UAE IA Standard · UAE
UAE awareness programmes,
evidenced control by control.
The UAE Information Assurance Standard v2.1, published by the UAE Cybersecurity Council in November 2025, requires federal entities and critical information infrastructure entities to maintain an awareness and training programme, evaluate its effectiveness and keep records of awareness campaigns.
- Framework
- UAE Information Assurance Standard v2.1, UAE Cybersecurity Council, November 2025
- Applies to
- Ministries, federal authorities and critical information infrastructure entities
- Where awareness fits
- M3.2.1 awareness and training programme; M3.4.1 awareness campaigns
- KeenSec evidence
- Simulation results, report logs, training certificates, policy acknowledgements
UAE rules on staff awareness
Three regulators,
one awareness record.
Scope differs: the IA Standard covers federal and critical entities, DESC covers Dubai Government entities, and CBUAE covers licensed financial institutions.
| Rule | What it says | Applies to |
|---|---|---|
| IA Standard v2.1, M3.2.1 | Develop, approve and maintain an awareness and training programme, and evaluate the effectiveness of the actions taken. | Federal and critical entities, always applicable |
| IA Standard v2.1, M3.4.1 | Plan and conduct security awareness campaigns, and keep comprehensive records of them. | Federal and critical entities, based on risk |
| DESC ISR v3.1, 1.4.1 to 1.4.5 | An awareness programme throughout the year, training for new users and periodic surveys to measure training effectiveness. | Dubai Government entities |
| CBUAE Operational Risk Management Regulation, 5.8 | Senior management must make sure staff receive regular and appropriate training. | Licensed financial institutions, from 14 September 2026 |
| CBUAE Operational Risk Management Regulation, 15.2 and 15.3 | Notify the Central Bank within 4 hours of events affecting critical operations, and within 72 hours of high-risk incidents. | Licensed financial institutions |
Lures that feel local
Couriers, utilities
and government services.
Delivery fees, utility bills and government-service notices reach people on SMS and WhatsApp as often as email.
“Courier desk” · unknown number
Parcel on hold
Your parcel is held at customs. Pay the clearance fee today to release it: parcel-release.example
- Unknown number
- Small fee, urgent deadline
Expectation to record
The awareness record
auditors can follow.
Staff tested across channels.
Outcomes per channel, team and campaign.
Staff report suspicious messages.
Phishing Reporter logs with automated analysis.
Staff complete awareness training.
LMS completions and certificates.
Staff accept your policies.
Dated records per person and version.
KeenSec helps you produce evidence for your awareness obligations: simulation results, report logs, training completions and certificates, and policy acknowledgements. Your auditor decides compliance.
This page is general information, not legal advice. KeenSec helps you produce evidence for your awareness obligations; your auditor or regulator decides whether you are compliant.
Primary sources
What this page is based on.
Checked on the regulator’s own website on 24 September 2026. Read the original before you rely on it.
- UAE Information Assurance Standard v2.1November 2025 · UAE Cybersecurity Council
- CBUAE Operational Risk Management Regulation (C 1/2026)In force 14 September 2026 · replaces Circular 163/2018
- CBUAE Consumer Protection Standards, Article 6Employee training on data controls, annual fraud awareness campaigns
- DESC standards and policies, including the Information Security RegulationDubai Government entities · ISR version 3.1
- Federal Decree-Law No. 45 of 2021 on Personal Data ProtectionIn force 2 January 2022 · executive regulations pending
Questions buyers ask
Frequently asked questions.
Does any UAE framework require phishing simulation?
No UAE framework we reviewed names it. The IA Standard asks you to evaluate the effectiveness of awareness actions, and DESC asks for periodic surveys to measure training effectiveness. Simulations are a practical way to do both.
Is the IA Standard the same as NESA?
It is the successor. The regulation once known as NESA became the UAE Information Assurance Regulation, and the UAE Cybersecurity Council now publishes the Information Assurance Standard v2.1.
Does KeenSec make us compliant with the UAE IA Standard?
No tool makes you compliant on its own. KeenSec helps you run staff awareness and produce evidence; your auditor decides compliance.
Can KeenSec support other UAE frameworks?
The same records can support other frameworks with awareness expectations, such as Dubai’s DESC ISR. Your compliance team maps the evidence to each one.
Let’s connect the dots
Every channel tested.
Every lesson on record.
Bring your awareness program, your reporting workflow, or the question your current metrics cannot answer.
Book a demo