SEC_PROTOCOL
ACTIVE
Central Bank of the UAE - Information Security Standards

CBUAE Cybersecurity
Compliance & Testing
Services

Comprehensive compliance solutions for UAE banks, financial institutions, and payment service providers. Meet every requirement of the Central Bank's Information Security Standards.

Speak A Cyber Expert
Enterprise Security
NDA Protected
24/7 Monitoring
Secure Infrastructure
What is CBUAE Cybersecurity Compliance?

Central Bank of the UAE — supervisor of every UAE bank, payment institution, and licensed financial intermediary.

The CBUAE is the federal financial regulator. Its cybersecurity mandates run through several instruments — the Information Security Regulation, the Operational Risk Standard, the Stored Value Facilities (SVF) framework, the Retail Payment Services framework, and the Open Finance Regulation — each setting specific controls for licensed institutions.

Scope

Banks, payment institutions, EMIs

All CBUAE-licensed banks, exchange houses, finance companies, SVF/RPS providers.

Frameworks

ISR, Op Risk, SVF, RPS, Open Finance

Multiple stacked regulations — applicable set depends on licence category.

Penalties

Fines, licence restrictions, withdrawal

CBUAE can fine, restrict activities, or revoke licences for material non-compliance.

Regulator

Central Bank of the United Arab Emirates

Federal authority for monetary policy, financial stability, and supervision.

Core cybersecurity controls: board-level cyber governance, three-lines-of-defence structure, threat-intelligence integration, periodic penetration testing, red-team exercises for systemic banks, encrypted core-banking and payment rails, fraud monitoring, and prompt breach notification to CBUAE. Open Finance adds API-security and consent-management obligations on top of the baseline.

How ITSEC helps — CBUAE risk frameworks, security testing, audit-ready docs, Open Finance API security

Industry Certifications & Accreditations

ISO 27001 Certified
Information Security Management
CREST Approved
Penetration Testing Excellence
PCI DSS QSA
Payment Card Industry Qualified
UAE Licensed
Dubai Economic Zone Authority

Proven Track Record in CBUAE Compliance

85+
Banks & FIs Served
100%
Compliance Success Rate
20+
Years Experience
24/7
Expert Support

"CBUAE compliance" isn't one rulebook

Ask five different CBUAE-licensed entities what their cybersecurity obligations are and you'll often get five different answers, because the Central Bank doesn't regulate through a single instrument. There are five overlapping ones, and which combination binds you depends on your licence category. Most institutions carry two or three at once without realising the full set applies to them.

Every licensed entity — bank, finance company, exchange house, payment institution — sits under the Information Security Regulation at minimum. It's the floor: a named security function reporting independently of IT, a defined risk-assessment cadence, access control, encryption at rest and in transit, logging, incident classification. Larger or systemically important institutions build on top of it, but nobody gets to skip it.

Sitting alongside that is the Operational Risk Standard, which treats cyber risk as one operational risk category among several. It wants a documented risk appetite statement, periodic business impact analysis, and recovery time objectives that have actually been tested — not numbers pulled from a policy template three years ago.

Two more frameworks apply narrowly but matter a great deal if they hit you. E-wallet and prepaid card issuers fall under the Stored Value Facilities framework, which segregates customer funds from operational accounts and calibrates monitoring to high-volume, low-value transaction patterns. Anyone doing payment initiation or merchant acquiring sits under Retail Payment Services, which increasingly expects sanctions screening at the point of settlement rather than as an after-the-fact report.

And then there's the one almost nobody is ready for: Open Finance. It demands real API-level security — OAuth consent flows, token lifecycle management, per-partner rate limiting — and a bank can be fully ISR-compliant and still fail an Open Finance review because its API gateway doesn't enforce consent properly.

What actually gets asked in a supervisory review

CBUAE reviews have moved away from "show me the policy" and toward "show me it firing." An examiner is far more likely to ask for the last board-level cyber risk report and what decision it triggered than to ask whether one exists at all. They'll want the escalation trail on your last three security incidents, however small, with time-to-detection and time-to-containment attached. They'll ask whether last cycle's penetration testing findings were actually remediated and independently retested — not just marked closed in a tracker somewhere.

The institutions that fail this kind of review usually aren't technically weak. They're undocumented. The gap is almost always in evidence discipline, not in the underlying controls.

What non-compliance actually costs

Beyond the fine schedule itself — and fines do scale with turnover and severity — CBUAE can order mandatory remediation on a fixed deadline, restrict specific licensed activities until a control is demonstrated, or in serious or repeat cases suspend the licence outright. The quieter cost is reputational: correspondent banking partners increasingly run their own due-diligence checks on an institution's CBUAE supervisory history before extending or renewing a relationship, and a public enforcement notice follows you into those conversations.

Where boards are now expected to actually engage

Cyber risk used to sit with IT. CBUAE has been pushing it toward the boardroom for a few years now, and that shift changes what evidence an institution has to produce. A board that receives a single red-amber-green heat-map slide and moves on isn't demonstrating oversight — CBUAE wants to see quantified exposure, a risk appetite that ties to specific control spend, and minutes showing the board actually pushed back on something.

The three-lines-of-defence question comes up constantly in our engagements: the business function running risk day-to-day, an independent compliance function challenging it, and internal audit testing whether the first two are doing their jobs. Examiners probe whether these lines are genuinely separate people, not the same person wearing two hats — because that's not oversight, it's a conflict of interest with a nicer name. Smaller finance companies without headcount for three full functions can run proportionate structures, but the principle holds regardless of size: nobody marks their own homework on cyber risk.

