CRYPTOGRAPHY COMPLIANCE / ADVANCED

UAE And GCC Cryptography Rules, And One Inventory For Many Regulators

The UAE National Encryption Policy and SAMA's quantum circular set the Gulf's direction on cryptography. This article explains both, then shows how one inventory can answer several regulators.

Checked against primary sources and independently reviewed on . Sources are listed at the end.

The Gulf states have moved quickly on cryptography and quantum readiness. The UAE has a national encryption policy with a post-quantum section, and Saudi Arabia’s central bank has set dated quantum requirements for the financial institutions it supervises. Many organisations in the region also answer to PCI DSS, and some to DORA through EU operations or customers.

This article covers the cryptography and quantum rules in the UAE and Saudi Arabia as of October 2026. It then closes the section with a practical question: how one well-built cryptographic inventory can serve several regulators at once. For the wider regulatory picture in each country, see Regulations Across Regions.

The UAE National Encryption Policy

The UAE Cyber Security Council issued the National Encryption Policy, version 1.0, dated September 2025.1 Its approval, together with an executive regulation, was announced on 27 November 2025.2 The policy sets encryption controls for data at rest and in motion, and requirements for key management, post-quantum cryptography, implementation and performance monitoring.3

Who it applies to. The policy text applies to federal ministries and authorities and to non-government critical information infrastructure (CII) entities. Where an emirate runs its own CII protection programme, the emirate lead handles applicability, enforcement and monitoring for emirate government entities and non-government CII entities. Where no such programme exists, the policy applies to emirate government entities directly.1

What the post-quantum section asks. Section 6 aims to prepare entities to protect information not classified as open from future quantum threats. Entities must:1

  • keep a list of every system and application that relies on public-key cryptography;
  • test new post-quantum standards in a lab before using them in production;
  • create a transition plan that analyses dependencies affecting the order of migration, retires technology that will become unsupported and validates new products;
  • adopt purchasing policies for post-quantum cryptography, which should cover new service levels and vendor surveys;
  • alert IT departments and vendors to the coming transition, and train staff.

How compliance is checked. The policy says its requirements are built into the UAE Information Assurance Standard, and that entities are expected to report compliance through the National Cyber Index Platform.1 The policy text reviewed for this article does not set a migration deadline.

How the standard carries it. In the UAE Information Assurance Standard, version 2.1, dated November 2025, the matching control is T3.4.4. Unlike the standard’s other cryptography controls, it applies according to each entity’s risk assessment rather than in every case. Its sub-controls cover the public-key inventory, lab testing and staff training, and as with any risk-based control an entity may skip or vary a sub-control with documented justification and accepted risk. The transition and adoption plans appear only as implementation guidance.4 Separately, the National IoT Security Policy, version 2.0, requires IoT consumers in its scope to take a risk-based approach to encryption that protects communications against classic and quantum threats.5

In May 2026 the Cyber Security Council announced a partnership with QuantumGate on a national Crypto Discovery Tool, built to requirements set by the UAE National Cryptography Center. It is designed to discover, inventory and monitor cryptographic assets across critical national infrastructure, as part of the national post-quantum migration programme.6 This is an announcement about national tooling rather than a new obligation.

Saudi Arabia: SAMA And The NCA

SAMA’s circular 482021280 of 27 August 2026 requires supervised financial institutions to make their procedures for identifying and classifying all cryptographic assets accurate and comprehensive by the end of Q4 2026, and to complete an enterprise-level quantum risk assessment with action plans by the end of Q1 2027.8 It also makes quantum risk a standing item for board-level committees. The previous article in this section covers it in more detail.

The National Cybersecurity Authority’s National Cryptographic Standards, NCS-1:2020, issued in July 2020, set minimum cryptographic requirements in the Kingdom. Their section on post-quantum cryptography noted that international standards were not yet available and that post-quantum algorithms would be considered in later versions.9 NIST has since published its main post-quantum standards, FIPS 203, 204 and 205, which US federal guidance now points agencies to, so organisations in scope should watch for a revised edition.10

  1. Upcoming

    Saudi Arabia · Saudi Central Bank (SAMA) Binding

    Ensure procedures identify and classify all cryptographic assets accurately and comprehensively.

    Circular 482021280 on quantum computing risks. Applies to SAMA-regulated financial institutions. Source · Verified 7 Oct 2026

  2. Upcoming

    Saudi Arabia · Saudi Central Bank (SAMA) Binding

    Complete a quantum risk assessment with action plans.

    Circular 482021280 on quantum computing risks. Applies to SAMA-regulated financial institutions. Source · Verified 7 Oct 2026

Countdowns run to the end of each deadline date (UTC) and are calculated in your browser. "Binding" means legally or contractually required; other labels describe supervisory expectations, guidance, drafts or announcements. Always check the source for the current text.

One Inventory, Many Regulators

A firm in Dubai or Riyadh that processes card payments and serves EU clients may face PCI DSS, DORA, SAMA and the UAE policy at once. Each asks for something slightly different, but the underlying data overlaps heavily. Building one inventory with the right fields, and producing different views from it, is far cheaper than answering each framework separately.

The table maps common inventory fields to six frameworks covered in this section. Named means the instrument asks for that information directly. Supports means the field is evidence you would use to meet a broader requirement in that instrument.

