NEWVenvera speaks your language: the full platform, in English, German, Spanish and Bulgarian.See what’s new →
VARA CISO Appointment and Staff Competency Rules
Learn

VARA CISO Appointment and Staff Competency Rules

·Alexander Sverdlov

VARA Compliance · Dubai

The CISO appointment rule is three sentences long, and the staff competency rule is one. Almost everything else you have read about VARA’s people requirements is somebody’s opinion. Here is the rulebook text, and where the binding requirements actually sit.

VARA CISO appointment and staff competency requirements for virtual asset service providers licensed in Dubai

A VASP licensed by Dubai’s Virtual Assets Regulatory Authority must appoint a Chief Information Security Officer. That requirement is a Rule, it is binding, and it sits in Part I, Section I of the Technology and Information Rulebook - not, as is often written, in the Company Rulebook. The staff competency requirement sits next to it in Part I, Section J of the same rulebook.

Both rules are short. Section I is three numbered rules. Section J is one. VARA sets a small number of hard obligations and leaves the rest to you. That is not a licence to guess: the surrounding rulebooks - Company, and Compliance and Risk Management - carry the prescriptive numbers (years of experience, residency, reporting lines) for the other mandated roles, and those numbers are frequently misattributed to the CISO.

This article separates three things that are usually blended together: the binding Rules on the CISO and on staff; the binding Rules on the other appointments VARA mandates; and the Guidance in Schedule 1, which is expressed as expectations rather than obligations. Every requirement below is quoted or paraphrased from VARA’s published rulebooks, with the rule reference alongside.

Technology and Information Rulebook, Part I, Section I

What the CISO rule actually says

Rule I.I.1 is the whole of the appointment obligation:

“VASPs must appoint a Chief Information Security Officer (‘CISO’) who is responsible for ensuring that the VASP complies with Part I and Part III of this Technology and Information Rulebook. The CISO must be a separate individual from the CO however the CISO may also take on the responsibilities of the Data Protection Officer under Rule II.B.2 of this Technology and Information Rulebook.”

VARA Technology and Information Rulebook, Rule I.I.1

Three things follow directly from that text, and nothing else does.

  • The CISO’s remit is defined by rulebook scope, not by job description. The CISO is accountable for the VASP’s compliance with Part I (technology governance, cybersecurity, keys and wallets, testing and audit, transactions, algorithm governance, business continuity) and Part III (confidential information) of the Technology and Information Rulebook.
  • The CISO cannot be the Compliance Officer. Two individuals, always. This is the one combination the rulebook forbids by name.
  • The CISO may be the Data Protection Officer. Rule II.B.2.a repeats it from the other direction: “The Data Protection Officer can be the same individual as the CISO of the VASP.”

Rule I.I.2 sets the standard for the person: “The CISO must be of sufficiently good standing and appropriately experienced.” That is the complete text. Rule I.I.3 puts the ongoing burden on Senior Management, who must regularly assess and review the effectiveness of the VASP’s processes, procedures and controls for complying with the rulebook, and must “allocate duties and apportion roles and responsibilities within the VASP to prevent conflicts of interests”.

What the CISO rule does not say

It sets no minimum number of years. It names no certification. It imposes no UAE residency requirement. It specifies no reporting line. It does not prohibit combining the CISO role with the CTO or the MLRO. Any article that gives you a number for the CISO - “five to seven years”, “must report to the CEO” - is quoting itself, not VARA. Where numbers exist, they attach to other roles, and those are set out below.

Company Rulebook & Compliance and Risk Management Rulebook

Every appointment VARA actually mandates, with the criteria

The CISO is one of several named appointments. The prescriptive criteria - years of experience, residency, full-time status, reporting line, VARA approval - vary sharply by role. This table is the part most VASPs get wrong, because the strict conditions on the Compliance Officer are routinely repeated as if they applied to the CISO.

