Skip to main content
Insights/UAE Compliance
UAE Compliance

UAE Information Assurance Standards: A Controls Primer for Critical-Sector Operators

Published 9 min read
The short answer

The UAE Information Assurance (IA) Standard is the federal baseline cybersecurity framework for critical entities, issued under the Cyber Security Council and operationalised through the TDRA IA Regulation. It groups management and technical controls into four priority levels (P1-P4); P1 controls are mandatory and must be implemented first, and cannot be demoted through risk acceptance. If TDRA designates you a critical entity under the CIIP Policy, compliance is mandatory, not voluntary.

On this page

Who this applies to: UAE-designated critical entities and CII operators across energy, water, telecoms, transport, healthcare and finance; government and semi-government bodies; and their in-scope IT, cloud and OT suppliers.

The UAE has moved decisively from "recommended practice" to enforced baseline for critical sectors. If your organisation runs infrastructure the state considers vital — or you supply the entities that do — the Information Assurance Standard is the control set auditors and government buyers will hold you to. This primer walks through scope, structure and where to start.

Key takeaway

P1 controls are the gate. They are mandatory, they cannot be demoted through risk acceptance, and demonstrating them is the first thing an auditor or a government procurement reviewer will check. Everything else is sequencing.

Who issues the UAE IA Standard, and what sits above it?#

The framework has a layered lineage that trips up newcomers. The Information Assurance Regulation is issued by the Telecommunications and Digital Government Regulatory Authority (TDRA). The IA Regulation provides management and technical information security controls for entities to establish, implement, maintain, and continuously improve information assurance, and the TDRA designates critical entities as per the UAE CIIP Policy to implement the regulation across the use, processing, storage and transmission of information.

Above the regulation sits the Critical Information Infrastructure Protection (CIIP) Policy. The CIIP Policy defines the governance and protection framework for the UAE's CII entities, establishing a unified approach to identifying critical assets, developing national risk profiles, setting baseline security requirements, and implementing assurance and enforcement mechanisms across vital sectors — established by the Cyber Security Council to ensure a baseline of security and cyber resilience for CII.

The Cyber Security Council (CSC) is now the steward of the IA Standard itself. The UAE IA Standard aligns with internationally recognised best practices including ISO/IEC 27001, NIST SP 800-53 and CIS Controls, plays a vital role in securing national digital assets, and the Council developed it to strengthen the protection of information and communication systems supporting the UAE's critical infrastructure.

A naming note worth internalising: the authority historically known as NESA (National Electronic Security Authority) — you will still see tenders and consultancies reference "NESA IAS" — now operates under the Signals Intelligence Agency (SIA), while the CSC maintains and audits the standard nationally. Treat "NESA IAS," "UAE IA Standard" and "UAE IA Regulation" as pointing at the same body of controls unless a document specifies otherwise.

UAE IA Standard (CSC)

Active

CII operators, gov entities

The control set itself. Aligned to ISO 27001, NIST SP 800-53, CIS Controls.

IA Regulation (TDRA)

Active

Designated critical entities

Operationalises the standard; TDRA designates entities under the CIIP Policy.

CIIP Policy (CSC)

Active

Vital sectors

Governance framework for identifying critical assets and enforcement.

NCSS 2025-2031 (CSC)

Active

All sectors

National strategy anchoring the shift to mandatory resilience.

View as table
RegimeWho it bindsStatus
UAE IA Standard (CSC)CII operators, gov entitiesActive — The control set itself. Aligned to ISO 27001, NIST SP 800-53, CIS Controls.
IA Regulation (TDRA)Designated critical entitiesActive — Operationalises the standard; TDRA designates entities under the CIIP Policy.
CIIP Policy (CSC)Vital sectorsActive — Governance framework for identifying critical assets and enforcement.
NCSS 2025-2031 (CSC)All sectorsActive — National strategy anchoring the shift to mandatory resilience.

Does the standard apply to my organisation?#

Scope is broader than many operators assume, and it is expanding. Mandatory application covers government bodies and any entity the TDRA designates as critical under the CIIP Policy. This includes all UAE federal and local government bodies; critical entities operating within Critical National Infrastructure sectors as identified by the TDRA; and while mandatory for designated entities, the TDRA strongly recommends all other UAE entities adopt these standards voluntarily.

