UAE Information Assurance Standards (NESA)
The UAE Information Assurance Standards set out 188 security controls across 15 control families, split into 60 management and 128 technical controls. A subset is marked Always Applicable and must be implemented regardless of risk assessment. Every other control is selected through risk assessment and phased in by priority tier, P1 to P4.
This page summarises the structure of the UAE Information Assurance Regulation and reproduces the Always Applicable control list in full. Section and control identifiers follow version 1.1 of the regulation as published by the TDRA. Confirm against the current published version before relying on it for an assessment.
How the Standards Are Organised
Two dimensions that are frequently confused: applicability and priority.
Applicability
Controls are either Always Applicable or applicable based on the outcome of your risk assessment. The regulation is explicit about the first category: these controls "must be implemented by each relevant entity regardless of its risk assessment outcomes", and "omission of any of these security controls constitutes non-conformity to this Regulation".
Priority
Separately, every control sits in one of four priority tiers, P1 to P4, which govern the order of implementation rather than whether a control applies. Entities may promote or demote P2, P3 and P4 controls based on risk assessment. P1 controls, where applicable, "may be augmented but never reduced".
Bereit, Ihre
Unternehmensinfrastruktur abzusichern?
Vereinbaren Sie ein technisches Briefing. Kein Sales-Pitch, nur Architekten und Ihr Team.
Always Applicable and P1 are not the same set. Several summaries in circulation describe the 39 P1 controls as the always applicable baseline. The regulation separates them: Annex A holds the Always Applicable list, all of it management controls, while Annex B holds the priority distribution. An entity can have a P1 control that is not always applicable, and an always applicable control outside P1.
Priority Distribution
Table 6 of the regulation distributes all 188 controls across the four tiers.
| Priority tier | Controls |
|---|---|
| None | |
| None | None |
The Always Applicable Controls in Full
Every one of these is a management control. None can be dropped on the basis of a risk assessment.
Always Applicable controls, UAE IA Regulation
| Control | Name | Family |
|---|---|---|
| M1.1.1 | Understanding the Entity and its Context | M1 Strategy and Planning |
| M1.1.2 | Leadership and Management Commitment | M1 Strategy and Planning |
| M1.1.3 | Roles and Responsibilities for Information Security | M1 Strategy and Planning |
| M1.2.1 | Information Security Policy | M1 Strategy and Planning |
| M1.2.2 | Supporting Policies for Information Security | M1 Strategy and Planning |
| M1.4.1 | Resources | M1 Strategy and Planning |
| M1.4.2 | Internal and External Communication | M1 Strategy and Planning |
| M1.4.3 | Documentation | M1 Strategy and Planning |
| M2.1.1 | Information Security Risk Management Policy | M2 Information Security Risk Management |
| M2.2.1 | Information Security Risk Identification | M2 Information Security Risk Management |
| M2.2.2 | Information Security Risk Analysis | M2 Information Security Risk Management |
| M2.2.3 | Information Security Risk Evaluation | M2 Information Security Risk Management |
| M2.3.1 | Information Security Risk Treatment Options | M2 Information Security Risk Management |
| M2.3.2 | Identification of Controls | M2 Information Security Risk Management |
| M2.3.3 | Risk Treatment Plan | M2 Information Security Risk Management |
| M2.3.4 | Statement of Applicability | M2 Information Security Risk Management |
| M2.3.5 | Information Security Objectives | M2 Information Security Risk Management |
| M2.4.1 | Risk Monitoring and Review | M2 Information Security Risk Management |
| M2.4.2 | Risk Communication and Consultation | M2 Information Security Risk Management |
| M3.2.1 | Awareness and Training Program | M3 Awareness and Training |
| M3.3.1 | Training Needs | M3 Awareness and Training |
| M3.3.2 | Implementation Plan | M3 Awareness and Training |
| M3.3.3 | Training Execution | M3 Awareness and Training |
| M4.1.1 | Human Resources Security Policy | M4 Human Resources Security |
| M4.2.1 | Screening | M4 Human Resources Security |
| M4.2.2 | Terms and Conditions of Employment | M4 Human Resources Security |
| M4.3.1 | Management Responsibilities | M4 Human Resources Security |
| M4.3.2 | Disciplinary Process | M4 Human Resources Security |
| M4.4.1 | Termination Responsibilities | M4 Human Resources Security |
| M4.4.2 | Return of Assets | M4 Human Resources Security |
| M4.4.3 | Removal of Access Rights | M4 Human Resources Security |
| M6.2.1 | Monitoring, Measurement, Analysis and Evaluation | M6 Performance Evaluation and Improvement |
| M6.2.2 | Internal Audits | M6 Performance Evaluation and Improvement |
| M6.3.1 | Corrective Action | M6 Performance Evaluation and Improvement |
| M6.3.2 | Continual Improvement | M6 Performance Evaluation and Improvement |
What the Baseline Actually Demands
M1.2.1 and M1.2.2 require an information security policy plus supporting policies, with M1.1.2 requiring demonstrable leadership commitment behind them. Assessors look for approval records and evidence of use.
