What Is NESA?

NESA stands for the National Electronic Security Authority, the UAE body that originally issued the UAE Information Assurance (IA) Standard. The agency itself has since been reorganized — its cybersecurity-standard-setting role now sits within the UAE's federal cybersecurity apparatus rather than a body still called "NESA" — but the standard itself is very much alive, still widely referred to as the "NESA IA Standard," and was substantially updated in 2025.

A standard that outlived its original name

Public reporting on exactly where NESA's functions landed is genuinely inconsistent: some sources point to the Signals Intelligence Agency (SIA), others to the UAE Cybersecurity Council (established by Cabinet decision in November 2020), and others to the TDRA (Telecommunications and Digital Government Regulatory Authority) as the body that has historically administered the IA Regulation. The UAE's own government portal confirms the Cybersecurity Council exists and was formed in 2020 to lead national cybersecurity strategy, but doesn't spell out a clean line back to "NESA." The honest, practical takeaway: the exact current org chart isn't cleanly documented in one public source, so treat "NESA" going forward as shorthand for the standard, not a specific still-operating agency.

What the IA Standard actually requires

Version 1.1 (in force roughly 2014–2024) organized 188 controls, each priority-rated P1–P4, into 15 control families split across 6 Management domains and 9 Technical domains. Version 2.0, rolled out in 2025, restructured this into a far more granular 134 main controls and 449 sub-controls across 47 sub-families — a shift explicitly meant to add coverage for cloud, AI, IoT, and supply-chain risk that the original version didn't address.

Who actually has to comply

Compliance is mandatory for federal and Emirate-level government entities, critical infrastructure operators (energy, transport, finance, healthcare, telecom, defense), and semi-government entities. Version 2.0 expanded mandatory scope further to certain private-sector partners handling national or critical data — but it is not a blanket private-sector requirement the way a national data protection law is.

How it relates to ISO 27001

The IA Standard is explicitly designed to align with ISO/IEC 27001:2022's structure, so an organization that already runs an ISO-aligned Information Security Management System can map most of its existing controls across with less duplicated effort. This is a deliberate harmonization choice, not a formal ISO endorsement — the IA Standard remains its own distinct national standard.

Common Questions

Is NESA still an active UAE government agency?

Not under that name. Public sources describe its standard-setting function as reorganized into the UAE's federal cybersecurity apparatus around 2020, though the exact chain of authority isn't cleanly documented in one place. "NESA" now functions mainly as shorthand for the IA Standard itself, not an active agency.

What changed between IA Standard V1.1 and V2.0?

V2.0 (2025) restructured the standard from 188 controls across 15 families into a much more granular 134 main controls and 449 sub-controls across 47 sub-families, adding explicit coverage for cloud, AI, IoT, and supply-chain risks that V1.1 didn't address.

Do private UAE companies need to comply with the IA Standard?

Not as a blanket requirement. It's mandatory for federal and local government entities, critical infrastructure operators, and semi-government bodies; V2.0 expanded mandatory scope to certain private-sector partners handling national or critical data, but it isn't a general private-sector law the way GDPR or a PDPL is.

Working across multiple regional frameworks?

Practice mapping controls across standards in the GRC Track in CX Challenges, or get a personalized roadmap through 1:1 GRC mentorship.

Keep Reading

What Is ISO 27001?

The international standard the IA Standard is deliberately aligned with.

What Is GDPR?

The EU's data protection law, and the model many newer regional laws draw from.