We are exhibiting at GISEC Global 2026 · 16-18 Sept · Expo City DubaiBook a booth session with our CEO
AccuSights
Products
Assess
Comply
Protect
Free Tools
Email Breach Checker
Cyber Hygiene Test
Regulator directory
Regulatory calendar
ADHICS
ADGM
CBUAE
CSC
DFSA
DHA
DHCC
DIFC
DOH
FSRA
NIAF
Malaffi
MOHAP
NABIDH
NCAP
SCA
VARA
Healthcare
Finance
AI & Machine Learning
Defence & Military
Government Contractor
Professional Services
Technology & SaaS
Retail & Hospitality
Real Estate & Construction
Architecture, Design & Construction
Cybersecurity in Dubai
Cybersecurity in Abu Dhabi
Cybersecurity in Sharjah
All emirates
Chambers of Commerce
MSP
Partner Program
About Us
Why AccuSights
Compliance Center
Blog
Threat Dashboard
Threat Headlines
Contact

Blog / UAE compliance

UAE compliance

DESC ISR v3: What a Dubai Government Supplier Has to Show Before the Contract Is Signed

DESC ISR compliance for a Dubai government supplier: what ISR v3's 13 domains cover, who it applies to, and what to fix before the contract is signed.

Sam KhanSam Khan The Cyber MonkFounder and CEO2 September 2026 · 6 min read

Clause 14 turns up after the celebration

The managing director of a 40-person facilities-management firm in Al Quoz wins a three-year maintenance contract with a Dubai government entity in June. The team celebrates. The contract arrives in July, and the operations manager reads it properly for the first time on a Monday morning.

Clause 14 runs to two pages. It says that any supplier handling government information must align with the Dubai Information Security Regulation, that the entity may audit the supplier's controls, and that a security incident affecting government data must be reported to the entity within a fixed window. It asks for a named information security contact, a copy of the supplier's security policy, and confirmation of the standard the supplier follows.

The firm's IT is a shared server in the office, a Microsoft 365 tenant that the previous IT company set up, and forty phones with the job-scheduling app installed. The government entity will be sending building plans, access schedules and staff lists through that app. The security policy is a paragraph in the employee handbook that says not to share passwords.

The entity's procurement officer is friendly about it. She sends a template of the evidence they usually accept. The first item is "ISR gap assessment or equivalent, dated within twelve months." The contract start date is the first of September.

What the heck does this mean

DESC is the Dubai Electronic Security Centre, the emirate's cyber regulator. ISR is its Information Security Regulation, now at version 3, the set of requirements every Dubai government entity must meet. Since the entities cannot meet it alone, they push it down to the companies that handle their data, which is where a facilities firm comes in.

Government information: anything the entity shares with you to do the job, from building plans to staff lists to the access schedule for a substation.

Domain: a group of requirements on one theme. ISR v3 has thirteen, arranged under Governance, Operation and Assurance.

Governance: policies, roles, risk management, the part where someone is named as accountable.

Operation: the day-to-day controls, access, configuration, change, incident handling.

Assurance: proof that the controls work, audits, testing, reviews.

Zero trust: a design idea ISR v3 leans on, meaning no device or user is trusted just for being on the network; each is checked every time.

Alignment: what the contract asks of you. Not a certificate, but evidence that your controls match the regulation's expectations for the data you hold.

A supplier does not need to run a government security programme. It needs to show the entity that its slice of government data is handled to the entity's standard, and to be able to prove it when asked.

The numbers that matter

ISR v3 organises its requirements across 13 domains grouped into Governance, Operation and Assurance categories, and builds in zero-trust concepts, according to DESC's ISR v3 as published in 2025. Thirteen domains is a table of contents, not a mountain.

The regulation is mandatory for Dubai government entities and is required of vendors handling government data, per DESC's 2025 rules. The contract clause is the regulation reaching you through the entity.

UAE authorities blocked more than 200,000 attacks per day in 2026, rising to between 600,000 and 800,000 a day during the regional escalation earlier this year, according to the UAE Cyber Security Council's 2026 statements. Government data on a supplier's phones is one of the ways in, and the entities know it.

