Cybersecurity · UAE Compliance

NESA Compliance UAE: 7 Essential IAS Requirements

NESA compliance UAE guidance has a dating problem. Almost every published summary describes the standard as a set of 188 controls — but that figure belongs to the earlier edition. Version 2 of the UAE Information Assurance Standard was published in September 2025 and rebased onto ISO 27001:2022, restructuring the control set. A gap assessment run against the old edition will miss the changes.

NESA compliance UAE — security operations centre monitoring critical infrastructure
Sept 2025IAS Version 2 published
ISO 27001:2022New international baseline
P1–P4Control priority tiers
~80%Threats addressed by P1

Key takeaways

  • NESA no longer exists under that name. The authority was renamed, and national cybersecurity is coordinated by the UAE Cyber Security Council. "NESA" survives as shorthand for the standard.
  • Version 2 was published in September 2025 and rebased the framework onto ISO 27001:2022.
  • The widely-quoted 188-control figure describes the earlier edition. Treat any guidance repeating it as pre-dating the current version.
  • Controls are prioritised P1 to P4, with P1 designed to address roughly 80% of the threats the framework was built around.
  • Demonstrating compliance requires an external independent assessment, not only the internal audit the standard itself contains.
  • ISO 27001 covers much of the management side and little of the technical side. It reduces the work; it does not complete it.

NESA is no longer an agency

Worth settling first, because it affects how you read every other source on NESA compliance UAE.

The National Electronic Security Authority was the UAE federal body that created the Information Assurance framework. It no longer operates under that name. The authority was renamed the Signals Intelligence Agency, and national cybersecurity coordination now sits with the UAE Cyber Security Council, established by Cabinet decision in 2020. The Telecommunications and Digital Government Regulatory Authority has historically administered the Information Assurance Regulation.

Public reporting on exactly where each function landed is genuinely inconsistent — different sources point to different bodies as the current owner. What is consistent is that "NESA" now functions as shorthand for the standard rather than the name of a live agency, and that the standard itself is current and enforced.

The practical implication: the term is still what everyone searches, writes in tenders and says in meetings, so it remains useful. But when a supplier or consultant refers to "NESA" as though it were an active regulator you can call, that tells you something about how current their information is.

Diagram showing how NESA compliance UAE terminology maps to the current authorities and standard
One familiar name, several current bodies. The standard outlived the agency that wrote it.

IAS, IAR and what each term means

Three acronyms appear constantly and are used loosely. They point at related but distinct things.

TermWhat it is
IASUAE Information Assurance Standard — the control set. What you implement.
IARUAE Information Assurance Regulation — the obligation to implement it.
NESACommon shorthand for the above, after the authority that created the framework.

In practice the terms are used interchangeably, and a tender asking for "NESA compliance" means the IAS controls. The distinction matters mainly when reading official material, where the regulation and the standard are separate documents.

Version 2 and the 188-control problem

This is the section that matters most, because it is where most current guidance is out of date.

For years the framework was described as 188 controls, split between management and technical families, built on an earlier edition of ISO 27001. That description is repeated across consultancy pages, vendor blogs and compliance summaries — including sources published in 2026.

Version 2 of the standard was published in September 2025. It rebased the framework onto the 2022 edition of ISO 27001 and restructured the control set. Older control counts no longer map cleanly onto the current version.

Two consequences follow, and both have money attached:

Old gap assessments are stale

An assessment run against the previous edition will not reflect the restructured control set or the updated international baseline. If yours predates September 2025, it needs revisiting.

Guidance quoting 188 is dated

Not necessarily wrong about principles, but written against the previous version. Check the publication date of anything you are relying on.

Get the standard itself

Obtain the current edition and any sector supplements from the relevant UAE authority. Secondary summaries, including this one, are orientation rather than a compliance basis.

We have deliberately not stated a current control count in this article. The sources that would supply one still describe the previous version, and we have not verified a figure for Version 2 against the official standard. Stating a number we cannot support would reproduce exactly the problem this section describes.

Diagram comparing the earlier IAS edition against Version 2 for NESA compliance UAE
The framework did not simply grow. It was restructured onto a new international baseline.

How the standard is organised

The architecture has been stable in shape even as the content changed. Controls sit in two families.

Management controls cover governance and process — strategy and planning, risk management, awareness and training, human resource security, compliance, and performance evaluation. These are the controls an auditor tests through documentation, records and interviews.

Technical controls cover the operational security estate — asset management, access control, operations, communications, acquisition and development, incident management, and continuity. These are tested through configuration, logs and evidence from systems.

