NESA stands for the National Electronic Security Authority, the UAE body that originally issued the UAE Information Assurance (IA) Standard. The agency itself has since been reorganized — its cybersecurity-standard-setting role now sits within the UAE's federal cybersecurity apparatus rather than a body still called "NESA" — but the standard itself is very much alive, still widely referred to as the "NESA IA Standard," and was substantially updated in 2025.
A standard that outlived its original name
Public reporting on exactly where NESA's functions landed is genuinely inconsistent: some sources point to the Signals Intelligence Agency (SIA), others to the UAE Cybersecurity Council (established by Cabinet decision in November 2020), and others to the TDRA (Telecommunications and Digital Government Regulatory Authority) as the body that has historically administered the IA Regulation. The UAE's own government portal confirms the Cybersecurity Council exists and was formed in 2020 to lead national cybersecurity strategy, but doesn't spell out a clean line back to "NESA." The honest, practical takeaway: the exact current org chart isn't cleanly documented in one public source, so treat "NESA" going forward as shorthand for the standard, not a specific still-operating agency.
What the IA Standard actually requires
Version 1.1 (in force roughly 2014–2024) organized 188 controls, each priority-rated P1–P4, into 15 control families split across 6 Management domains and 9 Technical domains. Version 2.0, rolled out in 2025, restructured this into a far more granular 134 main controls and 449 sub-controls across 47 sub-families — a shift explicitly meant to add coverage for cloud, AI, IoT, and supply-chain risk that the original version didn't address.
Who actually has to comply
Compliance is mandatory for federal and Emirate-level government entities, critical infrastructure operators (energy, transport, finance, healthcare, telecom, defense), and semi-government entities. Version 2.0 expanded mandatory scope further to certain private-sector partners handling national or critical data — but it is not a blanket private-sector requirement the way a national data protection law is.
How it relates to ISO 27001
The IA Standard is explicitly designed to align with ISO/IEC 27001:2022's structure, so an organization that already runs an ISO-aligned Information Security Management System can map most of its existing controls across with less duplicated effort. This is a deliberate harmonization choice, not a formal ISO endorsement — the IA Standard remains its own distinct national standard.