Penetration testing in the UAE, Saudi Arabia and Qatar: what regulators and customers expect
If you run a technology company in Dubai, Riyadh or Doha, the question "do we need a pentest?" rarely has a one-line answer. Each country has its own regulators, the frameworks overlap, and some of them decide not only whether you test, but who is allowed to do the testing. This is a practical overview of what applies to whom, where a locally accredited provider is required, and where the pressure usually comes from for commercial companies: your customers, more often than your regulator.
Government entities, critical infrastructure and regulated financial institutions in all three countries face explicit penetration testing requirements, sometimes with rules on which providers they may use. Saudi Arabia has gone furthest for the wider private sector: its newer controls make pentesting mandatory for large private companies too. For most other commercial companies, the requirement arrives through customers, tenders, certifications and investors.
The frameworks at a glance
The table below covers the frameworks you are most likely to meet. It is an overview, not legal advice: scope and versions change, so always check the current text with your regulator or compliance lead.
| Country | Framework | Who it applies to | What it means for pentesting |
|---|---|---|---|
| UAE (federal) | UAE Information Assurance Standards (originally the NESA standards) | Federal government entities and critical information infrastructure | Technical security testing is part of the required controls |
| UAE (Dubai) | DESC Information Security Regulation (ISR) | Dubai government and semi-government entities, and certain suppliers handling their data | Regular testing, delivered by a provider accredited under DESC's Cyber Force programme |
| UAE (Abu Dhabi) | ADHICS | Healthcare entities in Abu Dhabi | Security assessments of systems that handle patient data |
| UAE (financial) | Central Bank of the UAE; DFSA in DIFC | Licensed financial institutions | Regular testing, proportionate to risk |
| Saudi Arabia | NCA Essential Cybersecurity Controls (ECC-2:2024) | Government entities and private companies that own, operate or host critical national infrastructure | Periodic penetration testing (control 2-11); critical systems under the CSCC at least every six months |
| Saudi Arabia | NCA NCNICC-1:2025 | Private companies outside critical infrastructure | Mandatory for large companies (Class A); recommended for small and medium companies (Class B) |
| Saudi Arabia (financial) | SAMA Cyber Security Framework | Institutions supervised by the Saudi Central Bank | Regular penetration testing |
| Qatar | National Information Assurance (NIA) Standard, NCSA | Government entities and organisations that must comply with or certify against the national standard | Security testing within the NIA controls; the NCSA also accredits penetration testing providers |
Two things stand out. First, Saudi Arabia's NCNICC-1:2025 is the big change for commercial companies: it extends baseline cybersecurity controls to private companies outside critical infrastructure. Class A covers companies with 250 or more employees or more than SAR 200 million in annual revenue, and for them penetration testing is mandatory. Second, all three countries now have personal data protection laws that require appropriate technical security measures. None of them prescribes a pentest literally, but a recent pentest report is one of the most common ways to show that those measures work.
Where the tester has to be local and accredited
This is the part many foreign providers leave out. Some schemes decide not only whether you test, but who may test.
- Dubai government and semi-government. Penetration tests for these entities must be delivered by a provider accredited under DESC's Cyber Force programme. Accreditation requires, among other things, a UAE trade licence, and test data has to stay within the UAE. A report from a provider outside the programme can be rejected.
- Saudi Arabia. Since August 2022, any entity that provides cybersecurity services in the Kingdom must register with the National Cybersecurity Authority. Auditors of organisations under the ECC generally expect the pentest to come from a registered provider.
- Qatar. The NCSA runs an accreditation scheme for penetration testing providers under its National Information Security Compliance Framework (NISCF). If your contract or certification refers to it, check whether an accredited provider is required.
If you fall into one of these groups, use a provider that is accredited or registered for that scope. Otherwise you risk paying for a test twice. I say this as a tester based in the Netherlands: for Dubai government work, I am not the right choice, and it would not be fair to pretend otherwise.
Outside these schemes, the choice of provider is largely up to you and to whoever will read the report: a customer, an auditor or an investor. For engagements with Saudi companies, the NCA registration point is worth raising early in any conversation with a provider.
Where the pressure comes from for commercial companies
For a SaaS company in Dubai Internet City, a fintech start-up in Riyadh or an e-commerce platform in Doha, the regulator is often not the one asking. These are:
- Enterprise customers and government buyers. Large companies and government entities in the region increasingly pass their own requirements on to suppliers, through security questionnaires and contract clauses. Saudi Arabia's NCNICC even requires large companies to include cybersecurity requirements in their contracts with third parties. A recent, independent pentest report answers the hardest questions on those questionnaires.
