top of page

The Assurance Gap in UAE IA Standard v2 — and How CAF v4.0 Closes It

Writer: PRAECEPTA CS
PRAECEPTA CS
Mar 28
8 min read

A PRAECEPTA Cybersecurity Perspective | September 2026



Executive Summary


The UAE Cyber Security Council published UAE Information Assurance Standard v2 on 22 September 2025, superseding the 2020 Information Assurance Regulation v1.1. Alongside the National Cybersecurity Strategy 2025–2031 (Cabinet-approved February 2025) and the National Cyber Accreditation Programme (NCAP) now rolling out through 2026, UAE Critical Information Infrastructure operators face the most substantive shift in national cyber obligations in five years.


UAE IA v2 remains, by design, a structured control catalogue — 15 families across M1–M6 (management) and T1–T9 (technical), with risk-based applicability and priority tiering. It tells you what controls must exist. It is considerably less prescriptive about how you demonstrate those controls actually work under adversary pressure.


That is the assurance gap. And it is where the UK NCSC Cyber Assessment Framework v4.0 (released 4 August 2025) has practical value — not as a replacement for UAE regulatory obligation, but as an internal assurance instrument that tests outcomes before a regulator does.


PRAECEPTA's position: run UAE IA v2 as your compliance baseline and CAF v4.0 as your effectiveness engine. The two are complementary, not competing. Organisations that operate both consistently outperform those running compliance alone — because they discover control failure on their own timetable rather than the auditor's.



Here is why adopting the NCSC CAF is the strategic advantage your organisation needs to master UAE IA v2.



1. The Real Problem: Control Existence ≠ Control Efficacy


Most UAE compliance programmes can answer the first-order question comfortably:


  • Is there a documented incident response plan? Yes.

  • Is there a patch management policy? Yes.

  • Is privileged access restricted by policy? Yes.


The harder questions determine whether you are actually defensible:


  • When last exercised, did the response plan measurably reduce time-to-containment — and were critical suppliers in the exercise?

  • What is your patch coverage as a percentage of the asset estate, and how confident are you that the denominator is complete?

  • Is least privilege technically enforced for privileged, service, and third-party accounts — or asserted in a document?


UAE IA v2 will hold you to the second set. A control catalogue alone will not prepare you for them. An outcome framework will.



2. What Changed in CAF v4.0 — and Why It Matters in the Gulf


CAF v4.0 comprises 4 objectives, 14 principles, and 41 contributing outcomes. The August 2025 revision is not cosmetic, and its changes map unusually well onto the MEA threat picture.

CAF v4.0 change

Regional relevance

A2.b Understanding Threat (new)

Requires understanding of adversary capability, method and motivation. For Gulf CII, that means specific engagement with regionally active clusters — OilRig/APT34, MuddyWater, Shamoon/Disttrack wiper lineage — not generic threat feeds.

A4.b Secure Software Development and Support (new)

Extends supply chain assurance into software provenance, internal development, and third-party code. Aligns directly with the vendor verification pressure NCAP will create in 2026.

C1.f (new)

Understanding user and system behaviour, using threat intelligence to surface anomalies — a decisive step beyond log aggregation.

C2 Threat Hunting (rewritten; formerly Proactive Discovery)

Explicit expectation of active, hypothesis-driven hunting.

D1 Response and Recovery (strengthened)

Realistic, tested plans with supplier participation.

AI and automation risk (woven throughout)

Distributed across relevant outcomes rather than isolated — the correct architectural treatment, and increasingly material as UAE entities adopt AI at pace.



3. Three Defensible Benefits — Stated Accurately


3.1 Prioritisation Within Mandated Scope

Regulatory caution — read this carefully. In the UAE, CII designation is determined by the Cyber Security Council and sector regulators. It is not self-assessed. CAF's "Essential Functions" concept originates in the UK NIS Regulations 2018 and does not transfer as a scope-reduction argument. Any attempt to use CAF scoping to narrow a regulator-assigned boundary should be expected to fail.

Used correctly, CAF's function-led thinking helps you sequence remediation and allocate budget within mandated scope — establishing which essential functions carry the greatest impact, and therefore which controls warrant investment first. That is a genuine planning advantage. It is not a scope negotiation instrument, and we do not present it as one.