What to do this week

  1. Name the information security contact clause 14 asks for, and give that person two hours a week to own the evidence folder. It can be the operations manager; it cannot be nobody. (CIS 15 Service Provider Management)
  2. List every place government data will live: the scheduling app, the phones, the shared server, email, the subcontractor's WhatsApp. Then list every subcontractor who will see it and what they have signed. (CIS 15 Service Provider Management)
  3. Harden the phones and the tenant: mandatory screen lock and encryption on every device with the scheduling app, MFA on Microsoft 365, admin rights removed from daily accounts, and the ability to wipe a lost phone. (CIS 4 Secure Configuration of Enterprise Assets and Software)
  4. Set the baseline for the server and laptops: supported operating systems, automatic updates on, local admin passwords unique, unused services off. Write down the baseline so the auditor can compare against it. (CIS 4 Secure Configuration of Enterprise Assets and Software)
  5. Write the incident page for this contract: what counts as an incident involving government data, who calls the entity, within what window, and who preserves the evidence. Run it once as a tabletop. (CIS 17 Incident Response Management)
  6. Commission a gap assessment against ISR v3's 13 domains, dated and signed, and file it as item one in the evidence folder the procurement officer described. (CIS 15 Service Provider Management)

Where AccuSights fits

Our assessment maps your controls to ISR v3's 13 domains and to the evidence the government entity's template asks for, and ranks the gaps so you fix what the contract cares about first. The read-only compliance agent then keeps the picture current between audits: read-only insight into where the gaps are, so you prioritise and keep an eye on them. We have no access to your systems and we do not remediate; you or your IT partner fix, we show you where.

Questions people ask

Is DESC ISR the same as NESA? No. NESA was the federal body whose Information Assurance Standard now sits with the UAE Cyber Security Council, and it applies across the country, especially to critical infrastructure. DESC is Dubai's own regulator, and the ISR is its rulebook for Dubai government entities and the suppliers who handle their data. The two overlap heavily on the controls, so a control set built for one gets you most of the way to the other.

Do private companies need DESC certification? Most do not need a certificate; they need to show alignment. The obligation lands on the government entity, which passes it to you through the contract, and the entity decides what proof it will accept: a gap assessment, a policy set, an ISO 27001 certificate with a mapping to ISR. DESC does run certification programmes for certain service providers, so if you sell cloud or security services into government, ask which one applies.

How is ISR compliance verified? For the government entity, by DESC, through its own assessment and reporting cycle. For a supplier, by the entity's contract and procurement team, which will ask for evidence at prequalification, at contract signature and during audits it is entitled to run. Keep an evidence folder organised by the 13 domains, and the verification becomes a file hand-over rather than a scramble.

Clause 14 is the entity telling you it takes its data seriously. Show it you do too, and the three-year contract becomes a reference for the next one.

Questions people ask

Is DESC ISR the same as NESA?

No. NESA was the federal body whose Information Assurance Standard now sits with the UAE Cyber Security Council, and it applies across the country, especially to critical infrastructure. DESC is Dubai's own regulator, and the ISR is its rulebook for Dubai government entities and the suppliers who handle their data. The two overlap heavily on the controls, so a control set built for one gets you most of the way to the other.

Do private companies need DESC certification?

Most do not need a certificate; they need to show alignment. The obligation lands on the government entity, which passes it to you through the contract, and the entity decides what proof it will accept: a gap assessment, a policy set, an ISO 27001 certificate with a mapping to ISR. DESC does run certification programmes for certain service providers, so if you sell cloud or security services into government, ask which one applies.

How is ISR compliance verified?

For the government entity, by DESC, through its own assessment and reporting cycle. For a supplier, by the entity's contract and procurement team, which will ask for evidence at prequalification, at contract signature and during audits it is entitled to run. Keep an evidence folder organised by the 13 domains, and the verification becomes a file hand-over rather than a scramble.

Controls this post maps to

CIS 15 Service Provider ManagementCIS 4 Secure Configuration of Enterprise Assets and SoftwareCIS 17 Incident Response Management

CIS Controls v8.1, the baseline the UAE IA Standard and ADHICS build on. These are the same controls our assessment scores.

Sam Khan, Founder and CEO. CISA and CRISC. More than two decades in financial services security and risk, from the Federal Reserve System to Guggenheim. Reads the week in threats so an owner does not have to. About the team →

Where AccuSights fits

Check, then repeat. We provide read-only insight so you prioritize the right things and keep an eye on them.

We have no access and do not remediate. You or your IT partner fix; we show you where, mapped to your regulators. Thirty minutes with an engineer draws the map for your organization.

Compliance is not security. The audit is not the exam; the attacker is.