Version 2 is reported to organise these into fifteen families — six management and nine technical — with each family breaking into sub-families and individual controls. We flag this as reported rather than confirmed, because we found it in one source and could not corroborate it against a second independent one or the official document.

Two structural features are worth knowing regardless of version. Each control is tagged either always applicable or applicable subject to risk assessment. And each control carries sub-controls that spell out what implementation actually requires, alongside implementation guidance — which is unusually practical compared with some international standards.

Priority tiers and what P1 means

Controls carry a priority from P1 to P4, and this is the framework's most useful design decision.

The prioritisation is threat-based rather than abstract. The framework was built around a set of commonly observed threats drawn from industry incident reporting, and controls were ranked by how much of that threat landscape each addresses. P1 controls are designed to address roughly 80% of those threats.

That gives a defensible sequencing argument. You are not expected to implement everything simultaneously. P1 first establishes the baseline, and the remaining tiers follow according to risk assessment outcomes. Assessors generally look at P1 first, and organisations that have not implemented P1 tend to struggle through the rest of the assessment regardless of what else they have done.

One important nuance: priorities other than P1 can shift based on your risk assessment. P1 does not move.

Diagram of the P1 to P4 priority tiers in NESA compliance UAE and the threat coverage of P1
Threat-based prioritisation. The first tier is where most of the risk reduction sits.

Who has to meet NESA compliance UAE obligations

NESA compliance UAE obligations are not universal, and establishing whether they bind you is the first task.

  • Federal and local government entities
  • Semi-government bodies
  • Operators of critical information infrastructure — typically energy, telecommunications, financial services, transport, health and similar sectors
  • Regulated sectors, where a sector regulator imposes the obligation
  • Suppliers to the above, increasingly, through contractual flow-down

That last category is the one that catches organisations out. A business with no direct obligation may still find IAS requirements written into a government or critical-infrastructure tender, at which point it becomes a commercial requirement regardless of regulatory scope. If you sell into government or critical infrastructure in the UAE, the question is when rather than whether.

Unlike ISO 27001, where you define your own scope, the IAS applies across the organisation once designated.

What NESA compliance UAE means for infrastructure

Most published guidance stops at governance. These are the requirements that translate into things that have to exist in the estate.

01

An accurate asset inventory

Technical control families begin with knowing what you have. Every downstream control depends on a current inventory of systems, data and their owners.

02

Access control that can be evidenced

Privileged access reviewed on a defined cycle, multi-factor authentication on remote and administrative access, and no orphaned accounts. Assessors ask for records, not policy statements.

03

Segmentation between zones of differing sensitivity

Separating regulated or critical systems from general corporate traffic limits lateral movement and narrows audit scope. Our guide to network segmentation covers the architecture; the framework's contribution is that it expects the separation to be deliberate and documented.

04

Logging and monitoring that produces evidence

Incident management controls assume detection. Logs that exist but are never reviewed satisfy neither the control nor the assessor.

05

Patch management with a documented SLA

A defined timeframe for critical patches, records of completion, and a documented exception process. Ad hoc patching without records is a common finding.

06

Incident response that has been exercised

A plan that has never been tested is a document. Exercise records, an incident log, and a defined path for reporting to your sector regulator are what get tested.

07

Backups with restoration test records

Continuity controls are about recoverability, not backup jobs completing. The evidence that matters is a successful restore, recorded.

The pattern across all seven is the same: the framework tests evidence, not intent. Most findings are not "you have no control" but "you cannot demonstrate the control operated." Building the evidence trail alongside the control is considerably cheaper than reconstructing it before an assessment.

IoT and operational technology have grown in emphasis as smart building, connected healthcare and industrial control systems have spread — typically requiring segmentation, monitoring and threat detection around device estates that cannot authenticate conventionally.

Diagram showing that NESA compliance UAE assessments test evidence rather than intent
The common finding is not a missing control. It is a control nobody can prove operated.

If you already hold ISO 27001

ISO 27001 helps materially, and it does not finish the job.

ISO 27001UAE IAS
BasisRisk-based, flexibleThreat-based, prescribed controls
StatusVoluntaryMandatory once designated
ScopeYou define itApplies across the organisation
Coverage overlapStrong on management controlsTechnical controls need separate work

An existing ISO 27001 certification substantially reduces the management-side effort, since much of the governance, risk and audit apparatus is already in place — particularly now Version 2 is rebased onto ISO 27001:2022. The technical control families are where the additional work sits, and a certified organisation still needs an IAS-specific gap assessment rather than assuming coverage.

Where to start

01

Confirm whether the obligation applies

Directly through designation, or indirectly through a contract. The answer determines everything downstream.

02

Obtain the current standard

Version 2 and any sector supplements, from the relevant UAE authority. Do not plan against a secondary summary.

