Insights · ISO 27001

ISO 27001 for financial firms: how it supports DFSA and FSRA expectations

What ISO/IEC 27001:2022 certifies, how its controls map to DFSA and FSRA cyber expectations, and how to read a supplier’s certificate.
The short answer

ISO/IEC 27001:2022 is the international standard for an information security management system (ISMS). Neither the DFSA nor the FSRA requires it, but it gives a regulated firm a structured, independently audited way to run the risk assessment, governance, supplier and incident processes its regulator expects. It certifies your management system within a defined scope, not compliance with a regulator’s rules.

Key points
  • ISO 27001 certifies a management system within a scope you define, audited by an accredited certification body.
  • Certificates issued to the 2013 edition expired on 31 October 2025, so any certificate you rely on should be to the 2022 edition.
  • Its controls map well to GEN 5.5 and the FSRA cyber rules, but the mapping is indicative and does not replace regulatory reporting.
  • Read a supplier’s certificate properly: accreditation, scope, dates and edition.

What ISO 27001 actually certifies

ISO 27001 certifies an information security management system: the policies, roles, risk process and controls you use to protect information, and the way you review and improve them. You decide the scope (for example, the whole firm or one service), assess your risks, and record which controls you apply in a Statement of Applicability. The 2022 edition’s Annex A lists 93 controls in four themes: organisational, people, physical and technological.

An accredited certification body audits you in two stages, then returns for surveillance audits, usually each year, with recertification every three years.

The 2022 edition and the October 2025 deadline

The transition period from the 2013 edition ended on 31 October 2025. Certificates issued to the 2013 edition expired by then, and an organisation that missed the deadline was treated as a new client requiring a full initial audit. If a supplier or client shows you an ISO 27001 certificate today, check that it refers to ISO/IEC 27001:2022.

How it maps to DFSA and FSRA expectations

The mapping below is indicative. It shows where ISO 27001 gives you a recognised structure for something the regulators already expect.

Regulator expectationISO 27001:2022 elementWhat it gives you
Governing-body approved framework and accountabilityClauses 4 and 5: context, scope, leadership and policyManagement commitment that is audited, not just written down
Cyber risk assessment and treatmentClause 6: risk assessment, treatment and Statement of ApplicabilityA repeatable method with recorded decisions
Asset inventoryAnnex A 5.9A maintained register of information and associated assets
Access control and authenticationAnnex A 5.15 to 5.18, 8.2 and 8.5Least privilege, access reviews and secure authentication
Third-party and ICT provider oversightAnnex A 5.19 to 5.23Supplier agreements, monitoring and cloud service controls
Monitoring and loggingAnnex A 8.15 and 8.16Logs and monitoring that are defined and reviewed
Incident responseAnnex A 5.24 to 5.28Planning, assessment, response, learning and evidence handling
Staff awarenessAnnex A 6.3Awareness, education and training
Resilience and recoveryAnnex A 5.29, 5.30 and 8.13Continuity and backup arrangements

ISO 27001 does not replace your regulatory obligations. Incident notification to the DFSA or FSRA, and your duties under DIFC or ADGM data protection law, still apply in full.

The path to certification

  1. Set the scope and secure management sponsorship.
  2. Run a gap assessment against the standard and your regulator’s expectations.
  3. Carry out the risk assessment, write the Statement of Applicability and treat the risks.
  4. Operate the controls long enough to produce records, and run an internal audit and management review.
  5. Complete the certification body’s stage 1 and stage 2 audits.
  6. Keep it alive: annual surveillance audits and recertification every three years.

Timelines depend on scope, maturity and how much evidence you already keep. A small, well-run firm is usually looking at months rather than weeks. Choose a certification body accredited by a recognised accreditation body, and confirm it is accredited for ISO 27001 in your sector.

Why your supplier’s certificate matters

Regulators expect you to carry out due diligence on your IT providers, and an ISO 27001 certificate is useful evidence, but only if you read it. Check the accreditation of the certification body, the scope statement (does it cover the services you buy, and the locations they run from), the validity dates and the edition. If you need more detail, ask to see the Statement of Applicability under a non-disclosure agreement.

Cre8 IT’s information security management system is certified to ISO/IEC 27001:2022, and we are also certified to ISO 9001 for quality management. We expect clients to ask these questions and are happy to answer them.

Sources and further reading

Last reviewed 19 September 2026. This guide is general information, not legal or regulatory advice. Rules change, so check the current text and take advice from your compliance officer or legal adviser before relying on it.

Written by
CEO, Cre8 IT
Rob Crossley is CEO of Cre8 IT, a Dubai-born managed IT and cyber security company that has supported businesses across the UAE, Saudi Arabia and the UK since 2012. Cre8 IT is certified to ISO 27001:2022 and ISO 9001 and is a certified Microsoft Partner.
FAQ

Frequently asked questions

Does the DFSA or FSRA require ISO 27001?

No. Neither regulator requires a specific standard. ISO 27001 is a widely recognised way to structure and independently evidence your approach, and it complements rather than replaces the regulators’ rules.

How long does ISO 27001 certification take?

It depends on your scope, existing controls and how much evidence you keep. A small, well-run firm is typically looking at several months. The stage 1 and stage 2 audits are only the last part of the work.

How long is an ISO 27001 certificate valid?

Three years, with surveillance audits in between (usually once a year), followed by recertification.
Related guides

Keep reading

Each guide links to the regulator’s own text and shows when it was last reviewed.
Cyber Essentials

Cyber Essentials for UAE firms: what it is and when it is worth it

What Cyber Essentials covers, what changed in April 2026, whether it matters for DIFC and ADGM firms, and how it compares with ISO 27001 and the regulators’ own rules.
4 min read · Reviewed 19 September 2026
Audit readiness

IT audit readiness for DIFC and ADGM firms: an evidence-first checklist

How to be ready when a regulator, auditor or client asks for proof of your IT and security controls: the evidence pack, a mock audit and a six-week plan.
3 min read · Reviewed 19 September 2026
Vendor management

IT vendor and outsourcing management for DFSA and FSRA firms

How to manage IT providers when you are regulated in DIFC or ADGM: a register, tiering, due diligence, contract terms and ongoing oversight.
4 min read · Reviewed 19 September 2026

Talk to a specialist about your obligations

Tell us about your firm and your regulator, and we will suggest a practical first step, whether that is a gap assessment or ongoing support.