What we do
01  Advanced Infrastructure 02  Applied AI & Data 03  AI Cybersecurity 04  AI Assurance
Engagements
AI estate inventory Assurance review
Industries
Financial Services Government & Public Sector Energy & Utilities Telecommunications Healthcare & Life Sciences Transport & Logistics Industrial & Manufacturing Retail, Hospitality & Real Estate
Research
The Trust Maturity Model The GCC Assurance Index Readiness self-assessment Case studies Perspectives Sector briefings Technology evaluations
Company
About us Partners Events Careers Contact العربية Talk to our team
Research  ·  Telecommunications

Stored here. But where does it travel?

What we are watching in this sector, and the research that touches it. This is the research view; the services view is on the industry page.

SECTOR VIEWUPDATED 26 AUGUST 2026RESEARCH ONLY
What we are watching

Three questions we put to every estate in this sector.

01

Re-routing that moves your jurisdiction

Whether automatic re-routing changes your jurisdictional position without a record.

02

What the control plane holds

What the control plane holds, and whether that metadata is itself in scope.

03

Reach of a compromised supplier credential

What a supplier credential can reach on the day it is compromised.

Obligations in force

What is already due, and what is coming.

Every obligation below is dated, named and externally imposed. Read them against what your organisation could evidence this week rather than against what it intends to build.

JAN 2026UAE

Child Digital Safety Law No. 26 (2025) in effect

Active content filtering and age verification by ISPs and platforms — in practice, AI-driven moderation.

ROLLING OUT 2026UAE — NCAP

National Cyber Accreditation Programme

That security and cloud suppliers serving critical infrastructure hold UAE accreditation.

IN FORCEUAE — TDRA

Telecommunications policies including in-country data residency

Regulated data held on residency-compliant infrastructure.

IN FORCEUAE federal — NESA

Information Assurance Standard v2 — CNI operators in scope

39 mandatory Priority One controls demonstrated.

IN FORCEUAE

Secure Supply Chain Programme

Software Bill of Materials transparency for government-facing supply.

DURING 2026UAE Cyber Security Council

National Encryption Policy — PQC migration planning

Cryptographic inventory across network and subscriber systems.

1 JAN 2026DIFC

Regulation 10 full enforcement — applies to DIFC-registered technology entities

Risk assessments, transparency, human oversight, or a named Autonomous Systems Officer.

IN FORCECBUAE

Applies to operator-owned wallets and payment arms

Fraud prevention, breach reporting; management liability under Decree-Law No. 6 (2025).

Reproduced from the Orvix Telecommunications industry page. Last reviewed 26 August 2026.

Looking for services rather than research?

The industry page sets out what we actually do in this sector and who delivers it.

Telecommunications →