Which UAE IA (NESA) Controls Are 'Always Applicable', Whatever Your Size
The Always Applicable controls of the UAE Information Assurance Standards cannot be dropped on the basis of a risk assessment, and they are not the same set as the 39 P1 controls. Here is what they cover, why the distinction matters, and what an assessor looks for.
Short answer. They are the management controls listed in Annex A of the UAE Information Assurance Regulation, spanning five families: M1 strategy and planning, M2 information security risk management, M3 awareness and training, M4 human resources security, and M6 performance evaluation and improvement. Company size does not change their applicability, and omitting any of them is non-conformity with the regulation.
This is the single most common error in circulation, and it changes both scope and sequencing. Several summaries describe the 39 P1 controls as the always applicable baseline. The regulation keeps them in separate annexes and they answer different questions.
Applicability answers whether a control applies at all. Always Applicable controls apply regardless of the outcome of your risk assessment. Everything else is selected through risk assessment and justified in the Statement of Applicability.
Priority answers when you implement. Every control sits in one of four tiers, P1 to P4, which govern implementation order. Entities may promote or demote P2, P3 and P4 controls on the basis of risk. P1 controls, where applicable, may be augmented but never reduced.
The consequence: you can have a P1 control that is not always applicable, and an always applicable control outside P1. Treating the two as one set produces a plan that is both too large in places and dangerously incomplete in others.
M1, strategy and planning. Understanding the entity and its context, demonstrable leadership commitment, defined roles and responsibilities, an information security policy plus supporting policies, resources, internal and external communication, and documentation. Assessors look for approval records and evidence of use, not for a document that exists.
M2, information security risk management. The largest group. Policy, identification, analysis, evaluation, treatment options, identification of controls, the risk treatment plan, the Statement of Applicability, security objectives, plus ongoing monitoring, review, communication and consultation. If your risk register is a spreadsheet nobody owns, this is the family that fails first.
M3, awareness and training. A programme, documented training needs, an implementation plan, and evidence of execution. An annual all-staff slide deck does not satisfy this on its own, because three of the four controls are about planning and evidence rather than delivery.
M4, human resources security. The full employment lifecycle: policy, screening, terms and conditions, management responsibilities, disciplinary process, and the termination trio of responsibilities, return of assets and removal of access rights. The termination controls are the ones most often found failing, because they depend on HR and IT sharing a process.
M6, performance evaluation and improvement. Monitoring, measurement, analysis and evaluation, internal audits, corrective action and continual improvement. This is the loop that makes everything above inspectable rather than merely present.
The full list with control identifiers is reproduced in document order on our UAE IA (NESA) reference page.
Annex A states a total of 34 management controls, while the table immediately beneath that sentence enumerates 35 identifiers. Work from the identifiers rather than the count. If you are asked to evidence "the 34 always applicable controls", produce the identifier list and the discrepancy resolves itself.
Not for applicability. It changes how the controls are implemented, not whether they are. A twenty-person entity still needs defined roles under M1.1.3, but those roles may sit with two people rather than a department. It still needs internal audits under M6.2.2, but the audit may be performed by someone from another function rather than by a dedicated internal audit team, provided they are independent of what they assess.
Where size genuinely bites is the evidence pipeline. Small teams that collect evidence manually spend a disproportionate share of their capacity on it, which is the argument for automating collection before hiring for it. See IT security governance in the UAE for how we build that layer.
Most of the work transfers. M1 to M6 line up closely with the ISO 27001 clauses on context, leadership, planning, support, operation, performance evaluation and improvement. Two artefacts carry over almost directly: the risk treatment plan and the Statement of Applicability, which M2.3.3 and M2.3.4 require by name.
What does not transfer is the priority tiering, which has no ISO equivalent and drives your implementation order. And note that conformity here is demonstrated through assessment and evidence rather than through a certificate: there is no NESA certificate to hang on the wall. A gap assessment report against the standards is what customers and regulators actually ask for. See information security audit in Dubai.
enterprise infrastructure?
Schedule a technical briefing. No sales pitch, just architects and your team.