Blog / UAE compliance
UAE compliance
DESC ISR v3: What a Dubai Government Supplier Has to Show Before the Contract Is Signed
DESC ISR compliance for a Dubai government supplier: what ISR v3's 13 domains cover, who it applies to, and what to fix before the contract is signed.
Clause 14 turns up after the celebration
The managing director of a 40-person facilities-management firm in Al Quoz wins a three-year maintenance contract with a Dubai government entity in June. The team celebrates. The contract arrives in July, and the operations manager reads it properly for the first time on a Monday morning.
Clause 14 runs to two pages. It says that any supplier handling government information must align with the Dubai Information Security Regulation, that the entity may audit the supplier's controls, and that a security incident affecting government data must be reported to the entity within a fixed window. It asks for a named information security contact, a copy of the supplier's security policy, and confirmation of the standard the supplier follows.
The firm's IT is a shared server in the office, a Microsoft 365 tenant that the previous IT company set up, and forty phones with the job-scheduling app installed. The government entity will be sending building plans, access schedules and staff lists through that app. The security policy is a paragraph in the employee handbook that says not to share passwords.
The entity's procurement officer is friendly about it. She sends a template of the evidence they usually accept. The first item is "ISR gap assessment or equivalent, dated within twelve months." The contract start date is the first of September.
What the heck does this mean
DESC is the Dubai Electronic Security Centre, the emirate's cyber regulator. ISR is its Information Security Regulation, now at version 3, the set of requirements every Dubai government entity must meet. Since the entities cannot meet it alone, they push it down to the companies that handle their data, which is where a facilities firm comes in.
Government information: anything the entity shares with you to do the job, from building plans to staff lists to the access schedule for a substation.
Domain: a group of requirements on one theme. ISR v3 has thirteen, arranged under Governance, Operation and Assurance.
Governance: policies, roles, risk management, the part where someone is named as accountable.
Operation: the day-to-day controls, access, configuration, change, incident handling.
Assurance: proof that the controls work, audits, testing, reviews.
Zero trust: a design idea ISR v3 leans on, meaning no device or user is trusted just for being on the network; each is checked every time.
Alignment: what the contract asks of you. Not a certificate, but evidence that your controls match the regulation's expectations for the data you hold.
A supplier does not need to run a government security programme. It needs to show the entity that its slice of government data is handled to the entity's standard, and to be able to prove it when asked.
The numbers that matter
ISR v3 organises its requirements across 13 domains grouped into Governance, Operation and Assurance categories, and builds in zero-trust concepts, according to DESC's ISR v3 as published in 2025. Thirteen domains is a table of contents, not a mountain.
The regulation is mandatory for Dubai government entities and is required of vendors handling government data, per DESC's 2025 rules. The contract clause is the regulation reaching you through the entity.
UAE authorities blocked more than 200,000 attacks per day in 2026, rising to between 600,000 and 800,000 a day during the regional escalation earlier this year, according to the UAE Cyber Security Council's 2026 statements. Government data on a supplier's phones is one of the ways in, and the entities know it.
What to do this week
- Name the information security contact clause 14 asks for, and give that person two hours a week to own the evidence folder. It can be the operations manager; it cannot be nobody. (CIS 15 Service Provider Management)
- List every place government data will live: the scheduling app, the phones, the shared server, email, the subcontractor's WhatsApp. Then list every subcontractor who will see it and what they have signed. (CIS 15 Service Provider Management)
- Harden the phones and the tenant: mandatory screen lock and encryption on every device with the scheduling app, MFA on Microsoft 365, admin rights removed from daily accounts, and the ability to wipe a lost phone. (CIS 4 Secure Configuration of Enterprise Assets and Software)
- Set the baseline for the server and laptops: supported operating systems, automatic updates on, local admin passwords unique, unused services off. Write down the baseline so the auditor can compare against it. (CIS 4 Secure Configuration of Enterprise Assets and Software)
- Write the incident page for this contract: what counts as an incident involving government data, who calls the entity, within what window, and who preserves the evidence. Run it once as a tabletop. (CIS 17 Incident Response Management)
- Commission a gap assessment against ISR v3's 13 domains, dated and signed, and file it as item one in the evidence folder the procurement officer described. (CIS 15 Service Provider Management)
Where AccuSights fits
Our assessment maps your controls to ISR v3's 13 domains and to the evidence the government entity's template asks for, and ranks the gaps so you fix what the contract cares about first. The read-only compliance agent then keeps the picture current between audits: read-only insight into where the gaps are, so you prioritise and keep an eye on them. We have no access to your systems and we do not remediate; you or your IT partner fix, we show you where.
