← Back to blog

Penetration Testing in Dubai: What's Actually Required

NIMR Security Team
penetration testingDubaiUAEcompliance

Penetration testing in Dubai is usually a compliance decision before it is a security decision. The emirate's government entities, free zones, and financial sector sit under distinct mandates, and a test that satisfies one does not automatically satisfy the others. This post maps the landscape and what to scope for.

Who requires testing in the UAE

Three layers of regulation touch security testing in the UAE:

  • Federal level. The UAE Information Assurance Regulation, overseen by the National Electronic Security Authority (NESA), applies to federal entities and critical infrastructure. For government entities, the UAE Cyber Essentials baseline sets the minimum expectations, including vulnerability management.
  • Dubai level. The Dubai Electronic Security Centre (DESC) enforces the Information Security Regulation (ISR) for Dubai Government entities. DESC is also the point of contact for reporting incidents affecting Dubai Government systems.
  • Sector level. The Central Bank of the UAE expects licensed financial institutions to demonstrate regular security testing and reporting. Free zones have their own layer on top.

Data protection changes the scope

The UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021) requires organizations to implement appropriate security measures for personal data. DIFC establishments sit under the DIFC Data Protection Law (Law No. 5 of 2020), which carries its own obligations.

The practical effect is that scope now has to include anything processing personal data, not just the crown-jewel systems. A VAPT scoped around the payment gateway alone will not satisfy a data-protection review; the customer portal, APIs, and internal systems that touch personal data are all in play.

Free zones add another layer. DIFC and ADGM run their own legal and data-protection regimes, and entities licensed there should check zone-level expectations alongside federal law. A mainland scope does not automatically cover a free zone entity's systems.

Where the systems actually run

A growing share of scope sits in UAE-hosted cloud regions from providers such as AWS and Microsoft Azure, alongside local data centre operators. Regulators expect the testing scope to cover the cloud estate, not just the classic on-premises perimeter. Ask any provider whether they test cloud-hosted applications, identity layers, and the API gateways in front of them, or only the legacy network edges.

What the tests actually cover

The technical substance is the same as anywhere else: web and API testing, network perimeter checks, mobile apps, and business logic. Our web app pentest walkthrough shows what an engagement looks like end to end, and the API penetration testing checklist covers the API pass.

What changes is the evidence. Regulators and compliance reviewers in the UAE want a report that maps findings to the specific mandate you are subject to, shows the test was performed by an independent team, and documents the remediation and retest cycle. A scan dump does not qualify; vulnerability assessments and penetration tests are different deliverables.

What buyers in Dubai typically ask

  • English reporting with clear reproduction steps, CVSS 3.1 scores, and CWE references.
  • Retest included so fixes are verified before the next audit cycle.
  • NDA and data handling for the systems under test, especially in free zones with separate data-protection regimes.
  • Cloud and SaaS coverage: whether the scope includes the cloud-hosted estate and third-party integrations.
  • Scope mapped to their mandate: DIFC-licensed entities, mainland companies, and Dubai Government contractors each have a different reference point.

How to read the report for a UAE review

Compliance reviews in Dubai rarely stop at the findings list. Expect reviewers to ask how each finding maps to the mandate in question, whether it was verified manually, and what the remediation plan is. A good report for this market names the control or regulation each finding affects, documents the tester's independence, and shows the retest. If a provider cannot show a sanitized sample report before you commit, treat that as a warning sign.

Takeaways

  • Identify your mandate first: federal (NESA), Dubai Government (DESC), sector (CBUAE), or free zone.
  • Include anything processing personal data in scope; the data protection law raised the bar.
  • Insist on verified findings with reproduction steps, not a scanner report.
  • Confirm the retest is part of the price before you commit.
  • Confirm cloud-hosted systems are in scope, not just the on-premises perimeter.

NIMR serves clients across the UAE and the Middle East, with reporting that maps findings to the specific regulation you answer to. Request a scoping call or review our web, API, and network VAPT services. For budgeting, see our penetration testing cost guidance.