The DESC Information Security Regulation (ISR) requires Dubai government entities and many of their suppliers to operate a managed information security programme that includes regular technical assessment of systems - in practice, periodic vulnerability assessment and penetration testing with findings tracked to closure and reported against the ISR controls. CyberFortify maps every engagement to the ISR, remediates and retests.
// 01 What the DESC ISR is
The Information Security Regulation issued by the Dubai Electronic Security Center - the emirate body responsible for cyber security across Dubai. The ISR sets the information security controls that Dubai government entities, and organisations serving them, must implement.
It frames security as a managed programme (an ISMS-style approach) with regular technical assessment of systems among its controls - which is where periodic vulnerability assessment and penetration testing fit.
The ISR is the standard most Dubai buyers ask about, and it reaches beyond government into the supply chain. For the practitioner view, see our DESC penetration testing requirements guide and the Dubai services overview.
// 02 The testing expectation in practice
Managed security programme
An ISMS-style programme with defined controls - testing sits within it, not as a one-off.
Regular technical assessment
Periodic vulnerability assessment and penetration testing of in-scope systems. Our manual-led testing satisfies the intent.
Findings tracked to closure
Findings must be remediated and closed - our retest is included to evidence it.
Reported against ISR
The report maps findings and coverage to the ISR controls a Dubai assessor checks.
// 03 Who is in scope - including suppliers
The ISR applies to Dubai government entities and, crucially, to many of the private-sector organisations that serve them. Suppliers and service providers handling Dubai government data or systems are frequently required to demonstrate ISR compliance as a condition of doing business - so the regulation reaches well beyond government into the supply chain. That is why a wide range of Dubai organisations, not just public bodies, need to be able to show ISR-aligned security testing. Financial firms in the DIFC additionally answer to the DFSA, personal data falls under the UAE PDPL, and federal government and critical sectors follow the UAE IA standard.
The ISR is not only a government obligation - it flows down to suppliers. A Dubai vendor that can show an ISR-mapped test wins and keeps government work; one that cannot, stalls. We produce exactly that evidence.
CyberFortify DESC-facing reporting// 04 Running the programme
Because the ISR frames testing as part of a managed programme, the discipline is to run it on a regular cadence tied to your risk and to any assessment or renewal dates, rather than as a one-off. Book ahead of any DESC assessment or contract milestone so findings can be remediated and retested before you need to show closure. A typical engagement is one to three weeks of active testing (about four to six weeks total). Map it alongside the wider region with the GCC compliance calendar, and compare providers with the best pentest companies in the UAE.
// 05 Frequently asked questions
Does the DESC ISR require penetration testing?
The ISR requires in-scope organisations to run a managed information security programme that includes regular technical assessment of systems - in practice periodic VAPT with findings tracked to closure and reported against ISR controls. It's framed as security testing within an ISMS rather than a standalone item, but penetration testing is the recognised way to satisfy the technical assessment expectation.
Who must comply?
Dubai government entities and, importantly, many private-sector organisations that serve them. Suppliers handling Dubai government data or systems are frequently required to demonstrate ISR compliance as a condition of doing business, so the regulation reaches into the supply chain - a wide range of Dubai organisations need ISR-aligned testing.
How does the ISR relate to UAE IA and the PDPL?
They're distinct regimes that can apply together. The DESC ISR is Dubai's emirate-level regulation; the UAE IA standard (historically NESA) is a federal standard for government and critical sectors; the UAE PDPL governs personal data federally; and the DIFC has its own data-protection regime. A Dubai organisation may need to satisfy several, so engagements map evidence to those that apply.
How does CyberFortify produce DESC-aligned evidence?
We scope to the in-scope systems and deliver a report mapping findings and coverage to the ISR controls, so a Dubai assessor or the entity's compliance team sees the technical assessment satisfied. Findings are remediated and retested to show closure, and reporting is framed for the ISR. For suppliers, this provides the evidence to demonstrate compliance to the government entity they serve.