Blog · C.23 · Compliance Guide

ADHICS penetration testing requirements — control OM 7.1 for Abu Dhabi healthcare

Abu Dhabi's healthcare cybersecurity standard is unusually explicit: it names penetration testing, vulnerability assessment and web security assessment on a yearly schedule. Here is exactly what ADHICS control OM 7.1 requires, who it applies to, and how it maps to the UAE IA Regulation.

ADHICSAbu DhabiHealthcareControl OM 7.1VAPT
ADHICS: Control OM 7.1 · Yearly Penetration Testing · Vulnerability Assessment · Web Security Assessment · Basic / Transitional / Advanced · DoH Abu Dhabi ADHICS: Control OM 7.1 · Yearly Penetration Testing · Vulnerability Assessment · Web Security Assessment · Basic / Transitional / Advanced · DoH Abu Dhabi
// TL;DR

ADHICS — the Abu Dhabi Healthcare Information and Cyber Security Standard, issued by the Department of Health Abu Dhabi (DoH) — contains the most explicit penetration testing mandate of the UAE frameworks. Control OM 7.1 (Technical Vulnerability Assessment), in the Operations Management domain, requires healthcare entities to "establish yearly schedules and conduct" penetration testing, vulnerability assessment, and web security assessment across their systems, networks, applications and infrastructure. Controls are graded Basic / Transitional / Advanced by entity size and risk. It applies to all DoH-regulated healthcare entities in Abu Dhabi — hospitals, clinics, labs, pharmacies and insurers. OM 7.1 maps directly to UAE IA control T7.7.1. Note that ADHICS v2 (2024) expanded the control set; confirm current numbering.

// 01 What is ADHICS and who must comply?

ADHICS is the mandatory cybersecurity standard for Abu Dhabi's healthcare sector, issued by the Department of Health Abu Dhabi — see also our sector guide to penetration testing for healthcare. Its purpose is to protect health information — some of the most sensitive personal data there is — across the emirate's healthcare providers. Its scope is deliberately broad. In the standard's own words, it covers "all DOH regulated health care entities and services within the Emirate of Abu Dhabi," and applies to "all healthcare/medical facility(s), healthcare professional(s) and support staff… diagnostic lab(s), pharmacy(s) and insurance provider(s)."

If you deliver, support or insure healthcare in Abu Dhabi, you are almost certainly in scope — and because the data is health information, the expectations around security testing are correspondingly strict.

// 02 Which ADHICS control requires penetration testing?

Penetration testing sits in the Operations Management domain, in the control group OM 7 — Security Assessment and Vulnerability Management. The key control is OM 7.1, Technical Vulnerability Assessment, accompanied by OM 7.2 (Security of Assessment Data). What makes ADHICS notable is that OM 7.1 does not leave testing to interpretation the way many frameworks do — it spells it out.

// Control OM 7.1Technical Vulnerability Assessment (verbatim)

"The healthcare entity shall conduct periodic independent assessment to ensure information assets are secure and always protected. The healthcare entity shall: 1. Establish yearly schedules and conduct:

a. Penetration testing on the entity's system, network, applications and security infrastructures and environment;

b. Vulnerability assessment on all entity's system, network, applications and security infrastructures and environment;

c. Web security assessments on web applications accessible over internet…"

Three distinct activities, all named, all on a yearly schedule, plus requirements elsewhere in OM 7 for pre-production security testing and for remediation and reporting. This is as explicit as compliance mandates get, and it means a healthcare entity cannot argue that a vulnerability scan alone satisfies ADHICS — penetration testing is named separately.

// 03 What OM 7.1 requires in practice

Read plainly, OM 7.1 requires a Abu Dhabi healthcare entity to run three testing activities every year, against its full estate, using independent assessment. Mapping them to what you actually commission:

OM 7.1 activityWhat it meansScope
Penetration testingYearlySystems, networks, applications, security infrastructure
Vulnerability assessmentYearlyAll systems, networks, applications, infrastructure
Web security assessmentYearlyInternet-facing web applications
Pre-production testingBefore go-liveNew systems and major changes
Remediation & reportingOngoingFindings tracked to closure

The "independent" requirement is important: the assessment must be genuinely independent of the systems being tested, which for most healthcare providers means engaging an external testing firm rather than relying solely on internal IT.

// 04 ADHICS control tiers: Basic, Transitional, Advanced

ADHICS does not apply every control identically to every entity. Each control is tagged with an implementation tier — Basic, Transitional or Advanced — and which tier applies depends on the entity's size, capability and risk profile. OM 7.1 is a Basic-tier control, which means it applies as a baseline expectation across the sector, not just to the largest hospitals. A small clinic and a major hospital both fall under the security-assessment requirement; the depth and sophistication expected scales with the tier.

This tiering is worth understanding when scoping, because it lets a smaller entity meet its obligation proportionately rather than being held to the same programme as a tertiary hospital — but the core requirement to test annually does not disappear at the Basic tier.

// 05 ADHICS v1 and v2 (2024)

ADHICS v1 (2019) established the framework, including the OM 7 security-assessment controls described here. In 2024, the DoH issued ADHICS v2, a substantial expansion — reported to grow the control set considerably — while retaining the security-assessment structure and the expectation of regular penetration testing and vulnerability assessment. If you are documenting compliance today, work from the current v2 text and confirm the exact control numbering, as some references may have shifted; but the underlying obligation to conduct annual penetration testing and vulnerability assessment carries forward from v1.

// 06 How ADHICS maps to the UAE IA Regulation

ADHICS does not exist in isolation — it explicitly ties itself to the federal baseline. The ADHICS document maps its OM 7 security-assessment controls directly to UAE IA Regulation control T7.7.1 (Technical Vulnerability Management). In other words, satisfying ADHICS OM 7.1 also demonstrates the federal T7.7.1 requirement. For a healthcare entity that is also treated as critical infrastructure, or that contracts with federal or Dubai entities, this mapping is the key to efficiency: one well-scoped annual penetration test, reported against both OM 7.1 and T7.7.1, covers both obligations. Our requirements finder lays the frameworks side by side.

// 07 Frequently asked questions

Does ADHICS require penetration testing?

Yes, explicitly. Control OM 7.1 requires healthcare entities to establish yearly schedules and conduct penetration testing, vulnerability assessment and web security assessment.

How often?

Yearly, per OM 7.1 — a literal annual requirement, plus pre-production testing for new systems.

Who must comply?

All DoH-regulated healthcare entities in Abu Dhabi — hospitals, clinics, medical facilities, professionals, diagnostic labs, pharmacies and insurance providers.

v1 vs v2?

v1 (2019) established OM 7 security assessment; v2 (2024) expanded the control set while retaining the testing structure. Confirm current v2 numbering.

// 08 Sources

Control references reflect ADHICS v1 (2019); v2 (2024) numbering should be confirmed against the current DoH-published standard before relying on this for a compliance submission.

AH

Ankur H.

Security & Compliance Specialist, CyberFortify

Maps technical findings to the frameworks UAE and GCC regulators assess — ADHICS, the UAE IA Regulation, DESC, SAMA and NCA ECC — so one engagement satisfies several obligations at once.

Abu Dhabi healthcare due for ADHICS testing?

CyberFortify delivers the yearly penetration testing, vulnerability assessment and web security assessment ADHICS OM 7.1 requires — independent, and reported against both ADHICS and the UAE IA Regulation.

Schedule scoping call → UAE IA requirements →