Blog / UAE compliance
UAE compliance
ISO 27001 for UAE Tenders: Why the Certificate Is Now a Bid Document
ISO 27001 UAE tender guide: why a current certificate is now a prequalification document, how long it takes a small firm, and what to do this week.
"In progress" is not a certificate
The founder of a 25-person software house in Dubai Internet City has been chasing a semi-government portal project for eight months. The relationship is good. The demo went well. The prequalification pack lists twelve documents, and eleven are in the folder by Wednesday.
Document seven is "Valid ISO 27001 certificate, with scope covering the services offered." The firm started its ISO project in January. It has policies, a risk register and a consultant who visits monthly. It does not have a certificate; the stage-one audit is booked for November. The founder attaches a letter from the consultant confirming the programme is "in progress and on track."
The prequalification result arrives the following Tuesday. Disqualified. The procurement officer is polite on the phone and does not budge: the criterion says certificate, the evaluation team cannot score a letter, and the rules do not allow a conditional pass. The project goes to a competitor with a certificate scoped to a different product line, which the founder finds hard to swallow.
He asks the procurement officer when the next tender in this area will open. She says spring. He asks whether the certificate would need to be in hand by then. She says by the submission date, and that the scope must match.
The consultant's timeline has the certificate landing in February. There is no slack in it.
What the heck does this mean
ISO 27001 is the international standard for an information security management system. Certification means an accredited outside body has audited your system and confirmed it works as documented. In the UAE it has moved from nice-to-have to a document that decides whether your bid is opened.
Management system: the set of policies, roles, risk decisions and records that show security is run, not improvised.
Scope: the offices, services and systems the certificate covers; a certificate for the Abu Dhabi office does not cover the Dubai product.
Statement of applicability: the list of controls you have chosen from the standard's annex and why; auditors read it first.
Stage one and stage two: the two audits on the way to a certificate; the first checks the paperwork, the second checks the practice.
Surveillance audit: the yearly check that keeps the certificate valid between three-year renewals.
Accredited certification body: an auditor firm that is itself checked by a national accreditation body; tenders want this, not a friend with a stamp.
The reason procurement teams like the certificate is that it moves the checking to someone else. An evaluator cannot verify your access reviews, but an accredited auditor already did. That is also why a letter fails: the evaluator would have to trust you instead.
The numbers that matter
There were 96,709 valid ISO 27001 certificates worldwide covering 179,877 sites in the ISO Survey 2024, published by ISO in 2025. The certificate is common enough that buyers now treat it as a floor, not a distinction.
Government and semi-government technology tenders in the UAE increasingly list a current ISO 27001 certificate as a mandatory prequalification criterion, according to 2026 procurement practice. Mandatory means scored as pass or fail before anyone reads your proposal.
ISO 27001's controls map to the majority of the requirements in ADHICS v2, DESC ISR v3 and the UAE IA Standard v2, according to AccuSights' own 2026 mapping analysis. One well-run management system produces evidence for three regulators, which is the real return on the certificate for a small firm.
What to do this week
- Fix the scope before anything else. Write one sentence describing the services, locations and systems the certificate must cover, checked against the tenders you actually want, and give it to the certification body now. (CIS 15 Service Provider Management)
- Run the access review the auditor will ask for: every user in Microsoft 365, the code repository and the cloud console, matched to a current employee or contractor, with leavers removed and the review signed and dated. (CIS 5 Account Management)
- Separate admin accounts from daily accounts for the three people who run production, and put MFA on all of them. It is a control, a finding and a tender question at the same time. (CIS 5 Account Management)
- Turn on and retain audit logs on the cloud platform, the repository and email for at least a year, and put one person's name against the monthly review. Evidence of review is what stage two wants. (CIS 8 Audit Log Management)
- Build the supplier register: every vendor with access to client data or production, what they have signed, and their own certificate status. Auditors and evaluators both read it. (CIS 15 Service Provider Management)
- Pull the audit dates forward. Ask the certification body for the earliest stage-one slot, even if the paperwork is 90% done; a found gap in October is better than a certificate in March. (CIS 15 Service Provider Management)
Where AccuSights fits
Our assessment maps your current controls to ISO 27001 and, through the same mapping, to ADHICS, DESC ISR and the IA Standard where they apply to you, so one gap list serves the tender and the regulator. The read-only compliance agent then keeps the evidence honest between audits: read-only insight into where the gaps are, so you prioritise and keep an eye on them. We have no access to your systems and we do not remediate; you or your IT partner fix, we show you where.
