If you are a UAE federal entity or a designated critical entity, the UAE Information Assurance Standard is mandatory and ISO 27001 is not. The IA texts oblige those entities to implement their controls, and the authority monitors compliance through self assessment reports it reviews and audits it can perform or commission. ISO/IEC 27001 is a voluntary international standard that ends in a certificate if you choose to be audited. The two overlap heavily: the IA texts name ISO/IEC 27001 among their sources and map their controls to it, so an ISO 27001 programme supplies much of what the IA asks for. But the IA Regulation calls itself "the sole point of reference for compliance against its requirements", it never mentions accepting a certificate, and it adds rules the standard does not have: a core of controls no risk assessment can remove, a priority order set by the authority, a written justification for every exclusion, and performance indicators you have to measure.
This guide compares the two from the primary texts: the UAE IA Regulation version 1.1 of March 2020, the UAE Information Assurance Standard that the UAE Cyber Security Council publishes today, in version 2.1 of November 2025, and ISO's own description of ISO/IEC 27001:2022. What each IA family asks for is in UAE IA requirements explained; how the ISO control set is built is in ISO 27001 Annex A explained.
| UAE IA | ISO 27001 | |
|---|---|---|
| What it is | A national control standard: the IA Regulation v1.1 (TDRA, March 2020), now the UAE IA Standard v2.1 (UAE Cyber Security Council, November 2025) | An international standard for an information security management system, ISO/IEC 27001:2022, published in October 2022 |
| Who must use it | v1.1: all UAE government entities and entities identified as critical; v2.1: Ministries and Federal Authorities and non government Critical Information Infrastructure entities | Nobody by law; organisations adopt it, or a customer or contract asks for it |
| Structure | 15 families, 6 management and 9 technical; v2.1 has 134 controls and 449 sub controls | Management system requirements in clauses 4 to 10, with 93 reference controls in Annex A |
| How controls are selected | A fixed always applicable core, plus the risk based controls your risk assessment selects | Your risk treatment selects the controls, recorded in a Statement of Applicability |
| How it is checked | Self assessment reports reviewed by the authority, which may perform or commission compliance audits and tests | Audit by an external certification body |
| What you receive | No certificate | A certificate, if the audit finds the system conforms |
What is the difference between UAE IA and ISO 27001?
One is a national control catalogue with a rule for selecting from it; the other is a management system standard. Both IA editions are organised into six management families, M1 to M6, from Strategy and Planning to Performance Evaluation and Improvement, and nine technical families, T1 to T9, from asset management to continuity. Every control carries sub controls that "specify mandatory implementation requirements" and a priority from P1 to P4, and the Standard supplies performance indicators to measure them.
ISO/IEC 27001:2022 asks you to run a management system: define its scope, assess and treat risk, set objectives, audit yourself internally and review the results at management level. Its Annex A is a reference list of 93 controls grouped under four headings, organizational, people, physical and technological, that you compare your risk treatment against. ISO's own page for the standard notes that it does not certify anyone: "Certification is performed by external certification bodies."
The practical difference is who decides the content. Under ISO 27001 your risk assessment decides which controls you need. Under the IA Standard part of that decision has already been made for you, and the authority, not a certification body, reviews whether you met it.
Which edition of each are you comparing?
This matters more than most comparisons admit, because the numbers changed on both sides. The IA Regulation v1.1 was published by the telecommunications regulator, now TDRA, and holds 188 controls by its own priority table: 39 at P1, 69 at P2, 35 at P3 and 45 at P4. The Standard the UAE Cyber Security Council publishes today, version 2.1, holds 134 controls and 449 sub controls in 15 families, 70 of them always applicable and 64 risk based. Version 1.1 names ISO/IEC 27001:2005 among the practices it is based on; version 2.1 references ISO/IEC 27001:2022 and maps its controls to the 2022 clauses in Annex D.
On the ISO side, ISO/IEC 27001:2022 was published on 25 October 2022, with Amendment 1 on climate action added in 2024. The accreditation rules in IAF MD 26 gave certified organisations until 31 October 2025 to transition, after which "all certifications based on ISO/IEC 27001:2013 shall expire or be withdrawn". A comparison built on the 2013 edition's 114 controls is comparing against a certificate nobody can hold any more.
Does an ISO 27001 certificate satisfy UAE IA?
No, and neither IA text says it does. Version 1.1 states that it "is meant to complement any existing information assurance programs at implementing entities" and that it "represents the sole point of reference for compliance against its requirements, as measured by the criteria associated with each of its security controls". Compliance is shown through the IA's own monitoring: the authority will "review entity compliance self-assessment reports" and, where appropriate, "perform or commission compliance audits for validating entity self-assessment reports". Version 2.1 keeps the same scheme with the Council in that role. Neither text contains a clause that treats a certificate as evidence of compliance.
What the certificate does give you is the machinery. A working ISO 27001 system already has a scope, a risk assessment and treatment plan, a Statement of Applicability, an internal audit programme and management review. Version 2.1 asks for every one of those inside its management families, down to a control named Management Review, M6.2.3. The work left is the IA structure on top: evidence filed per IA control, the always applicable set implemented in full, and the IA only rules below.

Where do UAE IA and ISO 27001 overlap?
In the management core and most of the technical estate. IA family M1 opens with understanding the entity and its context and leadership commitment, which is how ISO 27001 clauses 4 and 5 begin. M2 runs risk identification, treatment and a Statement of Applicability, which IA control M2.3.4 in version 1.1 compares against the IA's own risk based controls to verify "that no necessary controls have been omitted". M6 covers monitoring, internal audit, corrective action and continual improvement, the territory of ISO clauses 9 and 10. Asset management, physical security, operations, access control, supplier security, incident management and continuity appear in both.
