Suspect a breach? Report it immediately — response within 1 hour.Report an incident

NCAP National Cyber Accreditation Programme (United Arab Emirates)

A UAE national accreditation program for cybersecurity providers, rolling out in 2026, that restricts which actors are authorized to work with critical information infrastructure entities.

Last updatedAugust 22, 2026

Who's affected

Critical information infrastructure entities in the UAE and, indirectly, their entire cybersecurity supplier chain, which must hold NCAP accreditation to operate on this scope.

What the framework requires

NCAP is not primarily an obligations text for client entities: it is an accreditation regime that applies to providers themselves. For client organizations, the practical requirement is to audit their cybersecurity supplier chain and confirm that every provider working on the critical scope holds the NCAP accreditation required for the services in question.

Compliance steps

01

Map the cybersecurity supplier chain working within the critical scope

02

Verify the NCAP accreditation status of every relevant provider

03

Contractually require accreditation to be maintained over time

04

Prepare a continuity plan in case a provider loses accreditation

05

Document supplier-chain compliance for audit purposes

Common mistakes

  • Mistaking NCAP for a simple obligations text aimed at the client entity, when it primarily regulates provider market access
  • Failing to audit tier-2 or tier-3 subcontractors within the security supply chain
  • Discovering a provider's non-accreditation during an inspection rather than beforehand

Cross-mapping to other frameworks (UCM)

FrameworkCovered
nesa-uae-ia

Downloadable resource

Get the checklist by email.

Frequently asked questions

What exactly is NCAP?

An accreditation program for cybersecurity providers authorized to work on critical information infrastructure in the UAE, distinct from control frameworks such as UAE IA Standards.

Is EBH Security NCAP-accredited?

On the segment regulated by NCAP, EBH Security delivers its services through locally accredited providers in the UAE — a deliberate delivery model that combines EBH Security's methodological expertise with the partner's local accreditation for direct work within this scope.

Does NCAP close the UAE market to foreign providers?

It restricts direct work on the critical infrastructure scope to accredited providers only. Non-accredited actors, including foreign ones, can still contribute as a subcontractor to a locally accredited provider.

How should a client entity respond to NCAP?

By auditing its cybersecurity supplier chain and confirming that every party working on the critical scope holds the required accreditation, rather than seeking an accreditation that does not directly apply to it.