Questions people ask
Is DESC ISR the same as NESA? No. NESA was the federal body whose Information Assurance Standard now sits with the UAE Cyber Security Council, and it applies across the country, especially to critical infrastructure. DESC is Dubai's own regulator, and the ISR is its rulebook for Dubai government entities and the suppliers who handle their data. The two overlap heavily on the controls, so a control set built for one gets you most of the way to the other.
Do private companies need DESC certification? Most do not need a certificate; they need to show alignment. The obligation lands on the government entity, which passes it to you through the contract, and the entity decides what proof it will accept: a gap assessment, a policy set, an ISO 27001 certificate with a mapping to ISR. DESC does run certification programmes for certain service providers, so if you sell cloud or security services into government, ask which one applies.
How is ISR compliance verified? For the government entity, by DESC, through its own assessment and reporting cycle. For a supplier, by the entity's contract and procurement team, which will ask for evidence at prequalification, at contract signature and during audits it is entitled to run. Keep an evidence folder organised by the 13 domains, and the verification becomes a file hand-over rather than a scramble.
Clause 14 is the entity telling you it takes its data seriously. Show it you do too, and the three-year contract becomes a reference for the next one.
Questions people ask
Is DESC ISR the same as NESA?
No. NESA was the federal body whose Information Assurance Standard now sits with the UAE Cyber Security Council, and it applies across the country, especially to critical infrastructure. DESC is Dubai's own regulator, and the ISR is its rulebook for Dubai government entities and the suppliers who handle their data. The two overlap heavily on the controls, so a control set built for one gets you most of the way to the other.
Do private companies need DESC certification?
Most do not need a certificate; they need to show alignment. The obligation lands on the government entity, which passes it to you through the contract, and the entity decides what proof it will accept: a gap assessment, a policy set, an ISO 27001 certificate with a mapping to ISR. DESC does run certification programmes for certain service providers, so if you sell cloud or security services into government, ask which one applies.
How is ISR compliance verified?
For the government entity, by DESC, through its own assessment and reporting cycle. For a supplier, by the entity's contract and procurement team, which will ask for evidence at prequalification, at contract signature and during audits it is entitled to run. Keep an evidence folder organised by the 13 domains, and the verification becomes a file hand-over rather than a scramble.
Controls this post maps to
CIS Controls v8.1, the baseline the UAE IA Standard and ADHICS build on. These are the same controls our assessment scores.
Sources
Sam Khan, Founder and CEO. CISA and CRISC. More than two decades in financial services security and risk, from the Federal Reserve System to Guggenheim. Reads the week in threats so an owner does not have to. About the team →
Keep reading
Three more from the same shelf.
CBUAE Cyber Rules for Fintechs and the Suppliers Who Serve Banks
CBUAE cybersecurity framework explained for a small fintech or bank supplier: which regulations reach you, why the bank's questionnaire exists, and what to fix.
UAE complianceDIFC, ADGM or Federal PDPL: Which Data Rules Apply to Your Free-Zone Company
DIFC Data Protection Law, ADGM regulations or federal PDPL: how to tell which one governs your data, what changes at the free-zone boundary, and what to fix.
UAE complianceISO 27001 for UAE Tenders: Why the Certificate Is Now a Bid Document
ISO 27001 UAE tender guide: why a current certificate is now a prequalification document, how long it takes a small firm, and what to do this week.
