence type. It also covers VARA's rulebook for virtual asset providers and the TDRA's regulations for telecom licensees.
Frameworks by entity type
Select your entity type to see the frameworks that apply
This list is an illustrative starting point and is not legal advice. Your scoping call confirms the regulations that apply to each entity in your group.
The DIFC data-protection law applies instead of the federal PDPL. PCI DSS applies only where cards are handled.
Fintech or asset manager in the DIFC
- 1DFSA GEN 5.5 Cyber Risk
GEN 5.5 Cyber Risk Management is a section of the Dubai Financial Services Authority's General Module. It requires Authorised Persons in the DIFC to establish and maintain a written, board-approved cyber risk management framework. DFSA rule-making instrument RMI361/2023 added it, and it came into force on 1 January 2024.
- 2DIFC Data Protection Law 2020
The Data Protection Law, DIFC Law No. 5 of 2020, as amended, governs how controllers and processors established in the Dubai International Financial Centre process personal data. The DIFC Commissioner of Data Protection administers it.
- 3ISO 27001:2022
ISO 27001:2022 is the international standard for information security management systems. Its Annex A controls cover organisational, people, physical and technological themes. The management system runs continuously, with internal audit and certification.
- 4SOC 2
SOC 2 is the AICPA's attestation framework for service organisations. Reports cover the Trust Services Criteria: security, availability, processing integrity, confidentiality and privacy.
- 5PCI DSS
The Payment Card Industry Data Security Standard is the card brands' security standard for any entity that stores, processes or transmits cardholder data. It is organised into twelve requirement groups.
One control implementation supports every framework above. The mapping between frameworks shows what an existing ISO 27001 or SOC 2 programme already covers before you plan any work.
Frequently asked questions
Does the federal PDPL apply inside the DIFC or ADGM?
No. Federal Decree-Law No. 45 of 2021 does not apply in free zones that have their own data-protection law. A DIFC entity follows DIFC Law No. 5 of 2020, and an ADGM entity follows the ADGM Data Protection Regulations 2021. A group with mainland and free-zone entities applies all three, each to the relevant entity.
Is NESA still a framework?
NESA refers to the earlier framework. The current national baseline is the UAE Information Assurance Standard Version 2.1, issued by the UAE Cyber Security Council in November 2025. xmodo uses the current title and still recognises NESA as an alternative name.
Which DESC standard applies to a cloud provider?
The Cloud Service Provider (CSP) Security Standard applies, and compliance is verified through DESC certification. Dubai Government entities themselves follow the Information Security Regulation Version 3.1.
How do breach notification deadlines differ across the UAE?
ADGM's regulations set 72 hours where feasible. The DIFC law requires notification as soon as practicable. The DFSA requires material cyber incidents to be reported within 72 hours of awareness. xmodo sets up each deadline on the incident record on its own terms.