Enquire Us

What is NESA Compliance in the UAE?

NESA compliance means conforming to the UAE Information Assurance Standards, originally issued by the National Electronic Security Authority and now maintained under the UAE Cyber Security Council. There is no accredited NESA certificate.

What NESA means and who publishes the standard

NESA stands for the National Electronic Security Authority, the UAE federal body originally responsible for national cyber security. NESA published the UAE Information Assurance Standards, often shortened to the UAE IA Standards or simply the NESA standard. The authority was subsequently renamed the Signals Intelligence Agency, and national cyber security policy and the information assurance standards now sit under the UAE Cyber Security Council.

The name has therefore outlived the organisation. When a UAE tender, contract or regulator asks for NESA compliance, what is being asked for is conformity with the UAE Information Assurance Standards, whatever the current custodian is called. It is worth confirming with the requesting party which version and which regulator’s implementation applies, because sector regulators publish their own instructions on top of the national framework.

Who it applies to

The UAE Information Assurance Standards are aimed at entities whose compromise would have national consequences. In practice that means:

  • Federal and local government entities.
  • Operators of critical information infrastructure, which covers sectors including banking and finance, telecommunications, energy and utilities, transport, health and government services.
  • Organisations designated as critical by their sector regulator.
  • Suppliers and service providers whose contracts with government or critical sector entities pass the requirement down to them, which is how most private companies first encounter it.

Entities that are not designated may still adopt the standard voluntarily, and many do so because it gives a structured national reference point that sector regulators recognise.

How the standard is structured

The UAE Information Assurance Standards are organised into control families split between management controls and technical controls. There are fifteen families in total: six management families, referenced M1 to M6, and nine technical families, referenced T1 to T9.

The management families cover the governance side of information assurance, including strategy and planning, the information security risk management process, awareness and training, human resources security, compliance, and performance evaluation and improvement. The technical families cover the operational controls, including asset management, physical and environmental security, operations management, communications, access control, systems acquisition, development and maintenance, information security incident management, and information systems continuity management.

Two further concepts govern how the controls are applied:

  • Priority levels. Controls carry a priority rating from P1 to P4, which indicates the order in which they should be addressed. P1 controls are implemented first.
  • Always applicable and risk based controls. A subset of controls applies to every entity in scope regardless of its risk assessment. The remainder are selected on the basis of the entity’s own risk assessment and the threats it faces, which is why two entities in the same sector can legitimately end up with different applicable control sets.

This structure means that implementation begins with a proper risk assessment rather than with a control checklist. Without the risk assessment there is no defensible basis for deciding which risk based controls apply.

How compliance is actually demonstrated

This is the area where inaccurate information is most common. The UAE Information Assurance Standards are a national government framework. They are not part of the international accredited certification system, so there is no accredited certification body issuing a NESA certificate after a Stage 1 and Stage 2 audit, and there is no three year certificate subject to annual surveillance visits. That model belongs to ISO management system standards.

Compliance is instead demonstrated through assessment and reporting:

  • The entity performs an information security risk assessment and determines which risk based controls apply alongside the always applicable set.
  • It implements the controls, prioritised by the P1 to P4 ratings, and maintains the evidence for each.
  • It carries out compliance assessment against the applicable controls, either internally or with an independent assessor, producing a control by control status with gaps and a remediation roadmap.
  • It reports compliance status to its sector regulator or to the relevant national authority in the form and at the frequency that authority requires.
  • It closes gaps and re assesses, treating compliance as a continuing position rather than a one off event.

Many entities in scope also hold ISO/IEC 27001 certification. The two work well together, because the ISO management system provides the governance, risk assessment, internal audit and management review machinery, while the UAE Information Assurance Standards provide the national control set that a UAE regulator or client is actually asking about. An ISO/IEC 27001 certificate is not evidence of compliance with the national standard, and compliance with the national standard is not an ISO certificate. Where a contract asks for both, both are needed.

How Univate supports NESA compliance

Univate works with UAE government entities, critical sector operators and their suppliers on conformity with the national information assurance requirements. Typical work includes:

  • Confirming the applicable version of the standard and the sector regulator’s own instructions before any assessment work starts.
  • Information security risk assessment aligned to the standard, producing the basis on which risk based controls are selected.
  • Applicability determination, so the entity has a defensible list of controls in scope and controls excluded with reasons.
  • Gap assessment against the applicable management and technical control families, recorded control by control.
  • A prioritised remediation roadmap that follows the P1 to P4 sequence rather than treating every gap as equally urgent.
  • Policy, procedure and technical control implementation support across the control families.
  • Evidence preparation and compliance reporting for submission to the sector regulator or national authority.
  • Integration with ISO/IEC 27001 where the entity holds or wants that certification, so one management system serves both.

Frequently asked questions about NESA compliance

What does NESA stand for?

NESA stands for the National Electronic Security Authority, the UAE federal body that originally published the UAE Information Assurance Standards. The authority was later renamed the Signals Intelligence Agency, and national cyber security policy and the information assurance standards are now maintained under the UAE Cyber Security Council.

Is there a NESA certificate?

No. The UAE Information Assurance Standards sit outside the international accreditation system, so no accredited certification body issues a NESA certificate through a Stage 1 and Stage 2 audit with annual surveillance. Compliance is demonstrated through risk based control implementation, assessment and reporting to the relevant regulator or national authority.

Who has to comply with the UAE Information Assurance Standards?

Federal and local government entities and operators of critical information infrastructure in sectors such as banking and finance, telecommunications, energy, transport and health. Suppliers to those entities are commonly required to comply through contract, and other organisations may adopt the standard voluntarily.

How is the standard structured?

It is organised into fifteen control families, comprising six management families referenced M1 to M6 and nine technical families referenced T1 to T9. Controls carry priority ratings from P1 to P4, and are divided between controls that always apply and controls selected on the basis of the entity’s own risk assessment.

Does ISO/IEC 27001 certification satisfy NESA compliance?

No. They are complementary but not interchangeable. ISO/IEC 27001 provides an internationally certified management system, while the UAE Information Assurance Standards provide the national control set that a UAE regulator or client is asking about. Where both are required by a contract, both must be addressed.

Where do we start with NESA compliance?

Start by confirming with the requesting regulator or client which version of the standard applies and what reporting they expect. Then carry out the information security risk assessment, because the risk based portion of the control set cannot be determined without it, and only afterwards run the control by control gap assessment and build the prioritised remediation roadmap.

Been asked for NESA compliance by a UAE government client or sector regulator? Talk to Univate about a risk based assessment against the UAE Information Assurance Standards.

Univate Global delivers ISO certifications, data privacy compliance, and cybersecurity frameworks across 9 markets.