Suspect a breach? Report it immediately — response within 1 hour.Report an incident

Cybersecurity services — United Arab Emirates

Methodological support and subcontracting through locally accredited providers, within a regulatory framework overseen by the Cybersecurity Council and SIA.

Last updatedAugust 22, 2026

The local regulatory framework

The federal framework is overseen by the Cybersecurity Council, the Signals Intelligence Agency (SIA, formerly NESA), the Dubai Electronic Security Center (DESC) and the Abu Dhabi Digital Authority (ADDA). Applicable references include the UAE Information Assurance Standards (188 controls), the Dubai Information Security Regulation (ISR), ADHICS for the healthcare sector in Abu Dhabi, and the data protection regimes specific to the free zones (DIFC Data Protection Law, ADGM Data Protection Regulations). The National Cyber Accreditation Programme (NCAP), being rolled out in 2026, governs which providers are authorized to operate on critical information infrastructure.

Concrete obligations

Compliance with the UAE Information Assurance Standards (188 controls) for government entities and critical infrastructure operators

Mandatory NCAP accreditation for any provider operating on critical information infrastructure, a program being rolled out in 2026

Compliance with the Dubai Information Security Regulation (ISR) for entities under the Dubai government

Application of ADHICS for healthcare entities in the Emirate of Abu Dhabi

Compliance with free zone data protection regimes (DIFC Data Protection Law, ADGM Data Protection Regulations) for entities registered there

Delivered through subcontracting

In this market, EBH Security delivers exclusively through locally accredited subcontracting partners, in line with the applicable regulatory framework.

Priority sectors

FinanceEnergyHealthcare (Abu Dhabi)

Delivery modalities

Regulated segment (NCAP)

Delivery in partnership with a locally accredited provider, ensuring full compliance with the NCAP framework while drawing on EBH Security's expertise

Unregulated segment

Direct engagement possible for entities not subject to NCAP (outside critical information infrastructure)

Languages

English, Arabic, French

Local FAQ

Does EBH Security hold NCAP accreditation?

On the NCAP-regulated segment — a local accreditation program overseen by UAE authorities and being rolled out in 2026 — EBH Security operates in partnership with locally accredited providers. This approach ensures full compliance with the UAE's accreditation framework while drawing on EBH Security's expertise and methodologies.

How does EBH Security operate in this market?

Through methodological subcontracting with locally accredited providers, or through direct engagement for organizations outside the scope of critical information infrastructure.

Which entities are subject to NCAP?

The regime targets critical information infrastructure operators designated by federal and local authorities (Cybersecurity Council, SIA, DESC, ADDA). Companies outside this scope are not subject to the accreditation requirement.

Do the UAE IA Standards apply to all companies?

They apply primarily to government entities and critical infrastructure operators; private sector adoption is often voluntary, except in specifically regulated sectors (healthcare in Abu Dhabi via ADHICS, Dubai government entities via the ISR).

Does an entity registered in the DIFC or ADGM have specific obligations?

Yes, these free zones have their own data protection regimes (DIFC Data Protection Law, ADGM Data Protection Regulations), separate from the federal framework.

What is the typical timeline for subcontracted support?

Timelines depend on the local accredited partner selected and the scope of the engagement; they are defined jointly during scoping.

Can EBH Security run a direct security audit for a non-critical UAE SME?

Yes, provided the entity is not designated as a critical information infrastructure operator and therefore falls outside the NCAP scope.

Get in touch