- ISO 27001 and SOC 2. Companies that sell internationally often pursue one of these. Neither formally requires a pentest, but auditors expect one as evidence. See our pages on ISO 27001 pentests and SOC 2 pentests.
- Investors and acquirers. Technical due diligence routinely asks for a recent pentest of the core product. More on that in our due-diligence pentest.
- Customers in Europe. If you sell to European companies, EU rules reach you through your customers. NIS2 obliges them to assess the security of their suppliers, and financial customers do the same under DORA. We explained how that works in NIS2 and your supply chain.
Selling to enterprise customers in the Gulf or in Europe, and being asked for a recent pentest report? In a free 30-minute intake we define the scope your customers need and when you can have the report.
Book a free intake →What a report needs to hold up in the region
Whether the reader is a regulator, an auditor or a customer's security team, the same qualities make a report credible.
- Written for two audiences. A management summary in plain English for the board or the customer, and technical findings with reproduction steps for the engineers who fix them.
- Rated by risk. A CVSS score and a description of the business impact for each finding, so priorities are clear.
- Mapped to what you report against. Where relevant, findings linked to the framework the reader cares about, such as an ECC or NCNICC control, ISO 27001 Annex A, or SOC 2.
- Closed with a retest. A statement confirming which findings were fixed. Without it, a report shows problems but not that they were solved.
- Verifiable. A PDF is easy to edit. Every Resync report is digitally signed, so your customer or auditor can check for themselves that it is genuine and unchanged. See a sample report for the full structure.
Regulated government, critical infrastructure and financial work in the Gulf often requires a locally accredited tester; for most commercial companies, the requirement comes from customers and auditors, and what counts is a credible, independent and verifiable report.
Working with a tester based in the Netherlands
For companies outside the accredited schemes, a remote tester from Europe works well in practice. A few practical points:
- Time zones overlap. The UAE is two to three hours ahead of Amsterdam, Saudi Arabia and Qatar one to two hours, depending on the season.
- Working weeks overlap Monday to Thursday. The UAE works Monday to Friday; Saudi Arabia and Qatar work Sunday to Thursday. That leaves four shared working days a week for questions and updates.
- Most scopes are tested remotely as standard. Web applications, APIs, cloud environments and external infrastructure do not require anyone on site. Internal networks can be reached through a VPN or a jump host.
- Data handling under EU rules. An NDA is standard, and findings and test data are handled under the GDPR and not kept beyond what the engagement strictly requires.
- Data residency. If your own rules require data to stay in-country, agree up front what the tester may see. In most application tests, the tester works with test accounts and does not need production data at all.
Conclusion
Penetration testing requirements in the UAE, Saudi Arabia and Qatar depend on who you are. Government entities, critical infrastructure, healthcare and financial institutions face explicit rules, and in Dubai, Saudi Arabia and Qatar there are schemes that govern which providers may do the work. For them, a locally accredited or registered provider is the safe route. For most commercial companies, the question comes from customers, auditors and investors, and the answer is a recent, independent report with a retest, in a form the reader can verify. Not sure which applies to you? A free 30-minute intake gives clarity, with no obligation.
Frequently asked questions
Is penetration testing mandatory in the UAE?
For some organisations, yes: federal entities and critical information infrastructure under the UAE IA Standards, Dubai government and semi-government entities under DESC's ISR, healthcare entities in Abu Dhabi under ADHICS, and licensed financial institutions. For other companies it is usually not a legal requirement, but customers, auditors and investors often ask for it.
Do I need an NCA-registered provider in Saudi Arabia?
The NCA requires any entity that provides cybersecurity services in the Kingdom to register, and organisations under the ECC are generally expected to use registered providers. If you fall under the ECC or a sector regulator such as SAMA, check the provider requirements before you commission a test.
Can a European pentester test a company in Dubai or Riyadh?
For most commercial companies, yes. Web applications, APIs and cloud environments are tested remotely as standard. The exception is regulated work that requires a locally accredited provider, such as penetration tests for Dubai government and semi-government entities under DESC's Cyber Force programme.
How often should we test?
At least once a year and after every significant change is the common baseline. Some frameworks ask for more: Saudi Arabia's Critical Systems Cybersecurity Controls require testing of critical systems at least every six months. More on the reasoning in how often you should have a penetration test done.
A pentest report your customers will accept.
A manual penetration test of your web application, API or cloud environment by one OSCP-certified tester, with an English report your customers, auditors and investors can verify themselves. Fixed price, retest included.
Book free intake →