Dubai DESC Information Security Regulation (ISR)
The Information Security Regulation is issued by the Dubai Electronic Security Center and is mandatory for Dubai government and semi-government entities, and for the suppliers, cloud providers and managed service providers that handle their data. It is a control framework and an assessment regime rather than a certifiable standard.
ISR is the regulation that decides whether your organisation can hold Dubai government work. It is enforced through assessment rather than certification, and non-conformity is a procurement problem before it is a security problem.
Who ISR Binds
Government and semi-government bodies in the Emirate of Dubai are directly in scope and are assessed against the regulation.
Organisations that provide services to, or handle data on behalf of, Dubai government entities inherit the obligation contractually. This is how most private companies encounter ISR.
Cloud service providers and data centre operators serving Dubai government carry additional requirements around location, isolation and operational transparency.
Organisations running monitoring or response services for in-scope entities are assessed on the operations they perform, not just on their own corporate controls.
ISR is not a certification. There is no certificate to hang on the wall in the way ISO 27001 provides one. Conformity is demonstrated through assessment and evidence, and the practical consequence of failure is exclusion from Dubai government procurement.
Ready to secure your
enterprise infrastructure?
Schedule a technical briefing. No sales pitch, just architects and your team.
ISR v2 and ISR v3
ISR version 2 established the control set most organisations in Dubai first encountered. DESC has since released version 3, which restructures the requirements into a broader set of security domains and pulls supply chain and third-party risk management into a much more prominent position, alongside explicit treatment of cloud, operational technology, and security operations.
If your last gap assessment was against v2, expect the delta to concentrate in three places: supplier assurance, cloud responsibility boundaries, and the evidence you retain from monitoring and response activity. Check the current version and transition timeline with DESC directly, since these dates move.
DESC ISR questions
Does ISR apply to private companies in Dubai?
Not directly, but in practice yes for anyone in the Dubai government supply chain. The regulation binds Dubai government and semi-government entities. Private organisations become subject to it through contract when they provide services to those entities or handle their data, and the requirement is usually discovered during procurement rather than beforehand.
How does ISR relate to ISO 27001?
ISO 27001 gives you a certifiable management system; ISR tells you what Dubai expects inside it. The overlap on policy, risk management, access control and incident response is substantial, so existing ISO 27001 work usually transfers with mapping rather than rework. ISR then adds Dubai-specific expectations that ISO does not cover, and it is assessed rather than certified.
What happens if we fail an ISR assessment?
The consequence is commercial. Non-conformity puts existing contracts with Dubai government entities at risk and can remove you from future procurement, which is usually a larger and faster loss than any regulatory penalty. Remediation plans with agreed timelines are the normal path back.
How long does ISR readiness take?
For an organisation with a functioning ISO 27001 management system, a gap assessment plus targeted remediation typically runs three to six months. Starting without a documented management system, expect nine to twelve, because the policy architecture and the evidence pipeline have to be built before the controls can be assessed at all.
Does our data have to stay in Dubai to satisfy ISR?
Location is treated as a control decision tied to the classification of the data, not as a single blanket rule, and government data carries the tightest expectations. Cloud and hosting providers serving Dubai government entities also carry requirements on isolation and operational transparency that a standard multi-tenant offering may not meet. Confirm the current position with DESC or with the contracting entity before committing to an architecture, because this is one of the areas where public summaries are out of date most often.
Who performs an ISR assessment?
Assessment sits with DESC and with assessors operating under its regime, and in-scope government entities are assessed directly. Suppliers most often encounter it indirectly, through the contracting entity asking for evidence of conformity as a condition of the contract. Preparation work, gap assessment, remediation and evidence assembly, is done by your own team or an advisor; it is separate from the assessment itself.
What evidence should we retain?
Approved policies with version and approval records, the risk register and treatment decisions, access reviews, change records, supplier assessments, monitoring output, incident records including the ones that turned out to be nothing, and proof that training and exercises actually happened. Retention matters as much as collection: evidence reconstructed after the request arrives is what assessments are lost on, since it cannot show the control was operating at the time.
We already run a European compliance programme. How much of it transfers?
Most of the control substance, little of the reporting detail. Access control, logging, incident response, supplier management and business continuity map across cleanly from an ISO 27001, NIS2 or DORA programme. What does not transfer is who must be notified, in what timeframe, and in what form, plus the Dubai-specific expectations ISR adds around government data handling. Run one control set with framework-specific views rather than two parallel policy libraries.
Working with ISR
ISR arrived as a procurement condition with six weeks to answer it. The gap assessment told us what was genuinely missing rather than what a template said we should have.
The evidence pipeline was the part we underestimated. Once collection was automated, the assessment became a query against records we already held.
Where We Do This Work
Regulatory scoping, threat modelling and zero-trust architecture for groups operating in the Emirates. Cyber security consulting in Dubai.
Control-by-control gap assessment against this framework, evidenced finding by finding. Information security audit in Dubai.
One control set mapped to every framework that binds you, with the evidence pipeline behind it. IT security governance in the UAE.