UAE Central Bank Law: 16 September 2026 Deadline and CBUAE Compliance

The UAE Central Bank Law, Federal Decree-Law No. 6 of 2025, came into force on 16 September 2025 and introduced a one-year transitional period for affected businesses. With the deadline falling on 16 September 2026, fintechs, payment providers, insurers and qualifying technology businesses face an important compliance review. The law also expands the CBUAE regulatory framework through provisions including Article 62.

Mahesh Maddu September 14, 2026
UAE Central Bank Law

The UAE Central Bank Law, Federal Decree-Law No. 6 of 2025, introduced a consolidated regulatory framework for banking, payments, insurance and other regulated financial activities in the UAE. The law came into force on 16 September 2025, with Article 184 providing a one-year transitional period for affected entities to regularise their position. That transitional period ends on 16 September 2026.

The new framework is particularly significant for fintech businesses, payment technology providers and other companies whose activities may facilitate or enable Licensed Financial Activities. Article 62 adopts technology-neutral language, meaning that the regulatory analysis can depend on the activity being performed rather than simply the technology or platform used.

Businesses that may fall within the expanded CBUAE regulatory perimeter should assess their activities, licensing position, contractual arrangements and regulatory obligations before the transitional period ends.

Important

Regulatory treatment depends on the specific activity, business model, licence and applicable CBUAE requirements. Businesses should obtain UAE financial regulatory advice where the scope of the law is uncertain.

UAE Central Bank Law at a Glance

Item Details
Law Federal Decree-Law No. 6 of 2025
Regulator Central Bank of the UAE (CBUAE)
Effective date 16 September 2025
Transitional period One year under Article 184
Key deadline 16 September 2026
Key technology provision Article 62
Main regulatory areas Banking, payments, insurance and other Licensed Financial Activities
Businesses requiring attention Financial institutions, fintechs, payment businesses and qualifying technology providers

What Is the UAE Central Bank Law?

Federal Decree-Law No. 6 of 2025 is the UAE’s new consolidated Central Bank and financial-sector legislation. It modernises the country’s regulatory framework by bringing important banking, payment and insurance provisions under a single federal law while addressing developments in financial technology and digital financial services.

The law replaced the previous 2018 Central Bank Law and consolidated insurance regulation previously governed by the 2023 Insurance Decree-Law.

Its significance extends beyond traditional banks and insurers. The legislation provides a broader framework for activities involving payment services, Open Finance, virtual asset payment services and technology that facilitates Licensed Financial Activities.

The practical question for a business is therefore not simply whether it calls itself a bank, insurer, fintech or technology company. The more important question is what regulated activity the business actually performs or facilitates.

When Does the 16 September 2026 CBUAE Deadline Apply?

The new law came into force on 16 September 2025. Article 184 provides a transitional period for entities affected by the new regulatory framework to regularise their position.

That one-year period ends on 16 September 2026.

Businesses that may be newly affected should not assume that an existing commercial licence automatically permits them to continue an activity that now falls within the CBUAE regulatory framework.

Before the deadline, an affected business should determine whether it needs to:

  • obtain a CBUAE licence or authorisation;
  • obtain a required regulatory approval or No Objection Certificate;
  • modify its existing business activities;
  • restructure activities that fall outside the permitted scope; or
  • obtain professional advice where the regulatory position is unclear.

No general extension should be assumed unless the CBUAE formally announces one.

What Does Article 62 of the UAE Central Bank Law Mean?

Article 62 is one of the most important provisions for businesses operating at the intersection of financial services and technology.

The provision uses technology-neutral language when addressing persons carrying on, offering, issuing or facilitating Licensed Financial Activities. This means that the use of an API, mobile application, blockchain infrastructure, software platform or other technology does not, by itself, determine whether an activity is regulated.

The underlying activity and the way the business participates in or facilitates that activity remain critical to the analysis.

Payment API Providers

Businesses that provide APIs or technology infrastructure used in payment or other regulated financial processes should assess whether their activities amount to facilitating a Licensed Financial Activity.

The fact that the technology provider does not directly hold customer funds does not necessarily resolve the regulatory question.

