Insights · Cyber Essentials

Cyber Essentials for UAE firms: what it is and when it is worth it

What Cyber Essentials covers, what changed in April 2026, whether it matters for DIFC and ADGM firms, and how it compares with ISO 27001 and the regulators’ own rules.
The short answer

Cyber Essentials is a UK government-backed scheme, run with the NCSC and delivered by IASME through certification bodies, that verifies five technical controls. It is not a DFSA or FSRA requirement. It is a low-cost, well-recognised baseline, most useful if you belong to a UK group, serve UK clients or bid for UK work. ISO 27001 and the regulators’ rules cover much more.

Key points
  • Five controls: firewalls, secure configuration, user access control, malware protection and security update management.
  • Version 3.3 and the Danzell question set apply to new assessments from late April 2026, with stricter marking.
  • It is not required by the DFSA, the FSRA or UAE law, but it lines up well with the protective controls in their rules.
  • It does not cover governance, incident response or third-party oversight.
  • Certificates last 12 months.

What Cyber Essentials is

Cyber Essentials is a scheme developed by the UK’s National Cyber Security Centre (NCSC) and delivered by IASME. It checks that you have five basic technical controls in place, which together are designed to protect against the most common internet-based attacks:

  • Firewalls. Boundary and device firewalls that filter unwanted traffic.
  • Secure configuration. Remove unused software and accounts and change default settings.
  • User access control. Separate admin accounts, least privilege and multi-factor authentication.
  • Malware protection. Anti-malware or application allow-listing.
  • Security update management. Keep operating systems, firmware and applications patched.

There are two levels. Cyber Essentials is a self-assessment that a certification body verifies. Cyber Essentials Plus adds hands-on technical testing by an assessor.

What changed in April 2026

The requirements moved to version 3.3 and a new question set, Danzell, which replaces Willow, for new assessments from late April 2026. Organisations whose assessment account already existed have a six-month transition. The five controls are unchanged, but marking is stricter:

  • Multi-factor authentication is required for all cloud services where it is available.
  • Critical and high-risk security updates must be applied within 14 days for operating systems, firmware and applications. Missing this is an automatic fail.
  • Cloud services cannot be excluded from scope.
  • Scope descriptions are more detailed, legal entities must be named, and there are new rules on how Cyber Essentials Plus re-test samples are chosen.
  • The director’s declaration now includes an acknowledgement of ongoing compliance.

Does it matter in DIFC or ADGM?

Neither the DFSA nor the FSRA requires Cyber Essentials, and it is a UK scheme. It becomes useful when you are part of a UK group, serve UK clients, or bid for UK public-sector or supply-chain work that asks for it. Cre8 IT has a UK office and supports UK businesses as well as UAE ones.

It also lines up well with the protective controls in the DFSA’s GEN 5.5 (authentication, patching, malware protection and access control), which makes it a practical first milestone. It does not cover governance, incident response or third-party oversight, which regulators also expect.

Cyber Essentials, ISO 27001 and the regulators’ rules

Cyber EssentialsISO 27001:2022DFSA GEN 5.5 and FSRA cyber rules
What it isUK government-backed baseline schemeInternational standard for an information security management systemRegulatory rules for authorised firms
What it coversFive technical controlsGovernance, risk, people, suppliers and technologyGovernance, technical controls, third parties, incidents and reporting
How you show itCertificate (Essentials or Plus), renewed every 12 monthsCertificate from an accredited body, audited each yearEvidence to the regulator on request, plus incident reporting
Mandatory for DIFC and ADGM firms?NoNoYes

Getting ready

  • Scope honestly. List every user, device (including personal devices that reach firm data), network boundary and cloud service. Under version 3.3, cloud services stay in scope.
  • Fix the usual failure points first: unsupported operating systems, missing MFA on cloud accounts, patches older than 14 days, everyday use of admin accounts, default passwords and open ports.
  • Complete the self-assessment accurately and have a director sign the declaration.
  • Choose Cyber Essentials Plus if a client or contract asks for independently tested evidence.
  • Diarise renewal. Certificates last 12 months.

Certification itself is carried out by an accredited certification body. An MSP can prepare you and supply the technical evidence, and Cre8 IT helps clients scope, fix and evidence their controls, but no MSP can certify you.

Sources and further reading

Last reviewed 19 September 2026. This guide is general information, not legal or regulatory advice. Rules change, so check the current text and take advice from your compliance officer or legal adviser before relying on it.

Written by
CEO, Cre8 IT
Rob Crossley is CEO of Cre8 IT, a Dubai-born managed IT and cyber security company that has supported businesses across the UAE, Saudi Arabia and the UK since 2012. Cre8 IT is certified to ISO 27001:2022 and ISO 9001 and is a certified Microsoft Partner.
FAQ

Frequently asked questions

Is Cyber Essentials mandatory for companies in the UAE?

No. It is a UK scheme and is not required by the DFSA, the FSRA or UAE law. UK clients, parent companies or contracts may ask for it.

How long does a Cyber Essentials certificate last?

Twelve months. You renew every year, and your scope and answers are assessed against the current requirements.

Should we do Cyber Essentials or ISO 27001 first?

If you want a quick, low-cost baseline, especially for UK work, Cyber Essentials is a sensible first step and much of the work carries over. If you want a full management system that speaks to your regulator’s governance expectations, aim for ISO 27001. Many firms do both.
Related guides

Keep reading

Each guide links to the regulator’s own text and shows when it was last reviewed.
ISO 27001

ISO 27001 for financial firms: how it supports DFSA and FSRA expectations

What ISO/IEC 27001:2022 certifies, how its controls map to DFSA and FSRA cyber expectations, and how to read a supplier’s certificate.
4 min read · Reviewed 19 September 2026
Microsoft 365

Microsoft 365 governance for regulated firms: a practical baseline

How to govern Microsoft 365 in a DFSA- or FSRA-regulated firm: identity, devices, data, logging and licences, with a 30-day order of work.
4 min read · Reviewed 19 September 2026
Audit readiness

IT audit readiness for DIFC and ADGM firms: an evidence-first checklist

How to be ready when a regulator, auditor or client asks for proof of your IT and security controls: the evidence pack, a mock audit and a six-week plan.
3 min read · Reviewed 19 September 2026

Talk to a specialist about your obligations

Tell us about your firm and your regulator, and we will suggest a practical first step, whether that is a gap assessment or ongoing support.