Resources - Blog

What Is NESA Compliance? A Guide for UAE Organisations

The Kernel
August 9, 2026

NESA compliance refers to alignment with the UAE Information Assurance Standards (IAS), a set of 188 security controls across 18 management and technical domains that set the cybersecurity baseline for critical infrastructure, government, finance, energy, telecom, and healthcare organisations in the UAE. It is mandatory, not advisory, for organisations operating in these sectors.

What NESA stands for

NESA stands for the National Electronic Security Authority, the UAE federal body that originally published the Information Assurance Standards. In practice, "NESA compliance" and "IAS compliance" are used interchangeably across the market, and most organisations, vendors, and auditors still refer to the framework as NESA even though the governance structure behind it has evolved.

National cybersecurity leadership in the UAE now sits with the UAE Cyber Security Council, established under the National Cyber Security Strategy 2025 to 2031, with NESA's original function folded into the Signals Intelligence Agency. For organisations working through compliance today, this matters less than it sounds: the controls, the domains, and the audit expectations that make up the standard are still what people mean when they say NESA compliance.

Who actually has to comply

NESA/IAS compliance is mandatory for entities that operate, manage, or support UAE critical infrastructure and government systems. In practice, this covers:

- Government entities and semi-government organisations

- Financial services and banking institutions

- Energy, utilities, and critical national infrastructure operators

- Telecommunications providers

- Healthcare organisations managing sensitive or critical systems

Private sector organisations outside these categories are not formally mandated, but many adopt IAS controls voluntarily because it maps well to enterprise security best practice and because it is increasingly expected by government and critical infrastructure customers as a condition of doing business with them.

What the standard actually covers

The 188 controls span both management domains (governance, risk assessment, third party management, asset management) and technical domains (access control, cryptography, network security, operations security, incident management). It is a risk-based framework, meaning the specific controls an organisation needs to implement depend on the sensitivity of the systems and data involved, not a single fixed checklist applied identically everywhere.

For 2026, the direction of travel is toward continuous validation rather than a one-time audit. Organisations are increasingly expected to demonstrate ongoing monitoring, tested incident response plans, and board-level risk reporting, not just a certificate on file.

The identity and authentication controls that matter most

A significant portion of the technical domains sit squarely in identity and access management: who can access which systems, how that access is authenticated, how privileged accounts are controlled, and how all of it is logged and audited. This is where most organisations find the practical gap between what they currently have and what IAS actually expects.

A few patterns come up repeatedly during NESA-aligned assessments:

Password-based MFA is often treated as sufficient when it is not. A password plus an SMS code satisfies a basic MFA checkbox, but it does not hold up against the phishing and MFA fatigue attacks that are now common in the region. Controls that expect resistance to credential-based attacks point organisations toward hardware-backed or certificate-based authentication rather than one-time codes.

Privileged accounts frequently lack the audit trail regulators expect. Native system logs are rarely sufficient on their own to demonstrate who accessed what, when, and why, particularly for administrator and third party accounts.

Certificate and PKI management is often manual and inconsistent. Where certificate-based authentication is in scope, organisations without dedicated lifecycle management tools struggle to keep issuance, renewal, and revocation auditable at scale.

How organisations close these gaps in practice

Meeting the identity-related controls within IAS generally means combining a few things: authentication methods strong enough to resist modern credential attacks, centralised policy enforcement across both cloud and legacy systems, and reporting that produces evidence an auditor can actually use.

Pointsharp is built specifically for this kind of hybrid requirement. It delivers MFA, certificate-based authentication, and identity governance across cloud, on-premises, and legacy systems from one platform, which matters because most UAE enterprises are not running a single, clean, cloud-only environment. For the hardware-backed authentication layer, Yubico security keys provide the phishing-resistant credential that password-and-code MFA cannot, and pair directly with Pointsharp for full PKI lifecycle management.

This combination maps to the Identity Management, Strong Authentication, and Public Key Infrastructure controls within NESA/IAS specifically, alongside NCA, SAMA, and ISO 27001 where those also apply.

Getting started

NESA compliance is not a product you buy, it is a set of outcomes an assessor needs to see evidence of. The organisations that get through assessments smoothly are usually the ones that treated identity and authentication controls as infrastructure from the start, not a checklist exercise before an audit.

The Kernel works with financial services, government, and critical infrastructure organisations operating in the UAE, and maps every deployment we support directly to NCA, NESA, SAMA, and ISO 27001 as part of the engagement, not as a separate line item.

Not sure where your current authentication setup stands against NESA/IAS requirements?

Talk to our team | Explore our vendor portfolio

Want these in your inbox?

We publish practical, vendor-neutral writing on identity, authentication, and security operations in the region. No spam, no hard sell.

First name
Last name
Email
Thank you for subscribe.
Oops! Something went wrong while submitting the form.