UAE Information Assurance Standards (NESA)
The UAE Information Assurance Standards set out 188 security controls across 15 control families, split into 60 management and 128 technical controls. A subset is marked Always Applicable and must be implemented regardless of risk assessment. Every other control is selected through risk assessment and phased in by priority tier, P1 to P4.
This page summarises the structure of the UAE Information Assurance Regulation and reproduces the Always Applicable control list in full. Section and control identifiers follow version 1.1 of the regulation as published by the TDRA. Confirm against the current published version before relying on it for an assessment.
Have UAE IA (NESA) assessed against evidence Scope, deliverables and what you receive
How the Standards Are Organised
Two dimensions that are frequently confused: applicability and priority.
Applicability
Controls are either Always Applicable or applicable based on the outcome of your risk assessment. The regulation is explicit about the first category: these controls "must be implemented by each relevant entity regardless of its risk assessment outcomes", and "omission of any of these security controls constitutes non-conformity to this Regulation".
Priority
Separately, every control sits in one of four priority tiers, P1 to P4, which govern the order of implementation rather than whether a control applies. Entities may promote or demote P2, P3 and P4 controls based on risk assessment. P1 controls, where applicable, "may be augmented but never reduced".
enterprise infrastructure?
Schedule a technical briefing. No sales pitch, just architects and your team.
Always Applicable and P1 are not the same set. Several summaries in circulation describe the 39 P1 controls as the always applicable baseline. The regulation separates them: Annex A holds the Always Applicable list, all of it management controls, while Annex B holds the priority distribution. An entity can have a P1 control that is not always applicable, and an always applicable control outside P1.
Priority Distribution
Table 6 of the regulation distributes all 188 controls across the four tiers.
| Priority tier | Controls |
|---|---|
| All 188 controls, UAE IA Regulation v1.1, Annex B, Table 6 | |
| P1, highest relative impact, implement first | 39 |
| P2 | 69 |
| P3 | 35 |
| P4, risk-based, implement last | 45 |
The Always Applicable Controls in Full
Every one of these is a management control. None can be dropped on the basis of a risk assessment.
Always Applicable controls, UAE IA Regulation
| Control | Name | Family |
|---|---|---|
| M1.1.1 | Understanding the Entity and its Context | M1 Strategy and Planning |
| M1.1.2 | Leadership and Management Commitment | M1 Strategy and Planning |
| M1.1.3 | Roles and Responsibilities for Information Security | M1 Strategy and Planning |
| M1.2.1 | Information Security Policy | M1 Strategy and Planning |
| M1.2.2 | Supporting Policies for Information Security | M1 Strategy and Planning |
| M1.4.1 | Resources | M1 Strategy and Planning |
| M1.4.2 | Internal and External Communication | M1 Strategy and Planning |
| M1.4.3 | Documentation | M1 Strategy and Planning |
| M2.1.1 | Information Security Risk Management Policy | M2 Information Security Risk Management |
| M2.2.1 | Information Security Risk Identification | M2 Information Security Risk Management |
| M2.2.2 | Information Security Risk Analysis | M2 Information Security Risk Management |
| M2.2.3 | Information Security Risk Evaluation | M2 Information Security Risk Management |
| M2.3.1 | Information Security Risk Treatment Options | M2 Information Security Risk Management |
| M2.3.2 | Identification of Controls | M2 Information Security Risk Management |
| M2.3.3 | Risk Treatment Plan | M2 Information Security Risk Management |
| M2.3.4 | Statement of Applicability | M2 Information Security Risk Management |
| M2.3.5 | Information Security Objectives | M2 Information Security Risk Management |
| M2.4.1 | Risk Monitoring and Review | M2 Information Security Risk Management |
| M2.4.2 | Risk Communication and Consultation | M2 Information Security Risk Management |
| M3.2.1 | Awareness and Training Program | M3 Awareness and Training |
| M3.3.1 | Training Needs | M3 Awareness and Training |
| M3.3.2 | Implementation Plan | M3 Awareness and Training |
| M3.3.3 | Training Execution | M3 Awareness and Training |
| M4.1.1 | Human Resources Security Policy | M4 Human Resources Security |