Inventory FieldPCI DSS 12.3.3DORA RTS Arts. 6 And 7SAMA 482021280UAE National Encryption PolicyMAS TCRS/2024/01OMB M-26-15
Protocols and cipher suitesNamedSupports encryption in transit rules, Art. 6(2)Supports classification of all cryptographic assetsSupports public-key inventorySupports algorithm fieldNamed: scanners for protocols and cipher suites
Algorithm and key lengthSupports annual reviewSupports selection criteria, Art. 6(3)Supports classificationSupports public-key inventoryNamedSupports identifying quantum-vulnerable algorithms
Purpose and where usedNamedSupports classification-based policy, Art. 6(2)Named: data, systems and services linked to each assetNamed: systems and applicationsNamed: system or applicationSupports central CBOM
Keys and certificatesOutside 12.3.3 itselfNamed: key lifecycle and certificate register, Art. 7Supports classificationSupports key management sectionSupports inventorySupports agile key management
OwnerSupports annual reviewSupports key management controlsSupports committee reportingSupports transition planNamedSupports accountable officials
Data sensitivity and protection periodSupports annual reviewSupports the data classification basis, Art. 6(2)Named: classify by sensitivitySupports transition orderNamedNamed: data sensitive in 2030
Migration prioritySupports annual reviewSupports update provisions, Art. 6(4)Named: plans for priority assetsNamed: transition planNamed: prioritise critical assetsNamed: prioritised migration
Last review dateSupports evidence of the 12-month reviewSupports keeping the register up to dateSupports Q4 2026 and Q1 2027 deadlinesSupports performance monitoringSupports monitoringSupports a continuously updated inventory
One cryptographic inventory mapped to six frameworks. This is the author's mapping for planning purposes, not guidance from any of the regulators named. Check each framework's text for scope.

Sources for the columns: PCI DSS,11 the DORA technical standards,12 SAMA,8 the UAE policy,1 MAS13 and OMB M-26-15.10

Three lessons stand out from the mapping. First, the inventory has to go beyond what any single framework asks for. A PCI-only list of cipher suites misses the keys and certificates DORA names, and a DORA certificate register misses the algorithm detail MAS describes. Second, location and ownership fields do most of the work, because every framework needs to know where cryptography is and who can change it. Third, the review date matters everywhere. Each framework expects the inventory to stay current, whether that means a 12-month PCI DSS cycle, an up-to-date DORA register or SAMA’s dated deadlines.

Footnotes

  1. UAE Cyber Security Council, “National Encryption Policy”, version 1.0, September 2025, sections 1.2, 5, 6, 7 and 8. csc.gov.ae ↩ ↩2 ↩3 ↩4 ↩5

  2. Emirates News Agency (WAM), “UAE announces approval of National Encryption Policy, issuance of executive regulation”, 27 November 2025. wam.ae ↩

  3. The Official Portal of the UAE Government, “National Encryption Policy”, updated 2 July 2026. u.ae ↩

  4. UAE Cyber Security Council, “UAE Information Assurance Standard”, version 2.1, November 2025, sections 2.1 and 3.4, control T3.4.4. csc.gov.ae ↩

  5. UAE Cyber Security Council, “National IoT Security Policy”, version 2.0, September 2025, sections 1.2 and 2.2.2.3. csc.gov.ae ↩

  6. Abu Dhabi Media Office, “UAE Cybersecurity Council partners with QuantumGate to launch Crypto Discovery Tool”, 22 May 2026. mediaoffice.abudhabi ↩

  7. Central Bank of the UAE, Securities and Commodities Authority, Dubai Financial Services Authority and Financial Services Regulatory Authority, “Guidelines for Financial Institutions adopting Enabling Technologies”, issued 15 November 2021, Scope of Application and paragraphs 3.10, 3.48, 3.89 and 3.127, as published in the FSRA Rulebook (en.adgm.thomsonreuters.com); and CBUAE, announcement of 15 November 2021. centralbank.ae ↩

  8. Saudi Central Bank, “Circular 482021280: Enhancement of Operational Resilience to Address Quantum Computing Risks”, 27 August 2026. rulebook.sama.gov.sa ↩ ↩2

  9. National Cybersecurity Authority, “National Cryptographic Standards (NCS-1:2020)”, July 2020, section 7.2. nca.gov.sa ↩

  10. US Office of Management and Budget, “M-26-15: Execution of the Migration to Post-Quantum Cryptography”, including Appendix A, 24 June 2026. whitehouse.gov ↩ ↩2

  11. PCI Security Standards Council, “Payment Card Industry Data Security Standard: Requirements and Testing Procedures”, version 4.0.1, June 2024, requirement 12.3.3. pcisecuritystandards.org ↩

  12. European Commission, “Commission Delegated Regulation (EU) 2024/1774”, Articles 6 and 7, 13 March 2024. eur-lex.europa.eu ↩

  13. Monetary Authority of Singapore, “MAS/TCRS/2024/01: Advisory on Addressing the Cybersecurity Risks Associated with Quantum”, 20 February 2024. mas.gov.sg ↩

Knowledge Hub content is general information. It is not legal advice, a compliance certification, a guarantee of security or a substitute for an assessment of your own systems. Standards and rules change; check the sources for the latest position.