03

Check the date on any existing assessment

Anything predating September 2025 was run against the previous edition and needs revisiting.

04

Establish the asset inventory

Unglamorous, and every technical control depends on it.

05

Implement P1 first

Highest threat coverage, and what assessors look at first. Sequence the rest by risk assessment.

06

Build the evidence trail as you go

Records, logs, test results and review dates, captured while implementing rather than reconstructed later.

07

Plan for external assessment

Demonstrating compliance to a sector regulator requires an independent assessment, not just the internal audit the standard includes.

Sequence diagram for approaching NESA compliance UAE from scope confirmation to external assessment
Scope, then standard, then inventory, then P1. Skipping to controls without an inventory is where programmes stall.

Frequently asked questions

Does NESA still exist?

Not under that name. The National Electronic Security Authority was renamed the Signals Intelligence Agency, and national cybersecurity coordination now sits with the UAE Cyber Security Council, established in 2020. Public reporting on exactly where each function landed is inconsistent. "NESA" survives as common shorthand for the standard rather than as a live agency.

How many controls are in the UAE IAS?

The widely quoted figure of 188 controls describes the earlier edition of the standard. Version 2, published in September 2025, rebased the framework onto ISO 27001:2022 and restructured the control set, so older counts no longer map cleanly. Obtain the current standard from the relevant UAE authority rather than relying on a published figure.

What changed in Version 2?

The framework was rebased onto the 2022 edition of ISO 27001 and the control set was restructured. The practical consequence is that a gap assessment run against the previous edition will not reflect the current requirements, and guidance repeating older control counts predates the change.

What are P1 controls?

The highest priority tier. The framework ranks controls by how much of a defined threat landscape each addresses, and P1 is designed to cover roughly 80% of it. P1 is implemented first and its priority does not shift; other tiers can be adjusted based on risk assessment outcomes. Assessors typically review P1 before anything else.

Who has to comply with the IAS?

Federal and local government entities, semi-government bodies, operators of critical information infrastructure, and organisations in regulated sectors where a sector regulator imposes it. Increasingly it also reaches suppliers through contractual flow-down, so a business with no direct obligation may still face IAS requirements in a government or critical-infrastructure tender.

Does ISO 27001 certification cover NESA compliance?

It covers a substantial part of the management-side requirements and reduces the work, particularly now that Version 2 is rebased onto ISO 27001:2022. It does not cover the technical control families. A certified organisation still needs an IAS-specific gap assessment and technical remediation rather than assuming coverage.

Is an internal audit enough to demonstrate compliance?

No. The standard includes internal audit as a control family, but demonstrating compliance to a sector regulator requires an external, independent assessment. The internal audit supports the programme; it does not substitute for external validation.

What do assessors actually test?

Evidence rather than intent. The common findings are not an absence of controls but an inability to demonstrate they operated — a risk register never updated after an infrastructure change, patching without completion records, an incident response plan never exercised, or backups running without a recorded restoration test.

Building the controls the assessment tests

Most of the technical control families come down to infrastructure that exists and can be evidenced: segmented networks, controlled and logged access, monitoring that detects, and backups that demonstrably restore.

Magnus supplies firewalls and network security, segmentation-capable switching, and server and storage for recoverable backup across our cybersecurity solutions range. Tell us which control families you are working against and our pre-sales team will help specify the infrastructure side.

Get a quote

Source and limitations

The framework described here is the UAE Information Assurance Standard (IAS), implemented under the UAE Information Assurance Regulation (IAR), originally issued by the National Electronic Security Authority. Version 2 was published in September 2025 and rebased onto ISO 27001:2022.

Stated limitations. Of nine published sources reviewed, eight describe the framework as 188 controls — a figure that reflects the earlier edition — and they conflict with one another on the older detail, variously citing 35 or 39 mandatory controls. This article therefore states no current control count. The reported fifteen-family structure of Version 2 comes from a single source and could not be corroborated against a second independent source or the official document; it is presented as reported rather than confirmed. Public reporting on the current chain of authority between the Signals Intelligence Agency, the UAE Cyber Security Council and the Telecommunications and Digital Government Regulatory Authority is inconsistent, and this article reflects that inconsistency rather than resolving it.

The IAS control catalogue is the intellectual property of the relevant UAE authority. This article describes the framework's structure and intent in its own words and does not reproduce control text or control identifiers. Obtain the authoritative standard and any sector supplements from the relevant UAE authority and rely on those documents for compliance decisions. This is general information for infrastructure planning and is not compliance or legal advice.

By browsing this website, you agree to our privacy policy.
I Agree