In the UAE, security testing is not a nice-to-have — it is written into the rules. Federal standards, Dubai’s own regulator, the central bank and the data-protection law all expect organisations to test their defences and fix what they find. This guide explains which regulations apply to you, how often you need to test, and what kind of testing satisfies them.
Which UAE regulations require testing?
The obligation depends on your sector. Most organisations fall under at least one of these. For a side-by-side, see NESA vs DESC vs CBUAE.
- NESA / UAE IA StandardsThe federal Information Assurance Standards apply to government entities and critical-infrastructure operators. They expect regular vulnerability assessments and penetration testing as part of a managed security programme.Typically at least annually + after major changes
- DESC — Dubai Electronic Security CenterThe Information Security Regulation (ISR) applies to Dubai government entities and the suppliers that serve them. It expects independent testing and evidence that findings are remediated.Regular, independent testing expected
- CBUAEThe Central Bank’s frameworks cover banks, finance companies, exchange houses and payment providers, with clear expectations around vulnerability management and penetration testing.Risk-based, often more than annually
- TDRATelecom and digital service providers fall under the Telecommunications and Digital Government Regulatory Authority, which sets security-assurance expectations for the services they run.Ongoing assurance
- UAE PDPLThe Personal Data Protection Law requires appropriate technical measures to protect personal data. Independent testing such as VAPT is how organisations show those measures actually work.Demonstrable, effective measures
What kind of testing meets these requirements?
Different obligations call for different depth. Here is where each Rootsec service fits. Still deciding? Compare red teaming vs penetration testing.
- Vulnerability Assessment & Penetration Testing (VAPT)The workhorse of UAE compliance: combined scanning and hands-on exploitation, with a report written to stand up to a NESA, DESC or CBUAE audit.Best starting point for most regulatorsLearn more →
- Penetration TestingManual, expert-led testing of a specific application, network or cloud environment when you need depth on one target.Application & infrastructure focusLearn more →
- Red Team OperationsFull-scope adversary simulation across people, process and technology — the answer to “would our defences actually hold?”, and a strong fit for mature CBUAE and DESC programmes.Whole-organisation assuranceLearn more →
What determines the cost of VAPT?
There is no flat rate — and anyone who quotes one before scoping your environment is guessing. The price is driven by: See our full guide to penetration testing & VAPT cost in the UAE.
- Scope & sizeHow many applications, IP ranges, user roles and cloud environments are in scope. A single web app is a very different job from a full external and internal estate.
- Depth of testingA vulnerability assessment is lighter than a full penetration test; a red team is deeper again. The regulator and your risk appetite decide how deep you need to go.
- Retesting & evidenceWhether you need a retest after remediation, and audit-ready reporting for NESA / DESC / CBUAE, adds assurance — and time.
- UrgencyA deadline-driven engagement for a client questionnaire or an audit date is scoped differently from planned annual testing.
Frequently asked questions
Does NESA require penetration testing?
Yes. The UAE Information Assurance Standards that NESA oversees expect federal entities and critical-infrastructure operators to run regular vulnerability assessments and penetration testing, typically at least annually and after significant system changes, as part of a managed security programme.
How often do I need to perform VAPT in the UAE?
It depends on your regulator and your risk profile, but an annual test plus testing after any major change is the common baseline for NESA and DESC. CBUAE-regulated financial institutions often test more frequently, on a risk-based schedule.
Does DESC require independent security testing?
DESC’s Information Security Regulation expects Dubai government entities and their suppliers to undergo regular, independent testing and to demonstrate that findings have been remediated. Independent means tested by a party other than the team that built or runs the system.
Is penetration testing mandatory under the UAE PDPL?
The PDPL does not name a specific test, but it requires appropriate technical measures to protect personal data. Independent testing such as VAPT is the practical way organisations demonstrate those measures are in place and effective.
How much does VAPT cost in the UAE?
There is no fixed price. Cost is driven by scope (how many applications, IPs and users), the depth of testing, whether retesting and audit-ready reporting are included, and how time-critical the work is. We scope your environment first, then give you a clear, fixed picture — book a free call to start.