3.2 Supply Chain and Software Assurance — Now Time-Critical


Third-Party Security (T6) has been part of UAE IA since v1.1; it is not a new requirement. What is new is the enforcement environment. As NCAP rolls out during 2026, CII entities should anticipate tighter obligations to verify that cybersecurity service providers — MSSPs, cloud vendors, assessors — hold UAE accreditation.


CAF A4.a (Supply Chain) and A4.b (Secure Software Development and Support) provide a structured basis for supplier assessment that goes beyond questionnaire attestation into software provenance and SBOM analysis. Its contributing outcomes are a credible foundation for a tiered vendor assurance programme.


We describe A4 as structurally useful and well-drafted. We make no claim that it is an industry "gold standard" — no such consensus exists, and PRAECEPTA does not manufacture one.


3.3 Board-Legible Risk Reporting


CAF's four objectives translate technical posture into language a board can act on:


  1. Managing Security Risk

  2. Protecting Against Attack

  3. Detecting Events

  4. Minimising Impact


A board can absorb "we are Amber on Detecting Events" far more readily than "partial non-conformity, control T3.4.2." The framing shifts the conversation from cyber security to business resilience — which is where remediation budget is actually approved.



4. Indicative CAF v4.0 → UAE IA v2 Mapping

Validation note: Built on the published M1–M6 / T1–T9 family structure. Because v2 reorganised sub-families and realigned to ISO/IEC 27002:2022, family nomenclature and sub-control references must be confirmed against the controlled CSC v2 document before client issue. Mapping is indicative directional alignment, not regulator-endorsed equivalence.

CAF v4.0 Objective

CAF Principle

Indicative UAE IA v2 Family

Assurance value added by CAF

A. Managing Security Risk

A1 Governance

M1 Strategy & Planning; M6 Performance Evaluation & Improvement

Evidences genuine board engagement and accountable ownership, not signed-off documents


A2 Risk Management (incl. A2.b Understanding Threat)

M2 Information Security Risk Management

Tests whether risk decisions are informed by real adversary capability — the weakest link in most UAE risk registers


A3 Asset Management

T1 Asset Management

Drives asset inventory completeness and currency, the precondition for defensible scoping


A4 Supply Chain (incl. A4.b Secure Software Development & Support)

T6 Third-Party Security; T7 ISADM

Extends vendor assurance into software provenance and SBOM — directly relevant to NCAP-driven vendor verification

B. Protecting Against Attack

B1 Service Protection Policies, Processes & Procedures

M1; T3 Operations Management

Tests operational reality of policy, not existence of policy


B2 Identity & Access Control

T5 Access Control

Validates least privilege as enforced, including privileged and third-party access


B3 Data Security

T4 Communications; T3 Operations Mgmt

Data-at-rest/in-transit protection; interacts with the national encryption policy and UAE data residency duties


B4 System Security

T3 Operations Mgmt; T7 ISADM

Patch and secure-configuration hygiene, evidenced by coverage metrics


B5 Resilient Networks & Systems

T3; T9 Continuity Management

Segmentation and architectural resilience — omitted from the original draft


B6 Staff Awareness & Training

M3 Awareness & Training; M4 HR Security

Measures behavioural change, not training completion percentages

C. Detecting Events

C1 Security Monitoring (incl. C1.f)

T3 Operations Mgmt; T8 Incident Mgmt

Moves from log collection to detection efficacy against defined use cases


C2 Threat Hunting (v4.0 — formerly Proactive Discovery)

T3; T8

Builds hypothesis-driven hunting capability against regionally relevant TTPs

D. Minimising Impact

D1 Response & Recovery Planning

T8 Incident Management; T9 Continuity Management

Tests demonstrated restoration capability and supplier involvement, not plan existence


D2 Lessons Learned

M6 Performance Evaluation & Improvement

Evidences a closed continuous-improvement loop

Methodological caveat: This mapping expresses directional alignment for internal assurance purposes only. It is not endorsed by the UAE Cyber Security Council or the NCSC, and does not constitute evidence of UAE IA compliance in itself. Because v2 reorganised sub-families and realigned to ISO/IEC 27001:2022 and ISO/IEC 27002:2022, all family and sub-control references must be validated against the controlled CSC v2 publication for your entity and sector.