Embedded Finance Platforms

E-commerce platforms, marketplaces and other digital businesses increasingly integrate financial products into their customer journeys.

Examples can include payment services, financing products, insurance and other financial services.

Where a platform actively facilitates a regulated financial activity, its role should be assessed against the CBUAE framework rather than relying solely on its commercial or technology classification.

Fintech Infrastructure Providers

Fintech infrastructure businesses can occupy different positions in the regulatory chain.

A provider offering general-purpose software may have a different regulatory position from a provider that performs an integral function in delivering a Licensed Financial Activity.

Businesses should therefore assess:

  • what their technology actually does;
  • who controls the regulated activity;
  • whether customers interact with the technology to access a financial service;
  • contractual responsibilities between the provider and regulated institution; and
  • whether the service falls within a CBUAE-regulated activity.

Blockchain and Decentralised Platforms

Technology-neutral legislation means that using blockchain or decentralised architecture does not automatically place a business outside financial regulation.

Platforms involved in activities such as payments, lending, trading or other financial services should assess whether their particular activities fall within the relevant UAE regulatory framework.

The regulatory analysis may also involve other UAE regulators depending on the activity and structure.

Software and Cloud Providers

Not every technology vendor serving a bank automatically becomes a CBUAE-regulated entity.

The regulatory position can depend on the nature and degree of the provider’s involvement in the Licensed Financial Activity. General technology services may need to be distinguished from technology that directly facilitates a regulated financial function.

This distinction is important for banks and fintech businesses reviewing their outsourcing and technology arrangements.

Which Businesses May Fall Within the CBUAE Regulatory Perimeter?

The new framework covers a broad range of financial activities. Depending on the activity being conducted, businesses that should assess their CBUAE position include:

  • banks and other financial institutions;
  • payment service providers;
  • money exchange businesses;
  • insurance and reinsurance companies;
  • Open Finance providers;
  • virtual asset payment service providers; and
  • technology businesses that facilitate or enable Licensed Financial Activities.

The fact that a company is incorporated in a commercial free zone does not, by itself, determine whether its activities are outside federal financial regulation.

Insurance Companies in UAE Commercial Free Zones

The new Central Bank Law is also relevant to insurance businesses operating from UAE commercial free zones.

Insurance businesses located in zones such as DMCC, JAFZA, RAKEZ, IFZA, Meydan and SAIF Zone should review their regulatory position against the new framework where they conduct insurance or other regulated activities.

The key issue is whether the business has the appropriate CBUAE regulatory status for the activities it conducts. Depending on the circumstances, this may involve authorisation, approval, a No Objection Certificate or another regulatory route.

An existing free zone trade or commercial licence should therefore not automatically be treated as evidence that an insurance activity is permitted under the CBUAE framework.

Affected businesses should also review governance, capital, outsourcing, claims management, compliance and operational arrangements against the requirements applicable to their regulatory status.

What Financial Activities Are Covered by the New Framework?

The new law brings several important financial activities under a consolidated federal framework.

Financial Activity Regulatory Position Key Consideration
Banking activities CBUAE regulated Includes core banking functions such as deposit-taking and lending
Payment services CBUAE regulated Businesses providing regulated payment services should assess licensing requirements
Money exchange CBUAE regulated Subject to applicable CBUAE requirements
Insurance and reinsurance Covered by the consolidated framework Includes applicable insurance and Takaful activities
Open Finance Statutory regulatory framework Relevant to participating financial institutions and qualifying providers
Virtual asset payment services Specifically addressed Regulatory treatment depends on the service being provided
Technology enabling Licensed Financial Activities Article 62 relevant Scope depends on the activity and degree of facilitation

Open Finance Under the UAE Central Bank Law

Open Finance is another important development within the UAE’s financial regulatory framework.

The concept allows authorised third-party providers and financial institutions to use secure data and API-based connectivity to deliver financial services, subject to the applicable regulatory requirements.

For banks and other financial institutions, the development of Open Finance creates technology, data, security and operational considerations in addition to traditional licensing obligations.