Appointment Source rule Stated criteria
Chief Information Security Officer Technology and Information Rulebook I.I.1-2 Must be appointed. Must be a separate individual from the Compliance Officer. May also be the Data Protection Officer. Must be “of sufficiently good standing and appropriately experienced”. No years, no residency, no certification stated.
Compliance Officer (CO) Compliance and Risk Management Rulebook I.C.1 At least five (5) years of relevant experience in a compliance function; a Fit and Proper Person approved by VARA; resident in the UAE or a UAE passport holder; a full-time employee; reports directly to the Board. The appointment is reviewed annually.
Money Laundering Reporting Officer (MLRO) Compliance and Risk Management Rulebook III.A.1-2 At least two (2) years of experience handling AML/CFT matters; a Fit and Proper Person; appointment reviewed annually. Reports to the Board quarterly on the effectiveness of AML/CFT policies and procedures.
Data Protection Officer (DPO) Technology and Information Rulebook II.B.2.a Must have the competencies and experience to perform the statutory duties of the role under applicable data protection law, including Article 11 of the UAE PDPL. Can be the same individual as the CISO.
Responsible Individuals (two) Company Rulebook I.C.1-4 VASPs must appoint two (2) individuals of sufficient seniority responsible for the VASP’s compliance with all legal and regulatory obligations. Each must be a full-time employee, a Fit and Proper Person, a UAE resident or UAE passport holder, and notified to and approved by VARA during licensing. Any change requires prior VARA approval.
Company Secretary Company Rulebook I.E.1 The Board must appoint a Company Secretary independent of Senior Management, reporting directly to the Board. May be outsourced to an external entity, in which case Part IV (Outsourcing Management) applies.
Internal audit function Compliance and Risk Management Rulebook I.G.2 Where applicable, an objective internal audit function independent of the operational function, reporting directly to Senior Management, performing audit work at least quarterly.
External auditor Compliance and Risk Management Rulebook I.G.1 An independent third-party auditor for the financial statements, producing an annual report. VARA must be notified of the auditor’s name and contact details on appointment.

Two combination rules are worth stating precisely, because they cut in opposite directions. The Compliance Officer may hold more than one non-client-facing role, expressly including MLRO and head of the risk function, provided the roles do not create conflicting duties (Compliance and Risk Management Rulebook I.C.4, and III.A.4 from the MLRO side). The CISO, by contrast, may not be the CO. And under the Company Rulebook, a member of Senior Management may sit on the Board - except the CO and the head of any internal audit function (Company Rulebook I.D.5.a), both of whom should report directly to the Board (Company Rulebook II.B.3).

The minimum headcount that follows from the Rules, then, is not a matter of company size. Every licensed VASP needs at least: two Responsible Individuals, a Compliance Officer, an MLRO, a CISO, a DPO, and a Company Secretary. The CO may double as MLRO. The CISO may double as DPO. The CISO may not be the CO. VARA publishes no staffing table keyed to headcount, and any article that gives you one has invented it.

Company Rulebook, Parts II and III

How to evidence “appropriately experienced” when VARA gives no number

Illustrative Venvera dashboard view showing control effectiveness, open incidents and risk signals for a VARA-regulated VASP

Rule I.I.2 gives you two words and no threshold. The place to look for the assessment criteria is not the Technology and Information Rulebook at all - it is the Company Rulebook, which tells you how a VASP is expected to assess whether anyone in a supervisory post is suitably qualified.

Company Rulebook II.A.1 requires VASPs to maintain policies and procedures ensuring that all members of the Board, Senior Management and Staff are suitably qualified for their post, and it lists the criteria the internal assessment must include: academic credentials; professional qualifications; professional experience; awards and honours received; and memberships of professional and service organisations. II.A.2 adds that the Board can only appoint to supervisory positions Staff with relevant experience and qualifications, taking into account the responsibilities of the role and the VA Activities of the VASP.

That is the honest answer to “what does appropriately experienced mean?” It means: run the assessment the Company Rulebook prescribes, in writing, against the five named criteria, and keep the file. A certification such as CISSP or CISM is evidence under the “professional qualifications” heading; it is not a VARA requirement and it does not substitute for the assessment.

