GCGRA Compliance in the UAE: The Cybersecurity a Gaming Licence Demands
What GCGRA is, who needs a licence, and the cybersecurity a UAE gaming platform must demonstrate to be licensed and go live.
What ADHICS v2.0 requires of Abu Dhabi healthcare entities — who must comply, the control domains, your compliance timeline, and how to close the gaps.
Every hospital, clinic, insurer, and health-tech vendor operating in the Emirate of Abu Dhabi now sits inside the scope of a single, mandatory cybersecurity rulebook: the Abu Dhabi Healthcare Information and Cyber Security Standard, version 2.0 — ADHICS v2.0, issued by the Department of Health – Abu Dhabi (DoH). If your organisation stores, processes, or transmits health information in Abu Dhabi, ADHICS applies to you.
The first version of ADHICS was published in February 2019. Version 2.0 is a substantial update that raises the bar on governance, asset management, third-party risk, and incident response. This guide explains what ADHICS v2.0 is, who it covers, and the practical steps to reach and hold compliance.
ADHICS is the healthcare-sector information security standard for Abu Dhabi, published and enforced by the Department of Health – Abu Dhabi. It is mandatory for regulated healthcare entities — a condition of operating, not a best-practice badge. It also sits alongside the UAE's broader data-protection and sector regulations, so a provider is typically navigating ADHICS together with DoH licensing conditions and national data-protection duties at once. ITSEC's DHA and health-sector regulatory practice maps these overlapping obligations so a single control set can satisfy more than one authority.
ADHICS v2.0 applies across the Abu Dhabi health ecosystem: healthcare providers (hospitals, clinics, labs, pharmacies), payers (insurers and third-party administrators), and the health-tech and service vendors that build, host, or operate systems touching patient data. The common thread is health information — if your systems hold it, you are in scope. Vendors often discover their obligations late, assuming the hospital carries the burden, when in reality the vendor's own controls are assessed as part of the provider's third-party risk posture. ITSEC's healthcare and telemedicine security practice works with exactly these platforms.
ADHICS is structured around governance and control requirements familiar to anyone who has worked with ISO/IEC 27001, with healthcare-specific expectations layered on top. A programme has to demonstrate maturity across governance and an information-security management structure; asset and information classification; access control and identity; third-party and supply-chain security; operations, resilience and incident response; and physical and environmental controls. The move from v1 to v2.0 sharpens expectations around third-party risk, resilience, and the evidence you must retain to prove a control actually operates — not just that a policy exists on paper.
A recurring mistake is treating ADHICS as an exercise that starts when an assessment is scheduled. In practice, entities are expected to reach compliance within a defined window from official onboarding or release of the standard. That is less generous than it sounds: a mid-sized hospital has hundreds of systems and dozens of vendors, and discovery alone — building an accurate asset inventory and mapping where health data flows — can consume the first weeks. The organisations that pass cleanly start with an honest gap assessment, prioritise the highest-risk gaps, and run remediation as a managed programme with named owners and deadlines.
Scope and inventory every system and third party that touches health information, and classify the data. Run a gap assessment against the ADHICS v2.0 control set. Remediate by risk — access control, third-party contracts, logging and backup usually top the list. Then prove the controls with technical testing: governance documents are necessary but not sufficient, and penetration testing and vulnerability assessment turn "we have a policy" into "we tested it, and here is the evidence." Finally, operationalise and monitor — compliance is a state you hold, not a certificate you frame.
Healthcare organisations in the UAE rarely face a single regulator. A group operating across emirates may manage ADHICS in Abu Dhabi, Dubai Health Authority requirements in Dubai, and national data-protection duties across the whole footprint. The efficient path is one control framework mapped to every authority you answer to. ITSEC's dedicated ADHICS v2 compliance practice does this mapping, and where a health-tech business also needs UAE corporate structuring or licensing support, our sister firm SecureVisa Group covers the licensing and regulatory setup side.
ADHICS v2.0 is enforceable, healthcare-specific, and unforgiving of paper-only compliance. If you operate in Abu Dhabi's health sector — as a provider, a payer, or a vendor — the safest move is to know exactly where you stand before an assessor tells you. ITSEC runs ADHICS v2.0 gap assessments, remediation programmes, and the penetration testing that proves your controls work. Visit our ADHICS v2 compliance page to book a readiness assessment.