xmodoxmodo

Frameworks · Middle East

UAE IA Standard 2.1

The UAE Information Assurance Standard Version 2.1 is the national baseline of information security controls. The UAE Cyber Security Council issued it in November 2025. It replaces the UAE Information Assurance Regulation of 2020 and the earlier NESA standards. It binds government entities, critical information infrastructure operators and the suppliers in their scope.

Who it applies to

Federal and local government entities, operators of critical information infrastructure in every sector, and the service providers and suppliers those entities bring into scope. Organisations still assessed against the 2020 Information Assurance Regulation Version 1.1 run that edition alongside 2.1 until their assessor moves.

Main requirements

Governance

Information assurance governance, roles, risk management and compliance reporting to the Council.

Protection

Asset, access, cryptography, network, cloud and emerging-technology controls, applied according to the entity's classification.

Detection & response

Monitoring, incident management and national incident reporting duties.

Assurance

Audit, business continuity and supplier controls, with evidence kept on a schedule the assessor can inspect.

How xmodo supports it

  • 1

    Version 2.1 is set up with each of its requirements, including owners, evidence requirements and a calculated compliance status. Control families and counts come from the Council's published instrument and appear in the framework details panel.

  • 2

    The 2020 Regulation and Standard 2.1 run as separate editions. The version manager shows what changed and carries over evidence that still applies.

  • 3

    Mapping from ISO/IEC 27001:2022 and NIST CSF 2.0 shows your existing coverage before you plan any tasks.

  • 4

    National incident reporting duties run in the incident workflow, with timestamps from detection to notification.

Related frameworks

UAE IA Standard 2.1 shares requirements with the frameworks below. Controls you already run for any of them count towards UAE IA Standard 2.1 as well.

Frequently asked questions

Is this the NESA standard?

It started as the NESA standard. The control set began as the NESA Information Assurance Standards and was published as the UAE Information Assurance Regulation Version 1.1 in 2020. It is now the UAE Information Assurance Standard Version 2.1, issued by the UAE Cyber Security Council in November 2025. xmodo uses the current title and keeps NESA and IAR as alternative names, so your assessor and your team find the same page.

How does the Standard overlap with ISO 27001?

The overlap is substantial. Equivalent controls are mapped, so an existing ISO 27001 programme already meets a large share of the Standard. The remaining requirements appear as a gap list with owners.

Can a group run UAE IA 2.1 beside DESC ISR 3.1?

Yes. Both use the same control library. A Dubai Government entity in scope for both implements a shared control once and reports to each instrument separately.

Do you publish control counts for 2.1?

Yes, in the product. The counts come from the Council's instrument and appear in the framework details panel. We do not quote them in marketing material, because secondary summaries of the Standard give different figures and assessors work from the instrument.

See how xmodo works for your organisation

Get a demo on the frameworks that apply to you.

Get a demo