Regulation and standard

What does the UAE Information Assurance Regulation require for security awareness training?

Short answer

The UAE Information Assurance (IA) Regulation, published by the Telecommunications and Digital Government Regulatory Authority (TDRA), requires implementing entities to run an information security awareness and training program. Its M3 Awareness and Training family requires a program for everyone doing work for the entity, a documented training needs analysis, a delivery plan, effectiveness measurement, and training records. It is mandatory for government entities and designated critical entities, and recommended for all others.

By the Knowledge Foundry editorial team. How we write and check these pages

Published
Updated
Reading time
11 min
Jurisdiction
United Arab Emirates (federal)
Regulator
Telecommunications and Digital Government Regulatory Authority (TDRA)

Key takeaways

  • The current published text is UAE IA Regulation Version 1.1 (March 2020). The UAE government portal still presents it as the national baseline as at September 2026.
  • It binds UAE government entities and entities designated as critical under the Critical Information Infrastructure Protection (CIIP) Policy. Other organizations are encouraged to follow it voluntarily.
  • Control M3.2.1 (awareness and training program) and M3.3.1 (training needs, priority P1) are Always Applicable, so they cannot be excluded through risk assessment.
  • The program must determine competencies, provide training, evaluate its effectiveness, and keep records of education, training, skills, experience and qualifications.
  • Implementation guidance, such as mandatory annual awareness training, is informational. The controls and sub-controls are the mandatory part.

What is the UAE Information Assurance Regulation?

The UAE Information Assurance Regulation is the national catalog of management and technical security controls that designated UAE entities must implement to reach a minimum level of information assurance. The published text is Version 1.1, dated March 2020, and the UAE government portal describes it as developed by the Telecommunications and Digital Government Regulatory Authority (TDRA) to raise "the minimum level of protection of information assets and supporting systems across all entities in the UAE".

The regulation sits inside a wider national framework. It describes itself as a critical element of the National Information Assurance Framework (NIAF) and of the National Cyber Security Strategy. The NIAF and the CIIP Policy were originally issued under the Supreme Council for National Security by the former National Electronic Security Authority (NESA), which is why many practitioners still call these controls "the NESA standards".

The controls are split into six management families (M1 Strategy and Planning to M6 Performance Evaluation and Improvement) and nine technical families (T1 Asset Management to T9 Information Systems Continuity Management). Awareness and training is family M3, supported by M4 Human Resources Security. The drafters built the controls on ISO/IEC 27001 and 27002 (2005 editions), NIST SP 800-53 Revision 4, and the Abu Dhabi Information Security Standards, so an ISO/IEC 27001 awareness program covers much of the same ground.

Status as at September 2026

The UAE government portal page on cyber safety, updated September 2, 2026, still links Version 1.1 of the IA Regulation alongside the NIAF and CIIP Policy. The UAE Cybersecurity Council, established by Cabinet decision in November 2020, is building the wider legal and regulatory framework. No replacement for the IA Regulation was found on official portals reachable for this review, but organizations should confirm with their sector regulator or TDRA whether a newer version or sector specific standard applies to them.

Who must comply with the IA Regulation?

Compliance is mandatory for UAE government entities and for entities designated as critical, and voluntary for everyone else. The NIAF states that compliance "will be mandatory for all UAE government entities and other entities identified as critical", and that other UAE entities are highly recommended to follow the guidelines voluntarily.

Critical entities are identified through the CIIP Policy, which covers infrastructure supporting critical national services in sectors including chemicals, emergency services, health, nuclear, government, electricity and water, financial services (banking, insurance, stock exchanges, investments), and ICT. The IA Regulation's own scope section says the regulator "will designate the critical entities, as per the UAE CIIP Policy, mandated to implement the UAE IA Regulation".

In practice, private companies meet these controls in two ways: through direct designation, or because a government or critical entity customer writes them into supplier contracts. The regulation itself notes that an awareness and training program "might not be carried out by the entity and can, for example, be ensured contractually".

How do onshore law and free zones affect this?

The UAE has federal law that applies onshore across the seven emirates, emirate level rules, and financial free zones with their own civil and commercial law and regulators. The Dubai International Financial Centre (DIFC) and Abu Dhabi Global Market (ADGM) have their own data protection laws and financial regulators, such as the Dubai Financial Services Authority (DFSA).

