REGULATIONS ACROSS REGIONS / INTERMEDIATE

UAE: The National Encryption Policy And What Financial Regulators Expect

The UAE has a detailed national encryption policy with a post-quantum section, but it binds a defined set of entities and sets no migration date. Here is who is in scope as of October 2026.

Checked against primary sources and independently reviewed on . Sources are listed at the end.

The United Arab Emirates has one of the most detailed cryptography policies in the Gulf. The UAE Cyber Security Council’s National Encryption Policy covers data at rest, data in motion, key management and a dedicated section on post-quantum cryptography. It is also easy to misread. The policy binds a defined set of entities, it sets no date for post-quantum migration, and the financial regulators work from their own rulebooks.

This article sets out what the policy requires, how the UAE Information Assurance Standard carries it, who is in scope, and what the UAE’s financial regulators have and have not published, as of October 2026. It is general information, not legal advice. For the wider regional picture, start with the overview of post-quantum and cyber regulation in 2026.

What The National Encryption Policy Requires

The policy is version 1.0, dated September 2025 and marked as a first release.1 Its approval, together with an executive regulation, was announced on 27 November 2025, and the announcement said government entities must prepare officially approved plans to move from traditional encryption to post-quantum cryptography, with the Council overseeing the national migration.2 Status: Binding for the entities in its scope, explained below.

Entities must use encryption techniques from the National Crypto Library approved by the National Cryptography Center, and must keep weak, outdated or prohibited ciphers and hash functions out of their systems.1 All data that is not classified as open must be encrypted at rest throughout its life. Network traffic carrying such data must use TLS 1.2 as a minimum, and TLS 1.3 is strongly recommended. In key management, no single person may hold complete access to keys, key recovery must be tested periodically, and entities need a “break the glass” procedure for emergencies.1

The Post-Quantum Section

Section 6 asks entities to prepare their non-open information for the quantum threat. In plain terms, an entity in scope must:1

  • list every system and application that relies on public-key cryptography;
  • test the new post-quantum standards in a lab before production;
  • write a transition plan covering the order in which systems can move, retirement of technology that will stop being supported, and validation of new products;
  • adopt purchasing policies for post-quantum cryptography, which the policy says should cover new service levels and a survey of vendors to see what fits the entity’s roadmap;
  • tell IT teams and vendors about the transition, and train staff.

There is no deadline in the text. Compliance is monitored through the UAE Information Assurance Standard, and entities report status through the National Cyber Index Platform.1 Which Regulators Require A Cryptographic Inventory? compares the inventory duty with others worldwide.

The Information Assurance Standard Behind It

The Council’s UAE Information Assurance Standard, version 2.1, is dated November 2025 and applies to the same three groups as the encryption policy.3 Its controls come in two kinds. Controls marked always applicable must be implemented by any entity claiming compliance. The rest apply according to the entity’s risk assessment, and an entity may exclude one only with adequate justification submitted to the Council. Without a risk assessment, every control counts as applicable.3

Cryptography sits in sub-family T3.4. Governance (T3.4.1), encryption of classified data at rest and in motion (T3.4.2) and key management (T3.4.3) are always applicable, and T3.4.1 requires weak or outdated ciphers and hash algorithms to be replaced in good time.3 The post-quantum control, T3.4.4, was not in version 1.1. It applies based on risk assessment and sits in the second of four priority tiers. Its sub-controls cover the public-key inventory, lab testing before production and staff training. Because the control is risk-based, the standard also lets an entity skip or vary a sub-control if it documents the justification and the risk is formally accepted. The transition plan, new service levels and vendor surveys appear only as implementation guidance, which the standard says is for information.3

The encryption policy, by contrast, requires a transition plan and purchasing policies outright, and the standard’s own mapping ties the whole post-quantum section to T3.4.4. Entities in scope therefore need to read the two documents together.

