Regulation · Information assurance · United Arab Emirates

UAE IAS compliance: the Information Assurance Regulation explained

UAE IAS compliance means meeting the UAE Information Assurance Regulation, formerly known as the NESA standards. It sets 188 controls in 6 management and 9 technical families, prioritised from P1 to P4 and selected by risk, for government entities and critical infrastructure in the UAE and the organisations that serve them.

Key takeaways

What you need to know about UAE IAS

Risk-basedThe risk assessment decides which controls apply beyond P1.
P1 firstP1 controls are the foundation in every programme.
Close to ISO 27001The structure maps closely to ISO 27001 Annex A.
Suppliers in scopeThird-party security is its own family.
Name changesSearch for both "NESA" and "UAE IAS"; they mean the same standards.

Who must comply with UAE IAS?

UAE government entities, critical infrastructure and the organisations that serve them.

Federal and local governmentGovernment entities across the UAE.
Critical sectorsEnergy, finance, telecom, health, transport and other critical sectors.
Suppliers to governmentService providers and vendors to in-scope entities.
Cloud and IT providersHosting or processing data for in-scope entities.
Organisations seeking tendersGovernment tenders often ask for alignment.

QULDEX helps here first: the readiness check shows where you stand before you commit budget.

What the regulation requires

What does the UAE Information Assurance Regulation require?

The UAE Information Assurance Regulation requires in-scope entities to run a risk-based information assurance programme: management controls for strategy, risk, people and compliance, and technical controls from assets to continuity, implemented in priority order.

M1–M6 Manage

Management controls

Strategy, risk, awareness, HR, compliance, improvement.

In QULDEX: Management evidence mapped
T1–T9 Protect

Technical controls

Assets through continuity.

In QULDEX: Controls mapped to ISO 27001
P1–P4 Prioritise

Priority tiers

P1 first, then by risk.

In QULDEX: Priority tags on every control
Risk Select

Risk-based selection

Risk assessment decides applicability.

In QULDEX: Risk register
Audit Assure

Evaluation

Internal audit and improvement.

In QULDEX: Audit workspace
Control family explorer

What are the UAE IAS control families?

The 15 control families plus the priority model. Select any family to see what it covers, typical evidence and the matching ISO 27001 controls.

188controls
6management families
9technical families
P1–P4priorities

Showing up to 6 per group. Search, filter, or open a group to see all 16.

Management controls 6

  1. M1Strategy and planning

    Information security strategy, policy and the organisation's security management structure.

    In QULDEXQULDEX tracks this control family with owners, priority tags (P1–P4) and evidence, mapped to ISO 27001.

    Typical evidence
    Strategy, policy
    Maps to
    ISO 27001 5.1–5.3

  2. M2Information security risk management

    Risk assessment and treatment, and threat-driven control selection.

    In QULDEXThe risk register drives which controls apply.

    Typical evidence
    Risk register
    Maps to
    ISO 27001 6.1

  3. M3Awareness and training

    Security awareness and role-based training.

    In QULDEXQULDEX tracks this control family with owners, priority tags (P1–P4) and evidence, mapped to ISO 27001.

    Typical evidence
    Training records
    Maps to
    ISO 27001 A.6.3

  4. M4Human resources security

    Security before, during and after employment.

    In QULDEXQULDEX tracks this control family with owners, priority tags (P1–P4) and evidence, mapped to ISO 27001.

    Typical evidence
    Screening, NDAs
    Maps to
    ISO 27001 A.6.1–A.6.5

  5. M5Compliance

    Compliance with legal and regulatory requirements and the IA Regulation itself.

    In QULDEXQULDEX tracks this control family with owners, priority tags (P1–P4) and evidence, mapped to ISO 27001.

    Typical evidence
    Compliance register
    Maps to
    ISO 27001 A.5.31

  6. M6Performance evaluation and improvement

    Monitoring, internal audit and continual improvement of information assurance.

    In QULDEXAudits and findings run in the audit workspace.

    Typical evidence
    Audit reports
    Maps to
    ISO 27001 9.2, 10

Technical controls 9

  1. T1Asset management

    Inventory, ownership, classification and handling of information assets.

    In QULDEXQULDEX tracks this control family with owners, priority tags (P1–P4) and evidence, mapped to ISO 27001.