That overlap is why the sensible order is one control set mapped to both rather than two programmes. The ISO work supplies the system; the IA work decides whether it contains everything the authority requires.
What does UAE IA require that ISO 27001 does not?
A core you cannot scope out. In ISO 27001 your own risk treatment decides which Annex A controls you need. The IA fixes part of the answer: always applicable controls "shall be implemented by any entity wishing to claim compliance", and "the omission of any of these controls is not acceptable and constitutes non-conformity". The same rule applies to every one of their sub controls.
Exclusions signed by a named person. For risk based controls, "any exclusion of these controls needs to be justified and evidence needs to be provided such that the associated risks have been accepted by accountable persons or authorizing entities". Version 1.1 adds the default that makes skipping the risk assessment expensive: without one, "all the security controls detailed in these are deemed applicable and therefore mandatory".
A priority order. Controls carry a priority from P1 to P4. Under version 1.1 a P1 control, if applicable, "may be augmented but never reduced".
Measured indicators. Version 1.1 requires entities to "use performance indicators to measure the quality and effectiveness of the implemented security controls". Version 2.1 lets entities "use the performance indicators specified in the controls, or alternatively, develop their own tailored indicators" to assess how effective the controls are.
Reporting to an authority. The IA is monitored through self assessment reports and, where the authority chooses, compliance audits and tests. ISO 27001 reports to nobody but your certification body and whoever you show the certificate to.
What do other comparisons get wrong?
Three errors recur. The first is the claim that always applicable controls apply "unless justified by the risk assessment". Both editions say the opposite: they apply regardless of the risk assessment, and omitting one is non-conformity.
The second is counting against the wrong editions: 188 IA controls against 114 ISO controls. Both figures are out of date. The Council's current Standard has 134 controls, and ISO 27001:2022 has 93. The label NESA is out of date as well; version 1.1 names TRA and version 2.1 names the Cyber Security Council.
The third is warnings of fines and executive arrest for non-compliance. Neither IA text contains a penalty provision; the enforcement it describes is self assessment, review, audit and testing. That does not mean other UAE laws carry no sanctions, but the figures quoted are not in the IA Standard. Dubai government entities should also note that the Dubai Electronic Security Center publishes a separate Information Security Regulation, "applicable to all Dubai Government Entities", which version 2.1 lists among its references.
How do you comply with both?
Keep one control set and two indexes. Confirm which IA edition your regulator holds you to, and whether an Emirate programme carries out the assessment, because version 2.1 says that where an Emirate CIIP Program exists, assessment and monitoring are carried out "by the respective Emirate Lead". Map each Annex A control to the IA control it supports. Implement the always applicable set in full, add the IA controls ISO never asked for, and record every risk based exclusion with a signed acceptance. Then answer the authority in its self assessment format and keep the certificate running for customers who ask for it. The neighbouring Saudi comparison, SAMA CSF vs ISO 27001, follows the same pattern.

Check your own position
Fill in the middle column. The first two rows decide how the rest are read.
| Question | Your answer | Why it matters |
|---|---|---|
| Are you a federal entity or a designated critical entity? | If not, the IA Standard is recommended, not mandated. | |
| Which IA edition does your regulator name? | Version 1.1 and version 2.1 differ in control count, numbering and the always applicable set. | |
| Is every always applicable control implemented, with all its sub controls? | Omission of any one is non-conformity, whatever your risk assessment says. | |
| Does every excluded risk based control have a signed risk acceptance? | An exclusion without evidence of accepted risk does not count. | |
| Do you measure an indicator for each family? | The IA expects measured effectiveness, not only controls in place. | |
| Is your ISO 27001 certificate on the 2022 edition? | 2013 certificates expired or were withdrawn at the end of October 2025. |
If most rows are blank, the free compliance check gives you a starting position. UAE IA in Venvera holds every control as a record with the always applicable set locked, the P1 to P4 order and ISO 27001 mapping, so the same evidence answers both. The UAE IA checklist is the free spreadsheet version, and budgets are in UAE IA compliance cost and ISO 27001 certification cost.
Frequently asked questions
Is UAE IA mandatory?
For government entities and entities designated as critical, yes. Version 1.1 recommends that all other UAE entities adopt it voluntarily.
Does ISO 27001 certification mean UAE IA compliance?
No. The IA texts are their own reference for compliance, measured by the IA's controls and checked through self assessment reports and authority audits. The certificate is strong supporting evidence for the overlapping controls.
Is UAE IA the same as NESA?
The name NESA is still widely used for these controls, but the current texts do not use it. Version 1.1 names TRA; version 2.1 is published by the UAE Cyber Security Council.
How many controls does UAE IA have?
Version 2.1 has 134 controls and 449 sub controls, 70 always applicable and 64 risk based. Version 1.1 had 188 controls.
Is there a UAE IA certificate?
Neither IA text provides one. Compliance is shown through self assessment and, where the authority chooses, compliance audits and tests.
Primary sources
IA provisions are quoted from the UAE Information Assurance Regulation, version 1.1 of March 2020, sections 1.1, 3.1, 3.3 and 3.4, chapter 4, the roles table in chapter 3 and Annex B, and from the UAE Information Assurance Standard, version 2.1 of November 2025, sections 1.2, 1.4 and 3.6 and Annex A. ISO facts are from ISO's ISO/IEC 27001:2022 page and IAF MD 26:2023. Confirm the edition your regulator applies before relying on a reference.





