AppSec Audit Review

Regulatory guide

UAE Cybersecurity Compliance Guide for Web Applications

Which of several overlapping frameworks actually applies to a web application handling UAE user data, processing payments, or serving a regulated sector — and where independent security testing fits into satisfying each one.

By Dana Sarraf, Security Research Editor · last reviewed September 2026

Which Framework Actually Applies to You

This guide covers the frameworks relevant to web application security specifically. It is not a full legal compliance overview, but it is enough to work out which regime governs your situation and what kind of evidence it expects.

Most UAE companies are in scope for more than one at once, and the frameworks were not designed to dovetail. Three questions settle most of it: does the application touch cardholder data, does it touch personal data of people in the UAE, and does it serve a Dubai government entity or a licensed financial institution. Each "yes" adds a regime with its own vocabulary for the same underlying work.

DESC and Dubai's Cyber Force Programme

The Dubai Electronic Security Center sets cybersecurity requirements for government and government-adjacent entities operating in Dubai. Its Cyber Force programme, run jointly with CREST, is the recognized benchmark for penetration testing providers working in the emirate.

For companies in scope, engaging a DESC-aligned provider is typically a prerequisite for accepted testing — and the alignment has to be verified rather than taken from the vendor's own website. The programme distinguishes between a company registered under it and an individual holding a CREST certification who happens to work somewhere, which is a distinction that matters when a public-sector buyer asks for an approved supplier. This is why the accreditation column on our comparison table reports which of those two states each firm is in.

NESA and the Information Assurance Standard

The National Electronic Security Authority's Information Assurance standard applies primarily to critical infrastructure and government-related entities across the UAE. It sets baseline security controls, including requirements around security testing of systems in scope — web applications handling critical services fall under this where applicable.

Practically, IAS is a control-set regime rather than a testing regime: it tells you which controls must exist and be operating, and testing is one of the ways you evidence that they do. That makes an audit against the control set, rather than a standalone penetration test, the natural shape of the deliverable — with testing inside it.

UAE Personal Data Protection Law

The UAE Personal Data Protection Law sets requirements for how personal data is collected, processed and protected, applying broadly across sectors rather than to one industry. For a web application this means the application itself — anywhere it collects, stores or transmits personal data — is in scope for appropriate technical safeguards.

The PDPL does not name penetration testing as a required deliverable. What it requires is that safeguards appropriate to the risk are in place, which puts the burden on you to show how you established that they are. An independent test of the application's access control and data handling is the most direct evidence available, and it is considerably easier to produce before an incident than after one.

Central Bank of the UAE

Financial institutions regulated by the Central Bank of the UAE face additional, sector-specific cybersecurity requirements beyond the general frameworks above, often including mandated periodic testing of customer-facing applications.

Fintech companies and payment platforms should confirm CBUAE-specific requirements directly rather than assuming a general PDPL or ISO 27001 posture is sufficient. The gap between "we have an information security management system" and "we test this specific customer-facing application on the cadence our regulator specifies" is exactly where supervisory findings land.

PCI DSS

For any application processing card payments, PCI DSS applies regardless of where the company is headquartered. The PCI Security Standards Council explicitly distinguishes between vulnerability scanning and penetration testing, requiring the latter for certain in-scope systems — and requiring the former, quarterly, from an Approved Scanning Vendor.

These are two separate requirements met by two separate deliverables. Substituting one for the other is the single most common and most expensive mistake in this area; the audit versus penetration test comparison explains why the distinction exists at all.

ISO/IEC 27001

ISO 27001 certifies an organization's information security management system as a whole, rather than testing a specific application. It is frequently requested alongside — not instead of — a penetration test: the certification demonstrates management practices, while the test demonstrates that a specific application actually withstands attack.

Worth noting for vendor selection: a testing firm's own ISO 27001 certification says something about how that firm handles your data during an engagement. It says nothing about its testing competency. Buyers routinely read it as the latter, and it is not.

Where the Frameworks Overlap

The same web application test can serve several regimes at once, provided the report is scoped and written with that in mind from the start. It is much cheaper to specify this at scoping than to re-run testing per framework.

Framework Who is in scope What it expects for a web application
DESC / Cyber Force Dubai government, semi-government and critical information infrastructure Testing performed by a provider approved under the programme
NESA / IAS UAE critical infrastructure and government-related entities Control set evidenced, with security testing as one form of evidence
UAE PDPL Any organization processing personal data Technical safeguards appropriate to the risk, and a basis for saying so
CBUAE Licensed banks, payment providers and financial institutions Sector-specific requirements, often periodic testing of customer-facing systems
PCI DSS Anyone storing, processing or transmitting cardholder data Quarterly ASV scanning and periodic penetration testing, as separate requirements
ISO/IEC 27001 Voluntary, commonly required by enterprise customers A certified management system; testing supports it but is not the certification

Scope determinations here are summaries, not legal advice. Confirm applicability for your entity with your own counsel or your regulator before relying on it.

Where Independent Testing Fits

None of the frameworks above is satisfied by a development team asserting that security was considered during the build. Each expects independent, third-party validation. The difference between them is mainly in what kind of validation: a broad audit against a named standard, specific penetration testing evidence, or both.

Two practical points follow. First, confirm which applies before engaging a vendor, because it decides the deliverable you are buying and the accreditation the supplier needs. Second, ask for the report format in advance: the same testing effort can produce a document that maps onto your control set or one that does not, and that is a scoping decision rather than a quality difference. The NIST Cybersecurity Framework is a useful neutral vocabulary for mapping one report across several regimes when your obligations overlap.

Choosing a Provider for UAE Compliance

Not every firm offering "penetration testing" understands the documentation format a UAE regulator or auditor expects. When shortlisting, ask directly whether the firm has delivered reports accepted by the specific regulator or standard you are working toward — and whether the accreditation it claims is registered to the company or held by individual staff.

Check the claim yourself rather than accepting the marketing page: the CREST register is searchable, and accreditation status changes more often than websites are updated. That check is exactly what produced the accreditation column in our ranking, and it is why several firms there are recorded as not listed.

Ten firms, one framework

Every accreditation claim in the ranking was checked against the register it came from, and each firm's UAE presence is stated rather than implied.

Compare the firms Audit vs pentest