HomeFrameworksADGM FSRA Cyber Risk
Financial Services Regulatory Authority (FSRA), ADGM · United Arab Emirates (ADGM)

ADGM FSRA Cyber Risk Management Framework (GEN 3.5) compliance software

The FSRA's cyber risk rules for every ADGM Authorised Person — GEN 3.5, binding since 31 January 2026 — 43 rule paragraphs across seven sections, including the strictest incident-notification window in the UAE.

At a glance
  • RegulatorFSRA — Abu Dhabi Global Market
  • InstrumentADGM General Rulebook GEN 3.5 — made 29 July 2025, in force 31 January 2026
  • Structure7 sections, 18 Rules (3.5.1–3.5.18), 43 assessable paragraphs
  • NotificationMaterial Cyber Incident to the Regulator within 24 hours
ADGM FSRA Cyber RiskAvailable
Overview

What ADGM FSRA Cyber Risk requires

Who it applies to

  • ADGM Authorised Persons — banks, asset and fund managers, brokers, insurers, virtual-asset firms
  • Recognised Bodies and market infrastructure in ADGM
  • Third-party ICT and cloud providers to ADGM firms, in support of their clients' Rule 3.5.2 obligations
  • Groups with entities in both ADGM and DIFC

The Financial Services Regulatory Authority regulates financial services in Abu Dhabi Global Market. Its Cyber Risk Management rules — GEN 3.5 of the General Rulebook, made on 29 July 2025 and binding on every Authorised Person from 31 January 2026 — require a Cyber Risk Management Framework integrated into enterprise risk management, governing-body accountability, an ICT asset inventory and risk assessment, protective controls including MFA and encryption, ongoing monitoring and testing, detection, response and recovery, and notification of material Cyber Incidents to the Regulator.

The notification rule is the one ADGM firms notice first: immediately, and in any event no later than 24 hours after becoming aware of a material Cyber Incident. That is a third of the DFSA's window and shorter than the CBUAE's, and it makes detection and a tested response plan the practical precondition of compliance.

GRCLens transcribed the rules from the ADGM Rulebook paragraph by paragraph, so each 'must' is a control with the FSRA's Guidance beside it, and the six indicators on the dashboard are the ones an FSRA supervisor asks about — notification readiness first.

In the platform

How GRCLens supports ADGM FSRA Cyber Risk

ADGM FSRA Cyber Risk runs on the same shared control model as every other framework in GRCLens, so evidence captured once can satisfy several obligations at the same time.

24-hour readiness as an indicator

Unmet rules that the 24-hour notification depends on — monitoring and escalation, the response plan, investigation and containment, the notification rule itself — counted as one indicator that goes amber at a single gap.

Third-party ICT risk, wider than outsourcing

Rule 3.5.2 reaches every ICT Service including cloud, with due diligence, contractual notification and audit rights, and supervision. The vendor register the tenant already keeps supplies the evidence.

Rulebook wording with the FSRA's Guidance

Codes cite the rule and paragraph — 3.5.8(b) — so a supervisor can follow every assessment answer back to the text.

Beside the DFSA catalogue

The same seven-part shape as the DFSA's GEN 5.5, so a group with entities in both free zones sees two dashboards that read alike and evidences shared controls once.

Questions

ADGM FSRA Cyber Risk frequently asked questions

When did the FSRA's cyber rules become binding?

The rules were made on 29 July 2025 and became binding on every Authorised Person on 31 January 2026.

What is the incident notification requirement?

GEN 3.5.18: notify the Regulator immediately, and in any event no later than 24 hours after becoming aware, or having information that reasonably suggests, that a material Cyber Incident has occurred.

Does GRCLens also cover ADGM's Data Protection Regulations?

Not yet as a separate catalogue. ADGM's Data Protection Regulations 2021 are a distinct regime under the ADGM Office of Data Protection; talk to us if that is part of your programme.

Talk to us about ADGM FSRA Cyber Risk

Security Solution Consultants provides ADGM cyber risk readiness and advisory alongside the platform, so you can combine tooling with hands-on expertise.