DFSA & FSRA Cybersecurity Requirements: A vCISO Guide (2026)

DFSA & FSRA Cybersecurity Requirements: A vCISO Guide (2026)

DFSA & FSRA Cybersecurity Requirements: A vCISO Guide (2026)

DFSA and FSRA Cybersecurity Requirements: The vCISO Guide for DIFC and ADGM Firms (2026)

Last updated: September 2026.

The short answer first. Both of the UAE's financial free zones now have binding cyber rules. The DFSA turned cyber risk management into Rules for the firms it supervises in the DIFC in January 2024, in section GEN 5.5 of its Rulebook. The FSRA followed in ADGM with GEN 3.5, issued in July 2025 and in force since 31 January 2026. Both put ownership on the board and senior management, both expect a written framework, and both set a hard clock for reporting material cyber incidents: 72 hours to the DFSA, 24 hours to the FSRA.

Neither regulator says "appoint a CISO" the way VARA does for virtual asset firms. What they require is what a CISO exists to deliver: someone senior who can explain the firm's cyber risk to the board, run and test the controls, manage the IT providers, and make the call to the regulator when something breaks. For most DIFC and ADGM firms under a few hundred people, a virtual CISO is how that role gets filled without a full-time C-level salary.

This guide covers what each rulebook actually requires, where firms fall short in supervision, how data protection fits in, and what a regulator-ready programme looks like in its first 90 days.

Your vCISO in the UAE and Middle East
A named security leader of record, backed by a delivery team that builds the programme, not just advises. From $2,500 / mo

Your vCISO in the UAE and Middle East
A named security leader of record, backed by a delivery team that builds the programme, not just advises. From $2,500 / mo

DFSA and FSRA cyber rules at a glance

Area

DFSA (DIFC)

FSRA (ADGM)

Cyber rules

GEN 5.5 Cyber risk management

GEN 3.5 Cyber Risk Management

In force

January 2024

31 January 2026

Guidance behind the rules

Cyber Risk Management Guidelines, December 2020

IT Risk Management Guidance, November 2024

Who owns cyber risk

Governing Body and senior management

Board and senior management, with a senior manager responsible for advising on cyber risk

Framework

Written and approved by the Governing Body

Written, board-approved, proportionate to the firm

Incident reporting

Material incidents within 72 hours, on the ePortal form (GEN 5.5.19)

Material incidents within 24 hours, on Template A (GEN 3.5.18)

Testing

Cybersecurity testing programme, reviewed in supervision

Internet-facing systems at least once a year (GEN 3.5.14)

Outsourcing

GEN 5.3; the firm stays responsible

GEN 3.3.31 and 3.3.32; material outsourcing notified to the FSRA

Data protection

DIFC Data Protection Law No. 5 of 2020

ADGM Data Protection Regulations 2021

Both regimes scale with the firm. A ten-person fund manager is not expected to run a bank's programme, but it is expected to have every element in a form that fits its size, and to show evidence that each one works.

DFSA cybersecurity requirements for DIFC firms

The DFSA published its Cyber Risk Management Guidelines in December 2020, consulted on binding rules in Consultation Paper No. 147 in February 2023, and made them Rules in the General Module in January 2024. They now sit in GEN 5.5 and apply across the firms the DFSA supervises. The DFSA's own summary of the obligation is plain: every firm must implement an appropriate framework to identify and mitigate cyber risks, and to detect, respond to and recover from cyber incidents.

In practice, GEN 5.5 asks a DIFC firm to have:

  • a written cyber risk management framework, approved by the Governing Body, with senior management at board and executive level aware of the firm's vulnerabilities and resourcing the controls;

  • an up-to-date inventory of its ICT assets;

  • current anti-malware, network security controls, monitoring, and user access management;

  • a cybersecurity training programme for staff;

  • a written cyber incident response plan, reviewed at least once a year;

  • notification of material cyber incidents to the DFSA as soon as reasonably practicable and in any event within 72 hours, on the form in the DFSA ePortal (GEN 5.5.19).