Technology companies participating in the Open Finance ecosystem should also determine whether their role requires regulatory approval or licensing.

This makes Open Finance relevant not only to banks but also to fintech businesses, API providers and other participants in the financial technology ecosystem.

Digital Dirham and Virtual Asset Payment Services

The new framework also reflects the UAE’s move towards digital financial infrastructure.

The Digital Dirham forms part of the UAE’s central bank digital currency framework, while virtual asset payment services represent a separate regulatory area.

Businesses should not treat every digital asset-related activity as equivalent. The regulatory treatment can depend on whether the business is providing a payment service, dealing with virtual assets, operating financial infrastructure or performing another regulated activity.

Where a business operates across multiple regulatory categories, more than one UAE regulatory framework may need to be considered.

Does the UAE Central Bank Law Apply to DIFC and ADGM Companies?

DIFC and ADGM have their own financial-services regulatory frameworks.

Financial services businesses operating within the DIFC are generally subject to the DFSA regulatory framework, while relevant financial services businesses in ADGM fall under the FSRA framework.

However, incorporation in DIFC or ADGM does not by itself eliminate the need to analyse the CBUAE position.

Businesses should consider:

  • the exact activities covered by their existing DFSA or FSRA permissions;
  • where those activities are being conducted;
  • whether they operate outside their financial free zone;
  • whether they provide services to UAE customers outside the relevant financial centre; and
  • whether another federal regulatory framework applies.

The correct approach is therefore to assess the activity, licence and regulatory perimeter, rather than relying only on the location of incorporation.

What Should Businesses Do Before 16 September 2026?

Businesses that may be affected by the new CBUAE framework should take a structured approach.

1

Map Your Business Activities

Prepare a complete list of the financial, payment, insurance, technology and platform activities carried out by the business. Do not assess the company only by reference to the wording of its trade licence.

2

Identify Potentially Regulated Activities

Compare the activities against the applicable Licensed Financial Activities and consider whether Article 62 is relevant because the business facilitates or enables a regulated activity.

3

Review Existing Licences

Check whether the current licence, authorisation or regulatory permission actually covers the activities being conducted. An ordinary commercial or free zone licence may not be sufficient for a regulated financial activity.

4

Review Technology and Outsourcing Contracts

Banks, financial institutions and fintech businesses should review agreements with API providers, payment technology companies, software providers, data-processing providers, cloud infrastructure providers and other critical technology vendors.

5

Obtain Regulatory Advice

Where the regulatory position is unclear, businesses should obtain advice from UAE financial regulatory counsel with experience in CBUAE licensing and financial services regulation.

6

Regularise Your Position

Where CBUAE authorisation, licensing, approval or restructuring is required, businesses should begin the relevant process before the transitional period expires.

What Happens If a Business Is Not Compliant After the Deadline?

The consequences of non-compliance can be significant.

The new law provides the CBUAE with enforcement and supervisory powers, including administrative penalties and other measures available under the legislation.

The law also provides for substantial penalties, with certain administrative fines reaching up to AED 1 billion. In circumstances involving the unlawful conduct of a Licensed Financial Activity, criminal consequences may also apply under the relevant provisions.

The exact consequence depends on the nature of the breach, the activity involved and the applicable provisions of the law.

Businesses should therefore avoid treating the 16 September 2026 deadline as a routine licence renewal date. For entities within the new perimeter, it can require a broader review of licensing, governance, operations, technology and contractual arrangements.

Frequently Asked Questions

What is the UAE Central Bank Law?

+
The UAE Central Bank Law is Federal Decree-Law No. 6 of 2025. It establishes a consolidated federal framework covering the Central Bank’s regulatory and supervisory functions and important areas of banking, payments, insurance and financial services.

When did the new UAE Central Bank Law come into force?

+
Federal Decree-Law No. 6 of 2025 came into force on 16 September 2025. Article 184 provided a one-year transitional period for relevant entities to regularise their position, making 16 September 2026 an important compliance date.

What is the 16 September 2026 CBUAE deadline?