The Fit and Proper test, and who it binds

Company Rulebook Part III defines a Fit and Proper Person as someone who possesses the necessary academic qualifications and relevant professional or industry qualifications having regard to the function; is honest, reputable and has integrity; possesses adequate relevant global Virtual Asset sector and management experience, or such experience in another relevant sector; has a good understanding of the applicable regulatory framework; and is financially sound.

The Fit and Proper test is expressly attached to the Compliance Officer (I.C.1.b of the Compliance and Risk Management Rulebook), the MLRO (III.A.1.b), Responsible Individuals (Company Rulebook I.C.2.b), and all Staff performing compliance functions (Compliance and Risk Management Rulebook I.B.5). The CISO rule does not invoke it by name - but Company Rulebook II.A.1 still requires a documented suitability assessment for every supervisory post, and Rule I.I.2’s “sufficiently good standing” test covers similar ground. Running the Fit and Proper assessment on your CISO is the defensible course; claiming VARA compels it is not.

Technology and Information Rulebook, Part I, Section J

Staff competency: one sentence, and where the rest of it lives

Process view of a VARA staff competency programme covering onboarding, cybersecurity awareness and record keeping

Section J of the Technology and Information Rulebook is a single rule:

“In addition to relevant requirements in the Compliance and Risk Management Rulebook, VASPs must ensure that all Staff are aware of the latest cybersecurity risks and developments (including those specific to Virtual Assets and DLT), taking into account the type and level of cyber risks that they may face in their respective roles.”

VARA Technology and Information Rulebook, Rule I.J.1

Note what the rule does and does not do. It applies to all Staff, not just technical staff. It requires currency (“the latest”), it requires virtual-asset and DLT specificity, and it requires role-proportionality (“the type and level of cyber risks that they may face in their respective roles”). It sets no frequency. There is no annual mandate, no quarterly refresher requirement, and no tiered curriculum in the rulebook. Any training calendar you have seen presented as a VARA requirement is a vendor’s design choice.

The rule’s own opening words point you to where the operational training obligations are written: the Compliance and Risk Management Rulebook, Part I, Section J (Staff Management and Training). Those are Rules, and they do carry a timeline:

  • Hire only the qualified (I.J.1). Procedures to ensure the VASP only employs suitably qualified individuals with the requisite skills, knowledge and expertise for the duties they are employed to perform, duly registered with any applicable professional bodies.
  • Enough of them (I.J.2). Appropriate numbers of Staff to discharge relevant duties effectively. Unless a rulebook says otherwise, Staff are not required to be physically located in the Emirate, provided supervisory, monitoring and enforcement functions are effectively implemented to VARA’s satisfaction.
  • Training at the start and continuously (I.J.4). “Adequate training suitable for the duties which the Staff is required to perform in their role shall be provided at the beginning of their employment and on an ongoing basis.”
  • AML/CFT training on a regular basis (I.J.5), with monitoring of Staff compliance with established procedures.
  • Thirty days for policies (I.J.6). All operational policies and procedures must be communicated to new hires within their first thirty (30) calendar days. When policies are updated, the change must be promptly communicated to all Staff and the updated version made available at all times (I.J.7).

That thirty-day window is the only hard clock in the staff-training rules. It is a documentation obligation as much as a training one, and it is the kind of thing a supervisor can check against a record.

Venvera policy library showing policies with owners, versions and review dates for staff acknowledgement
Rule I.J.6 of the Compliance and Risk Management Rulebook gives you thirty days to put every operational policy in front of a new hire. That resolves to an acknowledgement record, not a training slide.

Guidance, not Rule: Schedule 1, Risk Category 1

Schedule 1 of the Technology and Information Rulebook is expressly issued as Guidance, phrased throughout as what VASPs are “expected to” do. Its Workforce security management standard (Risk Category 1, item 3) is where the familiar controls live: mandatory endpoint protection for all devices with access to any systems; regular security awareness training specific to common threats; background checks for all personnel with access to sensitive or critical systems; formalised onboarding and offboarding procedures for all staff including contractors; and minimum security requirements for personal devices used for work. Treat these as the expected standard of practice. Do not cite them as binding Rules, because they are not drafted as such.

