A UAE national accreditation program for cybersecurity providers, rolling out in 2026, that restricts which actors are authorized to work with critical information infrastructure entities.
Last updated — August 22, 2026
Critical information infrastructure entities in the UAE and, indirectly, their entire cybersecurity supplier chain, which must hold NCAP accreditation to operate on this scope.
NCAP is not primarily an obligations text for client entities: it is an accreditation regime that applies to providers themselves. For client organizations, the practical requirement is to audit their cybersecurity supplier chain and confirm that every provider working on the critical scope holds the NCAP accreditation required for the services in question.
Deadlines
Program rollout in 2026; compliance deadlines for entities and their providers are set by the authority in charge of the program according to its implementation timeline.
Sanctions
Sanctions fall under the authority in charge of NCAP; absent accreditation, a non-accredited provider simply loses the ability to legally operate within the regulated scope — in practice, the program's core structural consequence.
Map the cybersecurity supplier chain working within the critical scope
Verify the NCAP accreditation status of every relevant provider
Contractually require accreditation to be maintained over time
Prepare a continuity plan in case a provider loses accreditation
Document supplier-chain compliance for audit purposes
| Framework | Covered |
|---|---|
| nesa-uae-ia | ✓ |
Get the checklist by email.
An accreditation program for cybersecurity providers authorized to work on critical information infrastructure in the UAE, distinct from control frameworks such as UAE IA Standards.
On the segment regulated by NCAP, EBH Security delivers its services through locally accredited providers in the UAE — a deliberate delivery model that combines EBH Security's methodological expertise with the partner's local accreditation for direct work within this scope.
It restricts direct work on the critical infrastructure scope to accredited providers only. Non-accredited actors, including foreign ones, can still contribute as a subcontractor to a locally accredited provider.
By auditing its cybersecurity supplier chain and confirming that every party working on the critical scope holds the required accreditation, rather than seeking an accreditation that does not directly apply to it.