+
The date marks the end of the one-year transitional period provided under Article 184 for affected entities. Businesses that may fall within the new regulatory perimeter should assess their licensing and compliance position before the transition period ends.

What does Article 62 of the CBUAE Law cover?

+
Article 62 addresses persons carrying on, offering, issuing or facilitating Licensed Financial Activities and uses technology-neutral language. This means businesses using APIs, digital platforms or other technologies should assess whether their particular activities fall within the CBUAE regulatory perimeter.

Do fintech companies need a CBUAE licence?

+
Not every fintech company automatically requires a CBUAE licence. The requirement depends on the activities performed and whether those activities fall within the Licensed Financial Activities or other applicable CBUAE regulatory requirements. Fintech businesses should assess their specific business model rather than relying on the term ‘technology company’.

Does a fintech company in a UAE free zone need CBUAE approval?

+
Potentially. A free zone commercial licence does not automatically exclude a business from federal financial regulation. If the company’s activities constitute or facilitate a CBUAE-regulated activity, the appropriate regulatory requirements may apply.

Does Article 62 apply to software companies serving banks?

+
It can, depending on the nature of the service. A general software vendor is not necessarily a regulated financial services provider, but technology that directly facilitates or enables a Licensed Financial Activity may require closer regulatory assessment.

Are insurance companies in commercial free zones affected?

+
Insurance businesses operating from commercial free zones should review their regulatory position under the new Central Bank Law. The relevant requirements depend on the insurance activities conducted and the applicable CBUAE regulatory route.

Does the new Central Bank Law apply to DIFC companies?

+
DIFC financial services businesses are primarily regulated by the DFSA within the DIFC framework. However, the location of incorporation alone does not determine every federal regulatory obligation. Businesses should assess their actual activities, permissions and geographic scope.

Does the new Central Bank Law apply to ADGM companies?

+
ADGM financial services businesses are primarily regulated by the FSRA within the ADGM framework. However, businesses should still assess whether their activities outside ADGM or their wider operating model create additional UAE regulatory considerations.

Is there an extension to the 16 September 2026 deadline?

+
Businesses should not assume that the transitional period has been extended unless the CBUAE formally announces an extension or other applicable relief. Any business relying on the transition should verify the latest CBUAE position before the deadline.

What happens if a business misses the CBUAE compliance deadline?

+
The consequences depend on the nature of the non-compliance and the activity involved. Potential consequences can include administrative penalties, regulatory restrictions and, where applicable, criminal liability for conducting regulated activities without the required authorisation.

Final Takeaway

The UAE Central Bank Law 2025 represents a significant development in the country’s financial regulatory framework. For traditional financial institutions, fintech businesses, insurers and technology companies operating close to regulated financial activities, the most important issue is understanding whether their actual activities fall within the CBUAE perimeter.

With the 16 September 2026 transitional deadline approaching, businesses should not rely solely on their existing commercial or free zone licence. They should review their activities, regulatory permissions, technology relationships and operating structure and take appropriate action where the new framework applies.

For businesses uncertain about their regulatory position, obtaining specialist UAE financial regulatory advice before the deadline can help identify potential licensing or compliance issues and determine the appropriate next step.

Need Help Assessing Your CBUAE Compliance Position?

If your business may fall within the UAE Central Bank’s regulatory perimeter, IncHub can help you review your corporate structure and coordinate with specialist UAE regulatory counsel on the appropriate next steps.

Speak to an Expert

Sources and References

  1. CBUAE Laws & Regulations
  2. Central Bank of the UAE
  3. UAE Legislation Portal
  4. Ministry of Finance
  5. DIFC Regulations
  6. ADGM Regulations
  7. WAM
  8. CBUAE Open Finance

Mahesh Maddu

Founder & CEO, IncHub

Mahesh Maddu is the Founder and CEO of IncHub Group. With over 15 years of advisory experience, he has supported founders, family offices, and global investors in setting up and managing businesses across UAE mainland, free zones, and offshore jurisdictions. He holds an MBA from Bangalore University and is a certified Anti-Money Laundering specialist and STEP member, with expertise in trust and foundation structuring for high-net-worth clients.