Regulation · Information assurance · United Arab Emirates
UAE IAS compliance means meeting the UAE Information Assurance Regulation, formerly known as the NESA standards. It sets 188 controls in 6 management and 9 technical families, prioritised from P1 to P4 and selected by risk, for government entities and critical infrastructure in the UAE and the organisations that serve them.
UAE government entities, critical infrastructure and the organisations that serve them.
QULDEX helps here first: the readiness check shows where you stand before you commit budget.
The UAE Information Assurance Regulation requires in-scope entities to run a risk-based information assurance programme: management controls for strategy, risk, people and compliance, and technical controls from assets to continuity, implemented in priority order.
Strategy, risk, awareness, HR, compliance, improvement.
In QULDEX: Management evidence mappedAssets through continuity.
In QULDEX: Controls mapped to ISO 27001P1 first, then by risk.
In QULDEX: Priority tags on every controlRisk assessment decides applicability.
In QULDEX: Risk registerInternal audit and improvement.
In QULDEX: Audit workspaceThe 15 control families plus the priority model. Select any family to see what it covers, typical evidence and the matching ISO 27001 controls.
Showing up to 6 per group. Search, filter, or open a group to see all 16.
M1Strategy and planningInformation security strategy, policy and the organisation's security management structure.
In QULDEXQULDEX tracks this control family with owners, priority tags (P1–P4) and evidence, mapped to ISO 27001.
M2Information security risk managementRisk assessment and treatment, and threat-driven control selection.
In QULDEXThe risk register drives which controls apply.
M3Awareness and trainingSecurity awareness and role-based training.
In QULDEXQULDEX tracks this control family with owners, priority tags (P1–P4) and evidence, mapped to ISO 27001.
M4Human resources securitySecurity before, during and after employment.
In QULDEXQULDEX tracks this control family with owners, priority tags (P1–P4) and evidence, mapped to ISO 27001.
M5ComplianceCompliance with legal and regulatory requirements and the IA Regulation itself.
In QULDEXQULDEX tracks this control family with owners, priority tags (P1–P4) and evidence, mapped to ISO 27001.
M6Performance evaluation and improvementMonitoring, internal audit and continual improvement of information assurance.
In QULDEXAudits and findings run in the audit workspace.
T1Asset managementInventory, ownership, classification and handling of information assets.
In QULDEXQULDEX tracks this control family with owners, priority tags (P1–P4) and evidence, mapped to ISO 27001.
T2Physical and environmental securitySecure areas, equipment protection and environmental controls.
In QULDEXQULDEX tracks this control family with owners, priority tags (P1–P4) and evidence, mapped to ISO 27001.
T3Operations managementOperating procedures, change, capacity, malware protection, backup, logging and monitoring.
In QULDEXQULDEX tracks this control family with owners, priority tags (P1–P4) and evidence, mapped to ISO 27001.
T4CommunicationsNetwork security, information transfer and electronic messaging.
In QULDEXQULDEX tracks this control family with owners, priority tags (P1–P4) and evidence, mapped to ISO 27001.
T5Access controlAccess policy, user access management, privileged access and authentication.
In QULDEXAccess reviews run as recurring tasks.
T6Third-party securitySecurity requirements for suppliers and outsourced services.
In QULDEXEach supplier is assessed and linked to its services.
T7Information systems acquisition, development and maintenanceSecurity in system requirements, development and testing.
In QULDEXQULDEX tracks this control family with owners, priority tags (P1–P4) and evidence, mapped to ISO 27001.
T8Incident managementIncident detection, response, reporting and learning.
In QULDEXIncidents run with timers and reporting records.
T9Information systems continuity managementContinuity of information systems and recovery planning.
In QULDEXContinuity evidence is reused from ISO 22301.
P1–P4Control prioritiesPriority modelControls carry a priority from P1 to P4. P1 controls are the foundation every in-scope entity implements first; the rest follow from the risk assessment.
In QULDEXPriority tags drive the implementation plan and the dashboard.
Nothing matches that search.
