Framework · Last verified

UAE Information Assurance Regulation

The UAE IA Regulation sets minimum information-security controls that TDRA-designated critical entities must implement and demonstrate compliance with. TDRA designates which entities must comply, based on the UAE's Critical Information Infrastructure Protection Policy; the current text is Version 1.1, published March 2020.

Class
Framework
Owner
Telecommunications and Digital Government Regulatory Authority (TDRA)
Last verified

What it is

The regulation's own purpose statement: "The purpose of the UAE IA Regulation is to provide requirements to raise the minimum level of protection of information assets and supporting systems across all implementing entities in the UAE, as outlined in Section 2.1."

The document describes its own role directly: "this document serves as the national UAE IA Regulation that implementing entities have to demonstrate compliance with."

Scope is delegated to the regulator, not universal: "TRA will designate the critical entities, as per the UAE CIIP Policy, mandated to implement the UAE IA Regulation and apply its requirements to the use, processing, storage, and transmission of information or data, and the systems and processes used for those purposes."

Compliance has two tiers of controls: "Controls that are 'Always Applicable' – these security controls are essential and shall be implemented by any entity wishing to claim compliance with the UAE IA Regulation. Omission of any of these controls is not acceptable and constitutes non-conformity." A second, risk-assessed set is added on top: "The overall set of security controls that are 'Always Applicable' and those security controls that have been determined as being applicable based on the risk assessment are 'mandatory' for the entity to implement, and will be the basis of the compliance monitoring scheme."

Who owns it

The Regulation was issued under the Telecommunications Regulatory Authority (TRA) brand on its cover page (Version 1.1, March 2020); the authority was later renamed the Telecommunications and Digital Government Regulatory Authority (TDRA), the entity that hosts the current document.

Who asks for it

Statutory (scoped). The mandate is not general: the source text designates critical entities under the UAE Critical Information Infrastructure Protection (CIIP) Policy as the group required to implement the Regulation, not all UAE organizations.

Sources

Last verified:

This page is for information only; it does not accredit, certify or endorse any organisation. Requirements and programs change — always confirm against the primary source linked above.

Cite this page

Attributing this record helps other researchers verify it independently.

"UAE Information Assurance Regulation." Certifidex, FutureTechnologies. Last verified 1 September 2026. https://certifidex.com/frameworks/uae-ia-regulation

All frameworks & audits →