Outsourcing sits separately, in GEN 5.3, and the principle is the one every regulator applies: the firm stays responsible for what it outsources, including the managed IT provider and the cloud platform. This is where DIFC firms are most exposed. The DFSA found that where firms had outsourced their IT and cybersecurity, senior management often had limited or no oversight of cyber risk, which is exactly the gap the Rules were written to close.

The DFSA also runs a Threat Intelligence Platform, launched in January 2020 with the Dubai Electronic Security Center and aeCERT. Membership is voluntary and free for DIFC firms, and more than 250 firms and sharing communities had joined by mid-2023. For a small firm it is a threat intelligence feed at no cost, and there is little reason not to join.

The DFSA checks how firms are doing. Its 2024 Cyber Thematic Review surveyed 641 firms with a 95% response rate, and firm-specific cyber risk assessments continue on top of it. What it found is set out in the section on where firms fall short, below.

FSRA cybersecurity requirements for ADGM firms

The FSRA issued its Cyber Risk Management framework on 29 July 2025 and gave firms six months to comply. The Rules have applied since 31 January 2026 to all Authorised Persons and Recognised Bodies. They sit in a new section of the General Rulebook, GEN 3.5, and build on the FSRA's Information Technology Risk Management Guidance of November 2024, which remains the detailed reference for how controls should look.

GEN 3.5 asks an ADGM firm to have:

  • a written cyber risk management framework, approved by the board and proportionate to the nature, scale and complexity of the firm and its cyber risk;

  • a board and senior management that carry ultimate responsibility for cyber risk (GEN 3.5.3), set the firm's tolerance for it, receive regular reporting, and make sure a member of senior management is responsible for advising on it, with staff who have the expertise and resources to manage it;

  • an inventory of ICT assets, classified by how critical they are;

  • testing of internet-facing systems at least once a year (GEN 3.5.14), and ongoing monitoring of the environment;

  • a documented incident response and recovery plan (GEN 3.5.16);

  • notification of material cyber incidents to the FSRA immediately, and no later than 24 hours after the firm becomes aware of one or has information that reasonably suggests one has occurred (GEN 3.5.18).

The mechanics of that notification are fixed. The first report goes on Template A to incidents.fsra@adgm.com, with the firm's supervisor copied, and progress reports follow on Template B at a frequency the supervisor sets. A 24-hour clock does not wait for Monday, so the escalation path has to work at 2 a.m. on a Saturday.

Third parties get their own requirements. Before engaging a provider of ICT services, a firm must carry out due diligence and write clear security obligations into the contract. The provider must be required to notify the firm of cyber incidents with a material impact, and the firm must be able to verify the provider's controls, through audit reports or other means. Contracts should also cover subcontractors and set out how data is deleted or returned when the contract ends. Outsourcing more broadly sits in GEN 3.3.31 and 3.3.32: the firm stays responsible, and it must inform the FSRA of material outsourcing arrangements.

Virtual asset firms in ADGM carry more on top. The FSRA's virtual asset guidance expects penetration and stress testing of systems and an independent third-party audit of core systems at least once a year. MTFs and custodians should also have their infrastructure reviewed every year by third-party cybersecurity consultants, and private keys and wallets need controls that follow the technology governance rules in COBS 17.5.

Do DIFC and ADGM firms need a CISO?

Not by title. Neither the DFSA nor the FSRA lists a CISO among the roles that need individual approval. The DFSA's approvals centre on roles such as the Senior Executive Officer and the Money Laundering Reporting Officer, and the FSRA approves the Senior Executive Officer, Finance Officer, Compliance Officer, MLRO and other key senior managers. Compare VARA, which requires virtual asset service providers regulated in Dubai to appoint a CISO outright; our VARA CISO guide covers that regime.

