Compliance reference · United Arab Emirates

UAE Information Assurance Standards (NESA)

The UAE Information Assurance Standards set out 188 security controls across 15 control families, split into 60 management and 128 technical controls. A subset is marked Always Applicable and must be implemented regardless of risk assessment. Every other control is selected through risk assessment and phased in by priority tier, P1 to P4.

Issued by
TDRA, published as the UAE Information Assurance Regulation (originally issued under NESA)
Last reviewed

This page summarises the structure of the UAE Information Assurance Regulation and reproduces the Always Applicable control list in full. Section and control identifiers follow version 1.1 of the regulation as published by the TDRA. Confirm against the current published version before relying on it for an assessment.

188
security controls in total
60 / 128
management controls / technical controls
15
control families: M1 to M6 and T1 to T9
39
controls in the P1 priority tier
Structure

How the Standards Are Organised

Two dimensions that are frequently confused: applicability and priority.

Applicability

Controls are either Always Applicable or applicable based on the outcome of your risk assessment. The regulation is explicit about the first category: these controls "must be implemented by each relevant entity regardless of its risk assessment outcomes", and "omission of any of these security controls constitutes non-conformity to this Regulation".

Priority

Separately, every control sits in one of four priority tiers, P1 to P4, which govern the order of implementation rather than whether a control applies. Entities may promote or demote P2, P3 and P4 controls based on risk assessment. P1 controls, where applicable, "may be augmented but never reduced".

Ready to secure your
enterprise infrastructure?

Schedule a technical briefing. No sales pitch, just architects and your team.

Always Applicable and P1 are not the same set. Several summaries in circulation describe the 39 P1 controls as the always applicable baseline. The regulation separates them: Annex A holds the Always Applicable list, all of it management controls, while Annex B holds the priority distribution. An entity can have a P1 control that is not always applicable, and an always applicable control outside P1.

Annex B

Priority Distribution

Table 6 of the regulation distributes all 188 controls across the four tiers.

Priority tier Controls
None
None None
Annex A

The Always Applicable Controls in Full

Every one of these is a management control. None can be dropped on the basis of a risk assessment.

Always Applicable controls, UAE IA Regulation

Source: UAE Information Assurance Regulation v1.1, Annex A, Table 5, reproduced in document order. The Annex prose states a total of 34 management controls while the table itself enumerates the 35 identifiers listed here. Verify against the current published version before using this for an assessment.
ControlNameFamily
M1.1.1 Understanding the Entity and its Context M1 Strategy and Planning
M1.1.2 Leadership and Management Commitment M1 Strategy and Planning
M1.1.3 Roles and Responsibilities for Information Security M1 Strategy and Planning
M1.2.1 Information Security Policy M1 Strategy and Planning
M1.2.2 Supporting Policies for Information Security M1 Strategy and Planning
M1.4.1 Resources M1 Strategy and Planning
M1.4.2 Internal and External Communication M1 Strategy and Planning
M1.4.3 Documentation M1 Strategy and Planning
M2.1.1 Information Security Risk Management Policy M2 Information Security Risk Management
M2.2.1 Information Security Risk Identification M2 Information Security Risk Management
M2.2.2 Information Security Risk Analysis M2 Information Security Risk Management
M2.2.3 Information Security Risk Evaluation M2 Information Security Risk Management
M2.3.1 Information Security Risk Treatment Options M2 Information Security Risk Management
M2.3.2 Identification of Controls M2 Information Security Risk Management
M2.3.3 Risk Treatment Plan M2 Information Security Risk Management
M2.3.4 Statement of Applicability M2 Information Security Risk Management
M2.3.5 Information Security Objectives M2 Information Security Risk Management
M2.4.1 Risk Monitoring and Review M2 Information Security Risk Management
M2.4.2 Risk Communication and Consultation M2 Information Security Risk Management
M3.2.1 Awareness and Training Program M3 Awareness and Training
M3.3.1 Training Needs M3 Awareness and Training
M3.3.2 Implementation Plan M3 Awareness and Training
M3.3.3 Training Execution M3 Awareness and Training
M4.1.1 Human Resources Security Policy M4 Human Resources Security
M4.2.1 Screening M4 Human Resources Security
M4.2.2 Terms and Conditions of Employment M4 Human Resources Security
M4.3.1 Management Responsibilities M4 Human Resources Security
M4.3.2 Disciplinary Process M4 Human Resources Security
M4.4.1 Termination Responsibilities M4 Human Resources Security
M4.4.2 Return of Assets M4 Human Resources Security
M4.4.3 Removal of Access Rights M4 Human Resources Security
M6.2.1 Monitoring, Measurement, Analysis and Evaluation M6 Performance Evaluation and Improvement
M6.2.2 Internal Audits M6 Performance Evaluation and Improvement
M6.3.1 Corrective Action M6 Performance Evaluation and Improvement
M6.3.2 Continual Improvement M6 Performance Evaluation and Improvement
In practice

What the Baseline Actually Demands

A governed policy set, not a document

M1.2.1 and M1.2.2 require an information security policy plus supporting policies, with M1.1.2 requiring demonstrable leadership commitment behind them. Assessors look for approval records and evidence of use.

