Cybersecurity 2026

UAE Trends and Developments Contributed by: Muthmainur Rahman and Kajen Subramoney, Ankura Consulting Group LLC

ment should ensure that local surveillance laws do not undermine the actual level of protection. Federal Decree-Law No 26 of 2025 (Child Digital Safety) Drafted in 2025 and enacted in January 2026, this law imposes new cyber-safety obligations on digital platforms. • Content filtering – Internet service providers and digital platforms operating in the UAE are obligated to implement active content filtering mechanisms and age verification systems. • Compliance impact – For tech companies and social platforms, this requires deploying AI-driven content moderation tools and strict age-gating. Failure to comply attracts heavy fines. Strategic Response: The National Cyber Security Strategy (2025-2031) The UAE Government’s response to the hostile cyber - security environment is the National Cyber Security Strategy (2025-2031) (NCSS). The strategy is struc - tured around five pillars and shifts the UAE’s focus from “capacity building” to “active defence”. Pillar 1: establishing highly effective and cohesive cybersecurity governance This pillar aims to provide clarity, eliminate overlaps and promote collaboration among entities at the fed - eral, sectoral, and emirate levels. The rollout of the National Cyber Accreditation Pro - gramme (NCAP) during 2026 will begin to restrict the use of unaccredited cybersecurity service providers for critical information infrastructure (CII). Organisations must audit their supply chain to ensure their managed security service provider (MSSP) and cloud vendors hold the necessary UAE accreditation. Pillar 2: delivering a safe, secure and resilient digital environment Focused on protecting the population and critical assets, this pillar emphasises resilience through coor - dinated technical capabilities.

The Secure Supply Chain Program, in line with glob - al best practices, moves the UAE towards requiring Software Bill of Materials (SBOM) transparency for government procurement. Middle East firms frequently cite third-party breaches as a top risk, and this initiative makes vendor risk management a compliance obligation. The Cyber Pulse programme continues to empower the populace, having already trained 20,000 women in cybersecurity, a traditionally male field. Pillar 3: enabling the rapid and secure adoption of innovation To harness the potential of emerging technologies such as AI, this pillar focuses on mitigating the asso - ciated security and privacy risks. Establishing a Quantum Secure Program to mitigate the wave of impending “harvest now, decrypt later” global threats. As quantum computing approaches and the potential for rapid decryption looms, the UAE is actively funding post-quantum cryptography (PQC) research to build resilient data protection. Given the current pace of change and continued for - ward-looking approach, UAE authorities may issue guidance in 2026 requiring financial and government entities to produce a PQC migration roadmap. Pillar 4: strengthening national digital and cyber capabilities This pillar is dedicated to enhancing the UAE’s data, operational and technical maturity while fostering a vibrant local ecosystem. • A key initiative, the Cyber E71 programme, was established as a business incubator to nurture cyber startups and innovation in the UAE. • The Cyber Sniper initiative aims to upskill national talent and federal government personnel to address the latest security challenges.

437 CHAMBERS.COM

Powered by