Methodological support and subcontracting through locally accredited providers, within a regulatory framework overseen by the Cybersecurity Council and SIA.
Last updated — August 22, 2026
The federal framework is overseen by the Cybersecurity Council, the Signals Intelligence Agency (SIA, formerly NESA), the Dubai Electronic Security Center (DESC) and the Abu Dhabi Digital Authority (ADDA). Applicable references include the UAE Information Assurance Standards (188 controls), the Dubai Information Security Regulation (ISR), ADHICS for the healthcare sector in Abu Dhabi, and the data protection regimes specific to the free zones (DIFC Data Protection Law, ADGM Data Protection Regulations). The National Cyber Accreditation Programme (NCAP), being rolled out in 2026, governs which providers are authorized to operate on critical information infrastructure.
In this market, EBH Security delivers exclusively through locally accredited subcontracting partners, in line with the applicable regulatory framework.
Regulated segment (NCAP)
Delivery in partnership with a locally accredited provider, ensuring full compliance with the NCAP framework while drawing on EBH Security's expertise
Unregulated segment
Direct engagement possible for entities not subject to NCAP (outside critical information infrastructure)
Languages
English, Arabic, French
On the NCAP-regulated segment — a local accreditation program overseen by UAE authorities and being rolled out in 2026 — EBH Security operates in partnership with locally accredited providers. This approach ensures full compliance with the UAE's accreditation framework while drawing on EBH Security's expertise and methodologies.
Through methodological subcontracting with locally accredited providers, or through direct engagement for organizations outside the scope of critical information infrastructure.
The regime targets critical information infrastructure operators designated by federal and local authorities (Cybersecurity Council, SIA, DESC, ADDA). Companies outside this scope are not subject to the accreditation requirement.
They apply primarily to government entities and critical infrastructure operators; private sector adoption is often voluntary, except in specifically regulated sectors (healthcare in Abu Dhabi via ADHICS, Dubai government entities via the ISR).
Yes, these free zones have their own data protection regimes (DIFC Data Protection Law, ADGM Data Protection Regulations), separate from the federal framework.
Timelines depend on the local accredited partner selected and the scope of the engagement; they are defined jointly during scoping.
Yes, provided the entity is not designated as a critical information infrastructure operator and therefore falls outside the NCAP scope.