The sectors in scope are the usual critical-infrastructure set. The UAE Cybersecurity Council maintains the national registry of CII operators, spanning sectors such as energy, water, telecommunications, transport, healthcare, and financial services. Designation is not a formality — it changes your obligations materially. CII designation triggers requirements around advanced threat detection, supply chain security, and mandatory participation in national threat intelligence sharing that go significantly beyond what any sector-specific financial or healthcare framework requires.

For maritime and logistics operators specifically, transport is a named CII sector — so port operators, terminal systems and vessel-shore IT that touch UAE critical infrastructure should assume relevance and confirm designation status with the TDRA. Scoping explicitly reaches operational technology, not just corporate IT. This includes IT and OT systems for critical infrastructure entities, and entities must determine the criticality of each asset to the organisation's mission and to national services.

Suppliers are increasingly pulled in too. If you sell IT services, cloud infrastructure or managed security to a designated entity, expect IA alignment to appear in pre-qualification. Government and semi-government buyers routinely screen vendors for IA Regulation alignment during procurement, and failing to produce the right artefacts can end a bid before technical scoring begins.

Watch out

Do not self-assess your way out of scope. Designation is a TDRA decision under the CIIP Policy, not a judgement you make internally. If you handle vital-sector data or serve a designated entity, verify your status with the TDRA rather than assuming you are exempt.

How are the controls structured — and where do I start?#

The IA control set is split into two families and prioritised into four tiers. The management family covers governance, risk assessment, policy, training and compliance; the technical family covers physical security, access control, operations management, incident response and related areas.

The priority mechanism is the operationally important part. Security controls are grouped into four priority levels — P1, P2, P3 and P4 in order of importance — and while all applicable controls across the four levels are mandatory for critical entities, they are required to begin implementation with P1 controls given their highest relative impact in protecting against critical threats and building foundational information assurance capabilities.

The one rule you cannot negotiate around: critical entities may alter — promote or demote — the suggested priority of controls based on their risk assessment, with the exception of top-priority (P1) controls, which if applicable may not be demoted. In practice, P1 is your baseline and your audit gate. P2 through P4 are where a documented, defensible risk assessment earns you sequencing flexibility.

Two framing points from the CSC's own guidance are worth keeping in mind so you don't over-read the tiers. Control priority does not equate to control criticality; the priority levels assigned to each control are intended to help entities plan the sequence of their implementation efforts, rather than dictate that a specific control is inherently more critical than another. And the standard is built to flex to your risk profile. It promotes a risk-driven methodology, ensuring organisations prioritise controls based on the potential impact of cyber threats, and instead of enforcing uniform compliance, it allows entities to tailor requirements according to their environment, data sensitivity and criticality.

Note on control counts: secondary sources cite different totals — commonly "188 controls" for the earlier structure, with 2025 v2 reporting appearing to reorganise the families. Because these numbers vary by source and version, confirm the exact control and sub-control count against the current CSC-published IA Standard rather than relying on a vendor summary.

Your situationMandatoryRe-prioritisableAudit gate
P1 controlsAppliesNot applicableFixedAppliesFirst check
P2 controlsAppliesConditionalVia risk assessmentPartial / recommended
P3 controlsAppliesConditionalVia risk assessmentPartial / recommended
P4 controlsAppliesConditionalVia risk assessmentNot applicable
AppliesNot applicableConditionalPartial / recommended

What changed with the 2025 v2 update?#

The framework was refreshed in 2025 for the first time in roughly a decade. The UAE IA Standard Version 2 is a national cybersecurity framework issued by the UAE Cyber Security Council in 2025, building on the previous version with updated controls and integrations to address modern technologies such as AI/ML, IoT, cloud, and post-quantum cryptography.

Reporting indicates the structural bones carried over while the content was modernised. While the six management and nine technical control domains remain consistent with the earlier version, UAE IA V2 refines their structure, intent and interconnectivity — the Cyber Security Council modernised and harmonised the framework rather than reinventing it. The areas that reportedly tightened are exactly the ones critical-sector operators find hardest: cloud security governance, OT security for industrial control systems, and supply-chain risk management. Treat the specific v2 control counts and domain mappings as "verify with the CSC" until you are reading the published document — the trade and vendor summaries do not fully agree.