| M4.2.1 | Screening | M4 Human Resources Security |
| M4.2.2 | Terms and Conditions of Employment | M4 Human Resources Security |
| M4.3.1 | Management Responsibilities | M4 Human Resources Security |
| M4.3.2 | Disciplinary Process | M4 Human Resources Security |
| M4.4.1 | Termination Responsibilities | M4 Human Resources Security |
| M4.4.2 | Return of Assets | M4 Human Resources Security |
| M4.4.3 | Removal of Access Rights | M4 Human Resources Security |
| M6.2.1 | Monitoring, Measurement, Analysis and Evaluation | M6 Performance Evaluation and Improvement |
| M6.2.2 | Internal Audits | M6 Performance Evaluation and Improvement |
| M6.3.1 | Corrective Action | M6 Performance Evaluation and Improvement |
| M6.3.2 | Continual Improvement | M6 Performance Evaluation and Improvement |
What the Baseline Actually Demands
M1.2.1 and M1.2.2 require an information security policy plus supporting policies, with M1.1.2 requiring demonstrable leadership commitment behind them. Assessors look for approval records and evidence of use.
M2 covers identification, analysis, evaluation, treatment options, a treatment plan, a Statement of Applicability, objectives, and ongoing monitoring and communication. Eleven of the always applicable controls sit here.
M3 requires a programme, documented training needs, an implementation plan, and evidence of execution. An annual all-staff slide deck does not satisfy it on its own.
M4 spans screening before employment, contractual terms, management responsibilities, a disciplinary process, and the termination trio: responsibilities, return of assets, and removal of access rights.
M6 requires monitoring and evaluation, internal audits, corrective action, and continual improvement. This is the loop that turns the rest of the programme into something inspectable.
The 128 technical controls in T1 to T9 apply according to your risk assessment, phased by priority tier. The Statement of Applicability is where you justify each inclusion and exclusion.
Turning the Control Set into a Programme
Reading the control set answers what is required. It does not answer where you stand against it, which is a measurement, or what closing the distance costs, which is a plan. Those are two separate engagements and they run in that order.
A NESA gap analysis in the UAE scores every control against evidence and produces the Statement of Applicability and a costed remediation plan, normally in four to six weeks. NESA implementation then closes the findings in priority order, Always Applicable and P1 first, and builds the evidence pipeline that keeps the next assessment cheap. Where the estate runs in the cloud, which side of the shared responsibility line evidences each control is set out in our cloud security controls reference.
UAE IA (NESA) questions
Which UAE IA (NESA) security controls are 'Always Applicable' regardless of a company's size?
The Always Applicable controls are all management controls, listed in Annex A of the UAE Information Assurance Regulation. They cover strategy and planning (M1), the full risk management cycle (M2), awareness and training (M3), human resources security across the employment lifecycle (M4), and performance evaluation and improvement (M6). They must be implemented regardless of the outcome of your risk assessment, and omitting any of them is non-conformity with the regulation.
One detail worth knowing: Annex A states a total of 34 management controls, while the table beneath that sentence enumerates 35 identifiers. The full list is reproduced on this page so you can work from the identifiers rather than the count. Note also that Always Applicable is not the same thing as the P1 priority tier, which holds 39 controls and governs implementation order rather than applicability.
How many controls are in the UAE IA Standards in total?
188 security controls, split into 60 management controls in families M1 to M6 and 128 technical controls in families T1 to T9. Annex B distributes them across four priority tiers: 39 in P1, 69 in P2, 35 in P3, and 45 in P4.
Can we drop a P1 control if our risk assessment says it is unnecessary?
No. Entities may promote or demote controls in P2, P3 and P4 based on their risk assessment, but the regulation states that P1 controls, where applicable, may be augmented and never reduced. Applicability itself is still determined by the standard, so a control that does not apply to your environment at all is handled through the Statement of Applicability rather than by demotion.
Is NESA still the regulator?