Who Is In Scope

Section 1.2 of the policy covers three groups: federal ministries and authorities, non-government entities that operate critical information infrastructure (CII), and emirate government entities.1 Where an emirate runs its own CII protection (CIIP) programme, the emirate’s lead body handles applicability, enforcement and monitoring for emirate government entities and non-government CII entities in that emirate. Where an emirate has no such programme, the policy applies to its government entities directly. The Council can approve exceptions.

A private company that is not a designated CII operator is not bound by the policy text. The introduction, repeated on the UAE government portal, describes a broader purpose of supporting organisations and individuals that handle critical and personal data,4 but section 1.2 sets who must comply.

Three companion policies dated September 2025 use the same scope and point back to the encryption policy.5 The National Cloud Security Policy v2.0 makes cloud consumers in scope ensure their providers comply. Providers must support customer-held keys. Those holding Confidential/Restricted data or higher must generate, store and manage hosted keys in the UAE, and those holding data above Confidential/Restricted must use UAE-based hardware security modules. The National Data Exchange Security Policy v1.0 requires encrypted, integrity-protected and authenticated channels. The National IoT Security Policy v2.0 reaches further. Any company that provides, builds or deploys IoT services in the UAE must follow it, while other organisations may treat it as advice. IoT consumers in scope must take a risk-based approach to encryption that secures communications against classic and quantum threats.5

  1. UAE Cyber Security CouncilIssues the National Encryption Policy, the Information Assurance Standard and companion policies, and runs the National Post-Quantum Migration Programme.
  2. Federal And Emirate Government Entities And Non-Government CII OperatorsBound by the National Encryption Policy, including its post-quantum section, and by the Information Assurance Standard. Emirate CIIP leads enforce where they exist. Binding.
  3. IoT Service ProvidersCompanies that provide, build or deploy IoT services in the UAE must follow the National IoT Security Policy. Binding.
  4. Dubai Government EntitiesBound by the Dubai Electronic Security Center Information Security Regulation. Binding. Its control text is available only on request.
  5. Financial InstitutionsJoint 2021 enabling technologies guidelines from the CBUAE, SCA, DFSA and FSRA cover encryption and key management. Guidance. FSRA told ADGM firms that the Council policies in its October 2025 notice are not mandatory for them. A firm designated as CII would still be in scope.
  6. Other Private OrganisationsNot bound by the policy unless designated CII. Contractual standards such as PCI DSS may still apply.
Who the UAE's cryptography and cyber instruments reach, as of October 2026. The highlighted layer is the scope of the National Encryption Policy and the Information Assurance Standard; organisations in other layers fall inside it if they are government entities or designated CII.

The Financial Regulators

In November 2021 the Central Bank of the UAE (CBUAE), the Securities and Commodities Authority (SCA), the Dubai Financial Services Authority (DFSA) and Abu Dhabi Global Market’s Financial Services Regulatory Authority (FSRA) jointly issued Guidelines for Financial Institutions Adopting Enabling Technologies.6 They cover APIs, cloud, biometrics, big data and AI, and distributed ledgers, and apply in proportion to size and risk to every institution those regulators license that uses, or plans to use, these technologies. Binding rules take precedence. Status: Guidance. The guidelines ask firms to encrypt personal data handled through APIs, use key management to segregate customer data in the cloud, encrypt biometric data, and, for ledgers, split offline root keys among several owners and keep online root keys in hardware security modules. Ledger continuity teams should watch cryptographic advances, but the text never mentions quantum computing.6

The FSRA’s Notice FSRA/FCCP/146/2025 of 17 October 2025 told firms about newly released Council policies on incident response, information sharing, security operations centres and cloud security, and said firms need not adhere to them but should keep up to date.7 It predates the 27 November 2025 approval announcement and does not mention the encryption policy. It also reminded firms that section 3.5.16 of the FSRA General Rulebook requires an incident response plan from 31 January 2026. Status: the notice is Guidance; the GEN rule is Binding on FSRA-regulated firms.

  1. In effect

    United Arab Emirates (ADGM) · ADGM Financial Services Regulatory Authority Binding

    Maintain an incident response plan, which GEN section 3.5.16 requires from this date.