Questions people ask
How long does ISO 27001 take for a small company? For a 20 to 30 person firm with decent IT hygiene, plan on six to nine months from gap assessment to certificate: two to three months to build the management system and close gaps, a month or two of running it so there is evidence, then the two-stage certification audit. The slow part is never the auditor; it is the firm deciding who owns risk, access reviews and vendor checks. Start those decisions in week one.
Is ISO 27001 legally required in the UAE? No law requires it. What requires it is the buyer: government and semi-government tenders increasingly list a current certificate as a prequalification criterion, and large private customers borrow the same language. So it is contractually required for the work you want, which in practice is the same thing as required. Check each tender's wording; some accept equivalents, most now do not.
Which certification body is accepted for tenders? Tenders usually ask for a certificate from a certification body accredited by a recognised accreditation body, meaning one that belongs to the international accreditation network. Ask the body for its accreditation certificate and scope before you sign, and check that the scope on your certificate matches the service you are bidding, because a certificate scoped to the wrong office or product can be rejected at prequalification.
The competitor did not have better software. It had document seven. Get yours before spring, scoped to the work you want, and let the demo do the rest.
Questions people ask
How long does ISO 27001 take for a small company?
For a 20 to 30 person firm with decent IT hygiene, plan on six to nine months from gap assessment to certificate: two to three months to build the management system and close gaps, a month or two of running it so there is evidence, then the two-stage certification audit. The slow part is never the auditor; it is the firm deciding who owns risk, access reviews and vendor checks. Start those decisions in week one.
Is ISO 27001 legally required in the UAE?
No law requires it. What requires it is the buyer: government and semi-government tenders increasingly list a current certificate as a prequalification criterion, and large private customers borrow the same language. So it is contractually required for the work you want, which in practice is the same thing as required. Check each tender's wording; some accept equivalents, most now do not.
Which certification body is accepted for tenders?
Tenders usually ask for a certificate from a certification body accredited by a recognised accreditation body, meaning one that belongs to the international accreditation network. Ask the body for its accreditation certificate and scope before you sign, and check that the scope on your certificate matches the service you are bidding, because a certificate scoped to the wrong office or product can be rejected at prequalification.
Controls this post maps to
CIS Controls v8.1, the baseline the UAE IA Standard and ADHICS build on. These are the same controls our assessment scores.
Sources
Sam Khan, Founder and CEO. CISA and CRISC. More than two decades in financial services security and risk, from the Federal Reserve System to Guggenheim. Reads the week in threats so an owner does not have to. About the team →
Keep reading
Three more from the same shelf.
CBUAE Cyber Rules for Fintechs and the Suppliers Who Serve Banks
CBUAE cybersecurity framework explained for a small fintech or bank supplier: which regulations reach you, why the bank's questionnaire exists, and what to fix.
UAE complianceDIFC, ADGM or Federal PDPL: Which Data Rules Apply to Your Free-Zone Company
DIFC Data Protection Law, ADGM regulations or federal PDPL: how to tell which one governs your data, what changes at the free-zone boundary, and what to fix.
Reputation and business riskThe Enterprise Security Questionnaire: How to Answer 212 Questions Without Lying or Losing the Deal
How to answer a security questionnaire from a big customer without lying or losing the deal: the 212-question workbook, what 'yes' commits you to, a method.
