The Assurance Gap in UAE IA Standard v2 — and How CAF v4.0 Closes It

A PRAECEPTA Cybersecurity Perspective | September 2026
Executive Summary
The UAE Cyber Security Council published UAE Information Assurance Standard v2 on 22 September 2025, superseding the 2020 Information Assurance Regulation v1.1. Alongside the National Cybersecurity Strategy 2025–2031 (Cabinet-approved February 2025) and the National Cyber Accreditation Programme (NCAP) now rolling out through 2026, UAE Critical Information Infrastructure operators face the most substantive shift in national cyber obligations in five years.
UAE IA v2 remains, by design, a structured control catalogue — 15 families across M1–M6 (management) and T1–T9 (technical), with risk-based applicability and priority tiering. It tells you what controls must exist. It is considerably less prescriptive about how you demonstrate those controls actually work under adversary pressure.
That is the assurance gap. And it is where the UK NCSC Cyber Assessment Framework v4.0 (released 4 August 2025) has practical value — not as a replacement for UAE regulatory obligation, but as an internal assurance instrument that tests outcomes before a regulator does.
PRAECEPTA's position: run UAE IA v2 as your compliance baseline and CAF v4.0 as your effectiveness engine. The two are complementary, not competing. Organisations that operate both consistently outperform those running compliance alone — because they discover control failure on their own timetable rather than the auditor's.

Here is why adopting the NCSC CAF is the strategic advantage your organisation needs to master UAE IA v2.
1. The Real Problem: Control Existence ≠ Control Efficacy
Most UAE compliance programmes can answer the first-order question comfortably:
Is there a documented incident response plan? Yes.
Is there a patch management policy? Yes.
Is privileged access restricted by policy? Yes.
The harder questions determine whether you are actually defensible:
When last exercised, did the response plan measurably reduce time-to-containment — and were critical suppliers in the exercise?
What is your patch coverage as a percentage of the asset estate, and how confident are you that the denominator is complete?
Is least privilege technically enforced for privileged, service, and third-party accounts — or asserted in a document?
UAE IA v2 will hold you to the second set. A control catalogue alone will not prepare you for them. An outcome framework will.
2. What Changed in CAF v4.0 — and Why It Matters in the Gulf
CAF v4.0 comprises 4 objectives, 14 principles, and 41 contributing outcomes. The August 2025 revision is not cosmetic, and its changes map unusually well onto the MEA threat picture.
CAF v4.0 change | Regional relevance |
A2.b Understanding Threat (new) | Requires understanding of adversary capability, method and motivation. For Gulf CII, that means specific engagement with regionally active clusters — OilRig/APT34, MuddyWater, Shamoon/Disttrack wiper lineage — not generic threat feeds. |
A4.b Secure Software Development and Support (new) | Extends supply chain assurance into software provenance, internal development, and third-party code. Aligns directly with the vendor verification pressure NCAP will create in 2026. |
C1.f (new) | Understanding user and system behaviour, using threat intelligence to surface anomalies — a decisive step beyond log aggregation. |
C2 Threat Hunting (rewritten; formerly Proactive Discovery) | Explicit expectation of active, hypothesis-driven hunting. |
D1 Response and Recovery (strengthened) | Realistic, tested plans with supplier participation. |
AI and automation risk (woven throughout) | Distributed across relevant outcomes rather than isolated — the correct architectural treatment, and increasingly material as UAE entities adopt AI at pace. |
3. Three Defensible Benefits — Stated Accurately
3.1 Prioritisation Within Mandated Scope
Regulatory caution — read this carefully. In the UAE, CII designation is determined by the Cyber Security Council and sector regulators. It is not self-assessed. CAF's "Essential Functions" concept originates in the UK NIS Regulations 2018 and does not transfer as a scope-reduction argument. Any attempt to use CAF scoping to narrow a regulator-assigned boundary should be expected to fail.
Used correctly, CAF's function-led thinking helps you sequence remediation and allocate budget within mandated scope — establishing which essential functions carry the greatest impact, and therefore which controls warrant investment first. That is a genuine planning advantage. It is not a scope negotiation instrument, and we do not present it as one.
