NEWVenvera speaks your language: the full platform, in English, German, Spanish, Bulgarian and Arabic.See what’s new
What UAE IA Compliance Actually Costs
Learn

What UAE IA Compliance Actually Costs

·Alexander Sverdlov

There is no published price for UAE Information Assurance compliance, and any article quoting one is quoting itself. What the authority published is a Regulation, and the Regulation sets out the mandates that create the cost: a core of controls that no risk assessment can remove, a documented entity risk assessment that decides how much of the rest stays in scope, a rule that every exclusion has to be justified and evidenced, a priority order that starts at P1, and performance indicators that have to be measured rather than asserted.

So the honest way to budget is to price those mandates rather than hunt for a benchmark. Two implementing entities of identical size can differ by a factor of three, and almost all of the difference sits in one place: how much of the risk based control set their assessment leaves applicable, and how much evidence they already hold for it.

FactDetail
Source text used hereThe UAE Information Assurance Regulation, version 1.1 of March 2020, published by TDRA. The UAE Cyber Security Council publishes the Information Assurance Standard today, so confirm which version your regulator holds you to before you scope.
Who must implement itAll UAE government entities and other entities identified as critical, designated under the UAE Critical Information Infrastructure Protection Policy. Every other entity in the UAE is encouraged to adopt it voluntarily.
Default applicabilityBefore a risk assessment, every control is treated as applicable. In the absence of an entity risk assessment, all controls are deemed applicable and mandatory.
Always Applicable controlsA defined set that must be implemented regardless of risk assessment outcomes. Omission constitutes non conformity, and the same rule applies to all of their sub controls.
PrioritisationControls are grouped P1 to P4. Entities are required to begin with P1, and P1 may be augmented but never reduced, even where a risk assessment suggests otherwise.
ExclusionsAn entity may exclude a risk based control, but the exclusion needs justification and evidence that the associated risk has been accepted by an accountable person or authorising entity.
MeasurementPerformance indicators must be used to measure the quality and effectiveness of implemented controls. Deviating from the published indicators requires a reason and replacements.
The four mechanics of the UAE IA Regulation that create compliance cost: always applicable controls, P1 first sequencing, justified exclusions and recurring performance indicators

What does UAE IA compliance cost?

Not a number the Regulation supplies. The useful answer is a shape: a large first year driven by assessment and remediation, then a recurring annual figure that never goes to zero because compliance here is monitored rather than certified once.

The first year carries four lines. Scoping and the entity risk assessment, which is the cheapest line and the one that determines every other. Remediation, which is by far the largest and is almost entirely a function of how far your current controls sit from the requirement. Evidence and tooling, which looks like a one off and is not. Audit and reporting, which recurs.

Anyone who has budgeted for SAMA CSF compliance will recognise the pattern. Gulf regulators do not price frameworks; they mandate obligations and let the obligations price themselves.

The five step sequence that sets a UAE IA budget, from confirming you are an implementing entity through the risk assessment, always applicable controls and P1 gaps to performance measurement

Which requirements actually create the cost?

1. The Always Applicable core

Some controls represent foundational information assurance capabilities and are marked Always Applicable. These have to be implemented by every relevant entity regardless of its risk assessment outcomes, and omitting one constitutes non conformity to the Regulation. They are concentrated in the management families rather than the technical ones, which is why the first invoice is often governance work and not hardware: entity context, leadership commitment, roles and responsibilities, an information security policy and the supporting policies beneath it, resources, communication and documentation.

This is the part of the bill that is fixed. You cannot risk assess your way out of it, and it is where a small entity feels the Regulation most, because the governance overhead is nearly the same whether you run five systems or five hundred.

2. The risk assessment, and the price of excluding a control

Before you run a risk assessment, the Regulation treats every control as applicable to you. That default is the single most expensive sentence in the document, and it works in your favour only if you actually do the assessment: in the absence of one, all controls are deemed applicable and therefore mandatory.

Exclusion is allowed, but it is not free. An entity may exclude a control on the basis of the assessment, provided adequate justification is submitted to the authority, and any exclusion of a risk based control has to carry evidence that the associated risk has been accepted by an accountable person or authorising entity. Scoping work is therefore never a paperwork saving. It is a trade: you spend on the assessment and the acceptance record to avoid spending on the control.

3. Sub controls, not controls

Budgets get built against control counts and then blown apart by sub controls. Each control carries a set of sub controls that specify mandatory implementation requirements. Every sub control of an Always Applicable control has to be implemented, and omission of any of them is non conformity. For risk based controls a sub control may be skipped or implemented differently, but only with justification and evidence of accepted risk.

If you are estimating effort, estimate at sub control level. A control that reads like a single line of policy can carry a handful of separate implementation requirements underneath it.

4. Performance indicators

The Regulation attaches performance indicators to control families and sub families, and entities have to use them to measure the quality and effectiveness of what they implemented. You may deviate, but then you have to give a reason and specify the replacements. That turns compliance into a measurement programme with an annual cost rather than a project with an end date.

Relative effort across UAE IA budget lines, showing remediation as the largest line against risk assessment, evidence and tooling, and annual audit and reporting

Why the recurring number is the real one

Compliance under this Regulation is defined as the comparison between the requirements and the actual state of implementation inside an entity, measured control by control and overall. The authority runs a compliance monitoring scheme, set out in the national information assurance governance, that gives it visibility of that state over time.