The gaps we keep finding, engagement after engagement

A few patterns show up often enough across ITSEC's CBUAE readiness work that they're worth naming plainly.

Risk registers that haven't been substantively touched in over a year are probably the single fastest way to trigger a finding — even when the underlying risks genuinely haven't changed much, a static register reads to an examiner as a risk function that isn't paying attention. Vendor risk assessments tend to happen once, at onboarding, and never again, even for vendors sitting directly on core banking or payment data; CBUAE wants ongoing monitoring, not a one-time checkbox.

Incident response plans are frequently reviewed on paper and never actually exercised. The first time most of these plans get tested for real is during an actual incident, at 3am, when nobody has time to discover the plan's assumptions were wrong. Encryption key rotation is another one — a documented rotation schedule sitting next to production keys that haven't actually rotated on schedule is trivial for a reviewer to catch and reads badly once they do.

And Open Finance integrations built fast to hit a deadline often work fine for the business while quietly missing proper token expiry, scope limitation, or revocation handling — functional, but not what the regulation was actually asking for. None of this is exotic. It's the kind of thing a properly scoped readiness review catches months before a supervisory examination does, which is rather the point of running one proactively.

Speak with ITSEC about CBUAE compliance across ISR, Operational Risk, SVF, RPS, and Open Finance.

Consult Cyber Experts →

CBUAE Cybersecurity Compliance — Mandatory for All UAE-Licensed Financial Institutions

Information Security Standards — Mandatory for All Licensed FIs

The Central Bank of the UAE (CBUAE) mandates comprehensive cybersecurity controls for all licensed banks, financial institutions, and payment service providers. These Information Security Standards are based on ISO 27001 and require annual third-party security assessments, incident reporting within 24 hours, and board-level oversight of cybersecurity risks. If your annual CBUAE assessment is due, ITSEC delivers the full penetration test, gap report, and remediation roadmap within 4 weeks.

ISO 27001 Alignment

Comprehensive Information Security Management System (ISMS) based on international standards

24-Hour Incident Reporting

Mandatory notification to CBUAE for all material cybersecurity incidents

Payment System Security

PCI DSS compliance, SWIFT CSP controls, and secure payment gateway architecture

CBUAE Information Security Standards: 8 Core Requirements

Mandatory cybersecurity controls for all UAE-licensed financial institutions

Information Security Governance
Board-level cybersecurity oversight and CISO appointment
Access Control & Authentication
Multi-factor authentication and privileged access management
Data Protection & Encryption
At-rest and in-transit encryption for customer data
Network Security
Segmentation, firewalls, and intrusion detection systems
Security Monitoring
24/7 SOC, SIEM, and continuous vulnerability management
Incident Response
24-hour CBUAE notification and BCDR plans
Third-Party Risk
Vendor security assessments and cloud provider validation
Security Testing
Annual penetration testing and vulnerability assessments

Our CBUAE Compliance Services

Information Security Governance review

Technical controls assessment (ISO 27001 alignment)

Board reporting and CISO function review

Policy and procedure documentation audit

Risk management framework evaluation

Detailed remediation roadmap with timelines

ITSEC Standard

External & internal network penetration testing

Mobile banking app security testing

Social engineering and phishing simulations

Web application security assessment

Wireless network security review

KYC/AML system security assessment

ITSEC Standard

PCI DSS Level 1 compliance assessment

Payment gateway penetration testing

Real-time payment system security

SWIFT Customer Security Programme (CSP) audit

ATM & card skimming security review

Crisis management capability assessment

ITSEC Standard

Quarterly vulnerability scanning

Incident response retainer (24/7)

Policy updates for regulatory changes

Monthly security health checks

CBUAE incident notification support

CISO advisory services

ITSEC Standard

Frequently Asked Questions

What financial institutions must comply with CBUAE Information Security Standards?
All UAE-licensed banks (commercial, retail, Islamic), finance companies, payment service providers, money exchange houses, and insurance companies regulated by CBUAE must comply with the Information Security Standards.
How often must we conduct security assessments?
CBUAE requires annual third-party penetration testing and vulnerability assessments. Additionally, continuous vulnerability scanning and quarterly internal security reviews are recommended best practices.
What is the incident reporting timeline to CBUAE?
Material cybersecurity incidents must be reported to CBUAE within 24 hours of discovery. This includes data breaches, system compromises, ransomware attacks, and any incident affecting customer data or operations.
Do we need ISO 27001 certification for CBUAE compliance?
While ISO 27001 certification is not explicitly mandated, CBUAE's Information Security Standards are closely aligned with ISO 27001. Many banks pursue certification as it demonstrates comprehensive compliance and international best practices.
What are the SWIFT CSP requirements for UAE banks?
Banks using SWIFT must comply with the SWIFT Customer Security Programme (CSP), which includes mandatory and advisory controls. ITSEC provides specialized SWIFT CSP attestation services.
How long does a CBUAE compliance assessment take?
A comprehensive gap assessment typically takes 4-6 weeks, depending on the size and complexity of your institution. Penetration testing projects range from 2-4 weeks for core systems.
ITSEC UAE cybersecurity coverage map

Ready to Secure Your Digital Assets?

Get a comprehensive security assessment from our expert team. Protecting businesses since 2011.

Consult Cyber Experts
NDA Protected
24hr Response
Global Coverage
×

ITSEC Security Agent

AI-Powered • 24/7 Active

👋 Welcome to ITSEC – UAE's first AI-augmented cybersecurity firm.

I'm your AI Security Agent. How can I assist you with your cybersecurity needs today?
ITSEC AI
Secured by ITSEC AI • ISO 27001 Certified