Who is in scope
Telecom licensees, digital government entities, and critical sectors under the UAE Information Assurance regulation and standard.
TDRA / aeCERT
Regulates telecom and digital government; operates aeCERT, the national computer emergency response team, and the UAE Information Assurance standard for critical sectors.
Telecom licensees, digital government entities, and critical sectors under the UAE Information Assurance regulation and standard.
Incident reporting to aeCERT for licensees and designated entities.
UAE Information Assurance Regulation and the UAE IA Standard (now v2, maintained with the Cyber Security Council); IoT regulatory policy; aeCERT as the national CERT.
The standard many still search for as “NESA” is the UAE Information Assurance Standard, now in version 2 under the Cyber Security Council with TDRA. Same lineage, current name UAE IA.
Summary for orientation, with attribution to the regulator, last checked September 2026. The regulator's own publications govern; consult them and your advisers for decisions. Where this page and the instrument differ, follow the instrument and tell us, so we can fix it.
A note on authority: the regulator, auditor or certifying body has the final say on whether you comply. Much regulator language is still being clarified, and we say so rather than guess. We help interpret the requirements, scope what applies to you, gap-assess against what is published today, and keep you compliance-ready and secure as the guidance evolves. We hold no regulatory authority and do not certify; where a regulator has its own process, that process governs.
Book a demo
Tell us your sector and we will show you which UAE regulations apply to you, where the gaps are, and how one control set covers them all.