TestUnity LLC

    TestUnity LLC

    Securing Technology, Empowering Innovation

    All articles
    ISO 27001ComplianceUAE

    ISO 27001 Certification in the UAE: A Step-by-Step Guide

    TestUnity Security Team25 August 20269 min read

    ISO/IEC 27001 is the international standard for information security management, and in the UAE it has quietly become a commercial prerequisite. Government tenders, banking partners, and enterprise procurement teams increasingly ask for it before they will sign. This guide walks through what certification actually involves, how long it takes, and where UAE organisations tend to get stuck.

    What ISO 27001 actually certifies

    A common misconception is that ISO 27001 certifies your product or your servers. It does not. It certifies your Information Security Management System (ISMS) — the set of policies, processes, roles and controls by which your organisation manages information risk. The certificate says an accredited body has audited that system and found it conforms to the standard.

    The current version is ISO/IEC 27001:2022, which restructured the Annex A controls into 93 controls across four themes: organisational, people, physical, and technological. If you were certified against the 2013 version, you are expected to transition.

    The path to certification

    1. Define the scope

    Scope is the single most important early decision. It defines which parts of the business, which locations, and which systems the ISMS covers. A tightly-drawn scope (for example, "the SaaS platform and its supporting corporate functions") is faster and cheaper to certify than "the entire company." Draw it around what your customers actually care about.

    2. Run a gap assessment

    A gap assessment measures your current state against the standard's requirements and the Annex A controls. The output is a prioritised remediation plan: which policies are missing, which controls are informal and need documenting, and where technical work is required. For most UAE SMEs this reveals 30–60 gaps of varying size.

    3. Build the ISMS

    This is the bulk of the work — typically two to four months:

    • Risk assessment and treatment. Identify information assets, assess risks, and decide how each is treated. This drives which Annex A controls apply.
    • Statement of Applicability (SoA). A register of all 93 controls stating whether each applies and why. Auditors live in this document.
    • Core policies. Information security policy, access control, cryptography, supplier security, incident response, business continuity, and more.
    • Operational evidence. The ISMS must be running, not just written. Access reviews, risk reviews, management reviews, and internal audits all need to have actually happened.

    4. Internal audit and management review

    Before the certification body arrives, you must audit yourself and hold a formal management review. This is a requirement, not a formality — the external auditor will ask to see both.

    5. Stage 1 and Stage 2 audits

    Certification is a two-stage external audit:

    • Stage 1 is a documentation review. The auditor checks your ISMS is designed correctly and you are ready. Minor findings here are normal.
    • Stage 2 is the main event: the auditor tests whether the controls actually operate, interviewing staff and sampling evidence. Pass it and you receive a certificate valid for three years, subject to annual surveillance audits.

    How long does it take?

    For a UAE SME starting from scratch, four to eight months is realistic. The variables are scope size, how much security maturity already exists, and how quickly leadership can free up staff time. Organisations that already run cloud infrastructure with reasonable hygiene move faster than those documenting processes for the first time.

    What it costs

    Budget for two separate cost lines:

    1. The certification body (the auditor who issues the certificate) — priced by organisation size and scope, typically billed for Stage 1 + Stage 2 plus annual surveillance.
    2. The readiness work — building the ISMS, either with internal effort or a partner. This is usually the larger cost, and where good guidance pays for itself by avoiding a failed Stage 2.

    Note that the certification body and your readiness partner must be different — an accredited certifier cannot audit an ISMS it also built.

    Where UAE organisations get stuck

    • Scope creep. Trying to certify the whole company at once turns a four-month project into a year.
    • Documentation without operation. Beautiful policies that nobody follows fail Stage 2. Evidence of the system running is what auditors want.
    • Overlooking local context. UAE-specific obligations — the UAE Personal Data Protection Law (PDPL), and sector rules like the Dubai DESC standard or CBUAE requirements for financial firms — should be reflected in your risk assessment, not bolted on afterward.
    • Treating it as one-and-done. Surveillance audits recur annually; the ISMS has to stay alive.

    ISO 27001 or SOC 2?

    If your buyers are mostly in the US, you may hear SOC 2 requested instead. The two overlap heavily but serve different audiences and formats — we compare them directly in SOC 2 vs ISO 27001: which does your UAE business need?.

    Getting started

    The fastest way to de-risk certification is to start with a gap assessment so you know the size of the task before committing to an audit date. TestUnity runs ISO 27001 gap assessments and readiness programmes for UAE and GCC organisations, and can act as your readiness partner through to a successful Stage 2. Talk to our compliance team to scope it.