Krasper Technologies

NESA Implementation and Remediation in the UAE

NESA implementation is the work between a gap report and an assessment that passes: building the controls the report found missing, in the order the regulation expects, and leaving behind evidence that the control was operating rather than a document saying it should be.

Last reviewed

Scope, deliverables and pricing

Agree what will be assessed, what evidence is needed and what you receive before work starts.

Assessment scope and deliverables
StageWhat we agreeWhat you receive
ScopeEntities, frameworks, locations, systems and access constraints.A written scope, exclusions, evidence request list and delivery schedule.
AssessmentDocument review, interviews and the technical tests included in the engagement.Findings linked to evidence, with risk, control references and remediation priorities.
Remediation and re-testWhich fixes your team owns, where engineering support is needed and whether re-testing is included.An action plan with owners and acceptance evidence; re-test results where commissioned.

What determines the price?

The main drivers are the number of entities and frameworks, the systems and locations sampled, the depth of technical testing, evidence readiness and access restrictions. Implementation and re-testing are scoped explicitly, so a gap assessment is not mistaken for a remediation programme.

Share an architecture overview, the frameworks or customer requirements you need to meet, and your target date. We use these to agree a fixed scope and quote. The proposal states assumptions, exclusions and how changes are priced.

Short answer. Krasper Technologies implements the UAE Information Assurance Standards for organisations in the Emirates, taking a gap report and closing it. Work runs in priority order, the Always Applicable set and the P1 tier first, and covers policy architecture, technical control build, and the evidence pipeline that makes each control demonstrable. A first phase covering the Always Applicable controls and P1 typically runs twelve to twenty weeks; a full programme to P2 runs six to nine months alongside your own team. We do not assess the work we implement.

NESA or UAE IA? The standards were issued by the National Electronic Security Authority, and the industry still says NESA. The authority was folded into the Telecommunications and Digital Government Regulatory Authority (TDRA), and the current document is published as the UAE Information Assurance Regulation. The identifiers did not change with the name, so a NESA gap report and a UAE IA gap report describe the same 188 controls. We use both names on this page because both are still in use in procurement documents.

35
Always Applicable controls, closed first
39
P1 controls, closed second and never deferred
12 to 20
weeks for the Always Applicable set and P1
15
control families the programme has to reach eventually
Ready to secure your
enterprise infrastructure?

Schedule a technical briefing. No sales pitch, just architects and your team.

Sequence

The Order That Survives an Assessment

Priority tiers are a sequence, not a difficulty rating.

How a NESA Implementation Programme Runs

Remediation fails in a predictable way: the technical controls get built because they are satisfying, the governance controls get written late because they are not, and the assessment then finds an estate that is well configured and ungoverned. The sequence below is the one that avoids rebuilding.

  1. Close the Always Applicable set

    Thirty-five management controls that apply regardless of risk outcome: policy architecture, the risk management cycle, training with evidence, the employee lifecycle, internal audit. Nothing technical is assessed credibly until these exist, because they define who decided what.

  2. Build the asset and data inventory

    Every technical control is scoped by it, and remediation without it produces controls that cover the systems somebody remembered.

  3. Close the P1 technical controls

    Access control, logging with retention that survives an assessment, segmentation, cryptography and backup you have restored from. Built against the inventory rather than against the network diagram.

  4. Stand up the evidence pipeline

    Each control emits its evidence automatically, into retention. This is the step that decides whether the second assessment costs what the first one did.

  5. Work down P2 and below by risk

    From here the risk assessment drives selection, and exclusions become legitimate provided the Statement of Applicability justifies them.

  6. Rehearse the assessment

    A dry run against the evidence pack, run by someone who did not build the controls, before the assessor sees it.

Scope

What the Programme Covers

Policy architecture

One policy set with version and approval records, mapped to the control identifiers it satisfies, so a change is traceable to the control it moves. The wider discipline is IT security governance in the UAE.

Risk management cycle

Identification, analysis, evaluation, treatment and monitoring as an operating cycle with named owners, not a register updated before a board meeting.

Technical control build

Identity, segmentation, logging, cryptography and backup, implemented by engineers who will hand over runbooks rather than a slide pack.

