CYBER · PRIVACY · DIGITAL TRUSTPowered by Falconry360 Book a working session

Home/Markets/United Arab Emirates

Market pack

United Arab Emirates

Federal, emirate-level and financial free zone regimes apply at the same time, and they do not align neatly. The platform holds one control set and maps it across all of them.

PRIMARY AUTHORITIES
UAE Cyber Security Council, CBUAE, ADGM, DIFC
INSTRUMENTS IN THIS PACK
9 national and sector, plus 13 international standards
CONTRACTING
Registered UAE entities, onshore and in ADGM. UAE clients contract locally.

Regulatory register

What applies, to whom, and what the platform does about it. Indicative and maintained as the instruments change — applicability is confirmed per client during scoping.

United Arab Emirates — national and sector regulation
Authority or instrumentWhat it isWho it applies toWhat the platform does
UAE Cyber Security CouncilInformation Assurance Standards; National Cybersecurity StrategyFederal entities and critical national infrastructureIAS control mapping, maturity position and compliance evidence maintained continuously
Central Bank of the UAEInformation Security requirements; Consumer Protection Regulation and Standards; business continuity and outsourcing expectationsLicensed financial institutionsControl mapping, third-party and outsourcing registers, incident notification workflow, resilience testing evidence
Federal Decree-Law No. 45 of 2021Personal Data Protection LawControllers and processors operating onshoreRecords of processing, lawful basis, data subject rights workflow, cross-border transfer register, breach handling
ADGMData Protection Regulations 2021; FSRA technology and outsourcing expectationsADGM-registered entities and FSRA-regulated firmsSeparate privacy pack with its own notification timescales and registration obligations
DIFCData Protection Law No. 5 of 2020 and Regulations; DFSA technology risk expectationsDIFC-registered entities and DFSA-regulated firmsSeparate privacy pack, including the DIFC-specific accountability and transfer provisions
Dubai Electronic Security CenterInformation Security RegulationDubai government entities and designated Dubai-based organisationsISR control mapping and evidence, run alongside the federal standard rather than instead of it
Department of Health — Abu DhabiADHICS healthcare information and cyber security standardHealthcare providers and payers in Abu DhabiSector control pack mapped to the same underlying control library
NCEMANCEMA 7000 business continuity standardEntities within the national emergency management frameworkContinuity programme, BIA and exercise evidence aligned to the standard
Securities and Commodities AuthorityTechnology and cyber requirements for licensed market participantsOnshore capital markets firmsControl and reporting obligations folded into the same register
International standards operating alongside the national regimes
StandardScopeHow it is used
ISO/IEC 27001:2022 and 27002Information security management system and control setCertification readiness, live Statement of Applicability, continuous gap position
ISO/IEC 27701Privacy information managementExtends the ISMS control set with privacy-specific controls and DPO workflow
ISO/IEC 27017 and 27018Cloud security and cloud personal dataApplied where the estate is cloud-hosted or cloud-delivered
ISO 22301Business continuity managementBIA, recovery objectives, plan currency and exercise evidence
ISO/IEC 42001:2023AI management systemAI inventory, impact assessment and model governance
NIST CSF 2.0Cybersecurity frameworkUsed as the neutral spine when several national regimes apply at once
NIST SP 800-53 Rev. 5Control catalogueDepth mapping where a client's control set is US-derived
CIS Controls v8Prioritised technical control setCommon baseline for technology teams
COBIT 2019Technology governanceUsed in the Govern pillar for IT and digital governance structures
SOC 2Service organisation controlsTrust services criteria for clients who serve enterprise customers
PCI DSS 4.0Payment card securityApplied where card data is in scope
IEC 62443Industrial automation and control systemsApplied to OT estates alongside the national OT controls
Open FAIRRisk quantification taxonomyThe quantification method used throughout the Anticipate pillar

Hosting and contracting

Settle residency before tenant design. It is the item most often left until too late.

Data residency

Onshore UAE hosting is available and is the default for federal government, sovereign and government-related entities. ADGM and DIFC clients should expect residency to be tested against their own regulator's outsourcing and cloud expectations.

Contracting entity

Registered UAE entities, onshore and in ADGM. UAE clients contract locally.

How Falconry360 is hosted and secured

THE UAE PICTURE

Federal, emirate and financial free zone regimes apply at the same time, and they do not align neatly.

The UAE is the market where most groups discover that compliance is not one programme. A single group can sit under federal law, an emirate-level regulation and a free zone regime simultaneously — with three different privacy laws and three different notification clocks.

What is different here

  • Three privacy regimes in one country. Federal Decree-Law 45 of 2021 onshore, the ADGM Data Protection Regulations 2021, and DIFC Data Protection Law 5 of 2020. A group with entities in two of them needs one privacy operating model that applies the right rules to the right processing.
  • Emirate-level standards sit on top of federal ones. The Dubai Electronic Security Center's ISR for Dubai government and designated entities; ADHICS for Abu Dhabi healthcare. These run alongside the national standard, not instead of it.
  • Free zone supervisors have their own technology expectations. FSRA and DFSA set outsourcing, cloud and technology risk requirements distinct from CBUAE's, and a firm in ADGM or DIFC answers to those.
  • Sovereign and government-related entities carry an extra layer. Classification, residency and reporting obligations that a private-sector organisation of the same size does not face.
  • It is the natural group headquarters. Which means the UAE entity often carries consolidated oversight for subsidiaries in four other markets — a reporting problem before it is a control problem.

What a first engagement usually looks like

Indicative. Scope, estate size and the number of regimes in play move the dates.

  • Weeks 1–3 · Which regimes actually apply

    Map entities to regimes. Most groups are surprised by at least one obligation they did not know they carried, and by at least one they have been meeting unnecessarily.

  • Weeks 4–8 · One control set, several regimes

    A single normalised control library mapped to the UAE Information Assurance Standards, the applicable emirate standard, the sector supervisor's requirements and the relevant privacy regime — tested once.

  • Weeks 9–14 · Privacy operating model

    Records of processing bound to the governing regime per activity, rights workflow with the correct statutory clock, and a transfer register that reflects ADGM and DIFC conditions rather than federal ones by default.

  • Ongoing · Group oversight

    Consolidated exposure and per-entity regulatory position from one tenant, so a group board sees the whole picture and each entity board sees its own.

Falconry holds registered UAE entities, onshore and in ADGM. UAE clients contract locally.

Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.