Suspect a breach? Report it immediately — response within 1 hour.Report an incident

NESA / UAE IA Standards (United Arab Emirates)

A family of UAE information assurance standards (188 controls), historically issued under NESA and now sitting under the Cybersecurity Council / SIA (Signals Intelligence Agency) umbrella, with local implementations by DESC in Dubai and ADDA in Abu Dhabi.

Last updatedAugust 22, 2026

Who's affected

Government entities and critical information infrastructure operators in the UAE, along with their service providers. Depending on the sector or emirate, sectoral variants apply on top: Dubai ISR, ADHICS (healthcare, Abu Dhabi), SCA regulation (financial markets), DIFC Data Protection Law, ADGM Data Protection Regulations (financial free zones).

What the framework requires

Implementation of the 188 controls spanning governance, risk management, and technical protection domains, based on whichever standard applies to the entity (federal UAE IA, or the relevant sector/emirate variant).

Compliance steps

01

Identify the applicable standard(s) based on the entity, sector, and emirate

02

Gap analysis against the 188 UAE IA controls

03

Prioritize corrective actions by risk domain

04

Implement technical and organizational controls

05

Prepare for audit or review by the supervisory authority

Common mistakes

  • Treating UAE IA Standards as a single text when it is in fact a family of standards with sectoral and local variants
  • Overlooking the variant applicable to the relevant emirate or sector (e.g. ADHICS for healthcare)
  • Ignoring the link to the provider accreditation program (NCAP)

Cross-mapping to other frameworks (UCM)

FrameworkCovered
ncap-emirats

Downloadable resource

Get the checklist by email.

Frequently asked questions

Does NESA still exist as such?

The NESA acronym is still used out of habit, but the framework now sits under the Cybersecurity Council and the SIA; the 188 UAE IA controls remain the technical reference.

What is the difference between UAE IA and NCAP?

UAE IA Standards defines the security controls entities must apply; NCAP is a separate program that accredits which providers are authorized to work on critical infrastructure.

Does ADHICS apply outside the healthcare sector?

No, ADHICS is a sector-specific variant for healthcare in Abu Dhabi; other sectors fall under different texts (Dubai ISR, DIFC DP Law, ADGM DPR depending on the zone and activity).

Can EBH Security operate directly in this space?

For entities strictly within scope of these frameworks, delivery is subcontracted to locally accredited actors — see the NCAP page.