Federal Decree-Law No. 6 of 2025 - also referred to as CB Law 2025 - took effect on 16 September 2025, and full compliance is due 16 September 2026. That gives banking technology leaders roughly a year from the effective date to work through it, and the reason it deserves attention now rather than closer to the deadline is scope: FDL 6/2025 expands the regulatory perimeter well beyond traditional banking, and the penalty exposure for getting it wrong is AED 1 billion.
This is a central banking law, not a niche crypto regulation. It brings DeFi protocols, tokenised real-world assets, stablecoin issuers, and - critically for banks running partner or embedded-finance programmes - enabling technology providers within scope. If your institution works with technology partners whose platforms sit underneath a regulated financial product, that relationship is now part of what this law reaches.
FDL 6/2025 is not PTSR
It's worth being precise here, because the two frameworks get conflated and they shouldn't be. The Payment Token Services Regulation - CBUAE Circular 2/2024 - governs payment tokens and stablecoins specifically. Its transitional period ended 14 June 2025, and it has been fully in force since then, with its own licensing and registration pathways for Dirham and Foreign Payment Tokens.
FDL 6/2025 is a separate law with a separate deadline and a much broader scope. Where PTSR is about a category of instrument, FDL 6/2025 is about the full financial-system perimeter - including the technology providers that enable regulated financial activity, whether or not that activity involves a payment token at all. A bank can be fully compliant with PTSR and still have exposure under FDL 6/2025 if an embedded-finance programme, a sponsor-bank arrangement, or a technology vendor relationship falls within the expanded perimeter.
Two laws, two deadlines, two different questions. Confusing them is how banks end up compliant with the one they checked and exposed under the one they didn't.
What to check before 16 September 2026
For banks with technology partners, embedded-finance programmes, or sponsor arrangements, the practical work is assessment, not guesswork. A short list of what belongs on that assessment:
- Map every technology partner and embedded-finance programme against FDL 6/2025's expanded perimeter, not just against PTSR - a vendor that's clean on payment tokens can still be in scope as an enabling technology provider.
- Confirm that any partner or programme involving a shared or third-party ledger gives your institution full, bank-owned visibility and an unbroken audit trail - the standard a regulator will expect you to demonstrate, not just assert.
- Treat the September 2026 deadline as the forcing function to close this assessment now, while there's still time to restructure an arrangement rather than defend one after the fact.
The visibility point is where technology architecture actually matters. Outsourced and sponsored programmes are workable under FDL 6/2025, but only if the bank retains genuine oversight of what's happening on the ledger - not a quarterly report from a partner, but real audit-grade visibility into the underlying activity. That's the same principle behind a Digital Twin model: the bank keeps a complete, bank-controlled record of a programme running on partner infrastructure, so oversight isn't something you're asking a vendor to provide after the fact - it's built into how the arrangement works from day one.
FDL 6/2025 gives banks a full year to get this right. Institutions that use that year to map exposure and fix ledger visibility gaps will clear September 2026 without incident. Institutions that wait for the deadline to start asking these questions will be doing compliance work under a regulator's clock instead of their own.