    General Rulebook (GEN) section 3.5.16, as noted in FSRA Notice FSRA/FCCP/146/2025 (17 October 2025). Applies to FSRA Authorised Persons and Recognised Bodies in ADGM. Source · Explainer · Verified 7 Oct 2026

Countdowns run to the end of each deadline date (UTC) and are calculated in your browser. "Binding" means legally or contractually required; other labels describe supervisory expectations, guidance, drafts or announcements. Always check the source for the current text.

As of October 2026, no post-quantum or cryptographic inventory rule was found from the FSRA, the DFSA or the CBUAE. This reflects what could be found, not proof that nothing exists. A CBUAE rulebook search on 7 October 2026 found no post-quantum provisions; its technology risk rules for some licensed activities are not summarised here, and the DFSA rulebook refused automated access. In Dubai, the Dubai Electronic Security Center’s Information Security Regulation covers Dubai Government entities and those who work with them, but its text is released on request, and no DESC post-quantum guidance was found.8

The Migration Programme Around The Policy

On 22 May 2026 the Council announced a partnership with QuantumGate on a Crypto Discovery Tool for automated discovery, inventory and continuous monitoring of cryptographic assets under the UAE National Post-Quantum Migration Programme, feeding a UAE National PQC Index.9 Status: Announcement. It describes a national capability, not a new duty. The Council’s catalogue also lists a National Cyber Security Policy for Artificial Intelligence, among others.10 UAE AI governance is covered in AI Governance And Regulation, and the international frameworks alongside these rules are in Cryptography Compliance.

Footnotes

  1. UAE Cyber Security Council, “National Encryption Policy”, version 1.0, September 2025. csc.gov.ae ↩ ↩2 ↩3 ↩4 ↩5 ↩6

  2. Emirates News Agency (WAM), “UAE announces approval of National Encryption Policy, issuance of Executive Regulation”, 27 November 2025. wam.ae ↩

  3. UAE Cyber Security Council, “UAE Information Assurance Standard”, version 2.1, November 2025, sections 1.2, 2.1 and 3.4, controls T3.4.1 to T3.4.4, and Annexes C, F.1 and G. csc.gov.ae ↩ ↩2 ↩3 ↩4

  4. UAE Government portal, “National Encryption Policy”, last updated 2 July 2026. u.ae ↩

  5. UAE Cyber Security Council, “National Cloud Security Policy”, version 2.0, September 2025, sections 1.2, 2.3.2 and 3.3.2 (csc.gov.ae); “National Data Exchange Security Policy”, version 1.0, September 2025, sections 1.2 and 4.1 (csc.gov.ae); “National IoT Security Policy”, version 2.0, September 2025, sections 1.2 and 2.2.2. csc.gov.ae ↩ ↩2

  6. Central Bank of the UAE, Securities and Commodities Authority, Dubai Financial Services Authority and Financial Services Regulatory Authority, “Guidelines for Financial Institutions adopting Enabling Technologies”, issued 15 November 2021, Scope of Application and paragraphs 3.10, 3.48, 3.89, 3.127 and 3.152, as published in the FSRA Rulebook (en.adgm.thomsonreuters.com); and CBUAE, announcement of 15 November 2021. centralbank.ae ↩ ↩2

  7. ADGM Financial Services Regulatory Authority, Notice FSRA/FCCP/146/2025, “Updates to the National Cyber Security Policies from the UAE Cyber Security Council”, 17 October 2025. assets.adgm.com ↩

  8. Dubai Electronic Security Center, “Standards and Policies: Information Security Regulation”, accessed October 2026. desc.gov.ae ↩

  9. Abu Dhabi Media Office, “UAE Cybersecurity Council partners with QuantumGate to launch Crypto Discovery Tool”, 22 May 2026. mediaoffice.abudhabi ↩

  10. UAE Cyber Security Council, “Policies”, accessed October 2026. csc.gov.ae ↩

Knowledge Hub content is general information. It is not legal advice, a compliance certification, a guarantee of security or a substitute for an assessment of your own systems. Standards and rules change; check the sources for the latest position.