M2 covers identification, analysis, evaluation, treatment options, a treatment plan, a Statement of Applicability, objectives, and ongoing monitoring and communication. Eleven of the always applicable controls sit here.
M3 requires a programme, documented training needs, an implementation plan, and evidence of execution. An annual all-staff slide deck does not satisfy it on its own.
M4 spans screening before employment, contractual terms, management responsibilities, a disciplinary process, and the termination trio: responsibilities, return of assets, and removal of access rights.
M6 requires monitoring and evaluation, internal audits, corrective action, and continual improvement. This is the loop that turns the rest of the programme into something inspectable.
The 128 technical controls in T1 to T9 apply according to your risk assessment, phased by priority tier. The Statement of Applicability is where you justify each inclusion and exclusion.
UAE IA (NESA) questions
Which UAE IA (NESA) security controls are 'Always Applicable' regardless of a company's size?
The Always Applicable controls are all management controls, listed in Annex A of the UAE Information Assurance Regulation. They cover strategy and planning (M1), the full risk management cycle (M2), awareness and training (M3), human resources security across the employment lifecycle (M4), and performance evaluation and improvement (M6). They must be implemented regardless of the outcome of your risk assessment, and omitting any of them is non-conformity with the regulation.
One detail worth knowing: Annex A states a total of 34 management controls, while the table beneath that sentence enumerates 35 identifiers. The full list is reproduced on this page so you can work from the identifiers rather than the count. Note also that Always Applicable is not the same thing as the P1 priority tier, which holds 39 controls and governs implementation order rather than applicability.
How many controls are in the UAE IA Standards in total?
188 security controls, split into 60 management controls in families M1 to M6 and 128 technical controls in families T1 to T9. Annex B distributes them across four priority tiers: 39 in P1, 69 in P2, 35 in P3, and 45 in P4.
Can we drop a P1 control if our risk assessment says it is unnecessary?
No. Entities may promote or demote controls in P2, P3 and P4 based on their risk assessment, but the regulation states that P1 controls, where applicable, may be augmented and never reduced. Applicability itself is still determined by the standard, so a control that does not apply to your environment at all is handled through the Statement of Applicability rather than by demotion.
Is NESA still the regulator?
The standards were originally issued by the National Electronic Security Authority, which is why the framework is still widely called NESA. The regulation is now published and maintained under the UAE federal telecom and digital government authority, TDRA, as the UAE Information Assurance Regulation. The control identifiers are unchanged, so existing gap assessments remain usable.
Is there a NESA certificate?
No. Conformity with the UAE Information Assurance Regulation is demonstrated through assessment and evidence, not through a certificate issued by an accredited body in the way ISO 27001 works. Organisations that need something to show a customer usually pair an internal or third-party gap assessment report against the standards with ISO 27001 certification, which does produce a certificate.
How does the UAE IA framework map onto ISO 27001?
Substantially, and in a way that saves real work. The management families M1 to M6 line up closely with the ISO 27001 clauses on context, leadership, planning, support, operation, performance evaluation, and improvement, while the technical families T1 to T9 overlap heavily with Annex A. Two artefacts transfer almost directly: the risk treatment plan and the Statement of Applicability, which M2.3.3 and M2.3.4 require by name. What does not transfer is the priority tiering, which has no ISO equivalent and drives your implementation order.
What is the Statement of Applicability expected to contain?
A decision, with a reason, for every control in the standard. For included controls, record the implementation status and where the evidence lives. For excluded controls, record the justification, and make it specific to your environment rather than a statement that the control is not relevant. Control M2.3.4 makes the Statement of Applicability an Always Applicable requirement, so a missing or generic one is a non-conformity in its own right, not just a documentation gap.
Where do the technical control families T1 to T9 start?
With asset management and access control in practice, because almost every other technical family depends on knowing what you run and who can reach it. The regulation does not mandate that order, it mandates risk-based selection phased by priority tier, but an organisation that attempts monitoring, cryptography, or incident response before it has a reliable asset inventory ends up rebuilding those controls once the inventory arrives.
Working with the standards
The distinction between Always Applicable and the P1 tier was the thing our previous advisor had wrong. Correcting it changed both our scope and our sequencing.
We came in with an ISO 27001 management system and expected to start over. The mapping showed how much already counted, and the gap work concentrated on the priority tiers.
Where We Do This Work
One control set mapped to every framework that binds you, with the evidence pipeline behind it. IT security governance in the UAE.
Control-by-control gap assessment against this framework, evidenced finding by finding. Information security audit in Dubai.
Regulatory scoping, threat modelling and zero-trust architecture for groups operating in the Emirates. Cyber security consulting in Dubai.