3.2 Supply Chain and Software Assurance — Now Time-Critical
Third-Party Security (T6) has been part of UAE IA since v1.1; it is not a new requirement. What is new is the enforcement environment. As NCAP rolls out during 2026, CII entities should anticipate tighter obligations to verify that cybersecurity service providers — MSSPs, cloud vendors, assessors — hold UAE accreditation.
CAF A4.a (Supply Chain) and A4.b (Secure Software Development and Support) provide a structured basis for supplier assessment that goes beyond questionnaire attestation into software provenance and SBOM analysis. Its contributing outcomes are a credible foundation for a tiered vendor assurance programme.
We describe A4 as structurally useful and well-drafted. We make no claim that it is an industry "gold standard" — no such consensus exists, and PRAECEPTA does not manufacture one.
3.3 Board-Legible Risk Reporting
CAF's four objectives translate technical posture into language a board can act on:
Managing Security Risk
Protecting Against Attack
Detecting Events
Minimising Impact
A board can absorb "we are Amber on Detecting Events" far more readily than "partial non-conformity, control T3.4.2." The framing shifts the conversation from cyber security to business resilience — which is where remediation budget is actually approved.
4. Indicative CAF v4.0 → UAE IA v2 Mapping
Validation note: Built on the published M1–M6 / T1–T9 family structure. Because v2 reorganised sub-families and realigned to ISO/IEC 27002:2022, family nomenclature and sub-control references must be confirmed against the controlled CSC v2 document before client issue. Mapping is indicative directional alignment, not regulator-endorsed equivalence.
CAF v4.0 Objective | CAF Principle | Indicative UAE IA v2 Family | Assurance value added by CAF |
A. Managing Security Risk | A1 Governance | M1 Strategy & Planning; M6 Performance Evaluation & Improvement | Evidences genuine board engagement and accountable ownership, not signed-off documents |
A2 Risk Management (incl. A2.b Understanding Threat) | M2 Information Security Risk Management | Tests whether risk decisions are informed by real adversary capability — the weakest link in most UAE risk registers | |
A3 Asset Management | T1 Asset Management | Drives asset inventory completeness and currency, the precondition for defensible scoping | |
A4 Supply Chain (incl. A4.b Secure Software Development & Support) | T6 Third-Party Security; T7 ISADM | Extends vendor assurance into software provenance and SBOM — directly relevant to NCAP-driven vendor verification | |
B. Protecting Against Attack | B1 Service Protection Policies, Processes & Procedures | M1; T3 Operations Management | Tests operational reality of policy, not existence of policy |
B2 Identity & Access Control | T5 Access Control | Validates least privilege as enforced, including privileged and third-party access | |
B3 Data Security | T4 Communications; T3 Operations Mgmt | Data-at-rest/in-transit protection; interacts with the national encryption policy and UAE data residency duties | |
B4 System Security | T3 Operations Mgmt; T7 ISADM | Patch and secure-configuration hygiene, evidenced by coverage metrics | |
B5 Resilient Networks & Systems | T3; T9 Continuity Management | Segmentation and architectural resilience — omitted from the original draft | |
B6 Staff Awareness & Training | M3 Awareness & Training; M4 HR Security | Measures behavioural change, not training completion percentages | |
C. Detecting Events | C1 Security Monitoring (incl. C1.f) | T3 Operations Mgmt; T8 Incident Mgmt | Moves from log collection to detection efficacy against defined use cases |
C2 Threat Hunting (v4.0 — formerly Proactive Discovery) | T3; T8 | Builds hypothesis-driven hunting capability against regionally relevant TTPs | |
D. Minimising Impact | D1 Response & Recovery Planning | T8 Incident Management; T9 Continuity Management | Tests demonstrated restoration capability and supplier involvement, not plan existence |
D2 Lessons Learned | M6 Performance Evaluation & Improvement | Evidences a closed continuous-improvement loop |
Methodological caveat: This mapping expresses directional alignment for internal assurance purposes only. It is not endorsed by the UAE Cyber Security Council or the NCSC, and does not constitute evidence of UAE IA compliance in itself. Because v2 reorganised sub-families and realigned to ISO/IEC 27001:2022 and ISO/IEC 27002:2022, all family and sub-control references must be validated against the controlled CSC v2 publication for your entity and sector.
