Blog · C.24 · Compliance Guide

DESC ISR penetration testing requirements — Dubai's information security regulation

What the Dubai Electronic Security Center's Information Security Regulation expects of security testing, who it binds, and what can — and cannot — be stated about its cadence, given the control catalogue is access-restricted. An honest guide for Dubai government entities and their suppliers.

DESCDubai ISRGovernmentSuppliersVAPT
DESC ISR: Dubai Government & Suppliers · Compliance & Audit Domain · Penetration Testing & Vuln Scanning · ISR v3 · Dubai Cyber Security Strategy DESC ISR: Dubai Government & Suppliers · Compliance & Audit Domain · Penetration Testing & Vuln Scanning · ISR v3 · Dubai Cyber Security Strategy
// TL;DR

The Dubai Electronic Security Center (DESC) issues the Information Security Regulation (ISR), currently v3 (2023), which requires entities to perform technical assessments — penetration testing and vulnerability scanning — to identify gaps between documented controls and actual security posture. This sits within the ISR's compliance and audit domain. It applies to Dubai government and semi-government entities and their suppliers who handle Dubai government data, under the Dubai Cyber Security Strategy. One honest caveat: the ISR's full control text is access-controlled and not public, so specific control numbers and exact cadence cannot be quoted from the standard — reported cadences (quarterly VA, annual external pentest) are consultancy interpretation. DESC also maintains sector standards for cloud, data centres, SOCs and OT. There is no DESC standard called "DCS-1."

// 01 What is DESC and the ISR?

The Dubai Electronic Security Center is the government body responsible for cybersecurity across the Emirate of Dubai, and its flagship instrument is the Information Security Regulation (ISR). The ISR is Dubai's mandatory information-security control framework, structured across roughly thirteen domains spanning governance, operations and assurance. The current release, ISR v3 (around 2023), extended the earlier v2 with modern provisions for zero trust, cloud, IoT and supply-chain security, reflecting how Dubai's digital-government estate has grown.

The ISR operates within the broader Dubai Cyber Security Strategy, which sets the emirate's overall cyber posture. One point of clarification worth making, because it circulates online: there is no DESC standard named "DCS-1." DESC's published instruments are the ISR plus a set of sector-specific standards.

// 02 Who must comply?

The ISR binds Dubai government and semi-government entities, and critically, it flows down to their suppliers and vendors — any organisation that handles Dubai government data, including cloud service providers, data-centre operators and security operations centres. This supply-chain reach is the reason many private companies encounter DESC: not because they are government bodies, but because they serve one, and the ISR obligations arrive through the contract.

If you are bidding for or delivering services to a Dubai government entity, expect ISR compliance — including security testing — to be part of the requirement, and to be asked to evidence it.

// 03 What the ISR requires for penetration testing

Within the ISR, security testing is an assurance activity, sitting under the compliance and audit domain. The requirement, as described in reputable analysis of the standard, is that entities "perform technical assessments such as penetration testing and vulnerability scanning to identify gaps between documented controls and actual security posture." In other words, the ISR treats penetration testing as the means of verifying that the controls you claim to have actually work — the same assurance logic seen in SAMA's Cyber Security Review and elsewhere.

We should be straight about a limitation here, because a guide that pretends otherwise is not trustworthy: the ISR's detailed control catalogue is access-controlled and not publicly available. That means we cannot responsibly quote a specific ISR control number for penetration testing the way we can for Abu Dhabi's ADHICS OM 7.1 or the federal UAE IA T7.7.1. What we can say with confidence is that penetration testing and vulnerability scanning are required as technical assurance under the ISR's compliance domain, and that DESC-regulated entities are expected to conduct them.

// 04 How often? What can honestly be said

Because the control text is not public, any specific cadence must be labelled as interpretation rather than quoted regulation. Consultancy analysis of the ISR reports the following expectations — useful for planning, but to be confirmed with DESC or an accredited assessor for your specific obligations:

ActivityReported expectationStatus
Vulnerability assessmentQuarterlyConsultancy interpretation
Penetration testing (external-facing)AnnualConsultancy interpretation
Comprehensive testing (critical infrastructure)Bi-annualConsultancy interpretation

Treat these as a sensible baseline to plan around, not as quoted ISR text. The safe position for a DESC-regulated entity is to run at least annual penetration testing of external-facing services plus regular vulnerability assessment, and to confirm the exact obligation through official channels.

// 05 DESC's sector-specific standards

Beyond the ISR, DESC publishes standards tailored to particular technology domains. If your engagement with Dubai government touches any of these, expect the relevant standard to apply on top of the ISR:

CSP

Cloud Service Provider Standard

For cloud providers serving Dubai government workloads.

DC

Data Centre Security Standard

For data-centre operators hosting government data.

SOC

SOC Security Standard

For security operations centres providing monitoring services.

OT

ICS / OT Security Standard

For operational technology and industrial control environments.

// 06 How DESC fits the UAE framework stack

Dubai's ISR is one layer in the UAE's multi-tier model. The federal UAE IA Regulation is the national baseline; Abu Dhabi adds ADHICS for healthcare; Dubai adds the DESC ISR for its government ecosystem; and sector regulators such as the UAE Central Bank layer their own expectations. An organisation operating across the UAE may be subject to more than one. As with the rest of the Gulf, the efficient path is to scope a single penetration test broadly enough to satisfy every framework you answer to, and map the findings to each — even where, as with DESC, the mapping is to a domain rather than a public control number. (And to repeat the earlier clarification: "NIS 2" is an EU directive, not a UAE law — do not treat it as a Dubai requirement.)

// 07 Frequently asked questions

Does DESC require penetration testing?

Yes. The ISR requires technical assessments including penetration testing and vulnerability scanning, under its compliance and audit domain. The full control text is access-controlled.

Who must comply?

Dubai government and semi-government entities and their suppliers who handle Dubai government data — including cloud providers, data centres and SOCs.

How often?

Not quotable from the standard, as the control text is not public. Consultancy analysis reports quarterly VA, annual external pentest and bi-annual comprehensive testing — confirm your specific obligations with DESC.

Current version?

ISR v3 (around 2023), adding zero-trust, cloud, IoT and supply-chain provisions. DESC also has cloud, data-centre, SOC and OT sector standards.

// 08 Sources

Because the DESC ISR control catalogue is not public, this guide describes requirements functionally and labels cadence figures as interpretation. Confirm your specific obligations with DESC or an accredited assessor before relying on this for compliance.

AH

Ankur H.

Security & Compliance Specialist, CyberFortify

Maps technical findings to the frameworks UAE and GCC regulators assess — DESC, ADHICS, the UAE IA Regulation, SAMA and NCA ECC — and is candid about where control text is public and where it is not.

Serving Dubai government?

CyberFortify delivers ISR-aligned penetration testing for Dubai government entities and their suppliers — scoped to satisfy DESC assurance expectations and mapped to the wider UAE framework stack.

Schedule scoping call → UAE IA requirements →