UAE framework guide · Central Bank of the UAE (CBUAE)
CBUAE cyber security requirements in the UAE
What the Central Bank’s Rulebook asks licensed institutions to have operating: a technology and cyber risk framework, an incident response plan, testing proportionate to the risk, business continuity, and protected consumer data.
Who CBUAE applies to
- Payment Service Providers, under Article 13 (Technology Risk and Information Security) of the Retail Payment Services and Card Schemes Regulation, Circular 15/2021, in force from 6 June 2021, with Annex II as its best-practice guidance.
- All Licensed Financial Institutions, under Article 6 (Protection of Consumer Data and Assets) of the Consumer Protection Regulation, which sets the duties on consumer data.
- Not DIFC or ADGM firms for these instruments: the financial free zones have their own regulators, the DFSA and the FSRA.
What CBUAE asks for
The Central Bank of the UAE cyber and technology-risk requirements, as the regulator publishes it, by theme rather than clause number.
- A technology and cyber security risk management framework
- Article 13 requires a framework that ensures the adequacy of IT controls, cyber resilience, and the quality and security of systems, with adequate skilled resources to identify risk, protect critical services, contain incidents and restore services.
- An incident response plan that isolates and neutralises
- A cyber incident response and management plan to swiftly isolate and neutralise a cyber threat and resume affected services as soon as possible, describing the procedures for plausible threat scenarios.
- Testing proportionate to the risk
- Payment Service Providers above AED 10 million in monthly average transaction value must regularly assess the necessity of penetration and cyber-attack simulation testing, scoped to the risk profile and threat intelligence, covering networks, applications, social engineering and emerging threats, and must mitigate what the testing finds in a timely manner.
- The UAE Information Assurance Standards, at a minimum
- Article 13 states that a Payment Service Provider shall apply and meet at a minimum the UAE Information Assurance Standards, as amended from time to time, which connects this page to the NESA / SIA one.
- Business continuity, IT governance
- A business continuity management programme comprising business impact analysis, recovery strategies, a business continuity plan and alternative sites; and an IT governance framework with an independent technology audit function.
- Consumer data, for every licensed institution
- Article 6 of the Consumer Protection Regulation requires policies and control frameworks for the collection, protection and use of consumer data, a data management control framework able to identify and resolve information security breaches, secured digital channels with detailed activity monitoring, and more than one evidence of identity for online verification.
From requirement to what we run
Each theme, and the service, the technology guide and the portfolio vendors that support it. A mapping, not a compliance claim: the service is what makes the control demonstrable.
Portfolio capabilities that support alignment12
Each row is published on the matching vendor page and reproduced here from the same source. This is a capability map, not compliance advice: it is not a certification, an audit result or a guarantee of coverage, and it does not interpret the regulation. Confirm applicability and scope with the vendor and a qualified compliance advisor before relying on it.
Questions buyers ask
- Which CBUAE instruments carry the cyber requirements?
- The Central Bank regulates through its Rulebook. For payment service providers the specific one is Article 13, Technology Risk and Information Security, of the Retail Payment Services and Card Schemes Regulation (Circular 15/2021, in force from 6 June 2021), with Annex II as its best-practice guidance; it also requires them to apply and meet the UAE Information Assurance Standards at a minimum. For every licensed financial institution, Article 6 of the Consumer Protection Regulation sets the duties on consumer data. Both are linked below.
- Who is in scope?
- Every entity the Central Bank licenses, each under the regulation for its licence. The Article 13 technology-risk requirements apply to Payment Service Providers; the consumer data duties in the Consumer Protection Regulation apply to all Licensed Financial Institutions. Firms in the DIFC and ADGM answer to those zones’ own regulators for these matters.
- What does the regulator expect to see operating?
- A technology and cyber security risk management framework with the skilled resources to run it; an incident response plan that can isolate and neutralise a threat and resume services; testing scoped to the risk profile, with findings mitigated in a timely manner; a business continuity programme with impact analysis, recovery strategies, a plan and alternative sites; an IT governance framework with independent technology audit; and, for consumer data, a control framework that can identify and resolve breaches, secured digital channels with detailed activity monitoring, and multi-factor identity verification online.
- Is annual penetration testing mandatory?
- Article 13 is written as an obligation, for Payment Service Providers above the AED 10 million monthly threshold, to regularly assess the necessity of penetration and cyber-attack simulation testing, with scope set by the cyber risk profile and available threat intelligence and covering networks, applications, social engineering and emerging threats, and to mitigate what it finds in a timely manner. The article does not state a frequency; Annex II carries the best-practice guidance. Retesting, which the VAPT service includes, is how remediation is shown as done rather than logged.
- What counts as active monitoring to an examiner?
- Evidence that detection and response operate, not that tooling is deployed. Verified detections, containment actions taken on approval with their timestamps, and a monthly record of what the SOC saw and did are the artefacts the managed detection and response and SOC services produce as a matter of course.
- Is Protect24x7 approved by the Central Bank?
- No. Protect24x7 holds no Central Bank approval and this page is a capability map, not regulatory advice. The GRC service prepares the gap assessment against the instruments that apply to your licence and the evidence an examination asks for; the managed services are what produce that evidence month by month.
Sources
Every regulatory statement on this page comes from one of these documents. Where they are silent, so is the page.
