Gulf Cooperation Council

External attack surface management for Qatari organisations

Qatar has put a clock on external exposure. The NCSA’s National Vulnerability Management Guidelines, approved in January 2026, place critical vulnerabilities on external-facing assets in a 3 to 7 day remediation window. That only works if you know which assets face the internet. EASMLens tells you, continuously.

Serving organisations in Doha, Lusail.

What the rules in Qatar expect

National Vulnerability Management Guidelines

The NCSA approved the National Vulnerability Management Guidelines v1.0 in January 2026 for public and private organisations that operate critical infrastructure or national systems. Adoption is strongly encouraged. They call for a comprehensive, automated and live asset inventory including cloud instances (6.1), scanning frequencies by asset type (6.2), assessment of national advisories (6.3) and a reference SLA matrix (6.5).

The matrix puts critical vulnerabilities on external-facing assets, zero-days and actively exploited flaws in a 3 to 7 day remediation window, with high risks at 14 to 30 days. The first step is knowing which of your assets are external-facing. That is what EASMLens measures.

National Information Assurance Standard

NIAS version 2.1 has applied since May 2023. Its baseline controls require critical incidents to be reported to the NCSA within two hours (IM 8), SPF on email (NS 30), internet gateways that deny all services unless enabled (NS 25), and continued accountability for outsourced services (TM 1).

Qatar Central Bank: technology risks

The QCB Technology Risks Regulation requires banks to keep a detailed asset inventory (5.1.4), digitally sign DNS zone files (9.1.5.1), use SPF and DKIM (9.1.7.1, 9.4.4.2), run vulnerability assessments at least twice a year and two penetration tests a year (9.4.3), and report critical incidents within one hour (8.2.10). Clause 9.4.4.1 goes further than most regulators: banks must protect their domains against lookalike registrations and procure a domain monitoring service that flags deceptive registrations.

Personal data

Under the PDPPL (Law 13 of 2016), the NCSA’s breach notification guideline requires notice to the regulator and affected individuals within 72 hours where a breach may cause serious damage. Failure to notify can cost up to QAR 1,000,000 per violation.

What each rule asks for, and what EASMLens shows you

RuleWhat it asks forWhat EASMLens shows you
NCSA VM Guidelines 6.53 to 7 day remediation for critical vulnerabilities on external-facing assetsWhich of your assets are external-facing, so they enter the fastest tier
NCSA VM Guidelines 6.1Automated, live asset inventory including cloudInternet-facing assets and cloud endpoints discovered continuously
QCB 9.4.4.1Protect domains against lookalikes; buy domain monitoringYour domain estate and email posture, the baseline for lookalike monitoring
QCB 9.1.5.1, 9.1.7.1Signed DNS zones; SPF and DKIMDNSSEC, SPF, DKIM and DMARC status for every domain
NIAS NS 25Internet gateway denies services unless enabledServices answering on the internet that should not be

Reporting clocks

  • QCB-regulated banks

    Critical incidents within 1 hour of identification

  • NIAS entities

    Critical incidents to the NCSA within 2 hours

  • PDPPL controllers

    72 hours to the regulator and affected individuals where serious damage is possible

Questions for the board

  1. 1NCSA guidance puts external-facing assets in a 3 to 7 day fix window. Do we know which of our assets are external-facing, and are we meeting that window?
  2. 2For banks: do we have the domain monitoring service QCB 9.4.4.1 requires, and does it cover every domain our customers rely on?
  3. 3Could we report a critical incident to the NCSA within 2 hours if it started on a system nobody had on the inventory?

How EASMLens supports these obligations

  • Continuous identification of external-facing assets for the NCSA remediation tiers
  • Exposure intelligence on known vulnerabilities and actively exploited flaws
  • DNSSEC, SPF, DKIM and DMARC grading to support QCB domain and email controls
  • Detection of services exposed to the internet that the gateway policy should block
The NCSA runs accreditation for audit, advisory and penetration testing providers, and said in 2024 that it planned to license cybersecurity service providers. EASMLens is a software platform with automated vulnerability checks; it does not provide audit or penetration testing services. We will review the position if general provider licensing is introduced.

EASMLens discovers your attack surface from DNS, certificate transparency, internet-wide scan datasets and public records, then runs non-destructive checks against the assets in your scope. It never attempts exploitation. It provides discovery, monitoring and evidence. It does not certify an organisation against any framework, and no product can.

Frequently asked questions

Are the NCSA Vulnerability Management Guidelines mandatory?
They are guidelines whose adoption is strongly encouraged for organisations running critical infrastructure or national systems. Treat the SLA matrix as the NCSA’s stated expectation.
Does EASMLens provide domain monitoring for QCB 9.4.4.1?
EASMLens inventories your domains and grades their email and DNS security. Tell us how you meet 9.4.4.1 today and we will show where EASMLens fits alongside a lookalike monitoring service.
Does EASMLens scan our systems?
Yes, lightly. EASMLens discovers your estate passively from DNS, certificate transparency and internet-wide datasets, then runs non-destructive active checks, such as service detection and web server checks, against the assets in your scope. It never attempts to exploit a vulnerability, and it is not a penetration test.

Related guides

Primary sources

Regulatory content reviewed on . General information only, not legal advice.