NESA Implementation and Remediation in the UAE
NESA implementation is the work between a gap report and an assessment that passes: building the controls the report found missing, in the order the regulation expects, and leaving behind evidence that the control was operating rather than a document saying it should be.
Scope, deliverables and pricing
Agree what will be assessed, what evidence is needed and what you receive before work starts.
| Stage | What we agree | What you receive |
|---|---|---|
| Scope | Entities, frameworks, locations, systems and access constraints. | A written scope, exclusions, evidence request list and delivery schedule. |
| Assessment | Document review, interviews and the technical tests included in the engagement. | Findings linked to evidence, with risk, control references and remediation priorities. |
| Remediation and re-test | Which fixes your team owns, where engineering support is needed and whether re-testing is included. | An action plan with owners and acceptance evidence; re-test results where commissioned. |
What determines the price?
The main drivers are the number of entities and frameworks, the systems and locations sampled, the depth of technical testing, evidence readiness and access restrictions. Implementation and re-testing are scoped explicitly, so a gap assessment is not mistaken for a remediation programme.
Share an architecture overview, the frameworks or customer requirements you need to meet, and your target date. We use these to agree a fixed scope and quote. The proposal states assumptions, exclusions and how changes are priced.
Short answer. Krasper Technologies implements the UAE Information Assurance Standards for organisations in the Emirates, taking a gap report and closing it. Work runs in priority order, the Always Applicable set and the P1 tier first, and covers policy architecture, technical control build, and the evidence pipeline that makes each control demonstrable. A first phase covering the Always Applicable controls and P1 typically runs twelve to twenty weeks; a full programme to P2 runs six to nine months alongside your own team. We do not assess the work we implement.
NESA or UAE IA? The standards were issued by the National Electronic Security Authority, and the industry still says NESA. The authority was folded into the Telecommunications and Digital Government Regulatory Authority (TDRA), and the current document is published as the UAE Information Assurance Regulation. The identifiers did not change with the name, so a NESA gap report and a UAE IA gap report describe the same 188 controls. We use both names on this page because both are still in use in procurement documents.
enterprise infrastructure?
Schedule a technical briefing. No sales pitch, just architects and your team.
The Order That Survives an Assessment
Priority tiers are a sequence, not a difficulty rating.
How a NESA Implementation Programme Runs
Remediation fails in a predictable way: the technical controls get built because they are satisfying, the governance controls get written late because they are not, and the assessment then finds an estate that is well configured and ungoverned. The sequence below is the one that avoids rebuilding.
-
Close the Always Applicable set
Thirty-five management controls that apply regardless of risk outcome: policy architecture, the risk management cycle, training with evidence, the employee lifecycle, internal audit. Nothing technical is assessed credibly until these exist, because they define who decided what.
-
Build the asset and data inventory
Every technical control is scoped by it, and remediation without it produces controls that cover the systems somebody remembered.
-
Close the P1 technical controls
Access control, logging with retention that survives an assessment, segmentation, cryptography and backup you have restored from. Built against the inventory rather than against the network diagram.
-
Stand up the evidence pipeline
Each control emits its evidence automatically, into retention. This is the step that decides whether the second assessment costs what the first one did.
-
Work down P2 and below by risk
From here the risk assessment drives selection, and exclusions become legitimate provided the Statement of Applicability justifies them.
-
Rehearse the assessment
A dry run against the evidence pack, run by someone who did not build the controls, before the assessor sees it.
What the Programme Covers
One policy set with version and approval records, mapped to the control identifiers it satisfies, so a change is traceable to the control it moves. The wider discipline is IT security governance in the UAE.
Identification, analysis, evaluation, treatment and monitoring as an operating cycle with named owners, not a register updated before a board meeting.
Identity, segmentation, logging, cryptography and backup, implemented by engineers who will hand over runbooks rather than a slide pack.
Collection and retention wired into the systems that produce the evidence, so demonstrating a control is a query.
