Cyber & IT Risk

Supplier notification clauses must support ADGM reporting deadlines

ADGM’s cyber rules give regulated firms 24 hours to report a material incident. Most standard supplier contracts were never written to make that deadline achievable.

Eliga Consultancy 11 September 2026 Cyber Security, Outsourcing, UAE 5 minute read

The FSRA’s September cyber-threat updates reinforce its continuing supervisory focus on operational resilience under cyber rules effective from 31 January 2026, requiring material incident reporting within 24 hours of awareness.

01

What the framework actually requires

Governance, classification, monitoring, 24-hour reporting

Effective from 31 January 2026, binding on ADGM-regulated Authorised Persons.

The FSRA’s Cyber Security Risk Management rules require ADGM-regulated Authorised Persons to implement board-approved cyber risk governance, classify ICT assets, maintain continuous monitoring, and report material cyber incidents within 24 hours of becoming aware of them.

The framework was announced 29 July 2025 following Consultation Paper No. 3 of 2025, became effective from 31 January 2026, and the FSRA’s September 2026 cyber threat updates confirm continuing supervisory focus on operational resilience under these rules.

02

The 24-hour deadline is stricter than it sounds

No exception for weekends or holidays

The clock starts the moment you become aware, or reasonably should be.

Notification is required no later than 24 hours after the firm becomes aware of a material incident, or becomes aware of information reasonably suggesting one, and this applies regardless of weekends or public holidays.

For a firm depending on outside suppliers for parts of its technology stack, that 24-hour clock is only as fast as the slowest supplier notification in the chain.

A supplier clause allowing notification only after a completed investigation can leave the regulated customer unable to meet its own deadline.

03

Why this becomes a contract problem

Your deadline depends on your supplier’s clause

Most standard SaaS and IT agreements were never written with a 24-hour customer deadline in mind.

Many supplier agreements notify the customer only once the supplier has completed its own internal investigation, which can take days or weeks. For an ADGM-regulated customer, that structure makes compliance with the 24-hour rule effectively impossible, through no fault of the customer’s own response.

This is not a hypothetical gap. It is the default position in a large share of standard SaaS and managed service terms.

04

What supplier notification clauses need to say

Trigger on awareness, not conclusion

Four elements that actually let a regulated customer meet its own deadline.

The notification trigger should fire on the supplier becoming aware of an incident or reasonably suggestive information, not on completing an investigation.

Named escalation contacts should be specified in the contract itself, not left to be found during an actual incident.

Evidence-sharing obligations should be explicit, so the customer can assess materiality quickly rather than waiting on the supplier’s own assessment.

Cooperation duties should extend to the supplier’s own subcontractors, since an incident at a sub-processor is still an incident in the customer’s supply chain.

  • Awareness-based trigger, not an investigation-complete trigger.
  • Named escalation contacts, agreed in advance, not discovered mid-incident.
  • Evidence-sharing duties that let the customer assess materiality fast.
  • Subcontractor cooperation flowed down through the whole chain.
05

Who this reaches beyond the regulated firm itself

Every supplier in the chain

You do not have to be ADGM-regulated for this to be your problem.

Any business supplying SaaS or IT services into an ADGM-regulated customer needs contract terms that can actually support that customer’s 24-hour obligation, regardless of the supplier’s own regulatory status.

A supplier unwilling to accept an awareness-based notification trigger is effectively telling a regulated customer it cannot help them meet a binding regulatory deadline, which is worth knowing before the incident happens, not during it.

Questions this raises

Six questions the ADGM cyber risk framework tends to prompt, answered directly.

What does ADGM’s cyber risk framework actually require?

The FSRA’s Cyber Security Risk Management rules, effective from 31 January 2026, require ADGM-regulated Authorised Persons to maintain board-approved cyber governance, classify ICT assets, run continuous monitoring, and report material cyber incidents within 24 hours of becoming aware of them.

When was this framework actually introduced?

The FSRA announced the cyber risk management framework on 29 July 2025, following its Consultation Paper No. 3 of 2025, with the rules becoming effective from 31 January 2026 and continuing supervisory focus reinforced in FSRA updates through September 2026.

Does the 24-hour reporting deadline apply to weekends and holidays?

Yes. Notification of a material incident must happen no later than 24 hours after the firm becomes aware of it, or becomes aware of information reasonably suggesting an incident, regardless of weekends or public holidays.

Why does this matter for contracts with SaaS and IT suppliers?

Because a regulated firm’s own 24-hour deadline only works if its suppliers tell it about an incident fast enough to meet it. A supplier contract that allows notification only after a completed investigation can make the deadline impossible to hit.

What should supplier notification clauses actually require?

A notification trigger tied to the supplier becoming aware of an incident, not concluding an investigation, named escalation contacts, evidence-sharing obligations, and cooperation duties that extend to the supplier’s own subcontractors.

Does this only apply to financial services firms in ADGM?

The rules apply to ADGM-regulated Authorised Persons specifically. But any business supplying SaaS or IT services into that regulated population needs contracts that can actually support the customer’s 24-hour obligation, regardless of the supplier’s own regulatory status.

Sources

  1. ADGM Financial Services Regulatory Authority, cyber threat intelligence update, published 11 September 2026.
  2. ADGM Financial Services Regulatory Authority, cyber risk management framework announcement, published 29 July 2025.

Supplying SaaS or IT services into ADGM-regulated customers?

Eliga provides embedded commercial and technology counsel to scaling businesses. We can review whether your incident notification clauses can actually support a customer’s 24-hour regulatory deadline.

This page is general information about commercial law and technology. It is not legal advice and does not create a solicitor-client relationship. Take specific advice on anything you are about to negotiate or sign.