Now read the rules the way a supervisor does. Both make the board and senior management own cyber risk. The FSRA goes a step further: a member of senior management must be responsible for advising on cyber risk, and the people managing it must have the expertise and resources to do so. Somebody has to write the framework, run the testing, brief the board, manage the IT provider, and make the notification inside 72 or 24 hours. In a firm without a security lead that somebody does not exist, and the DFSA's 2024 review describes the result: outsourced IT, and senior management with limited or no oversight of cyber risk.

For most DIFC and ADGM firms, the practical answer is a named, qualified security lead who reports to the SEO and the board. Hiring one full time is rarely the right first step for a firm under a few hundred people. The work is front-loaded into building the framework, and the steady state needs a few days a month, not five days a week.

A virtual CISO fills the role at that ratio: a named senior person who owns the framework and the security side of the regulator relationship, backed by a delivery team for the hands-on work. The accountable senior manager stays inside the firm, and the vCISO gives that person the expertise the rules assume. Fintechs weighing the same choice under other UAE regimes will find the wider picture in our vCISO guide for UAE fintechs.

Data protection in the DIFC and ADGM

The UAE PDPL (Federal Decree-Law No. 45 of 2021) does not govern firms in the DIFC and ADGM. Both free zones have their own data protection laws, modelled closely on the GDPR. The security team usually owns half the work under them, because breach notification and security of processing run through the same incident process as the cyber rules.

In the DIFC, the Data Protection Law No. 5 of 2020, amended in 2025, is enforced by the Commissioner of Data Protection. A DPO is mandatory for controllers and processors that carry out High Risk Processing Activities on a systematic or regular basis, and personal data breaches must be reported to the Commissioner as soon as practicable.

In ADGM, the Data Protection Regulations 2021 are enforced by the Commissioner of Data Protection through the Office of Data Protection. A DPO is mandatory for public authorities, for regular and systematic monitoring of individuals on a large scale, and for large-scale processing of special categories of personal data. Breaches must be reported to the Commissioner within 72 hours of the firm becoming aware of them, and fines can reach USD 28 million.

The practical consequence is that one incident can start two clocks at once. A ransomware attack that exposes client data at an ADGM firm triggers the FSRA's 24-hour notification and the Commissioner's 72-hour one. At a DIFC firm it triggers the DFSA's 72 hours and the Commissioner's "as soon as practicable". The incident response plan should name every notification, its owner and its deadline in advance, so nobody works them out during the incident. Our PDPL guide covers group companies with onshore entities, and our DPO service page explains how a named DPO appointment works.

Where DIFC and ADGM firms fall short

The DFSA's 2024 Cyber Thematic Review is the best public evidence of where regulated firms in the region actually stand. Most firms reported the basics in place: over 90% identify and classify their IT assets, and almost all run access controls and anti-malware. The weak spots sit elsewhere, and they are consistent:

  • Third-party risk. Implementation sat below 70%. Only 75% of firms carried out due diligence on their service providers, and only two-thirds periodically checked those providers' compliance.

  • Incident response testing. 35% of firms did not test their incident response regularly, so the first real test of the plan is the real incident.

  • Monitoring. 20% had no continuous monitoring, and many smaller firms watched their infrastructure manually, during working hours only.

  • Late notification. Some firms did not notify the DFSA of material cyber incidents at all, or notified weeks later.

  • Oversight of outsourced IT. Where IT and cybersecurity were outsourced, senior management often had limited or no oversight of cyber risk.

None of these takes expensive technology to fix. Each one takes an owner, a calendar and a few hours of evidence every month. GEN 3.5 targets the same five points, so ADGM firms should expect FSRA supervisors to look there first.

A regulator-ready programme: the first 90 days

The sequence below is how we run it for a DIFC or ADGM firm starting from a thin base. It fits either rulebook, because the two ask for the same machine.

  1. Weeks 1 to 2, scope and gap assessment. Map systems, data and providers against GEN 5.5 or GEN 3.5 and against the data protection regime. Build the ICT asset inventory and classify each asset by criticality.

