UAE IA Standard · UAE

UAE awareness programmes,
evidenced control by control.

The UAE Information Assurance Standard v2.1, published by the UAE Cybersecurity Council in November 2025, requires federal entities and critical information infrastructure entities to maintain an awareness and training programme, evaluate its effectiveness and keep records of awareness campaigns.

Framework
UAE Information Assurance Standard v2.1, UAE Cybersecurity Council, November 2025
Applies to
Ministries, federal authorities and critical information infrastructure entities
Where awareness fits
M3.2.1 awareness and training programme; M3.4.1 awareness campaigns
KeenSec evidence
Simulation results, report logs, training certificates, policy acknowledgements

UAE rules on staff awareness

Three regulators,
one awareness record.

Scope differs: the IA Standard covers federal and critical entities, DESC covers Dubai Government entities, and CBUAE covers licensed financial institutions.

RuleWhat it saysApplies to
IA Standard v2.1, M3.2.1Develop, approve and maintain an awareness and training programme, and evaluate the effectiveness of the actions taken.Federal and critical entities, always applicable
IA Standard v2.1, M3.4.1Plan and conduct security awareness campaigns, and keep comprehensive records of them.Federal and critical entities, based on risk
DESC ISR v3.1, 1.4.1 to 1.4.5An awareness programme throughout the year, training for new users and periodic surveys to measure training effectiveness.Dubai Government entities
CBUAE Operational Risk Management Regulation, 5.8Senior management must make sure staff receive regular and appropriate training.Licensed financial institutions, from 14 September 2026
CBUAE Operational Risk Management Regulation, 15.2 and 15.3Notify the Central Bank within 4 hours of events affecting critical operations, and within 72 hours of high-risk incidents.Licensed financial institutions

Lures that feel local

Couriers, utilities
and government services.

Delivery fees, utility bills and government-service notices reach people on SMS and WhatsApp as often as email.

Simulated example
WhatsApp13:47

“Courier desk” · unknown number

Parcel on hold

Your parcel is held at customs. Pay the clearance fee today to release it: parcel-release.example

  • Unknown number
  • Small fee, urgent deadline
A sample courier lure.

Expectation to record

The awareness record
auditors can follow.

SIMULATION RESULTS

Staff tested across channels.

Outcomes per channel, team and campaign.

REPORT LOGS

Staff report suspicious messages.

Phishing Reporter logs with automated analysis.

TRAINING

Staff complete awareness training.

LMS completions and certificates.

POLICY ACKNOWLEDGEMENTS

Staff accept your policies.

Dated records per person and version.

KeenSec helps you produce evidence for your awareness obligations: simulation results, report logs, training completions and certificates, and policy acknowledgements. Your auditor decides compliance.

PLEASE NOTE

This page is general information, not legal advice. KeenSec helps you produce evidence for your awareness obligations; your auditor or regulator decides whether you are compliant.

Primary sources

What this page is based on.

Checked on the regulator’s own website on 24 September 2026. Read the original before you rely on it.

  1. UAE Information Assurance Standard v2.1November 2025 · UAE Cybersecurity Council
  2. CBUAE Operational Risk Management Regulation (C 1/2026)In force 14 September 2026 · replaces Circular 163/2018
  3. CBUAE Consumer Protection Standards, Article 6Employee training on data controls, annual fraud awareness campaigns
  4. DESC standards and policies, including the Information Security RegulationDubai Government entities · ISR version 3.1
  5. Federal Decree-Law No. 45 of 2021 on Personal Data ProtectionIn force 2 January 2022 · executive regulations pending

Questions buyers ask

Frequently asked questions.

Does any UAE framework require phishing simulation?

No UAE framework we reviewed names it. The IA Standard asks you to evaluate the effectiveness of awareness actions, and DESC asks for periodic surveys to measure training effectiveness. Simulations are a practical way to do both.

Is the IA Standard the same as NESA?

It is the successor. The regulation once known as NESA became the UAE Information Assurance Regulation, and the UAE Cybersecurity Council now publishes the Information Assurance Standard v2.1.

Does KeenSec make us compliant with the UAE IA Standard?

No tool makes you compliant on its own. KeenSec helps you run staff awareness and produce evidence; your auditor decides compliance.

Can KeenSec support other UAE frameworks?

The same records can support other frameworks with awareness expectations, such as Dubai’s DESC ISR. Your compliance team maps the evidence to each one.

Let’s connect the dots

Every channel tested.
Every lesson on record.

Bring your awareness program, your reporting workflow, or the question your current metrics cannot answer.

Book a demo