The controls your providers hold, evidenced, because a control you have outsourced is still a control you are assessed on.
Planned, delivered and recorded, since the Always Applicable set requires the record as much as the training.
We do not assess our own remediation. A gap analysis after implementation has to come from somebody with no stake in the result, whether that is your internal audit function or a third party. Where we ran the gap analysis first, the same separation applies in reverse: the assessment is independent of the build.
Controls You Do Not Operate Yourself
Most remediation programmes discover late that a third of their controls are operated by somebody else: a cloud provider, a managed service provider, a payroll platform. The control still has to be evidenced, and the only routes to that evidence are contractual or an attestation the provider already publishes. Sorting this at the start of the programme rather than in the final month is the difference between an assessment finding and a renegotiation. What each regime expects of a cloud provider is set out in our cloud security controls reference, and the contractual side belongs with cyber security consulting in Dubai.
NESA implementation: common questions
How long does NESA implementation take?
Twelve to twenty weeks to close the 35 Always Applicable controls and the 39 in the P1 tier, assuming a gap report already exists and an owner is assigned. Six to nine months for a programme that reaches P2 across a multi-entity estate. Starting without a documented management system adds roughly three months at the front, because the policy architecture and the risk cycle have to exist before technical controls can be evidenced against anything.
Can we implement without a gap analysis first?
You can, and it usually costs more. Without a baseline the programme is scoped from assumption, which in this regime reliably means the technical controls are over-built and the governance controls are discovered late. Where budget is the constraint, a short scoping assessment covering the Always Applicable set and P1 alone is a better compromise than none. See NESA gap analysis.
Do you do the work or advise our team?
We advise, specify and review; your team and your providers implement. Policy architecture and evidence automation we draft and hand over as documents and configuration; technical controls inside your estate are built by the team that will operate them, with us designing and reviewing. What we do not do is write a plan and leave.
What happens to the controls after the assessment?
They decay unless the evidence pipeline runs on its own. The single best predictor of a smooth second assessment is whether evidence collection was automated during the first programme or performed by hand for the deadline. We treat that as a deliverable rather than as a nice-to-have, which is also what makes the annual cost predictable.
Can this run alongside an ISO 27001 certification project?
It should. The management families map closely enough that running them as two programmes duplicates most of the effort and produces two policy libraries that drift apart. One control set with a view per framework is the pattern that survives, and it is the same approach we take when PDPL or DESC ISR obligations sit on top.
Does implementation cover the DESC ISR controls too?
Where the entity is in the Dubai government supply chain, yes, and it is cheaper done together. The overlap on policy, risk, access control and incident response is substantial, so the marginal work is the Dubai-specific expectations rather than a second programme. Our DESC ISR reference sets out what those add.
What This Page Is Based On
- UAE Information Assurance Regulation v1.1, Telecommunications and Digital Government Regulatory Authority, tdra.gov.ae. Control identifiers reproduced on our UAE IA (NESA) reference page.
- ISO/IEC 27001:2022, Information security management systems, International Organization for Standardization.
- Information Security Regulation, Dubai Electronic Security Center, desc.gov.ae. Summarised on our DESC ISR reference page.
Continue Reading
Where you stand against all 188 controls, evidenced control by control, in four to six weeks. NESA gap analysis in the UAE.
All 35 Always Applicable controls and the P1 to P4 distribution, reproduced with identifiers. UAE Information Assurance Standards reference.
What UAE IA and the DESC Cloud Service Provider expectations ask of a cloud estate, and who evidences what. Cloud security controls in the UAE.
Policy architecture, risk register and board reporting mapped once across every framework that binds you. IT security governance in the UAE.
Threat modelling, zero-trust architecture and regulatory scoping for groups operating in the Emirates. Cyber security consulting in Dubai.
Independent gap assessment and technical control testing, evidenced finding by finding. Information security assessment in Dubai.