UAE And GCC Cryptography Rules, And One Inventory For Many Regulators
The UAE National Encryption Policy and SAMA's quantum circular set the Gulf's direction on cryptography. This article explains both, then shows how one inventory can answer several regulators.
Checked against primary sources and independently reviewed on . Sources are listed at the end.
The Gulf states have moved quickly on cryptography and quantum readiness. The UAE has a national encryption policy with a post-quantum section, and Saudi Arabia’s central bank has set dated quantum requirements for the financial institutions it supervises. Many organisations in the region also answer to PCI DSS, and some to DORA through EU operations or customers.
This article covers the cryptography and quantum rules in the UAE and Saudi Arabia as of October 2026. It then closes the section with a practical question: how one well-built cryptographic inventory can serve several regulators at once. For the wider regulatory picture in each country, see Regulations Across Regions.
The UAE National Encryption Policy
The UAE Cyber Security Council issued the National Encryption Policy, version 1.0, dated September 2025.1 Its approval, together with an executive regulation, was announced on 27 November 2025.2 The policy sets encryption controls for data at rest and in motion, and requirements for key management, post-quantum cryptography, implementation and performance monitoring.3
Who it applies to. The policy text applies to federal ministries and authorities and to non-government critical information infrastructure (CII) entities. Where an emirate runs its own CII protection programme, the emirate lead handles applicability, enforcement and monitoring for emirate government entities and non-government CII entities. Where no such programme exists, the policy applies to emirate government entities directly.1
What the post-quantum section asks. Section 6 aims to prepare entities to protect information not classified as open from future quantum threats. Entities must:1
- keep a list of every system and application that relies on public-key cryptography;
- test new post-quantum standards in a lab before using them in production;
- create a transition plan that analyses dependencies affecting the order of migration, retires technology that will become unsupported and validates new products;
- adopt purchasing policies for post-quantum cryptography, which should cover new service levels and vendor surveys;
- alert IT departments and vendors to the coming transition, and train staff.
How compliance is checked. The policy says its requirements are built into the UAE Information Assurance Standard, and that entities are expected to report compliance through the National Cyber Index Platform.1 The policy text reviewed for this article does not set a migration deadline.
How the standard carries it. In the UAE Information Assurance Standard, version 2.1, dated November 2025, the matching control is T3.4.4. Unlike the standard’s other cryptography controls, it applies according to each entity’s risk assessment rather than in every case. Its sub-controls cover the public-key inventory, lab testing and staff training, and as with any risk-based control an entity may skip or vary a sub-control with documented justification and accepted risk. The transition and adoption plans appear only as implementation guidance.4 Separately, the National IoT Security Policy, version 2.0, requires IoT consumers in its scope to take a risk-based approach to encryption that protects communications against classic and quantum threats.5
In May 2026 the Cyber Security Council announced a partnership with QuantumGate on a national Crypto Discovery Tool, built to requirements set by the UAE National Cryptography Center. It is designed to discover, inventory and monitor cryptographic assets across critical national infrastructure, as part of the national post-quantum migration programme.6 This is an announcement about national tooling rather than a new obligation.
Saudi Arabia: SAMA And The NCA
SAMA’s circular 482021280 of 27 August 2026 requires supervised financial institutions to make their procedures for identifying and classifying all cryptographic assets accurate and comprehensive by the end of Q4 2026, and to complete an enterprise-level quantum risk assessment with action plans by the end of Q1 2027.8 It also makes quantum risk a standing item for board-level committees. The previous article in this section covers it in more detail.
The National Cybersecurity Authority’s National Cryptographic Standards, NCS-1:2020, issued in July 2020, set minimum cryptographic requirements in the Kingdom. Their section on post-quantum cryptography noted that international standards were not yet available and that post-quantum algorithms would be considered in later versions.9 NIST has since published its main post-quantum standards, FIPS 203, 204 and 205, which US federal guidance now points agencies to, so organisations in scope should watch for a revised edition.10
- Upcoming
Saudi Arabia · Saudi Central Bank (SAMA) Binding
Ensure procedures identify and classify all cryptographic assets accurately and comprehensively.
- Upcoming
Saudi Arabia · Saudi Central Bank (SAMA) Binding
Complete a quantum risk assessment with action plans.
One Inventory, Many Regulators
A firm in Dubai or Riyadh that processes card payments and serves EU clients may face PCI DSS, DORA, SAMA and the UAE policy at once. Each asks for something slightly different, but the underlying data overlaps heavily. Building one inventory with the right fields, and producing different views from it, is far cheaper than answering each framework separately.
