Blog / UAE compliance

UAE compliance

NCAP: What National Accreditation Changes for Anyone Selling Cybersecurity to UAE Government and Critical Sectors

NCAP is the Cyber Security Council's accreditation programme for cybersecurity providers. What it is built on, what is not published yet, and how to prepare.

Sam KhanSam Khan The Cyber ExpertFounder and CEO21 September 2026 · 6 min read

The tender question nobody on the team could answer

The founder of a 25-person security services company in Dubai Silicon Oasis is finishing a tender response on a Sunday night. His team does vulnerability testing and incident work for a handful of semi-government entities and two banks. Good people, ten years of work, references that pick up the phone.

Section 4, question 3: does the bidder hold national accreditation for the delivery of cybersecurity services in the UAE, and if so, provide the reference number.

He calls two friends who bid on the same work. One says he ticked "in progress". The other left it blank and lost on a technicality he still does not understand. Nobody can point him at a register to check. He types "in progress", which is what everyone types, and sits with the feeling that a market he built a business in has started asking a question he cannot answer.

He is not behind. The question arrived before the answer did. What he can control is whether he is ready on the day the answer exists, or scrambling for six months with a tender he cannot bid on.

What the heck is NCAP

NCAP is the national accreditation programme run by the UAE Cyber Security Council, built on the UAE Information Assurance Standard v2 published in 2025. Its subject is providers: the companies selling cybersecurity services into government and the sectors the country treats as critical.

Accreditation: a national body deciding that a provider meets a defined standard for the services it delivers, as opposed to a certificate a provider buys from a commercial auditor.

The UAE Information Assurance Standard v2 (2025): the control catalogue the programme sits on, organized into management and technical families covering governance, asset handling, access, operations, incident work and third parties.

Critical sectors: the parts of the economy where an outage or a leak affects more than the customer. Energy, health, finance, transport, government services and telecoms sit in that group in most national schemes.

Two things are worth saying plainly. There is no public register of accredited providers yet, and no published deadlines. Anyone selling you urgency around a date is inventing it. Buyers, though, have already started asking, and the control work behind the question is identical whether the scheme names you next year or the year after.

The numbers that matter

Third parties were involved in 48 percent of breaches in the Verizon 2026 Data Breach Investigations Report, up 60 percent year on year. That single figure is why national accreditation programmes exist at all. A provider with privileged access to twenty client networks is the most efficient target in the market, and every regulator in the region can read that report as easily as you can.

Credential abuse accounted for 13 percent of breaches in the same Verizon 2026 report. For a services company that number lands somewhere specific: the shared admin account your engineers use at three client sites, the jump box with a password from 2021, the ex-employee whose VPN certificate was never revoked.

The Center for Internet Security's Community Defense Model v2.0 found that Implementation Group 1, a set of 56 safeguards, defends against 77 percent of attack techniques. The IA Standard is longer and more formal, but the overlap with those 56 is heavy. Doing the basics properly is not preparation for accreditation on top of security work. It is the same work, written down.

What to do this week

  1. Read the NCAP page and then the IA Standard v2 control families themselves, and mark each family green, amber or red for your own company. Two hours with a printout tells you more than any consultant's readiness deck. (CIS 15 Service Provider Management)
  2. Kill shared administrative accounts across your client estate. Every engineer works under a named identity with a second factor, and privileged access is requested and time-bound rather than standing. This is the finding that ends more provider assessments than any other. (CIS 6 Access Control Management)
  3. Turn on and retain logs for every action your team takes inside a client environment, with at least twelve months of retention and one person who reviews them monthly. If you cannot show who connected to which client at 02:00 last March, you cannot be accredited and you should not want to be. (CIS 8 Audit Log Management)
  4. Build the evidence pack now: your own asset inventory, your access review records, your incident procedure with the last exercise date, your subcontractor list and what each one can reach. Every scheme asks for a version of this, and it takes weeks to assemble the first time. (CIS 15 Service Provider Management)
  5. Run the Obligations Finder for your own entity, not just for your clients. Providers carry PDPL duties as processors, and plenty of security companies have never written down which of their client contracts make them one. (CIS 15 Service Provider Management)
  6. Answer the tender question plainly and then attach what you do have: the standard you align to, the controls in place, the audit dates. Buyers respect a mapped answer more than a tick in a box they cannot verify either. (CIS 8 Audit Log Management)

Where AccuSights fits

Our assessment maps your company against the regulators and standards that apply to you as a provider, including the IA Standard families NCAP is built on, and ranks the gaps so your engineers know what to close first. The read-only compliance agent then gives you continuing insight into access, assets and evidence, so you can prioritise and keep an eye on the picture between formal reviews. We have no access to your systems and we do not remediate. You or your IT partner fix; we show you where.

Questions people ask

Is NCAP accreditation mandatory today? The Cyber Security Council runs the programme and it is built on the UAE Information Assurance Standard v2 (2025), but there is no public register and no published deadlines yet. Nobody can point you at a date that binds you today. What is already happening is that tender documents ask about national accreditation, and buyers make their own decisions with or without a rulebook.

What is NCAP actually built on? The UAE Information Assurance Standard v2, published in 2025 by the Cyber Security Council. If you want to prepare in a way that will not be wasted, that document is where to start, because the control families it defines are the same ones any national scheme would test you against.

We already hold ISO 27001. Does that count? It counts as evidence, not as a substitute. An ISO certificate proves you run a management system and were audited against it. A national scheme asks a narrower question about the services you deliver into UAE government and critical sectors, who delivers them, and how you handle your customers' data. Map your existing controls to the IA Standard families and you will see where the two overlap and where they do not.

Every accreditation scheme eventually asks the same question: would you hire yourself. Answer it on paper this quarter, and the official version will be a formality.

Questions people ask

Is NCAP accreditation mandatory today?

The Cyber Security Council runs the programme and it is built on the UAE Information Assurance Standard v2 (2025), but there is no public register and no published deadlines yet. Nobody can point you at a date that binds you today. What is already happening is that tender documents ask about national accreditation, and buyers make their own decisions with or without a rulebook.

What is NCAP actually built on?

The UAE Information Assurance Standard v2, published in 2025 by the Cyber Security Council. If you want to prepare in a way that will not be wasted, that document is where to start, because the control families it defines are the same ones any national scheme would test you against.

We already hold ISO 27001. Does that count?

It counts as evidence, not as a substitute. An ISO certificate proves you run a management system and were audited against it. A national scheme asks a narrower question about the services you deliver into UAE government and critical sectors, who delivers them, and how you handle your customers' data. Map your existing controls to the IA Standard families and you will see where the two overlap and where they do not.

Controls this post maps to

CIS 15 Service Provider ManagementCIS 6 Access Control ManagementCIS 8 Audit Log Management

CIS Controls v8.1, the baseline the UAE IA Standard and ADHICS build on. These are the same controls our assessment scores.

Sam Khan, Founder and CEO. CISA and CRISC. More than two decades in financial services security and risk, from the Federal Reserve System to Guggenheim. Reads the week in threats so an owner does not have to. About the team →

Where AccuSights fits

Check, then repeat. We provide read-only insight so you prioritize the right things and keep an eye on them.

We have no access and do not remediate. You or your IT partner fix; we show you where, mapped to your regulators. Thirty minutes with your Risk Assessor draws the map for your organization.

Compliance is not security. The audit is not the exam; the attacker is.