United Arab Emirates

Middle East

The UAE regulates telecom through the TDRA (formerly TRA). Cybersecurity is coordinated with the UAE Cybersecurity Council. The CIIP program treats telecom operators as critical information infrastructure.

Regulator: TDRA + UAE Cybersecurity Council

Primary frameworks: TDRA Regulatory Framework, UAE Information Assurance Standard, CIIP program, aeCERT guidance

Licensing conditions

Public Telecommunications Licenses embed security obligations. Operators must maintain a documented information-security management system and report significant incidents.

Signaling security

TDRA has issued specific guidance requiring SS7/Diameter/GTP screening at international borders in line with GSMA FS.11/FS.19/FS.20 categories.

Data localization

Certain classes of subscriber data must remain in-country. This influences roaming-signaling architecture — home-routed becomes strongly preferred.

Key takeaways

  • TDRA guidance aligns closely to GSMA specs — GSMA compliance work translates directly.
  • License conditions carry more weight than published rules; operators track their own licence terms first.
  • Data localization pushes home-routed roaming even where LBO would be operationally simpler.