Evidence automation

Collection and retention wired into the systems that produce the evidence, so demonstrating a control is a query.

Supplier assurance

The controls your providers hold, evidenced, because a control you have outsourced is still a control you are assessed on.

Training and exercises

Planned, delivered and recorded, since the Always Applicable set requires the record as much as the training.

We do not assess our own remediation. A gap analysis after implementation has to come from somebody with no stake in the result, whether that is your internal audit function or a third party. Where we ran the gap analysis first, the same separation applies in reverse: the assessment is independent of the build.

Cloud and outsourcing

Controls You Do Not Operate Yourself

Most remediation programmes discover late that a third of their controls are operated by somebody else: a cloud provider, a managed service provider, a payroll platform. The control still has to be evidenced, and the only routes to that evidence are contractual or an attestation the provider already publishes. Sorting this at the start of the programme rather than in the final month is the difference between an assessment finding and a renegotiation. What each regime expects of a cloud provider is set out in our cloud security controls reference, and the contractual side belongs with cyber security consulting in Dubai.

NESA implementation: common questions

How long does NESA implementation take?

Twelve to twenty weeks to close the 35 Always Applicable controls and the 39 in the P1 tier, assuming a gap report already exists and an owner is assigned. Six to nine months for a programme that reaches P2 across a multi-entity estate. Starting without a documented management system adds roughly three months at the front, because the policy architecture and the risk cycle have to exist before technical controls can be evidenced against anything.

Can we implement without a gap analysis first?

You can, and it usually costs more. Without a baseline the programme is scoped from assumption, which in this regime reliably means the technical controls are over-built and the governance controls are discovered late. Where budget is the constraint, a short scoping assessment covering the Always Applicable set and P1 alone is a better compromise than none. See NESA gap analysis.

Do you do the work or advise our team?

We advise, specify and review; your team and your providers implement. Policy architecture and evidence automation we draft and hand over as documents and configuration; technical controls inside your estate are built by the team that will operate them, with us designing and reviewing. What we do not do is write a plan and leave.

What happens to the controls after the assessment?

They decay unless the evidence pipeline runs on its own. The single best predictor of a smooth second assessment is whether evidence collection was automated during the first programme or performed by hand for the deadline. We treat that as a deliverable rather than as a nice-to-have, which is also what makes the annual cost predictable.

Can this run alongside an ISO 27001 certification project?

It should. The management families map closely enough that running them as two programmes duplicates most of the effort and produces two policy libraries that drift apart. One control set with a view per framework is the pattern that survives, and it is the same approach we take when PDPL or DESC ISR obligations sit on top.

Does implementation cover the DESC ISR controls too?

Where the entity is in the Dubai government supply chain, yes, and it is cheaper done together. The overlap on policy, risk, access control and incident response is substantial, so the marginal work is the Dubai-specific expectations rather than a second programme. Our DESC ISR reference sets out what those add.

Sources

What This Page Is Based On

  • UAE Information Assurance Regulation v1.1, Telecommunications and Digital Government Regulatory Authority, tdra.gov.ae. Control identifiers reproduced on our UAE IA (NESA) reference page.
  • ISO/IEC 27001:2022, Information security management systems, International Organization for Standardization.
  • Information Security Regulation, Dubai Electronic Security Center, desc.gov.ae. Summarised on our DESC ISR reference page.
Related

Continue Reading

Gap analysis

Where you stand against all 188 controls, evidenced control by control, in four to six weeks. NESA gap analysis in the UAE.

The control set itself

All 35 Always Applicable controls and the P1 to P4 distribution, reproduced with identifiers. UAE Information Assurance Standards reference.

Cloud controls

What UAE IA and the DESC Cloud Service Provider expectations ask of a cloud estate, and who evidences what. Cloud security controls in the UAE.

Governance

Policy architecture, risk register and board reporting mapped once across every framework that binds you. IT security governance in the UAE.

Consulting

Threat modelling, zero-trust architecture and regulatory scoping for groups operating in the Emirates. Cyber security consulting in Dubai.

Assessment

Independent gap assessment and technical control testing, evidenced finding by finding. Information security assessment in Dubai.