  2. Weeks 2 to 4, risk assessment and framework. Write the cyber risk management framework, agree the risk tolerance with the board, and name the senior manager accountable for cyber risk.

  3. Weeks 3 to 6, incident response and notification. Write the incident response plan with the regulator and Commissioner notifications built in, each with an owner and a deadline, and pre-fill the notification forms as far as possible. Then run a tabletop exercise.

  4. Weeks 4 to 8, third parties. List every ICT provider, rank them by criticality, run due diligence on the critical ones, and fix the contracts: security obligations, incident notification to you, assurance rights, subcontracting, and data return at exit. Notify the regulator of material outsourcing where the rules require it.

  5. Weeks 6 to 10, controls and monitoring. Close the hygiene gaps: multi-factor authentication on email and remote access, access reviews, patching, encryption, logging. Put continuous monitoring in place, in-house or through a 24/7 SOC.

  6. Weeks 8 to 12, testing and board reporting. Penetration test the internet-facing systems, fix what the test finds, and retest. Take the framework, the risk register and the test results to the board, and minute the approval.

After day 90 the work settles into a cycle: quarterly reporting to senior management, an annual framework review, annual testing, incident response exercises, and training on a schedule. If you already hold ISO/IEC 27001, most of this machinery exists, and the work is mapping the rulebook onto it; our ISO 27001 guide explains the overlap from the other direction.

What it costs: vCISO vs full-time CISO in the DIFC and ADGM

A full-time CISO credible enough for a DIFC or ADGM board is a senior hire on a senior package. Most of that person's first year goes into building a framework that then needs a fraction of their time. We set out the arithmetic in virtual CISO vs full-time CISO cost and the market bands in how much a vCISO costs in the UAE.

Dynova's vCISO plans are public. The Advisor plan starts at USD 2,500 a month. The Builder plan, at USD 4,500 a month, is the usual fit for a DIFC or ADGM firm building its programme from a thin base, and it includes a named DPO of record. The Team plan, at USD 8,500 a month, adds continuous penetration testing. Firms that need detection outside office hours add our SOC for startups from USD 3,900 a month.

One cost belongs in the plan and rarely appears in quotes: the time of your own people. Even with a provider carrying the delivery, the SEO, the compliance officer and whoever manages IT will spend a few hours a week on interviews, evidence and decisions during the first 90 days.

Frequently asked questions

Does the DFSA require a CISO?

Not by title. GEN 5.5 makes the Governing Body and senior management responsible for cyber risk and requires a framework that someone senior has to build and run. In practice the DFSA expects a competent, named owner of cyber risk, and a vCISO reporting to the SEO and the board is a common way for smaller DIFC firms to provide one.

Does the FSRA require a CISO?

Not by title either. GEN 3.5 requires a member of senior management to be responsible for advising on cyber risk, and the people managing it to have the right expertise and resources. A vCISO provides that expertise and the delivery, while the accountable senior manager stays inside the firm.

How quickly must a cyber incident be reported in the DIFC and ADGM?

To the DFSA, as soon as reasonably practicable and in any event within 72 hours, on the ePortal form under GEN 5.5.19. To the FSRA, immediately and no later than 24 hours after the firm becomes aware of a material incident, on Template A under GEN 3.5.18. Personal data breaches also go to the relevant Commissioner of Data Protection on their own timeline.

When did the FSRA cyber risk rules take effect?

The FSRA issued them on 29 July 2025, and they have applied to Authorised Persons and Recognised Bodies since 31 January 2026.

Is penetration testing mandatory in the DIFC and ADGM?

In ADGM, GEN 3.5.14 requires testing of internet-facing systems at least once a year, and virtual asset firms face an additional annual third-party audit of core systems. In the DIFC, the DFSA expects a cybersecurity testing programme and reviews it in supervision. An annual external penetration test of internet-facing systems, with retesting of fixes, is the defensible minimum in both.