A complete risk management cycle

M2 covers identification, analysis, evaluation, treatment options, a treatment plan, a Statement of Applicability, objectives, and ongoing monitoring and communication. Eleven of the always applicable controls sit here.

Awareness and training that is planned

M3 requires a programme, documented training needs, an implementation plan, and evidence of execution. An annual all-staff slide deck does not satisfy it on its own.

Employee lifecycle security

M4 spans screening before employment, contractual terms, management responsibilities, a disciplinary process, and the termination trio: responsibilities, return of assets, and removal of access rights.

Measurement and internal audit

M6 requires monitoring and evaluation, internal audits, corrective action, and continual improvement. This is the loop that turns the rest of the programme into something inspectable.

Everything else by risk assessment

The 128 technical controls in T1 to T9 apply according to your risk assessment, phased by priority tier. The Statement of Applicability is where you justify each inclusion and exclusion.

UAE IA (NESA) questions

Which UAE IA (NESA) security controls are 'Always Applicable' regardless of a company's size?

The Always Applicable controls are all management controls, listed in Annex A of the UAE Information Assurance Regulation. They cover strategy and planning (M1), the full risk management cycle (M2), awareness and training (M3), human resources security across the employment lifecycle (M4), and performance evaluation and improvement (M6). They must be implemented regardless of the outcome of your risk assessment, and omitting any of them is non-conformity with the regulation.

One detail worth knowing: Annex A states a total of 34 management controls, while the table beneath that sentence enumerates 35 identifiers. The full list is reproduced on this page so you can work from the identifiers rather than the count. Note also that Always Applicable is not the same thing as the P1 priority tier, which holds 39 controls and governs implementation order rather than applicability.

How many controls are in the UAE IA Standards in total?

188 security controls, split into 60 management controls in families M1 to M6 and 128 technical controls in families T1 to T9. Annex B distributes them across four priority tiers: 39 in P1, 69 in P2, 35 in P3, and 45 in P4.

Can we drop a P1 control if our risk assessment says it is unnecessary?

No. Entities may promote or demote controls in P2, P3 and P4 based on their risk assessment, but the regulation states that P1 controls, where applicable, may be augmented and never reduced. Applicability itself is still determined by the standard, so a control that does not apply to your environment at all is handled through the Statement of Applicability rather than by demotion.

Is NESA still the regulator?

The standards were originally issued by the National Electronic Security Authority, which is why the framework is still widely called NESA. The regulation is now published and maintained under the UAE federal telecom and digital government authority, TDRA, as the UAE Information Assurance Regulation. The control identifiers are unchanged, so existing gap assessments remain usable.

Is there a NESA certificate?

No. Conformity with the UAE Information Assurance Regulation is demonstrated through assessment and evidence, not through a certificate issued by an accredited body in the way ISO 27001 works. Organisations that need something to show a customer usually pair an internal or third-party gap assessment report against the standards with ISO 27001 certification, which does produce a certificate.

How does the UAE IA framework map onto ISO 27001?

Substantially, and in a way that saves real work. The management families M1 to M6 line up closely with the ISO 27001 clauses on context, leadership, planning, support, operation, performance evaluation, and improvement, while the technical families T1 to T9 overlap heavily with Annex A. Two artefacts transfer almost directly: the risk treatment plan and the Statement of Applicability, which M2.3.3 and M2.3.4 require by name. What does not transfer is the priority tiering, which has no ISO equivalent and drives your implementation order.

What is the Statement of Applicability expected to contain?

A decision, with a reason, for every control in the standard. For included controls, record the implementation status and where the evidence lives. For excluded controls, record the justification, and make it specific to your environment rather than a statement that the control is not relevant. Control M2.3.4 makes the Statement of Applicability an Always Applicable requirement, so a missing or generic one is a non-conformity in its own right, not just a documentation gap.

Where do the technical control families T1 to T9 start?

With asset management and access control in practice, because almost every other technical family depends on knowing what you run and who can reach it. The regulation does not mandate that order, it mandates risk-based selection phased by priority tier, but an organisation that attempts monitoring, cryptography, or incident response before it has a reliable asset inventory ends up rebuilding those controls once the inventory arrives.

Working with the standards

The distinction between Always Applicable and the P1 tier was the thing our previous advisor had wrong. Correcting it changed both our scope and our sequencing.
Client reference on file Information Security Manager, Critical infrastructure operator, UAE
We came in with an ISO 27001 management system and expected to start over. The mapping showed how much already counted, and the gap work concentrated on the priority tiers.
Client reference on file Head of Compliance, Telecommunications supplier, UAE
Related

Where We Do This Work

Governance

One control set mapped to every framework that binds you, with the evidence pipeline behind it. IT security governance in the UAE.

Audit

Control-by-control gap assessment against this framework, evidenced finding by finding. Information security audit in Dubai.

Consulting

Regulatory scoping, threat modelling and zero-trust architecture for groups operating in the Emirates. Cyber security consulting in Dubai.