Thank you
Our team of industry domain experts combined with our guaranteed SLAs, our world class technology .
Get Immediate Help
The Dubai Information Security Regulation, issued by the Dubai Electronic Security Center, sets the mandatory minimum information security requirements for Dubai Government entities and their suppliers. The current version, ISR V3, organises requirements into 13 domains across three classes: Governance, Operation, and Assurance. This guide explains who falls in scope, how the domains are structured, and how ISR compares to ISO 27001 and NESA for entities holding more than one certification.
Understanding this structure first makes the rest of this guide, and any certification conversation with DESC, considerably easier to follow.
Dubai maintains its own regulation alongside the federal NESA framework because Dubai Government entities carry risk and operational context that a purely federal standard does not fully address, and because DESC needs direct authority to update requirements at the pace of Dubai's digital transformation programme. Our cyber security companies in Dubai guide covers the broader provider landscape entities can draw on when building an ISR compliance programme.
ISR presents minimum control requirements, and Dubai Government entities are expected to conduct their own applicability review against the regulation's domains and controls, implementing a "right-fit" set of controls proportionate to risk and to the value of the information being protected rather than defaulting to blanket implementation regardless of context.
| Entity type | In scope | Obligation level | How it usually arises |
| Dubai Government entities | Yes | Full ISR compliance | Direct regulatory obligation |
| Semi-government entities | Yes | Full ISR compliance, scoped per entity structure | Direct regulatory obligation |
| Employees, consultants, and contractors | Yes | Bound by the regulation while engaged with government entities | Contractual and employment terms |
| Cloud service providers serving Dubai Government | Yes | DESC CSP Security Standard, layered on ISR and international standards | Certification required before onboarding as an approved CSP |
| Suppliers and contractors to in-scope entities | Yes, indirectly | Obligations flow down through contract | Procurement and vendor agreements |
Suppliers to Dubai Government entities are the group most often surprised by their own ISR exposure, since a private company selling into government does not automatically think of itself as bound by a government information security regulation until the obligation arrives through a procurement contract. Confirming scope position early, before a tender rather than during one, avoids a difficult scramble later.
Entities pursuing NESA alignment or ISO 27001 certification will recognise most of this structure directly, since domains like Access Control, Incident and Problem Management, and Business Continuity Planning map closely to equivalent control areas in both frameworks. The dedicated Cloud Security domain and the emphasis on assurance and performance assessment as a distinct domain, rather than folded into general audit, are the two areas where ISR's structure diverges most from its international counterparts.
The most notable change requires the information security function to be led by a UAE National serving as CISO, reporting directly to Top Management, a governance accountability requirement with no equivalent in NESA or ISO 27001. V3 also formalised new mandated roles beyond the CISO position, specifically Information Security Champions, Internal Auditors, and a defined Incident Response Team, each with roles and responsibilities set out directly in the regulation. On data residency, V3 prevents storing or processing critical government information outside the UAE, explicitly extending to cloud services, which entities already using or evaluating cloud infrastructure must weigh directly against their architecture.
Realistic timelines depend heavily on existing maturity, following the same pattern seen across other UAE compliance frameworks: an entity with an existing ISO 27001 or NESA programme typically moves through ISR gap closure considerably faster than one building a security programme from nothing, since the underlying control work substantially overlaps. Our cyber security audit cost guide covers UAE audit pricing more broadly, including the factors that move cost for a regulatory-standard-specific audit like this one.
| Area | ISO 27001 | NESA / UAE IAS | DESC ISR |
| Governance and policy | Annex A governance controls | Management controls domain | Domain 1, with the added UAE National CISO requirement |
| Risk management | Annex A risk-related controls | Risk management domain | Domain 3, closely aligned in substance |
| Access control | Dedicated Annex A domain | Dedicated technical domain | Domain 5, closely aligned in substance |
| Incident management | Annex A incident controls | Incident management domain | Domain 4, closely aligned in substance |
| Supplier assurance | Annex A supplier relationship controls | Covered within broader domains | Addressed through Domain 2 and contractual flow-down |
| Audit and assurance | Internal audit requirement | Audit and compliance obligations | Domains 11 and 12, with Assurance treated as its own domain |
| Cloud security | Addressed generally, not as a dedicated domain | Addressed generally | Domain 13, a dedicated domain with residency restrictions |
An entity already holding NESA compliance alignment or ISO 27001 certification carries genuine efficiency into ISR, particularly across governance, risk, access control, and incident management, where the underlying control substance is closely comparable even though the specific documentation and evidence format ISR expects differs from either.
Preparing before a tender, rather than scrambling once a procurement requirement surfaces mid-process, is the practical difference between winning a government contract smoothly and losing weeks to a compliance gap discovered too late. Our IT security audit guide covers the kind of readiness assessment a supplier can commission proactively to understand its own gap position before a tender response is due.
Our GRC overview covers how a governance function typically coordinates this kind of multi-framework compliance work in practice. This article provides general guidance on ISR's structure and requirements and does not constitute legal advice; the current ISR V3 standard, available directly from DESC, remains the authoritative source for any specific compliance decision.
Don’t Let Cyber Attacks Ruin Your Business
Call
UK: +44 (0)20 3336 7200
KSA: +966 1351 81844
UAE: +971 454 01252
Contents
To keep up with innovation in IT & OT security, subscribe to our newsletter
Recent Posts
Cyber Compliance | 16/09/2026
Cyber Compliance | 16/09/2026
Cyber Compliance | 16/09/2026
What does DESC stand for?
The Dubai Electronic Security Centre, the government body responsible for protecting information across Dubai's public sector.What is the Dubai Information Security Regulation?
DESC's mandatory minimum information security standard for Dubai Government entities, currently at Version 3.Who must comply with ISR?
Dubai Government and semi-government entities, and, through contract, their suppliers and contractors.Is ISR the same as NESA?
No. NESA is federal; ISR is Dubai-specific, though the two share substantial overlap in controls. See NESA compliance.Does ISO 27001 cover ISR requirements?
Partially. Governance, risk, and access control align closely; ISR's UAE National CISO and cloud residency rules do not appear in ISO 27001.How long does ISR certification take?
Timeline depends on existing maturity; entities with NESA or ISO 27001 already in place typically move faster.Do suppliers to the Dubai government need ISR compliance?
Yes, indirectly. Obligations typically flow down through the procurement contract rather than applying automatically.