Does ISO 27001 certification satisfy GEN 5.5 or GEN 3.5?

It covers most of the machinery: risk assessment, asset management, access control, supplier security, incident management, testing and management review. It does not cover the regulator-specific parts, such as the 72-hour or 24-hour notification, the FSRA's reporting templates, outsourcing notifications, and board reporting in the form the regulator expects. Treat ISO/IEC 27001:2022 as the base and map the rulebook on top of it.

Does the UAE PDPL apply to DIFC and ADGM firms?

No. The PDPL does not apply in free zones that have their own data protection laws. DIFC firms follow the DIFC Data Protection Law No. 5 of 2020, and ADGM firms follow the ADGM Data Protection Regulations 2021. Groups with onshore entities often need both.

Do we have to join the DFSA Threat Intelligence Platform?

No. Membership is voluntary and free for DIFC firms. We recommend joining anyway, because it gives a small firm threat intelligence it would otherwise have to pay for.

Can a vCISO deal with the regulator for us?

On security matters, yes. In our engagements the vCISO prepares the framework and evidence for supervisory reviews and thematic surveys, drafts incident notifications, and joins regulator meetings alongside the SEO or compliance officer. Formal regulatory responsibility stays with the firm's approved individuals.

Working with Dynova in the DIFC and ADGM

If you are applying for a DFSA or FSRA licence, or already hold one and need a named security lead to own GEN 5.5 or GEN 3.5, get in touch. We will map what your licence category requires, where your gaps are, and what the first 90 days should cover.

Related: VARA CISO Requirement: What Every VASP Must Do in 2026 · CBUAE Cybersecurity Requirements: Do You Need a CISO? · UAE PDPL Compliance: A vCISO and DPO Guide · Virtual CISO vs Full-Time CISO: The Real Cost in the UAE · ISO 27001 Certification in the UAE

Written by

Founder of Dynova, vCISO and DPO (CISSP, CISM)

Founder of Dynova, vCISO and DPO for regulated UAE companies. Formerly Head of Information Security and Privacy at Equiti. CISSP, CISM.

Guide

Experience

Get started

Don’t scale security harder. Scale smarter.

Dynova provides virtual CISO services, fractional CISO and DPO services in Dubai and across the UAE: security strategy, CBUAE, VARA, ISO 27001, PCI DSS, UAE PDPL and SOC 2 compliance, hands-on execution, penetration testing and code review, all under one named CISO.

info@business-ciso.com

+971 54 458 8631


Report incident:

soc@business-ciso.com


Dynova Services LLC-FZ, License 2644102.01, Issued by Meydan Free Zone, Dubai, UAE

Dynova is BSI Associate Consultant

Get started

Don’t scale security harder. Scale smarter.

Dynova provides virtual CISO services, fractional CISO and DPO services in Dubai and across the UAE: security strategy, CBUAE, VARA, ISO 27001, PCI DSS, UAE PDPL and SOC 2 compliance, hands-on execution, penetration testing and code review, all under one named CISO.

info@business-ciso.com

+971 54 458 8631


Report incident:

soc@business-ciso.com


Dynova Services LLC-FZ, License 2644102.01,

Issued by Meydan Free Zone, Dubai, UAE

Dynova is BSI Associate Consultant

Get started

Don’t scale security harder. Scale smarter.

Dynova provides virtual CISO services, fractional CISO and DPO services in Dubai and across the UAE: security strategy, CBUAE, VARA, ISO 27001, PCI DSS, UAE PDPL and SOC 2 compliance, hands-on execution, penetration testing and code review, all under one named CISO.

info@business-ciso.com

+971 54 458 8631


Report incident:

soc@business-ciso.com


Dynova Services LLC-FZ,

License 2644102.01,

Issued by Meydan Free Zone, Dubai, UAE

Dynova is BSI Associate Consultant