Read that as a budgeting instruction. There is no certificate that closes the file for three years. Your applicable control set moves when your systems move, every exclusion has to keep its justification current, and every performance indicator has to keep producing a number. Firms that treat the first year as the cost and the following years as maintenance consistently under budget the following years by the largest margin.

A recurring UAE IA compliance view showing always applicable controls met, risk based controls in scope, exclusions carrying evidence and P1 controls still open

What does an ISO 27001 ISMS take off the bill?

A useful amount, because the Regulation was not written from scratch. Its controls draw on ISO/IEC 27001, 27002, 27005, 27010 and 27032, on NIST Special Publication 800-53, and on the Abu Dhabi information security standards. If you already run a certified ISMS, the risk assessment machinery, the policy set, the asset inventory, the access control regime and the supplier controls are largely reusable as evidence.

What does not transfer is the shape of the obligation. ISO 27001 lets you scope by declaring a scope. This Regulation starts from all controls applicable and makes you argue each exclusion down, with the Always Applicable set outside the argument entirely. Budget for translation work, not for a copy. Our guide to ISO 27001 covers where the underlying evidence overlaps.

What the other results get wrong

Three things recur across the published guidance.

The first is quoting a control count as though it were a cost driver. It is not. The driver is how many controls survive your risk assessment and how many sub controls sit beneath each one. Two entities working from the same document can end up with applicable sets that differ by half.

The second is treating the risk assessment as optional scoping. It is the mechanism that decides your bill, and skipping it does not save money, it makes every control mandatory by default.

The third is pricing a project rather than a programme. Performance indicators and the compliance monitoring scheme are recurring obligations. A budget with no year two line is not a UAE IA budget.

Size your own UAE IA budget

Fill this in for your own entity. Any row you cannot answer is a line you have not yet costed.

QuestionYour answerWhy it drives the cost
Have you been designated as a critical entity, or are you adopting voluntarily?Designation makes implementation obligatory rather than commercial, which changes the deadline and the audit exposure.
Do you have a current, documented entity risk assessment?Without one, every control in the Regulation is applicable and mandatory.
How many risk based controls does your assessment leave applicable?This is the number your remediation budget is actually a function of.
Can you evidence acceptance of risk for every control you excluded?An exclusion without an accountable acceptance record is a finding, not a saving.
Are all P1 controls closed, and closed first?P1 may be augmented but never reduced, so it is the one part of the sequence you cannot reorder.
Who produces your performance indicator numbers each year?If the answer is nobody, your year two budget is missing.

If you want a baseline before committing to a plan, the UAE IA compliance checklist walks the control families, UAE IA compliance software compares the platforms that hold them, and a free compliance check tells you which of the six rows above you are going to struggle with.

The bottom line on UAE IA compliance cost: the recurring number is the real one because the Regulation is measured rather than certified once

Frequently asked questions

Does the UAE IA Regulation state a compliance cost?

No. It sets requirements and a compliance monitoring approach. Every figure you find published is an estimate from an implementer, including ours, and should be treated as one.

Can we reduce cost by excluding controls?

Only within limits, and never for free. Always Applicable controls cannot be excluded at all, and omission is non conformity. Risk based controls can be excluded on the basis of the assessment, with justification submitted to the authority and evidence that an accountable person accepted the risk.

Do we have to implement every sub control?

Every sub control of an Always Applicable control, yes. For controls that are applicable because of your risk assessment, a sub control may be skipped or implemented differently if that is appropriately justified and the risk acceptance is evidenced.

Why does the Regulation insist on P1 first?

Because prioritisation is designed for phased implementation against the most common threats. Entities may promote or demote the suggested priority of controls based on their risk assessment, with the exception of P1, which may be augmented but never reduced.

Does ISO 27001 certification make us compliant?

No, but it lowers the cost. The Regulation draws on the ISO 27000 series and NIST SP 800-53, so much of the underlying evidence is reusable. The applicability rules, the Always Applicable set and the performance indicators are specific to this Regulation and have to be met on their own terms. Our UAE IA framework page sets out how the two sit together.

Primary sources

Applicability, prioritisation, sub control and compliance rules above are taken from the UAE Information Assurance Regulation, version 1.1, March 2020 published by TDRA, chapters 3 to 5, and from the UAE Cyber Security Council pages on the Information Assurance Standard. Cost shapes and relative effort are Venvera planning estimates from implementation work, not figures from the Regulation. Confirm the version of the Standard your regulator applies before scoping.

Alexander Sverdlov

Alexander Sverdlov

CEO & Founder

Alexander is the founder of Venvera and a 20+ year veteran of European cybersecurity and compliance. He has led security and risk programmes for regulated financial institutions, fintechs and SaaS companies operating under DORA, NIS2, GDPR, ISO 27001 and the EU AI Act. Before Venvera, he founded Atlant Security, an offensive security consultancy that ran penetration tests, red-team exercises and ISO 27001 readiness programmes for clients across the EU and the Middle East. He writes on the cross-framework realities of running modern compliance: how to map one control to many obligations, where the spreadsheets fall apart, and what regulators are actually asking for once the auditor sits down.

More articles by Alexander

CONTINUE READING