5. Sector Overlays You Cannot Ignore
UAE IA v2 rarely operates alone. Depending on sector and emirate, expect concurrent obligations:
Sector / jurisdiction | Additional framework |
Banking & finance | CBUAE Cybersecurity Framework |
Abu Dhabi healthcare | ADHICS v2 (Department of Health) |
Dubai government entities | DESC ISR v3 |
DIFC / ADGM entities | DIFC Data Protection Law 2020 / ADGM Data Protection Regulations 2021 |
All CII | National encryption policy and executive regulation (approved late 2025) |
Entities with EU nexus | NIS2 (EU) 2022/2555; DORA (EU) 2022/2554 for financial entities |
Data sovereignty flag: where CAF-based assessment evidence, log data, or assessment artefacts are processed by non-UAE providers or stored outside the UAE, review residency obligations under UAE IA v2, the applicable sector framework, and any DIFC/ADGM data protection regime before engagement commencement. This is a recurring failure point in cross-border assurance work.
6. A Realistic Implementation Pathway
We have deliberately corrected the timelines and deliverables commonly overpromised in this market.
Confirm your regulatory baseline. Obtain the controlled UAE IA v2 publication and your CII designation and priority tiering from the CSC or your sector regulator. Do not proceed on secondary summaries or vendor blog content.
Establish the CAF v4.0 reference set. Download CAF v4.0 and its Indicators of Good Practice directly from NCSC. Note that the relevant NCSC assurance vehicle for independent CAF audit is the Cyber Resilience Audit (CRA) scheme; in UK central government, CAF is applied via GovAssure. There is no NCSC publication called "CAF Ready" — treat any source citing one as unreliable.
Run a scoped outcome assessment. For a single essential function, assess against all 14 principles and applicable contributing outcomes. Realistic duration: 10–15 working days including evidence gathering and validation. A five-day exercise across 41 contributing outcomes is not a credible CII-scale assessment, and we will not scope one.
Produce a Target Implementation Plan (TIP). A prioritised, costed remediation roadmap with named owners and dates, correlating each CAF outcome gap to the corresponding UAE IA v2 family and sub-control. (Note: "TIP" here means Target Implementation Plan — not a threat intelligence platform.)
Correlate to predicted audit findings. Where CAF C1/C2 outcomes are not achieved, expect corresponding pressure on UAE IA monitoring and incident management controls (T3, T8). Treat CAF gaps as leading indicators.
Remediate root cause, then re-test. Close the loop and evidence it — CAF D2 and UAE IA M6 both require demonstrated continuous improvement.
Verify your assurance partners' accreditation status. As NCAP matures through 2026, confirm that assessors, MSSPs and cloud providers serving your CII estate hold current UAE accreditation. Apply this test to PRAECEPTA as rigorously as to any other provider.
7. PRAECEPTA's Assessment
The prevailing market narrative frames UAE IA v2 as a wholesale shift from checklist to outcomes. That is an overstatement, and repeating it does clients a disservice.
UAE IA v2 is a modernised, ISO-aligned, risk-tiered control catalogue. It is a significant improvement. It is not an outcome-based maturity framework, and it does not natively answer "can you prove this control works?"
The CAF is outcome-based. That is precisely why the pairing works — and why it is more honest and more useful to present CAF as an assurance layer above a compliance baseline than as a compliance substitute or shortcut.
Organisations that internalise this distinction stop treating audit as an event to survive and start treating assurance as a capability to operate. That is the difference between a compliant organisation and a resilient one — and only one of those categories reliably withstands a determined adversary.
Engage PRAECEPTA
CAF v4.0 → UAE IA v2 Readiness Assessment. Scoped to your designated essential functions, delivered against CAF v4.0's 41 contributing outcomes, correlated to your applicable UAE IA v2 families and sector overlays, and reported to both technical and board audiences.
Disclaimer. This document constitutes security architecture and assurance guidance. It does not constitute legal advice. Engage qualified UAE-licensed legal counsel for binding interpretation of the UAE Information Assurance Standard v2, sector-specific regulation, data protection obligations, and cross-border data transfer requirements. Framework mappings are indicative for internal assurance planning and are not endorsed by the UAE Cyber Security Council or the UK NCSC. All references must be validated against controlled source publications applicable to your entity, sector and emirate at the time of use.




Comments