Cyber Security & Compliance Services in the UAE

UAE Information Assurance Standards, Dubai ISR and federal Personal Data Protection Law compliance for organisations operating across the Emirates.

Federal standards and emirate-level rules

The UAE combines federal direction with emirate-specific regulation, and knowing which applies to you is the first question worth answering properly. Organisations frequently assume a single national regime and discover mid-programme that a second, emirate-level one also applies.

UAE Information Assurance Standards

The UAE Information Assurance Standards — historically associated with NESA — define national controls for entities supporting critical information infrastructure across sectors including energy, banking, aviation, healthcare, ICT and transport. The standards cover both management and technical controls, and are prioritised so that a subset must be addressed first rather than the whole set at once. Responsibility for the standards has moved between federal bodies over recent years, so it is worth confirming the current supervising authority for your sector rather than relying on older guidance.

Dubai: the DESC Information Security Regulation

The Dubai Electronic Security Center issues the Information Security Regulation for Dubai government entities and their partners. If you operate in Dubai and supply a government entity, ISR is usually the regime that reaches you in practice, and it is assessed independently of the federal standards.

Federal Personal Data Protection Law

The UAE’s federal personal data protection law governs the processing of personal data, with obligations covering lawful basis, transparency to data subjects, security measures, and responses to data subject requests. Specialised regimes apply in the financial free zones — the DIFC and ADGM each have their own data protection legislation and regulators, which are separate from the federal law and generally more prescriptive.

The free zone question

This is where UAE compliance most often goes wrong. An organisation established in the DIFC or ADGM is subject to that zone’s data protection law and regulator, not the federal law. Advice written for mainland UAE does not transfer cleanly, and a privacy programme built against the wrong instrument can require substantial rework.

We establish which regime actually applies before designing the programme — including for groups that operate across mainland and free zone entities simultaneously, which is common and needs handling deliberately rather than by assumption.

Our services in the UAE

  • UAE IA Standards readiness — gap assessment against the applicable controls, prioritised remediation and evidence.
  • Dubai ISR compliance — assessment and audit preparation for Dubai government entities and their suppliers.
  • Data protection implementation — federal PDPL, or DIFC and ADGM regimes where applicable.
  • ISO/IEC 27001 certification support — frequently the most efficient umbrella where several UAE obligations overlap.
  • PCI DSS advisory — for payment environments across the Emirates.
  • Third-party and cloud risk assessment, penetration testing and virtual CISO support.

Where you want tooling rather than spreadsheets, GRCLens runs ISO/IEC 27001, SOC 2, PCI DSS and other frameworks on one shared control model, and can be deployed on-premises or in a UAE-hosted environment where residency matters. Our Dubai presence means on-site delivery where an engagement needs it.

Frequently asked questions

Do the UAE IA Standards apply to private companies?

They apply to entities supporting critical information infrastructure and to government bodies, and reach private organisations both directly by sector and indirectly through contract. Sector matters more than ownership here.

We are in the DIFC. Does the federal data protection law apply to us?

Generally no — DIFC entities are subject to DIFC data protection legislation and its own commissioner. Groups operating across both mainland and free zone entities need to handle each under the right regime rather than applying one policy to everything.

Is ISR separate from the federal standards?

Yes. The Dubai ISR is issued by DESC and applies to Dubai government entities and their partners. Some organisations are in scope for both ISR and the federal standards, which is manageable but needs mapping so the work is not done twice.

Do you deliver on site in the UAE?

Yes. We have a Dubai presence and deliver workshops, assessments and board sessions on site alongside remote delivery.

Talk to us about compliance in the Emirates

Tell us where you are established and which authority is asking, and we will tell you which regime actually applies before any work begins. Get in touch.