Digital banking in the United Arab Emirates (UAE) is experiencing a strategic transformation owing to rising cyber-attacks and exploitation of mobile app security vulnerabilities.
Digital Banking & Rising Mobile App Fraud in the UAE
With the UAE positioned as a regional fintech hub across Dubai and Abu Dhabi, CBUAE’s directive signals a decisive move toward phishing-resistant, mobile-first authentication across the banking ecosystem.
- Fraud activity continues to escalate across the region as attackers exploit inadequate authentication controls.
- As reported by Khaleej Times, 'By 2028, app scam losses through real-time payments in the UAE are expected to hit $26.8 million.'
- In response, the Central Bank of the UAE (CBUAE) has implemented firm measures to enhance consumer protection and asked institutions to comply with their requirements.
Read ahead to know details about CBUAE compliance and mobile app security.
CBUAE Notice: Directive and Its Effect
In May 2025, the CBUAE released a notice that is poised to significantly reshape how banks secure their customers against digital fraud and scams.
- Financial institutions are required to transition away from SMS- and email-based one-time passwords (OTPs) and static passwords, adopting more robust and sophisticated authentication mechanisms such as app-based authenticators, biometric verification, device-bound passkeys, and behavioural biometrics.
- For fintech leaders, aligning with the new CBUAE mandate marks a shift from traditional single-factor credentials toward continuous, intelligence-led identity assurance.
Understanding the New Regulations: Moving Away from SMS OTPs
The regulator’s mandate calls for UAE-licensed banks and financial institutions to retire legacy authentication controls such as SMS and email OTPs. This shift is driven by three key considerations:
- Rising Fraud Exposure: Threat actors are increasingly leveraging phishing techniques, SIM-swap attacks, and message interception to compromise OTPs. As a result, strengthening mobile banking fraud prevention in the UAE has become an urgent priority to safeguard customer accounts.
- User Experience Challenges: Traditional SMS codes introduce friction during login and payment flows, generating avoidable delays and degrading the overall end-user experience.
- Global Regulatory Alignment: The UAE is aligning with jurisdictions such as Singapore and the European Union (EU), which are advocating for the adoption of phishing-resistant authentication methods.
Critical Timelines: UAE Banking Compliance 2025
The CBUAE has set a strict timeline for digital banking authentication compliance. Institutions cannot afford to delay their migration strategies if they wish to meet the UAE Banking Compliance goals.
- July 2025: UAE banks must begin shifting to enhanced authentication.
- March 2026: Advanced authentication becomes the mandatory standard.
Banks and financial institutions must modernise their security systems, including upgrading apps and integrating passkeys, to meet this deadline.
The Shared Accountability
The CBUAE mandate underscores a renewed focus on consumer protection, raising the bar for how UAE’s financial institutions manage transaction security.
- The expectation is increasingly that enterprises must proactively safeguard users against interception attacks, rather than relying solely on user vigilance.
- This effectively places the onus on institutions to secure the communication channel, requiring a move beyond standard SMS/Email delivery to mitigate institutional risk.
What Must Fintechs Fix?
To meet the requirements outlined in the notice, banks and financial institutions must deploy, amongst other aspects, advanced authentication mechanisms capable of validating both the end user and their device in real time. A straightforward example is an app-based authentication flow that replaces SMS OTPs:
- The end user receives a push notification within the bank’s secure mobile application.
- The user selects either approval or denial of the request.
- The action is verified using biometrics or a PIN.
To enhance mobile app security, UAE banks and financial institutions are required to implement several advanced technologies such as, but not limited to, the following:
- Device Binding: Authentication credentials are tied to a specific device or hardware token, preventing their use if copied or stolen.
- Passkeys (FIDO2/WebAuthn): Cryptographic, device-stored credentials that provide phishing-resistant login experiences.
- Soft Tokens: One-time codes generated within the bank’s secured application, ensuring they are never transmitted across vulnerable channels such as SMS.
Impact on the UAE Banking Ecosystem
The CBUAE directive introduces structural changes that will influence institutions, customers, and the broader financial landscape.
- For banks: The directive might require substantial investment in modern authentication frameworks, yet it creates long-term operational efficiencies. Transitioning to ‘passwordless’ authentication lowers OTP-related costs and enables institutions to redirect resources toward innovation.
- For end users: Instead of manually entering OTPs, end users will authenticate using built-in device capabilities such as fingerprint or facial recognition. This results in faster access, fewer authentication errors, and improved protection against phishing attacks.
- For the broader ecosystem: The mandate is expected to strengthen confidence in digital banking and accelerate the uptake of online services, marking a strategic shift in the UAE financial sector’s mobile app security landscape.
The Strategic Fast-mover Advantage
It is understandable for the banking sector to perceive this directive as an additional layer of complex and costly compliance. Yet, forward-looking institutions should recognise it as a pivotal strategic moment.
- The mandate creates an opportunity to outpace competitors by delivering a digital experience that is significantly more secure while being substantially simpler for end users.
- End users will encounter fewer SMS-based verification steps and more immediate, app-based approvals, resulting in faster and more secure interactions.
- The UAE’s transition is consistent with global regulatory movements, including the Monetary Authority of Singapore’s 2024 directive, and forms part of the Financial Infrastructure Transformation (FIT) Programme.
Thus, fintech organisations that implement device-bound authentication early can differentiate themselves as leaders in compliant, user-centric mobile app security.
Ensure CBUAE-Ready Mobile App Security
Protectt.ai helps UAE banks and fintechs comply with CBUAE authentication mandates using zero-trust device binding and runtime app protection.
Frequently Asked Questions (FAQ)
Here are some frequently asked questions and their short answers about CBUAE Compliance and Mobile App Security.
When does the CBUAE’s transition from SMS OTPs take effect?
The transition begins in July 2025, when UAE banks must start shifting toward app-based authentication. By March 2026, advanced authentication will be the required standard.
What are the approved alternatives to SMS OTPs in the UAE?
Conceptually, technologies such as device binding, passkeys (FIDO2/WebAuthn), and soft tokens generated within a secure app can be considered as alternatives to SMS OTPs.
Why is the Central Bank of the UAE phasing out SMS OTPs?
SMS and email OTPs are being phased out because they are vulnerable to SIM-swap attacks, message interception, and phishing. This move also aligns with the global regulatory move to adopt phishing-resistant methods.
How does the new authentication mandate affect the end user experience?
The shift is expected to improve the end user experience by removing friction. Instead of waiting for an SMS code, end users will use faster methods like biometric approval (fingerprint or face ID) or push notifications directly inside their banking app.
Secure your Corporate App with Protectt.ai
If you are looking for ways to comply with CBUAE regulations regarding mobile app security, do visit our AppBind Page (Zero Trust Device And SIM Binding Solution) and Request a Demo.