Family codes follow the UAE Information Assurance Regulation. Summaries are QULDEX paraphrases; the regulation is the authority.
Run a risk assessment, implement the P1 controls first, then the controls your risk profile selects, and evidence them for the sector regulator. Most entities need 6 to 12 months, less with ISO 27001.
Check whether you are in a critical sector or supply one, and who supervises you.
Assess risks and select applicable controls (M2).
The foundation controls, first.
P2 to P4 controls your risk assessment requires.
Internal audit and management review (M6).
Durations are QULDEX planning ranges.
Sector regulators and auditors ask for these records.
| Document | Family | Where it lives in QULDEX |
|---|---|---|
| Information security strategy and policy | M1 | Policy library |
| Risk assessment and control selection | M2 | Risk register |
| Training records | M3 | Evidence vault |
| Compliance register | M5 | Policy library |
| Internal audit reports | M6 | Audit workspace |
| Asset inventory | T1 | Risk register |
| Access reviews | T5 | Evidence vault |
| Supplier assessments | T6 | Vendor register |
| Incident reports | T8 | CAPA automation |
| Continuity and DR tests | T9 | Evidence vault |
Family codes follow the UAE IA Regulation.
Most entities need 6 to 12 months. P1 coverage, supplier controls and the risk-based selection drive the effort.
Bars show the upper end of each range on one scale (12 months = full width).
Check these eight things first. Nothing you enter leaves this page.
The IA Regulation was modelled closely on ISO 27001. Organisations operating in both the UAE and Saudi Arabia can reuse most evidence for NCA ECC.
| UAE IAS | ISO 27001:2022 | NCA ECC-2:2024 | UAE PDPL | Shared evidence |
|---|---|---|---|---|
| M1 Strategy | 5.1–5.3 | 1-1, 1-2 | — | Strategy |
| M2 Risk | 6.1 | 1-5 | Security measures | Risk register |
| T1 Assets | A.5.9 | 2-1 | Records of processing | Inventory |
| T5 Access | A.5.15–A.5.18 | 2-2 | — | Access reviews |
| T6 Third parties | A.5.19–A.5.22 | 4-1 | Processor duties | Vendor register |
| T8 Incidents | A.5.24–A.5.27 | 2-13 | Breach notification | Incident reports |
| T9 Continuity | A.5.29–A.5.30 | 3-1 | — | DR tests |
Indicative mapping for planning. The full crosswalk is in the QULDEX control library.
QULDEX is UAE IAS compliance and audit management software built from EGV Group's audit delivery, used by in-scope entities, their advisors and auditors. Pick your role to see who does what.
For government entities, critical sectors and suppliers.
For information assurance consultants and internal audit.
For independent and sector auditors.
Requirements with owners, test steps and the crosswalk to 50+ frameworks.
Explore →EvidenceEvidence linked to controls and findings, with upload, review and approval history.
Explore →RiskRisk assessment and treatment, with decisions traced to the controls they drive.
Explore →FindingsFindings from internal and external audits tracked to closure with due dates.
Explore →The UAE Information Assurance Regulation and its standards, originally issued by NESA and now published by the TDRA. It sets 188 controls for government entities and critical sectors.
Yes. "NESA standards" is the older name; the same Information Assurance Standards now sit under the UAE IA Regulation, with the Signals Intelligence Agency as the successor to NESA.
The highest-priority controls that every in-scope entity implements first. P2 to P4 controls follow based on the risk assessment.
UAE government entities and organisations in critical sectors, plus suppliers that handle their information. Sector regulators can require it.
Most of it, because the regulation was modelled on ISO 27001, but UAE IAS adds priority tiers and UAE-specific requirements.
NCA ECC, SAMA CSF, UAE IAS and Gulf data protection laws.
blog.quldex.comA file-naming scheme auditors can follow.
blog.quldex.comHow many samples auditors look at.
blog.quldex.comThe control set UAE IAS maps to.
Reviewed by
Answer a short readiness check and get a gap summary by family. No sales call needed to see the result.