The IA Regulation's reach depends on designation rather than on where a company is licensed: it binds government entities and entities designated as critical. A free zone firm that is not designated is not directly bound, but may still meet the controls through contracts, and must meet its own regulator's technology risk and data protection rules. Emirate level frameworks also exist. The Dubai Electronic Security Center (DESC) publishes an Information Security Regulation that applies to all Dubai Government Entities and is organized into thirteen domains.

Security awareness also supports personal data duties. Onshore organizations should read this page with the UAE Personal Data Protection Law page, since both expect staff to handle information securely.

What do the M3 Awareness and Training controls require?

Family M3 requires an awareness and training policy, a program for all persons doing work for the entity, a needs based training plan, measured results, training records, and awareness campaigns. Its stated objective is "to ensure sufficient information security awareness and training is provided and to build a specialized workforce". Each control carries a priority (P1 highest to P4) and an applicability label.

M3 controls in UAE IA Regulation Version 1.1
ControlWhat the entity must doPriorityApplicability
M3.1.1 Awareness and Training PolicyDevelop and maintain a policy that sets the framework for objectives and the roles of providers and recipients of trainingP2Based on risk assessment
M3.2.1 Awareness and Training ProgramInform people of their contribution to information security and the implications of not conforming; determine competencies; provide training; evaluate effectiveness; keep recordsP2Always applicable
M3.3.1 Training NeedsIdentify the security skills needed, assess current skills, and identify gapsP1Always applicable
M3.3.2 Implementation PlanIdentify solutions for each need, set a delivery timeline, and allocate resourcesP3Always applicable
M3.3.3 Training ExecutionDeliver training to plan and find alternatives if the plan slipsP2Always applicable
M3.3.4 Training ResultsMeasure knowledge and skills before and after training and correct training that misses its outcomesP2Based on risk assessment
M3.3.5 Records DocumentationKeep an individual training record for each target and review records periodicallyP2Based on risk assessment
M3.4.1 Awareness CampaignPlan and run awareness campaigns scoped to the security risks of users' activitiesP2Based on risk assessment

Sub-control 2 of M3.2.1 requires the entity to "determine the necessary competencies for personnel performing work effecting information security", and sub-control 5 requires it to "maintain records of education, training, skills, experience and qualifications". M3.3.1 is the family's only P1 control, which means a training needs analysis is the first thing an implementing entity must put in place.

Can an entity exclude any of the training controls?

Always Applicable controls cannot be excluded, and risk based controls can only be excluded with documented justification. Chapter 4 of the regulation says omission of an Always Applicable control or any of its sub-controls "is not acceptable and constitutes non-conformity". Annex A lists 34 Always Applicable controls, all in the management families.

For controls marked "based on risk assessment", such as M3.3.4 Training Results and M3.3.5 Records Documentation, the entity may exclude a control or deviate from a sub-control only if it justifies the decision and provides evidence that accountable persons have accepted the risk. Where no entity risk assessment exists, the regulation treats every control as applicable and mandatory.

Priority governs sequence. Critical entities must begin with P1 controls and may promote or demote other priorities based on their risk assessment, but P1 controls "may be augmented but never reduced". Entities must also use performance indicators to measure the quality and effectiveness of implemented controls; for M3 the family indicator is the percentage of awareness and training objectives met.

How do the controls map to learning outcomes and evidence?

Each training control should translate into a defined learning outcome and a piece of evidence an assessor can inspect. The table below is an original mapping for illustration, not text from the regulation.

Illustrative mapping of IA Regulation training controls to outcomes and evidence
ControlLearning outcomeAssessmentEvidence retained
M3.2.1 (1)Staff can explain how their role affects information security and the consequences of non-conformityScenario questions at onboardingOnboarding completion and score per person
M3.3.1Required security skills are defined per role and gaps are knownSkills self-assessment plus manager validationRole based skills matrix and gap register
M3.3.3Specializt staff can apply secure configuration and patching procedures for systems they runPractical task or observed walkthroughTraining plan versus delivery log, with reasons for any slippage
M3.3.4Knowledge measurably improves after trainingPre and post assessmentBefore and after results and corrective actions
M4.3.1Users have read and accepted relevant security policies before accessAttestation on first accessTimestamped acceptance record linked to policy version

A training matrix that links roles, required competencies and completions is the simplest way to meet M3.3.1 and M3.3.5 together. Because M3.2.1 requires evaluating effectiveness, completion counts alone are weak evidence; see completion tracking vs competency verification and how to prepare training records for an audit.

What does the implementation guidance suggest, and is it mandatory?

