Who is in scope
Dubai government entities and the cloud and service providers that hold or process their data.
DESC
Dubai’s cyber authority. Its ISR v3 standard and CSP certification are mandatory for cloud and service providers that serve Dubai government, with data-residency requirements.
Dubai government entities and the cloud and service providers that hold or process their data.
As the ISR prescribes for the entity; suppliers report through their government client.
Information Security Regulation (ISR) v3 and the Cloud Service Provider Security Standard, with certification and data-residency requirements.
If you host or process their data, expect the CSP standard and ISR alignment to be a condition of the contract. Starting from an ISO 27001 base makes the gap manageable.
Summary for orientation, with attribution to the regulator, last checked September 2026. The regulator's own publications govern; consult them and your advisers for decisions. Where this page and the instrument differ, follow the instrument and tell us, so we can fix it.
A note on authority: the regulator, auditor or certifying body has the final say on whether you comply. Much regulator language is still being clarified, and we say so rather than guess. We help interpret the requirements, scope what applies to you, gap-assess against what is published today, and keep you compliance-ready and secure as the guidance evolves. We hold no regulatory authority and do not certify; where a regulator has its own process, that process governs.
Book a demo
Tell us your sector and we will show you which UAE regulations apply to you, where the gaps are, and how one control set covers them all.