The table maps common inventory fields to six frameworks covered in this section. Named means the instrument asks for that information directly. Supports means the field is evidence you would use to meet a broader requirement in that instrument.
| Inventory Field | PCI DSS 12.3.3 | DORA RTS Arts. 6 And 7 | SAMA 482021280 | UAE National Encryption Policy | MAS TCRS/2024/01 | OMB M-26-15 |
|---|---|---|---|---|---|---|
| Protocols and cipher suites | Named | Supports encryption in transit rules, Art. 6(2) | Supports classification of all cryptographic assets | Supports public-key inventory | Supports algorithm field | Named: scanners for protocols and cipher suites |
| Algorithm and key length | Supports annual review | Supports selection criteria, Art. 6(3) | Supports classification | Supports public-key inventory | Named | Supports identifying quantum-vulnerable algorithms |
| Purpose and where used | Named | Supports classification-based policy, Art. 6(2) | Named: data, systems and services linked to each asset | Named: systems and applications | Named: system or application | Supports central CBOM |
| Keys and certificates | Outside 12.3.3 itself | Named: key lifecycle and certificate register, Art. 7 | Supports classification | Supports key management section | Supports inventory | Supports agile key management |
| Owner | Supports annual review | Supports key management controls | Supports committee reporting | Supports transition plan | Named | Supports accountable officials |
| Data sensitivity and protection period | Supports annual review | Supports the data classification basis, Art. 6(2) | Named: classify by sensitivity | Supports transition order | Named | Named: data sensitive in 2030 |
| Migration priority | Supports annual review | Supports update provisions, Art. 6(4) | Named: plans for priority assets | Named: transition plan | Named: prioritise critical assets | Named: prioritised migration |
| Last review date | Supports evidence of the 12-month review | Supports keeping the register up to date | Supports Q4 2026 and Q1 2027 deadlines | Supports performance monitoring | Supports monitoring | Supports a continuously updated inventory |
Sources for the columns: PCI DSS,11 the DORA technical standards,12 SAMA,8 the UAE policy,1 MAS13 and OMB M-26-15.10
Three lessons stand out from the mapping. First, the inventory has to go beyond what any single framework asks for. A PCI-only list of cipher suites misses the keys and certificates DORA names, and a DORA certificate register misses the algorithm detail MAS describes. Second, location and ownership fields do most of the work, because every framework needs to know where cryptography is and who can change it. Third, the review date matters everywhere. Each framework expects the inventory to stay current, whether that means a 12-month PCI DSS cycle, an up-to-date DORA register or SAMA’s dated deadlines.
Footnotes
-
UAE Cyber Security Council, “National Encryption Policy”, version 1.0, September 2025, sections 1.2, 5, 6, 7 and 8. csc.gov.ae ↩ ↩2 ↩3 ↩4 ↩5
-
Emirates News Agency (WAM), “UAE announces approval of National Encryption Policy, issuance of executive regulation”, 27 November 2025. wam.ae ↩
-
The Official Portal of the UAE Government, “National Encryption Policy”, updated 2 July 2026. u.ae ↩
-
UAE Cyber Security Council, “UAE Information Assurance Standard”, version 2.1, November 2025, sections 2.1 and 3.4, control T3.4.4. csc.gov.ae ↩
-
UAE Cyber Security Council, “National IoT Security Policy”, version 2.0, September 2025, sections 1.2 and 2.2.2.3. csc.gov.ae ↩
-
Abu Dhabi Media Office, “UAE Cybersecurity Council partners with QuantumGate to launch Crypto Discovery Tool”, 22 May 2026. mediaoffice.abudhabi ↩
-
Central Bank of the UAE, Securities and Commodities Authority, Dubai Financial Services Authority and Financial Services Regulatory Authority, “Guidelines for Financial Institutions adopting Enabling Technologies”, issued 15 November 2021, Scope of Application and paragraphs 3.10, 3.48, 3.89 and 3.127, as published in the FSRA Rulebook (en.adgm.thomsonreuters.com); and CBUAE, announcement of 15 November 2021. centralbank.ae ↩
-
Saudi Central Bank, “Circular 482021280: Enhancement of Operational Resilience to Address Quantum Computing Risks”, 27 August 2026. rulebook.sama.gov.sa ↩ ↩2
-
National Cybersecurity Authority, “National Cryptographic Standards (NCS-1:2020)”, July 2020, section 7.2. nca.gov.sa ↩
-
US Office of Management and Budget, “M-26-15: Execution of the Migration to Post-Quantum Cryptography”, including Appendix A, 24 June 2026. whitehouse.gov ↩ ↩2
-
PCI Security Standards Council, “Payment Card Industry Data Security Standard: Requirements and Testing Procedures”, version 4.0.1, June 2024, requirement 12.3.3. pcisecuritystandards.org ↩
-
European Commission, “Commission Delegated Regulation (EU) 2024/1774”, Articles 6 and 7, 13 March 2024. eur-lex.europa.eu ↩
-
Monetary Authority of Singapore, “MAS/TCRS/2024/01: Advisory on Addressing the Cybersecurity Risks Associated with Quantum”, 20 February 2024. mas.gov.sg ↩
Knowledge Hub content is general information. It is not legal advice, a compliance certification, a guarantee of security or a substitute for an assessment of your own systems. Standards and rules change; check the sources for the latest position.