This update did not happen in isolation. It aligns with the wider strategic shift. The UAE Cyber Security Council's National Cyber Security Strategy 2025-2031, approved in February 2025 and published in September, has formally shifted the country's position from voluntary guidance to mandatory resilience.

What should a critical-sector operator do first?#

A pragmatic sequence, defensive framing throughout:

1

Confirm scope and designation

  • Verify CII/critical-entity designation status with the TDRA under the CIIP Policy.
  • Inventory in-scope IT and OT assets and rate criticality to national services.
  • Identify supplier relationships that pull vendors into scope.
2

Establish the P1 baseline

  • Map current controls to the P1 set; treat P1 as non-negotiable.
  • Close gaps in identity and access, patching, logging/monitoring and incident response.
  • Document a risk assessment to justify P2-P4 sequencing.
3

Evidence and sustain

  • Maintain policy, risk assessment and incident response documentation for audit.
  • Justify any control exclusion or deviation through authorised risk acceptance.
  • Build continuous monitoring so evidence is generated, not reconstructed.

The documentation discipline matters as much as the controls. Entities are required to justify any exclusions or deviations through proper risk acceptance by authorised personnel, and performance indicators are included to help organisations assess the quality and effectiveness of their implementation. An IA audit tests whether you can show your working — asset scoping, the risk assessment behind your prioritisation, and evidence that P1 is genuinely operational.

If you already run an ISO 27001 ISMS, you have a real head start, because the standard is designed to integrate with existing management systems rather than replace them. But mapping is not compliance: you still need to trace your controls to the IA control set and evidence the mandatory sub-controls the standard specifies. Where scope, designation, or a specific control interpretation is unclear, confirm directly with the TDRA or Cyber Security Council rather than relying on secondary guidance.

Getting IA scoping and P1 evidence right the first time is far cheaper than remediating a failed audit or a lost tender. If you want a second set of eyes on your designation status, control mapping, or OT scope, book a consultation with Solas Security.

Primary sources: TDRA UAE IA Regulation v1.1; Cyber Security Council — UAE IA Standard; u.ae — Cyber safety and digital security; u.ae — CIIP Policy; CSC — National Cybersecurity Strategy 2025-2031; u.ae — Data protection laws (PDPL). v2 control-count and domain details reported by trade/vendor sources; verify against the CSC-published standard.

Frequently asked

Is the UAE IA Standard mandatory or voluntary?

It is mandatory for entities the TDRA designates as critical under the CIIP Policy, and for government bodies. The TDRA recommends all other UAE entities adopt it voluntarily to raise their baseline, but for designated critical entities it is a compliance obligation, not guidance.

What are the P1-P4 priority levels?

Controls are grouped into four priority tiers by relative impact. All applicable controls across all four tiers are mandatory for critical entities, but implementation begins with P1 as the foundational baseline. P1 controls cannot be demoted through risk acceptance; P2-P4 may be re-prioritised based on a documented risk assessment.

How does the IA Standard relate to ISO 27001 and NIST?

The Cyber Security Council states the standard aligns with ISO/IEC 27001, NIST SP 800-53 and CIS Controls. An existing ISO 27001 ISMS gives you a strong head start, but you still need to map to the IA control set and evidence the mandatory sub-controls the standard specifies.

Who designates an entity as 'critical'?

The TDRA designates critical entities under the UAE Critical Information Infrastructure Protection (CIIP) Policy, which the Cyber Security Council established. Designation triggers mandatory implementation of the IA Regulation across the use, processing, storage and transmission of in-scope information.

Does the IA Standard cover operational technology?

Yes. Scoping for critical infrastructure entities covers both IT and OT systems. Verify the current OT and supply-chain requirements against the Cyber Security Council's published IA Standard, as the 2025 v2 update reportedly strengthened these areas.

Vishnu Karakkatt

Written by

Vishnu Karakkatt

CEO & Founder

Meet the team
Talk to a practitioner

Get a security consultation

Bring your environment, your regulators, and your hardest question. We answer control-by-control.