The standards were originally issued by the National Electronic Security Authority, which is why the framework is still widely called NESA. The regulation is now published and maintained under the UAE federal telecom and digital government authority, TDRA, as the UAE Information Assurance Regulation. The control identifiers are unchanged, so existing gap assessments remain usable.
Is there a NESA certificate?
No. Conformity with the UAE Information Assurance Regulation is demonstrated through assessment and evidence, not through a certificate issued by an accredited body in the way ISO 27001 works. Organisations that need something to show a customer usually pair an internal or third-party gap assessment report against the standards with ISO 27001 certification, which does produce a certificate.
How does the UAE IA framework map onto ISO 27001?
Substantially, and in a way that saves real work. The management families M1 to M6 line up closely with the ISO 27001 clauses on context, leadership, planning, support, operation, performance evaluation, and improvement, while the technical families T1 to T9 overlap heavily with Annex A. Two artefacts transfer almost directly: the risk treatment plan and the Statement of Applicability, which M2.3.3 and M2.3.4 require by name. What does not transfer is the priority tiering, which has no ISO equivalent and drives your implementation order.
What is the Statement of Applicability expected to contain?
A decision, with a reason, for every control in the standard. For included controls, record the implementation status and where the evidence lives. For excluded controls, record the justification, and make it specific to your environment rather than a statement that the control is not relevant. Control M2.3.4 makes the Statement of Applicability an Always Applicable requirement, so a missing or generic one is a non-conformity in its own right, not just a documentation gap.
Where do the technical control families T1 to T9 start?
With asset management and access control in practice, because almost every other technical family depends on knowing what you run and who can reach it. The regulation does not mandate that order, it mandates risk-based selection phased by priority tier, but an organisation that attempts monitoring, cryptography, or incident response before it has a reliable asset inventory ends up rebuilding those controls once the inventory arrives.
Where We Do This Work
All 188 controls tested against evidence and scored by tier, in four to six weeks. NESA gap analysis in the UAE.
Closing what a gap report found, in the order an assessment expects. NESA implementation in the UAE.
What each regime asks of a cloud estate, and which side of the shared responsibility line evidences it. Cloud security controls in the UAE.
One control set mapped to every framework that binds you, with the evidence pipeline behind it. IT security governance in the UAE.
Control-by-control gap assessment against this framework, evidenced finding by finding. Information security assessment in Dubai.
Regulatory scoping, threat modelling and zero-trust architecture for groups operating in the Emirates. Cyber security consulting in Dubai.
Turn UAE IA (NESA) requirements into an assessment plan
Agree what will be assessed, what evidence is needed and what you receive before work starts.
Start with the applicable document version, the entities and systems in scope, and any requirements imposed by your customer. Record exclusions and their rationale before testing controls.
Primary source: UAE Information Assurance Regulation v1.1 (PDF).
Worked example: testing an access review
Illustrative example, not a client result: an access policy requires regular reviews, but the team cannot show a completed review. The assessment records the missing evidence, the affected systems and the risk. The remediation names an owner, a due date and the evidence needed to close the finding: an approved review and records of any access removed.
Map the finding to the control in the version that applies to your organisation. A policy document alone does not establish that a control operates.
| Stage | What we agree | What you receive |
|---|---|---|
| Scope | Entities, frameworks, locations, systems and access constraints. | A written scope, exclusions, evidence request list and delivery schedule. |
| Assessment | Document review, interviews and the technical tests included in the engagement. | Findings linked to evidence, with risk, control references and remediation priorities. |
| Remediation and re-test | Which fixes your team owns, where engineering support is needed and whether re-testing is included. | An action plan with owners and acceptance evidence; re-test results where commissioned. |
What determines the price?
The main drivers are the number of entities and frameworks, the systems and locations sampled, the depth of technical testing, evidence readiness and access restrictions. Implementation and re-testing are scoped explicitly, so a gap assessment is not mistaken for a remediation programme.
Share an architecture overview, the frameworks or customer requirements you need to meet, and your target date. We use these to agree a fixed scope and quote. The proposal states assumptions, exclusions and how changes are priced.