Skip to content
Protect24x7
Esc

Try XDR, DLP, CrowdStrike or PDPL. Arrow keys to move, Enter to open.

Talk to our SOC

UAE framework guide · UAE Cyber Security Council (CSC)

NESA / SIA compliance in the UAE

The national baseline for critical information infrastructure: 134 controls in 15 families, each with a priority and an applicability rule. Published today by the Cyber Security Council; still searched by the names it carried before.

Who NESA / SIA applies to

  • Ministries and federal authorities, and non-government critical information infrastructure (CII) entities. That is the standard’s own scope statement.
  • Emirate government entities and non-government CII where an Emirate runs its own CIIP programme: that Emirate lead carries out the applicability assessment, enforcement and monitoring. Where no such programme exists, the standard applies to Emirate government entities directly.
  • Private-sector entities that adopt it: the standard notes it has been adopted by numerous private sector entities beyond the CII sectors, and sector regulators can require it. The Central Bank’s payment regulation, for one, requires payment service providers to meet it at a minimum.

What NESA / SIA asks for

The UAE Information Assurance Standard, as the regulator publishes it, by theme rather than clause number.

15 families, 134 controls, 449 sub-controls
Control families are split into management and technical. Each control carries a priority from P1 to P4 and an applicability rule; the sub-controls are the mandatory implementation requirements an entity claiming compliance has to meet.
Always applicable, or risk-based
70 controls are always applicable and their omission constitutes non-conformity. 64 apply based on the entity’s risk assessment, and excluding any of them needs justification and evidence that the associated risk is addressed.
Risk-based, phased implementation
The standard sets out a risk-based approach and a phased implementation that addresses prevalent threats first, with performance indicators per family so an entity can measure its own effectiveness.
Self-assessment, then review
Entities report compliance by self-assessment. The Cyber Security Council’s stated role is to review those reports and, where appropriate, commission compliance audits or testing to validate them.
Roles at national, Emirate, sector and entity level
The document defines who plans, implements and monitors information assurance at each level, which is where a named security owner inside your organisation comes from.

From requirement to what we run

Each theme, and the service, the technology guide and the portfolio vendors that support it. A mapping, not a compliance claim: the service is what makes the control demonstrable.

Portfolio capabilities that support alignment17

Each row is published on the matching vendor page and reproduced here from the same source. This is a capability map, not compliance advice: it is not a certification, an audit result or a guarantee of coverage, and it does not interpret the regulation. Confirm applicability and scope with the vendor and a qualified compliance advisor before relying on it.

Questions buyers ask

NESA, SIA or the UAE IA Standard: which is it?
One standard, three names. The current document is the UAE Information Assurance Standard, version 2.1 of November 2025, published by the UAE Cyber Security Council as part of the National Information Assurance Framework. People still say NESA because the original standard was issued by the National Electronic Security Authority, and SIA because that authority became the Signals Intelligence Agency. Search any of the three and this is the document you are looking for.
Who has to comply?
Ministries and federal authorities, and non-government critical information infrastructure entities, by the standard’s own scope. Emirate government entities come under their Emirate’s CIIP programme where one exists, and under the standard directly where one does not. Sector regulators can require it too: payment service providers licensed by the Central Bank must meet it at a minimum.
How is the standard structured?
15 control families, 47 sub-families, 134 controls and 449 sub-controls, split into management and technical families. Each control carries a priority from P1 to P4 and an applicability rule: 70 controls are always applicable, 64 apply based on the entity’s risk assessment, and excluding one of those needs documented justification. If you have read that it has 188 controls, that was the earlier edition.
How is compliance checked?
By self-assessment against the mandatory controls, meaning the always-applicable ones plus those your risk assessment brings in. The Cyber Security Council’s role, as the standard describes it, is to review those self-assessment reports and, where appropriate, perform or commission compliance audits and testing to validate them.
How does it relate to ISO 27001?
The standard aligns with ISO/IEC 27001, NIST SP 800-53 and the CIS Controls, and its structure will look familiar to anyone who has run an ISMS. It is not a substitute. ISO 27001 is a certifiable management-system standard you choose; the UAE IA Standard is a national baseline your sector or Emirate may require. The GRC service maps one set of evidence to both, so the work is done once.
Is Protect24x7 an accredited assessor?
No. Protect24x7 holds no accreditation or approval under the standard, and this page is a capability map rather than compliance advice. What the GRC team does is the gap assessment against the current edition, the control mapping to its families, and the evidence collection ahead of a review; the managed services are what make the monitoring and incident-management controls demonstrable.

Sources

Every regulatory statement on this page comes from one of these documents. Where they are silent, so is the page.

Being assessed against NESA / SIA?
A gap assessment against the current edition, controls mapped to it, and the evidence collected before the review, not during it.
Talk to the GRC team