External Attack Surface Management in the UAE: What Is Verified and What Is Not
We are going to be more careful about the UAE than most vendors are, because the honest position is that the public evidence base is thin, and several claims in circulation cannot be verified against any primary source.
Start with what changed
The UAE Cyber Security Council, established in November 2020, replaced NESA as the national authority. Marketing material that still refers to NESA as the regulator is out of date by more than five years.
The UAE Information Assurance Standard remains operative, but here is the difficulty: the control text is not publicly obtainable. The Cyber Security Council's policy pages do not serve the document. That has a practical consequence worth stating. Any vendor quoting specific IAS control identifiers to you should be asked where they obtained the standard, because those control references circulate widely and trace back to secondary blog content rather than to a published source.
Similarly, the frequently cited "UAE IA Standard v2 (2025), 15 families, 134 controls, 449 sub-controls" is asserted by numerous consultancies and confirmed by none of them against the Council's own site. We do not repeat it as fact.
Where IAS does bind, it binds by reference
The clearest verifiable path is financial services. The Central Bank of the UAE Rulebook, Article 13 of C 15/2021, in force since 6 June 2021, requires payment service providers to "apply and meet at a minimum the UAE Information Assurance Standards". Larger PSPs "shall regularly assess the necessity" of penetration testing covering networks both external and internal.
Note the wording. It is a risk-based obligation to assess necessity, not a mandated frequency. If you have been told the Central Bank requires annual external vulnerability scanning, that is an overstatement of Article 13.
Dubai and DESC
The Dubai Electronic Security Center's Information Security Regulation covers 13 domains and is mandatory for all Dubai Government entities, including their contractors. ISR v3.0 was announced at GISEC in April 2024, alongside the ASAAS audit automation platform.
The document is available only by email request, and as recently as March 2026 DESC's own cloud service provider standard still referenced "ISR:2017 v.02". Claims that ISR v3 mandates quarterly vulnerability assessment and annual external penetration testing appear in vendor marketing but not in any DESC source we could obtain. Treat them as unverified.
What is clear is that DESC certification for cloud service providers, data centres and SOC providers is mandatory for anyone serving Dubai Government, and contractors are explicitly in scope of ISR.
Abu Dhabi Global Market
The most concrete new UAE cyber obligation is the ADGM FSRA Cyber Risk Management Framework, issued 29 July 2025, with compliance required from 31 January 2026. If you are an ADGM-regulated firm, this is the instrument with a real date attached.
Data protection
The federal PDPL Executive Regulations had still not been issued as at March 2026, and the Emirates Data Office is not fully operational. Any citation of "Cabinet Decision 83/2022" or "111/2023" as PDPL implementing regulations should be treated with suspicion; we could find no such instrument.
The DIFC regime is separate and more mature. The applicable law is Data Protection Law No. 5 of 2020, not 2019 as often cited, with July 2025 amendments adding a private right of action.
Our honest assessment
No UAE instrument that we could verify mandates external attack surface monitoring or internet-facing asset discovery by name. That is a genuine finding, not a gap in our research.
What that means is that in the UAE the case for attack surface visibility is currently a risk case rather than a compliance case, with two exceptions: ADGM-regulated firms with a live February 2026 obligation, and any organisation contracting with Dubai Government under ISR.
We would rather tell you that than sell you a mandate that does not exist. If your driver is a specific contract or regulator requirement, send us the clause and we will tell you honestly whether attack surface monitoring addresses it.