Back to Frameworks
Frameworks

UAE Information Assurance Regulation (United Arab Emirates)

Framework Name

UAE Information Assurance Regulation (IAR), Version 1.1

Type

Mandatory for entities designated as Critical Information Infrastructure; voluntary, though strongly encouraged, for all other UAE sectors

Region / Jurisdiction

United Arab Emirates

Enforcing Body / Certifying Party

Telecommunications and Digital Government Regulatory Authority (TDRA), overseen by the UAE Signals Intelligence Agency (SIA), formerly known as the National Electronic Security Authority (NESA). Compliance is typically demonstrated through Information Security Management System audits, which can be satisfied through ISO 27001 certification or IAR-specific assessment

Penalty / Consequence of Non-Compliance

No explicit published fine schedule, unlike the UAE's PDPL. Consequences instead include increased regulatory scrutiny, mandatory and often costly audits, imposed corrective action plans, and in serious cases, suspension of operations for entities handling critical information

What It Is & Why It Matters

The UAE IA Regulation, first issued in 2014 and currently in its 1.1 version from 2020, sets management and technical security controls aimed at raising the baseline level of information assurance across UAE entities, with particular focus on those operating critical information infrastructure. It's structured around two categories: management controls, covering things like business continuity, incident response, risk management, and asset management, and technical controls addressing the actual security mechanisms protecting systems and data. It takes a deliberately risk-based approach, requiring entities to identify, assess, and prioritize the controls that address their highest risks first, rather than applying a single fixed checklist.

It matters because it's a foundational piece of the UAE's National Cyber Security Strategy, aimed at establishing a consistent security baseline across critical sectors, telecommunications, government services, and other essential infrastructure, rather than leaving cybersecurity maturity to vary unpredictably by organization. Its structure and control families are deliberately built to align with international frameworks like ISO 27001 and NIST CSF, both of which we've covered elsewhere on this list, meaning an organization already certified against ISO 27001 has a genuine head start toward IAR compliance rather than starting from scratch.

Who Needs It

  • You operate Critical Information Infrastructure in the UAE and are legally required to implement IAR's management and technical controls
  • You are a UAE government entity or a business in a sector TDRA has designated as critical
  • You already hold ISO 27001 certification and want to understand how much of that work carries over toward IAR compliance
  • You're a cloud or infrastructure provider, like AWS, needing to maintain an independent third-party IAR attestation for UAE customers
Book A Demo