Thank you
Our team of industry domain experts combined with our guaranteed SLAs, our world class technology .
Get Immediate Help
The UAE Information Assurance Regulation, administered through the UAE Information Assurance Standard, organises its requirements into 15 control families: six Management families and nine Technical families. Version 2, effective from September 2025, rebased the standard onto ISO 27001:2022 and introduced explicit priority tagging for every control. This checklist works through the confirmed family structure and gives a practical starting point for self-assessment before a formal gap assessment.
Working through the checklist family by family gives a more usable picture than treating individual controls in isolation.
This checklist works through the standard's 15 control families, giving a practitioner a structured way to self-assess before committing budget to a formal engagement. It is not exhaustive, and it does not replace the judgement of a qualified compliance professional or the authority of the published standard.
Every control within these 15 families carries a priority tag, P1 through P4, with P1 controls mandatory regardless of risk assessment outcome and P2 through P4 applied based on an entity's specific risk profile. This priority tiering, not the family structure alone, is what actually determines implementation order for most organisations.
| Control area | What you must have in place | Evidence auditors expect | Your rating |
| Information Security Strategy (M1-P1) | A senior-leadership-approved strategy aligning security investment with business objectives | Signed, dated strategy document with leadership sign-off | |
| Strategic alignment review | Periodic review confirming the strategy still reflects current business priorities | Review records showing update cadence |
A strategy document that exists but was never formally approved by senior leadership is a common gap: the content may be sound, but the accountability chain the standard requires is missing.
| Control area | What you must have in place | Evidence auditors expect | Your rating |
| Risk Management Framework (M2-P1) | A documented, repeatable process for identifying, analysing, and treating risk | Framework document plus evidence of actual application | |
| Live risk register | A risk register updated as the environment changes, not a static annual document | Dated risk register entries showing periodic reassessment |
Treating the risk register as a document produced once for an audit, rather than a living record updated after infrastructure changes or new deployments, is the most common gap in this family in practice.
| Control area | What you must have in place | Evidence auditors expect | Your rating |
| Security Awareness Training (M3-P1) | Mandatory training for all personnel, documented and tracked | Training completion records and attendance logs | |
| Role-specific awareness | Additional awareness content for higher-risk roles | Role-mapped training records |
Generic, one-size-fits-all training that satisfies the letter of the requirement but does not reflect actual role-based risk tends to draw scrutiny during assessment. Our vulnerability assessment service covers the technical side of the risk picture this training is meant to support.
| Control area | What you must have in place | Evidence auditors expect | Your rating |
| Asset inventory (T1-P1) | A comprehensive hardware and software asset inventory | Current, centrally accessible inventory | |
| Data classification (T1.2) | Data classified according to criticality, with appropriate rigour for higher classifications | Classification records and labelling evidence | |
| Access control hygiene | No orphaned accounts, privileged access reviewed regularly, MFA enforced for remote access | Access review records and MFA configuration evidence |
Orphaned accounts belonging to former staff or contractors, and privileged accounts reviewed only annually rather than quarterly, are consistently among the most frequently identified gaps in this family across UAE assessments.
| Control area | What you must have in place | Evidence auditors expect | Your rating |
| Critical patch SLA (T5-P1) | A documented service level for applying critical patches | Patch deployment records against the stated SLA | |
| Patch completion tracking | Recorded completion dates and documented exceptions where patches are delayed | Patch logs showing dates and exception justifications |
The absence of a documented SLA for critical patches, with patches applied ad hoc and no recorded completion evidence, is one of the most consistently identified P1 gaps in practice.
| Control area | What you must have in place | Evidence auditors expect | Your rating |
| Incident response plan (T6-P1) | A documented, exercised incident response plan | Records of tabletop exercises or live incident drills | |
| Incident log | A maintained log of security incidents, however minor | A current, dated incident log |
An incident response plan that exists but has never been exercised, alongside no maintained incident log, is a recurring finding at exactly the family the standard treats as mandatory. Our enterprise penetration testing guide and incident response guide both cover the technical work that typically feeds this family's evidence base.
| Area | ISO 27001 Annex A | UAE IAR |
| Governance | Organisational controls | M1: Strategy and Planning |
| Risk management | Risk assessment and treatment | M2: Information Security Risk Management |
| Asset management | Asset management controls | T1: Information Asset Management |
| Access control | Dedicated Annex A domain | Embedded within T1 and related technical families |
| Incident management | Incident management controls | T6: Incident Management |
| Business continuity | Business continuity controls | T9: Information Systems Continuity Management |
| Supplier security | Supplier relationship controls | Addressed within the Technical family set (T7/T8 area) |
An organisation already holding ISO 27001 certification carries genuine efficiency into NESA alignment specifically because Version 2 deliberately rebased onto the current ISO 27001:2022 control structure, narrowing the gap between the two frameworks considerably compared to the earlier version of the standard.
This article provides general guidance on the UAE Information Assurance Standard's structure and does not constitute legal or compliance advice; the current published standard remains the authoritative source for any specific compliance decision.
Don’t Let Cyber Attacks Ruin Your Business
Call
UK: +44 (0)20 3336 7200
KSA: +966 1351 81844
UAE: +971 454 01252
Contents
To keep up with innovation in IT & OT security, subscribe to our newsletter
Recent Posts
Cyber Compliance | 16/09/2026
Cyber Compliance | 16/09/2026
Cyber Compliance | 16/09/2026
What does NESA IAR stand for?
The UAE Information Assurance Regulation, historically associated with the National Electronic Security Authority (NESA).Who must comply with the UAE Information Assurance Regulation?
Federal and local government entities, semi-government bodies, and critical information infrastructure operators. See NESA compliance.How many controls does the IAR contain?
The prior version held 188 controls across 15 families; Version 2 restructured the framework with explicit priority tagging per control.What is control prioritisation in the IAR?
Every control carries a P1 (mandatory) to P4 (risk-based) tag, determining implementation sequence.Does ISO 27001 cover NESA requirements?
Substantial overlap exists, especially since Version 2 was rebased onto ISO 27001:2022. See ISO 27001 certification.What evidence do NESA assessors ask for?
Dated, verifiable records tied to each control: policies, training logs, patch records, and incident documentation.How often is a NESA assessment required?
Cadence varies by entity designation; P1 controls in particular expect ongoing, not one-time, evidence.