Technology and Information Rulebook, Parts II and III

The CISO also owns confidential information and the data-incident clock

Rule I.I.1 makes the CISO responsible for the VASP’s compliance with Part III of the Technology and Information Rulebook as well as Part I. Part III is short and it is aimed squarely at staff behaviour:

  • Familiarise and certify (III.A.3). VASPs must familiarise Staff with their internal policies on the collection and processing of confidential information and with the Part III requirements applicable to them, and must periodically certify their Staff’s compliance with those internal policies. This is an explicit, recurring attestation duty.
  • Need-to-know sharing (III.A.4). Staff must not share confidential information inside the VASP or with any other entity “unless it is absolutely necessary for the purposes of conducting VA Activities related to such confidential information”.
  • No trading on it (III.A.5). Neither the VASP nor its Staff may use or share confidential information for the purpose of trading Virtual Assets by any entity.

Part II carries the personal-data obligations, and it is where the twenty-four hour clock lives - a clock that is widely misdescribed. Rule II.C.2 requires the VASP to notify VARA within twenty-four (24) hours following notification by the VASP to a data regulator or to a Data Subject of any incident affecting, or potentially affecting, Personal Data, and to provide VARA with a summary of that report (and, where the data regulator is in the UAE, a copy of it). The trigger is your notification to the data regulator or the data subject, not the moment you detect the incident.

The other clock: seventy-two hours

Do not confuse the data-incident clock with the cybersecurity one. Rule I.K.1 requires a VASP to report a material cybersecurity event, or an event triggering the BCDR Plan that materially impacts business operations, to VARA as soon as reasonably practicable and in any event no later than seventy-two (72) hours from detection. That one runs from detection. Both sit inside the CISO’s Part I and Part III remit, and both need a named escalation path that works at 3am.

Keeping the evidence a supervisor would ask for

Venvera evidence repository showing stored compliance artefacts with owners and freshness status
The Part III duty to periodically certify Staff compliance with internal confidentiality policies is an artefact with a date on it, or it did not happen.

Almost every obligation above resolves to a record: the suitability assessment behind an appointment, the policy acknowledgement inside thirty days, the periodic certification of Staff compliance under Part III, the incident escalation that met a 24-hour or 72-hour clock. VARA does not publish a template for any of them, which is precisely why they go missing.

Venvera does not ship a VARA framework module. What it does ship is the underlying machinery those records live in: a policy library with acknowledgement tracking, a risk register, an evidence repository with freshness tracking, incident management, third-party risk management, and a control crosswalk across the frameworks it does cover, including ISO 27001, NIST CSF and UAE Information Assurance. If your CISO is carrying the Part I and Part III remit without a system of record behind it, that is the gap worth closing first.

Put the evidence behind your appointments in one place

Policies, acknowledgements, risks, incidents and control evidence, kept audit-ready and reusable across the frameworks you already run.

Book a demo →

Frequently Asked Questions

Does every VARA-licensed VASP have to appoint a CISO?

Yes. Rule I.I.1 of the Technology and Information Rulebook states that VASPs must appoint a Chief Information Security Officer, responsible for ensuring the VASP complies with Part I and Part III of that rulebook. It is a Rule with binding effect and it applies to all VASPs licensed by VARA to carry out any VA Activity in the Emirate.

Can the CISO also be the Compliance Officer or the Data Protection Officer?

The CISO must be a separate individual from the Compliance Officer - Rule I.I.1 says so expressly. The CISO may take on the responsibilities of the Data Protection Officer, and Rule II.B.2.a confirms it from the other side: the DPO can be the same individual as the CISO. The rulebook does not address combining the CISO with the CTO or the MLRO, so no VARA rule prohibits it, but Rule I.I.3 requires Senior Management to apportion roles so as to prevent conflicts of interest.

