We are exhibiting at GISEC Global 2026 · 16-18 Sept · Expo City DubaiBook a booth session with our CEO
AccuSights
Products
Assess
Comply
Protect
Free Tools
Email Breach Checker
Cyber Hygiene Test
Regulator directory
Regulatory calendar
ADHICS
ADGM
CBUAE
CSC
DFSA
DHA
DHCC
DIFC
DOH
FSRA
NIAF
Malaffi
MOHAP
NABIDH
NCAP
SCA
VARA
Healthcare
Finance
AI & Machine Learning
Defence & Military
Government Contractor
Professional Services
Technology & SaaS
Retail & Hospitality
Real Estate & Construction
Architecture, Design & Construction
Cybersecurity in Dubai
Cybersecurity in Abu Dhabi
Cybersecurity in Sharjah
All emirates
Chambers of Commerce
MSP
Partner Program
About Us
Why AccuSights
Compliance Center
Blog
Threat Dashboard
Threat Headlines
Contact

Blog / UAE compliance

UAE compliance

UAE IA Standard v2 and NCAP: What "Accredited" Means and Who Has to Care

UAE Information Assurance Standard v2 and NCAP accreditation, explained for a supplier to critical infrastructure: what changed in 2026 and what to do now.

Sam KhanSam Khan The Cyber MonkFounder and CEO2 September 2026 · 6 min read

The utility's letter uses a word the integrator has not seen before

The general manager of a 35-person industrial-controls integrator in Mussafah has serviced the same water utility for eleven years. His engineers know the pumping stations by nickname. The relationship is good enough that the renewal usually arrives as a phone call.

This year it arrives as a letter. The utility's new head of cyber has rewritten the supplier terms. Two requirements stand out. The integrator must operate an "IA-aligned control set" for any system that touches the utility's operational network, and any security testing of those systems must be performed by an "NCAP-accredited testing partner."

The general manager has heard of NESA. He has never heard of NCAP. He calls the penetration testing company that has done the utility work for the last four years, a good firm, and asks if they are accredited. They say they have applied. He asks when they will hear. They do not know, because nobody has published a timeline.

He calls the utility's head of cyber, who is helpful and firm. The control set is non-negotiable; the utility is being assessed against the IA Standard and cannot carry a supplier who is not. On the testing partner, she says the programme is new and she will accept an accredited firm when one is available, but the integrator should show it has asked.

He has a control set of sorts: a firewall between the office and the engineering laptops, a shared VPN account for remote support, and a laptop that has not been patched since it was configured for a site visit in 2023. That laptop plugs into the pumping station's network twice a month.

What the heck does this mean

The UAE Information Assurance Standard is the national baseline for protecting information and systems. It began under NESA, the National Electronic Security Authority, and now sits with the UAE Cyber Security Council. Version 2 was updated in 2025.

Critical information infrastructure: the systems whose failure would hurt the country, such as water, power, transport, health and telecoms. The utility is one; the integrator's laptop is on its network.

Management controls: the policy, governance, risk and people requirements. Sixty of them.

Technical controls: the requirements on networks, access, patching, logging and testing. One hundred and twenty-eight.

NCAP: the National Cyber Accreditation Program, run by the Cyber Security Council, built on IA Standard v2. It accredits the providers who are allowed to deliver security services to critical infrastructure.

Accredited provider: a security firm the Council has checked and listed for a defined scope of work. As of September 2026 there is no public register and no published deadlines, so the letter from the utility is ahead of the paperwork.

Active defence: the phrase from the National Cybersecurity Strategy 2025-2031 for the shift from building capacity to going after threats. It is why utilities are tightening supplier terms now.

For a supplier, the meaning is simple. If your engineers touch a critical network, your controls are part of the operator's controls, and the operator will be assessed on them.

The numbers that matter

IA Standard v2 was updated in 2025 and covers 188 controls, 60 management and 128 technical, according to the UAE Cyber Security Council's 2025 publication. The management controls are where most small suppliers are weakest, because nobody has written anything down.

The NCAP rollout during 2026 restricts unaccredited providers from serving critical information infrastructure, per the UAE Cyber Security Council's 2026 programme announcements. The programme is live in principle and still filling in its lists in practice, which is why the utility's letter and the testing firm's application are both in limbo.

The National Cybersecurity Strategy 2025-2031 shifts the country's posture from capacity building to active defence, according to the UAE Cyber Security Council's 2025 strategy. Supplier terms like the one in the letter are the strategy arriving in a small company's inbox.