    Typical evidence
    Asset inventory
    Maps to
    ISO 27001 A.5.9–A.5.13

  2. T2Physical and environmental security

    Secure areas, equipment protection and environmental controls.

    In QULDEXQULDEX tracks this control family with owners, priority tags (P1–P4) and evidence, mapped to ISO 27001.

    Typical evidence
    Physical access logs
    Maps to
    ISO 27001 A.7

  3. T3Operations management

    Operating procedures, change, capacity, malware protection, backup, logging and monitoring.

    In QULDEXQULDEX tracks this control family with owners, priority tags (P1–P4) and evidence, mapped to ISO 27001.

    Typical evidence
    Operational records
    Maps to
    ISO 27001 A.8.6–A.8.16

  4. T4Communications

    Network security, information transfer and electronic messaging.

    In QULDEXQULDEX tracks this control family with owners, priority tags (P1–P4) and evidence, mapped to ISO 27001.

    Typical evidence
    Network diagrams
    Maps to
    ISO 27001 A.8.20–A.8.22

  5. T5Access control

    Access policy, user access management, privileged access and authentication.

    In QULDEXAccess reviews run as recurring tasks.

    Typical evidence
    Access reviews
    Maps to
    ISO 27001 A.5.15–A.5.18

  6. T6Third-party security

    Security requirements for suppliers and outsourced services.

    In QULDEXEach supplier is assessed and linked to its services.

    Typical evidence
    Supplier assessments
    Maps to
    ISO 27001 A.5.19–A.5.22

  7. T7Information systems acquisition, development and maintenance

    Security in system requirements, development and testing.

    In QULDEXQULDEX tracks this control family with owners, priority tags (P1–P4) and evidence, mapped to ISO 27001.

    Typical evidence
    SDLC evidence
    Maps to
    ISO 27001 A.8.25–A.8.29

  8. T8Incident management

    Incident detection, response, reporting and learning.

    In QULDEXIncidents run with timers and reporting records.

    Typical evidence
    Incident reports
    Maps to
    ISO 27001 A.5.24–A.5.27

  9. T9Information systems continuity management

    Continuity of information systems and recovery planning.

    In QULDEXContinuity evidence is reused from ISO 22301.

    Typical evidence
    DR tests
    Maps to
    ISO 22301

Priorities 1

  1. P1–P4Control prioritiesPriority model

    Controls carry a priority from P1 to P4. P1 controls are the foundation every in-scope entity implements first; the rest follow from the risk assessment.

    In QULDEXPriority tags drive the implementation plan and the dashboard.

Family codes follow the UAE Information Assurance Regulation. Summaries are QULDEX paraphrases; the regulation is the authority.

Compliance path

How do you comply with UAE IAS?

Run a risk assessment, implement the P1 controls first, then the controls your risk profile selects, and evidence them for the sector regulator. Most entities need 6 to 12 months, less with ISO 27001.

  1. Confirm scope and regulator

    Check whether you are in a critical sector or supply one, and who supervises you.

  2. Risk assessment

    Assess risks and select applicable controls (M2).

  3. Implement P1 controls

    The foundation controls, first.

  4. Implement risk-selected controls

    P2 to P4 controls your risk assessment requires.

  5. Audit and evaluate

    Internal audit and management review (M6).

  6. Keep improving

    YearlyRisk assessment
    PeriodicInternal audit
    On changeRe-assess controls

Durations are QULDEX planning ranges.

Records to keep

Which documents does UAE IAS need?

Sector regulators and auditors ask for these records.

DocumentFamilyWhere it lives in QULDEX
Information security strategy and policyM1Policy library
Risk assessment and control selectionM2Risk register
Training recordsM3Evidence vault
Compliance registerM5Policy library
Internal audit reportsM6Audit workspace
Asset inventoryT1Risk register
Access reviewsT5Evidence vault
Supplier assessmentsT6Vendor register
Incident reportsT8CAPA automation
Continuity and DR testsT9Evidence vault

Family codes follow the UAE IA Regulation.

Time and cost

How long does UAE IAS take and what drives the effort?

Most entities need 6 to 12 months. P1 coverage, supplier controls and the risk-based selection drive the effort.