How many years of experience does VARA require a CISO to have?

None are stated. Rule I.I.2 requires only that the CISO be “of sufficiently good standing and appropriately experienced”. The five-year minimum belongs to the Compliance Officer (Compliance and Risk Management Rulebook I.C.1.a) and the two-year minimum to the MLRO (III.A.1.a). Neither applies to the CISO. What does apply is Company Rulebook II.A.1, which requires a documented suitability assessment against academic credentials, professional qualifications, professional experience, awards and honours, and professional memberships.

Does the CISO have to be resident in the UAE?

No residency requirement is stated for the CISO. The UAE residency or UAE passport condition applies to the Compliance Officer (Compliance and Risk Management Rulebook I.C.1.c) and to both Responsible Individuals (Company Rulebook I.C.2.c). More generally, Compliance and Risk Management Rulebook I.J.2 states that, unless otherwise stated in the Regulations and Rulebooks, Staff are not required to be physically located in the Emirate, provided the VASP can ensure supervisory, monitoring and enforcement functions are effectively implemented to VARA’s satisfaction.

How often must VASP staff receive cybersecurity training under VARA?

The Technology and Information Rulebook sets no frequency. Rule I.J.1 requires that all Staff are aware of the latest cybersecurity risks and developments, including those specific to Virtual Assets and DLT, proportionate to the risks they face in their roles. The Compliance and Risk Management Rulebook adds that adequate training must be provided at the beginning of employment and on an ongoing basis (I.J.4), that AML/CFT training must be provided on a regular basis (I.J.5), and that operational policies and procedures must be communicated to new hires within their first thirty calendar days (I.J.6). Annual and quarterly training cadences are common practice, not VARA requirements.

Which rulebook contains the CISO and staff competency rules?

The Technology and Information Rulebook, Part I, Sections I and J. They are frequently misattributed to the Company Rulebook. The Company Rulebook governs the Board, Senior Management, Responsible Individuals, the Company Secretary, competence assessments and the Fit and Proper test; the Compliance and Risk Management Rulebook governs the Compliance Officer, the MLRO, internal and external audit, and staff management and training.

Primary sources

Every requirement in this article is taken from VARA’s published rulebooks. Confirm the current version before relying on any specific rule, since VARA revises the rulebooks from time to time.

  • VARA Technology and Information Rulebook - Part I Section I (CISO), Part I Section J (Staff Competency), Part I Section K (72-hour notification), Part II (Personal Data Protection, including the DPO and the 24-hour notification), Part III (Confidential Information), Schedule 1 (Guidance).
  • VARA Compliance and Risk Management Rulebook - Part I Section C (Compliance Officer), Part I Section G (Audit), Part I Section J (Staff Management and Training), Part III Section A (MLRO).
  • VARA Company Rulebook - Part I Sections C, D and E (Responsible Individuals, Senior Management, Company Secretary), Part II Sections A and B (Competence, Segregation of Duties), Part III (Fit and Proper Requirements).
  • VARA Rulebooks index - the current, effective versions of all rulebooks.

Last updated: July 2026. This article is general information, not legal advice. Confirm the current rulebook text and consult VARA directly for entity-specific guidance.

Alexander Sverdlov

Alexander Sverdlov

CEO & Founder

Alexander is the founder of Venvera and a 20+ year veteran of European cybersecurity and compliance. He has led security and risk programmes for regulated financial institutions, fintechs and SaaS companies operating under DORA, NIS2, GDPR, ISO 27001 and the EU AI Act. Before Venvera, he founded Atlant Security, an offensive security consultancy that ran penetration tests, red-team exercises and ISO 27001 readiness programmes for clients across the EU and the Middle East. He writes on the cross-framework realities of running modern compliance: how to map one control to many obligations, where the spreadsheets fall apart, and what regulators are actually asking for once the auditor sits down.

More articles by Alexander

RELATED POSTS