2025-06-19

Added · Updated

Technology and Information Rulebook

VASPs must implement a comprehensive Technology Governance and Risk Assessment Framework, appoint a CISO, and maintain an annually reviewed Cybersecurity Policy. They must safeguard cryptographic keys with no single point of failure, store backups separately, and enforce strict access controls with audit logs. VASPs must conduct annual third-party vulnerability assessments and penetration tests, providing results to VARA upon request.

Virtual Assets Regulatory Authority logo

United Arab Emirates

Virtual Assets Regulatory Authority

Scan of the document's first page
Share

Get VARA alerts — same-day email on every new publication.

Annotated text · 299 obligations · 4 permissions · 0 reporting items
  • Obligation 299
  • Permission 4
  • Definition / condition 61
  • Reporting template 0
  • background, boilerplate

Read the rest free

Lineage: In force

Law No. 4 of 2022 Regulating Vi…Law No. 4 of 2022 Regulating Virtual Assets in the Emirate of DubaiVirtual Assets and Related Acti…Virtual Assets and Related Activities Regulations 2023Technology and InformationRulebook2025-06-19 · this documentTechnology and Information Rulebook (2025-06-19)
amendssupersedesissued underrefers toproposed or not in RegAlertarrows run from the older text to the one that changes it

Source: Virtual Assets Regulatory Authority — original document · Summary generated with machine assistance and reviewed before publication; the authoritative text is the regulator's original document. How RegAlert works

More like this from VARA

We email you every new VARA publication the day it's published.

Topics