Where the time goes

Scoping1–2 wk
Risk assessment3–6 wk
P1 controls2–4 mo
Other controls2–6 mo
Audit1–2 mo

Bars show the upper end of each range on one scale (12 months = full width).

What changes the effort

  • Existing ISO 27001: maps closely to most families
  • Sector: regulators may add requirements
  • Suppliers: third-party controls take time
  • Risk profile: decides how many P2–P4 controls apply
  • Data location: cloud hosting rules may apply
Readiness check · 2 minutes

How ready are you for UAE IAS?

Check these eight things first. Nothing you enter leaves this page.

M1Do you have an approved information security strategy and policy?
M2Is there a current risk assessment driving control selection?
P1Have you implemented all P1 controls?
T1Is your asset inventory complete?
T5Are access rights reviewed and privileged access controlled?
T6Are supplier security requirements in contracts?
T8Can you detect and report incidents?
M6Is there an internal audit of the programme?
Crosswalk

How UAE IAS maps to ISO 27001, NCA ECC and the UAE PDPL

The IA Regulation was modelled closely on ISO 27001. Organisations operating in both the UAE and Saudi Arabia can reuse most evidence for NCA ECC.

UAE crosswalk

UAE IASISO 27001:2022NCA ECC-2:2024UAE PDPLShared evidence
M1 Strategy5.1–5.31-1, 1-2—Strategy
M2 Risk6.11-5Security measuresRisk register
T1 AssetsA.5.92-1Records of processingInventory
T5 AccessA.5.15–A.5.182-2—Access reviews
T6 Third partiesA.5.19–A.5.224-1Processor dutiesVendor register
T8 IncidentsA.5.24–A.5.272-13Breach notificationIncident reports
T9 ContinuityA.5.29–A.5.303-1—DR tests

Indicative mapping for planning. The full crosswalk is in the QULDEX control library.

Where QULDEX fits

How QULDEX runs UAE IAS from risk assessment to audit

QULDEX is UAE IAS compliance and audit management software built from EGV Group's audit delivery, used by in-scope entities, their advisors and auditors. Pick your role to see who does what.

For government entities, critical sectors and suppliers.

  1. ScopeConfirm scopeScope and regulator recorded
  2. RiskAssess riskRisk register drives selection
  3. P1Implement P1P1 controls tracked first
  4. ControlsImplement the restControls mapped to ISO 27001
  5. SuppliersAssess suppliersVendor register
  6. AuditHost the auditControlled evidence sharing
Without one systemWith QULDEX
188 controls in a spreadsheetControls with priority tags and evidence
Risk assessment separate from controlsRisk drives control selection
ISO 27001 and IAS run separatelyOne control set mapped to both
Supplier security uncheckedThird-party status tracked
10+years of audit delivery500+audits deliveredBoth sidesof the audit on one platformRBACand a full audit trail on every action
FAQ

UAE IAS questions people ask

What is UAE IAS?

The UAE Information Assurance Regulation and its standards, originally issued by NESA and now published by the TDRA. It sets 188 controls for government entities and critical sectors.

Is NESA the same as UAE IAS?

Yes. "NESA standards" is the older name; the same Information Assurance Standards now sit under the UAE IA Regulation, with the Signals Intelligence Agency as the successor to NESA.

What are P1 controls?

The highest-priority controls that every in-scope entity implements first. P2 to P4 controls follow based on the risk assessment.

Who must comply with UAE IAS?

UAE government entities and organisations in critical sectors, plus suppliers that handle their information. Sector regulators can require it.

Does ISO 27001 cover UAE IAS?

Most of it, because the regulation was modelled on ISO 27001, but UAE IAS adds priority tiers and UAE-specific requirements.

Sources

References

  1. UAE Information Assurance Regulation, Telecommunications and Digital Government Regulatory Authority (TDRA). tdra.gov.ae
  2. UAE Information Assurance Standards (originally NESA). tdra.gov.ae
  3. ISO/IEC 27001:2022. iso.org

Reviewed by

Manisha Dubey

Framework reviewer · QULDEX

Reviewed this page against the UAE Information Assurance Regulation: control families, priorities and scope.

Page history
  • : Page first built: control family explorer, priority model and readiness check

Know your P1 coverage before the next review

Answer a short readiness check and get a gap summary by family. No sales call needed to see the result.

Schedule
Book a Demo