What to do this week

  1. Separate the networks. Engineering laptops that visit customer sites get their own segment, away from office email and the shared drive, and the site-visit laptop never joins the office Wi-Fi again. (CIS 12 Network Infrastructure Management)
  2. Kill the shared VPN account. One named account per engineer, MFA on each, and a log of who connected to which customer site and when. The utility will ask for that log. (CIS 12 Network Infrastructure Management)
  3. Patch the field laptops and the remote-access gateway this week, then put them on a schedule: critical fixes within days, everything else monthly, with a record of what was done. (CIS 7 Continuous Vulnerability Management)
  4. Run a vulnerability scan across every device that touches a customer network and file the results with the fixes, dated, so the control set has evidence rather than intentions. (CIS 7 Continuous Vulnerability Management)
  5. Write to the testing firm and to the Council asking about accreditation status and scope, and keep the correspondence; the utility said it wants to see that you asked. Book the next penetration test for after the answer. (CIS 18 Penetration Testing)
  6. Map what you already do to the 188 controls on one spreadsheet, truthfully, with "none" where there is nothing. A truthful 40% is a plan; a fictional 100% is a problem waiting for an assessor. (CIS 7 Continuous Vulnerability Management)

Where AccuSights fits

Our assessment maps your controls against IA Standard v2 and the terms your critical-infrastructure customer has set, and ranks the gaps so the engineers fix what the operator will be assessed on first. The read-only compliance agent then keeps that map current: read-only insight into where the gaps are, so you prioritise and keep an eye on them. We have no access to your systems and we do not remediate; you or your IT partner fix, we show you where. A falcon sees the whole plain and strikes one point. That is what a control set should do for you.

Questions people ask

Is NESA compliance mandatory for private companies? The IA Standard is mandatory for government entities and for operators of critical information infrastructure, and it reaches private companies through those operators. If you supply, integrate or maintain systems for a utility, an airport, a hospital group or a telecom, expect the operator to require alignment in the contract. A private company with no such customers is not bound by it, though the standard is still a sound baseline.

What is the difference between the IA Standard and ISO 27001? ISO 27001 is an international management-system standard you can be certified against by an accredited body anywhere in the world. The IA Standard is the UAE's own control set, with 188 controls split between management and technical, written for the national context and now the base for NCAP. They overlap heavily; an ISO 27001 programme gets you a long way, but the IA Standard adds controls and evidence expectations the certificate alone does not prove.

How do I check if a provider is NCAP accredited? As of September 2026 there is no public register and no published deadlines, because the programme is still rolling out. Ask the provider for its accreditation letter or scope document from the UAE Cyber Security Council, check that the scope covers the service you are buying, and confirm with the Council if the contract depends on it. A provider that says it is accredited but cannot show the paper is not accredited yet.

Eleven years of trust got the integrator the phone call. A patched laptop and a named VPN account will get him the next eleven.

Questions people ask

Is NESA compliance mandatory for private companies?

The IA Standard is mandatory for government entities and for operators of critical information infrastructure, and it reaches private companies through those operators. If you supply, integrate or maintain systems for a utility, an airport, a hospital group or a telecom, expect the operator to require alignment in the contract. A private company with no such customers is not bound by it, though the standard is still a sound baseline.

What is the difference between the IA Standard and ISO 27001?

ISO 27001 is an international management-system standard you can be certified against by an accredited body anywhere in the world. The IA Standard is the UAE's own control set, with 188 controls split between management and technical, written for the national context and now the base for NCAP. They overlap heavily; an ISO 27001 programme gets you a long way, but the IA Standard adds controls and evidence expectations the certificate alone does not prove.

How do I check if a provider is NCAP accredited?

As of September 2026 there is no public register and no published deadlines, because the programme is still rolling out. Ask the provider for its accreditation letter or scope document from the UAE Cyber Security Council, check that the scope covers the service you are buying, and confirm with the Council if the contract depends on it. A provider that says it is accredited but cannot show the paper is not accredited yet.

Controls this post maps to

CIS 12 Network Infrastructure ManagementCIS 7 Continuous Vulnerability ManagementCIS 18 Penetration Testing

CIS Controls v8.1, the baseline the UAE IA Standard and ADHICS build on. These are the same controls our assessment scores.

Sam Khan, Founder and CEO. CISA and CRISC. More than two decades in financial services security and risk, from the Federal Reserve System to Guggenheim. Reads the week in threats so an owner does not have to. About the team →

Where AccuSights fits

Check, then repeat. We provide read-only insight so you prioritize the right things and keep an eye on them.

We have no access and do not remediate. You or your IT partner fix; we show you where, mapped to your regulators. Thirty minutes with an engineer draws the map for your organization.

Compliance is not security. The audit is not the exam; the attacker is.