5. Sector Overlays You Cannot Ignore

UAE IA v2 rarely operates alone. Depending on sector and emirate, expect concurrent obligations:

Sector / jurisdiction

Additional framework

Banking & finance

CBUAE Cybersecurity Framework

Abu Dhabi healthcare

ADHICS v2 (Department of Health)

Dubai government entities

DESC ISR v3

DIFC / ADGM entities

DIFC Data Protection Law 2020 / ADGM Data Protection Regulations 2021

All CII

National encryption policy and executive regulation (approved late 2025)

Entities with EU nexus

NIS2 (EU) 2022/2555; DORA (EU) 2022/2554 for financial entities

Data sovereignty flag: where CAF-based assessment evidence, log data, or assessment artefacts are processed by non-UAE providers or stored outside the UAE, review residency obligations under UAE IA v2, the applicable sector framework, and any DIFC/ADGM data protection regime before engagement commencement. This is a recurring failure point in cross-border assurance work.



6. A Realistic Implementation Pathway


We have deliberately corrected the timelines and deliverables commonly overpromised in this market.


  1. Confirm your regulatory baseline. Obtain the controlled UAE IA v2 publication and your CII designation and priority tiering from the CSC or your sector regulator. Do not proceed on secondary summaries or vendor blog content.

  2. Establish the CAF v4.0 reference set. Download CAF v4.0 and its Indicators of Good Practice directly from NCSC. Note that the relevant NCSC assurance vehicle for independent CAF audit is the Cyber Resilience Audit (CRA) scheme; in UK central government, CAF is applied via GovAssure. There is no NCSC publication called "CAF Ready" — treat any source citing one as unreliable.

  3. Run a scoped outcome assessment. For a single essential function, assess against all 14 principles and applicable contributing outcomes. Realistic duration: 10–15 working days including evidence gathering and validation. A five-day exercise across 41 contributing outcomes is not a credible CII-scale assessment, and we will not scope one.

  4. Produce a Target Implementation Plan (TIP). A prioritised, costed remediation roadmap with named owners and dates, correlating each CAF outcome gap to the corresponding UAE IA v2 family and sub-control. (Note: "TIP" here means Target Implementation Plan — not a threat intelligence platform.)

  5. Correlate to predicted audit findings. Where CAF C1/C2 outcomes are not achieved, expect corresponding pressure on UAE IA monitoring and incident management controls (T3, T8). Treat CAF gaps as leading indicators.

  6. Remediate root cause, then re-test. Close the loop and evidence it — CAF D2 and UAE IA M6 both require demonstrated continuous improvement.

  7. Verify your assurance partners' accreditation status. As NCAP matures through 2026, confirm that assessors, MSSPs and cloud providers serving your CII estate hold current UAE accreditation. Apply this test to PRAECEPTA as rigorously as to any other provider.



7. PRAECEPTA's Assessment

The prevailing market narrative frames UAE IA v2 as a wholesale shift from checklist to outcomes. That is an overstatement, and repeating it does clients a disservice.


UAE IA v2 is a modernised, ISO-aligned, risk-tiered control catalogue. It is a significant improvement. It is not an outcome-based maturity framework, and it does not natively answer "can you prove this control works?"


The CAF is outcome-based. That is precisely why the pairing works — and why it is more honest and more useful to present CAF as an assurance layer above a compliance baseline than as a compliance substitute or shortcut.


Organisations that internalise this distinction stop treating audit as an event to survive and start treating assurance as a capability to operate. That is the difference between a compliant organisation and a resilient one — and only one of those categories reliably withstands a determined adversary.



Engage PRAECEPTA


CAF v4.0 → UAE IA v2 Readiness Assessment. Scoped to your designated essential functions, delivered against CAF v4.0's 41 contributing outcomes, correlated to your applicable UAE IA v2 families and sector overlays, and reported to both technical and board audiences.

Disclaimer. This document constitutes security architecture and assurance guidance. It does not constitute legal advice. Engage qualified UAE-licensed legal counsel for binding interpretation of the UAE Information Assurance Standard v2, sector-specific regulation, data protection obligations, and cross-border data transfer requirements. Framework mappings are indicative for internal assurance planning and are not endorsed by the UAE Cyber Security Council or the UK NCSC. All references must be validated against controlled source publications applicable to your entity, sector and emirate at the time of use.

Comments


bottom of page