UAE

CBUAE Compliance and Mobile App Security: What UAE Fintechs Must Fix Before March 2026

Learn how UAE banks and fintechs must comply with CBUAE’s SMS OTP phase-out by March 2026 and strengthen mobile app security.

By · · 5 Min

CBUAE Compliance and Mobile App Security: What UAE Fintechs Must Fix Before March 2026

Digital banking in the United Arab Emirates (UAE) is experiencing a strategic transformation owing to rising cyber-attacks and exploitation of mobile app security vulnerabilities.

Digital Banking & Rising Mobile App Fraud in the UAE

With the UAE positioned as a regional fintech hub across Dubai and Abu Dhabi, CBUAE’s directive signals a decisive move toward phishing-resistant, mobile-first authentication across the banking ecosystem.

Read ahead to know details about CBUAE compliance and mobile app security.

CBUAE Notice: Directive and Its Effect

In May 2025, the CBUAE released a notice that is poised to significantly reshape how banks secure their customers against digital fraud and scams.

Understanding the New Regulations: Moving Away from SMS OTPs

The regulator’s mandate calls for UAE-licensed banks and financial institutions to retire legacy authentication controls such as SMS and email OTPs. This shift is driven by three key considerations:

Critical Timelines: UAE Banking Compliance 2025

The CBUAE has set a strict timeline for digital banking authentication compliance. Institutions cannot afford to delay their migration strategies if they wish to meet the UAE Banking Compliance goals.

Banks and financial institutions must modernise their security systems, including upgrading apps and integrating passkeys, to meet this deadline.

The Shared Accountability

The CBUAE mandate underscores a renewed focus on consumer protection, raising the bar for how UAE’s financial institutions manage transaction security.

What Must Fintechs Fix?

To meet the requirements outlined in the notice, banks and financial institutions must deploy, amongst other aspects, advanced authentication mechanisms capable of validating both the end user and their device in real time. A straightforward example is an app-based authentication flow that replaces SMS OTPs:

To enhance mobile app security, UAE banks and financial institutions are required to implement several advanced technologies such as, but not limited to, the following:

Impact on the UAE Banking Ecosystem

The CBUAE directive introduces structural changes that will influence institutions, customers, and the broader financial landscape.

The Strategic Fast-mover Advantage

It is understandable for the banking sector to perceive this directive as an additional layer of complex and costly compliance. Yet, forward-looking institutions should recognise it as a pivotal strategic moment.

Thus, fintech organisations that implement device-bound authentication early can differentiate themselves as leaders in compliant, user-centric mobile app security.

Ensure CBUAE-Ready Mobile App Security

Protectt.ai helps UAE banks and fintechs comply with CBUAE authentication mandates using zero-trust device binding and runtime app protection.

Frequently Asked Questions (FAQ)

Here are some frequently asked questions and their short answers about CBUAE Compliance and Mobile App Security.

When does the CBUAE’s transition from SMS OTPs take effect?

The transition begins in July 2025, when UAE banks must start shifting toward app-based authentication. By March 2026, advanced authentication will be the required standard.

What are the approved alternatives to SMS OTPs in the UAE?

Conceptually, technologies such as device binding, passkeys (FIDO2/WebAuthn), and soft tokens generated within a secure app can be considered as alternatives to SMS OTPs.

Why is the Central Bank of the UAE phasing out SMS OTPs?

SMS and email OTPs are being phased out because they are vulnerable to SIM-swap attacks, message interception, and phishing. This move also aligns with the global regulatory move to adopt phishing-resistant methods.

How does the new authentication mandate affect the end user experience?

The shift is expected to improve the end user experience by removing friction. Instead of waiting for an SMS code, end users will use faster methods like biometric approval (fingerprint or face ID) or push notifications directly inside their banking app.

Secure your Corporate App with Protectt.ai

If you are looking for ways to comply with CBUAE regulations regarding mobile app security, do visit our AppBind Page (Zero Trust Device And SIM Binding Solution) and Request a Demo.