The implementation guidance is explicitly "for information purpose only", so it shapes good practice but does not create obligations. It lists methods such as mandatory annual awareness training, targeted role based training, internal awareness websites, seminars, awareness weeks, posters, and emails to all employees and contractors.

The guidance is still useful evidence of what an assessor will expect. It says trainings should take place as planned and not be "pushed off", and that if training continues not to take place in the planned timeframe "it is a non-conformity". It recommends assessing effectiveness, for example through an exam at the end of training or through interviews and feedback forms where an exam is not possible. It also advises updating training when technology, systems, services or threats change.

Critical entities are also told to take account of TRA's national awareness and capability building issuances. For government employees, TDRA offers an information security awareness session service covering twelve information security topics, which can complement but not replace an entity's own program.

What should a compliant awareness and training program include?

A program that meets the M3 and M4 controls has a small set of documented, reviewable components. Use this checklist to test an existing program.

  1. An approved awareness and training policy that assigns roles to providers and recipients (M3.1.1).
  2. A role based list of security competencies and a current skills gap assessment (M3.3.1).
  3. A training plan with solutions, timeline and allocated resources for each need (M3.3.2).
  4. A delivery log compared against the plan, with alternatives recorded when sessions slip (M3.3.3).
  5. Pre and post measures of knowledge or skill, and corrective action for training that underperforms (M3.3.4).
  6. An individual training record for every person in scope, reviewed on a set cycle (M3.3.5).
  7. Awareness campaigns scoped to user risks, with a timeline (M3.4.1).
  8. Policy acceptance on first access and communication of the disciplinary process (M4.3.1, M4.3.2).
  9. Performance indicators reported to management, and contract clauses for outsourced or supplier staff.

How does Knowledge Foundry approach this?

Knowledge Foundry models each IA Regulation control as a structured obligation linked to competencies, learning outcomes and assessment points before any content is written. That gives an entity a traceable path from M3.3.1 skills gaps to delivered training, measured results and individual records. It is used by government and defense organizations and critical infrastructure operators that need reviewable evidence.

Frequently asked questions

Does the IA Regulation say how often awareness training must be repeated?

No mandatory frequency is set in the controls. The implementation guidance lists mandatory annual awareness training as one possible method, but that guidance is informational. Entities set frequency in their own policy and plan, and must then deliver to that plan, since training that repeatedly misses its planned timeframe is described as a non-conformity.

Do contractors and suppliers need to be trained?

Yes, where they do work under the entity's control. The guidance for M3.2.1 says the program covers all persons doing work under the control of the entity, including outsiders with access to information, and that delivery can be ensured contractually. M4.3.1 also covers employees, contractors and third party users.

Does ISO/IEC 27001 certification satisfy the IA Regulation?

Not automatically. The regulation was built on ISO/IEC 27001 and 27002 and Annex C maps its controls to those standards, so an ISO program overlaps heavily. The IA Regulation adds its own priorities, Always Applicable controls, performance indicators and record requirements that an assessor will check separately.

Are penalties set out in the IA Regulation?

The regulation does not set fines. It defines compliance, non-conformity and a compliance monitoring scheme run by the regulator. Consequences for non-compliance depend on the entity's designation, its sector regulator, and any contracts that require compliance.

Is the IA Regulation the same as Dubai's Information Security Regulation?

No. The IA Regulation is a federal framework for government and critical entities. The Dubai Electronic Security Center's Information Security Regulation applies to Dubai Government Entities and is organized into thirteen domains. A Dubai government entity may need to satisfy both, and should map overlapping awareness requirements once.

Sources

  1. UAE Information Assurance Regulation, Version 1.1 (March 2020), Telecommunications and Digital Government Regulatory Authority, via the UAE Government portal
  2. Cyber safety and digital security, The Official Portal of the UAE Government (u.ae)
  3. The National Information Assurance Framework, Supreme Council for National Security, via the UAE Government portal
  4. Critical Information Infrastructure Protection (CIIP) Policy, Supreme Council for National Security, via the UAE Government portal
  5. Standards and Policies: Information Security Regulation (ISR), Dubai Electronic Security Center
  6. Information Security Awareness Session, Telecommunications and Digital Government Regulatory Authority

This page is general information, not legal or compliance advice. Check the primary sources above and obtain advice for your circumstances. See our editorial standards.

Ready to see it?

Bring a subject. Leave with a framework.

A 45-minute working session with our team on a real subject or program you own. You see the system operate on your material, and you keep the framework it produces.

We reply within one business day.