A primary-source-validated registry of UAE cybersecurity and data-protection mandates — the laws, rulebooks, and regulator policies that apply to organizations operating in the UAE.
Published and maintained by nshield.io, a Dubai-based cybersecurity firm with a Silicon Oasis SOC. Licensed CC BY 4.0 — free to use, adapt, and cite with attribution.
Version: v4.1 · As of: 25 July 2026 · Next re-validation: 20 October 2026
| Path | What it is |
|---|---|
mandates/master-registry.md |
All 14 mandates × 12 attributes. The master table. |
mandates/deadline-tracker.md |
Cross-sector deadline view. |
verticals/ |
Per-sector cuts: Finance, Healthcare, Real Estate, Retail, Logistics, Education, Professional Services, Telecom. |
data/regulations.json |
Machine-readable JSON version of the master table — for AI agents and programmatic consumers. |
SOURCES.md |
Primary-source domains and validation method. |
CITATION.md / CITATION.cff |
How to cite this registry (human and machine forms). |
AGENTS.md |
Instructions for AI agents consuming this repo. |
CHANGELOG.md |
Version history and revalidation log. |
- Federal Authority for Artificial Intelligence and Data — new consolidated regulator (Cabinet decision announced 14 June 2026); absorbs the UAE Data Office (PDPL), the AI Office, and TDRA's digital-government sector. Establishing instrument number pending gazette confirmation.
- PDPL Executive Regulations — still not issued as of 25 July 2026. Beware of circulating false claims that they were issued in 2026 (see
SOURCES.md). - DIFC amended Data Protection Regulations (CP3/2026) — AI-systems and certification provisions; enactment expected H2 2026.
- DFSA operational-resilience GEN section (CP170) — final rules expected late 2026.
- National Cyber Accreditation Programme (NCAP) — 2026 rollout; formal accreditation policy awaited on csc.gov.ae.
- Riayati/NUMR integration mandate (MOHAP) — mandate reported, official circular citation pending.
| Mandate | Status | Key date | Sector |
|---|---|---|---|
| Federal Cybercrime Law (Fed. DL 34/2021) | In force | 2 Jan 2022 | All |
| UAE PDPL (Fed. DL 45/2021) | In force · ER pending | Since 2 Jan 2022 | All (mainland) |
| Federal Health Data Law (FL 2/2019) | In force | Since 2019 | Healthcare |
| ADHICS v2.0 | Enforced | Basic Nov 2024 · Advanced May 2025 | Healthcare (Abu Dhabi) |
| NABIDH (DHA policy) | In force | 10 Nov 2024 | Healthcare (Dubai) |
| DIFC DPL (2025 amendments) | In force | 15 Jul 2025 | Finance / Real Estate (DIFC) |
| ADGM DPR | In force | 2021 | Finance / Real Estate (ADGM) |
| ADGM Cyber Risk Mgmt (GEN 3.5) | In force | 31 Jan 2026 | Finance (ADGM entities) |
| DFSA GEN 5.5 (Cyber Risk) | In force | 1 Jan 2024 | Finance (DFSA-authorised) |
| VARA T&I Rulebook | In force | 19 Jun 2025 | Crypto / Virtual Assets |
| TDRA Data Residency | In force | Ongoing | Telecom / ISPs / Cloud |
| CBUAE DL 6/2025 (reconciliation) | Active deadline | 16 Sep 2026 | Finance |
| Child Digital Safety Law | Deadline 2027 | Full compliance 1 Jan 2027 | All digital platforms |
| NCS 2025–2031 | Strategic | Phased through 2031 | All |
See mandates/master-registry.md for full attributes on each row.
- Source: UAE primary-source materials only — regulator websites, official gazettes, and statute text. Not legal newsletters, not vendor blogs.
- Validation: Every row is cross-checked against a primary-source URL. Discrepancies are logged and resolved against the most recent governing document.
- Cadence: Full re-validation every quarter. Next scheduled: 20 October 2026.
- Transparency: Sources and method documented in
SOURCES.md. Change log inCHANGELOG.md.
What this repo is not: legal advice. It's a reference table. Regulatory applicability to a specific organization depends on the entity's structure, licensing, and sector — consult qualified counsel.
This repo is intentionally structured for programmatic consumption. See AGENTS.md for:
- Stable URL conventions
- Schema of
data/regulations.json - Citation format expected by our human audiences
- What to link to when referencing a specific mandate
This repo is the structured data layer. The full UAE Cybersecurity Compliance Registry PDF covers what the data doesn't:
- PDPL "four years late" reframe — why the 2027 framing you've seen is wrong
- CBUAE DL 6/2025 reconciliation — 149-day countdown and what to do first
- NABIDH 24-hour breach procedure — the operational runbook
- Two-regulator overlaps (e.g. DFSA GEN 5.5 + DIFC DPL) and how to sequence compliance
- Penalty reality beyond statutory caps
- How to operationalize each mandate
Get the PDF:
- Email info@nshield.io · subject: "Registry PDF"
- LinkedIn DM: linkedin.com/company/neuralshieldsecurity
The PDF is free. We deliver it personally so we can answer the one question you actually have.
Dubai-headquartered cybersecurity firm serving UAE organizations — regulated and non-regulated. Silicon Oasis SOC, Microsoft Gold Partner, 20+ years of operating history. Clients include Zand (UAE's first digital bank) and Hoxton Capital Management.
- Website: nshield.io
- LinkedIn: linkedin.com/company/neuralshieldsecurity
- GitHub: github.com/nshield-security
CC BY 4.0 — attribution required. Both human citation (CITATION.md) and machine citation (CITATION.cff) formats are provided.