Table of Contents

Frequently Asked Questions

What does activity code 6202.95 permit a cyber risk testing business to do in Dubai

Activity code 6202.95, formally titled "Auditing, Reviewing & Testing Cyber Risks," permits a licensed entity to provide structured assessments of an organisation's digital security posture. Permitted services include penetration testing, vulnerability assessments, security architecture reviews, compliance audits, and red-team engagements.

There is an important operational distinction between passive and active services. Passive work — reviewing policies, assessing configurations, and producing gap analyses — sits comfortably within the licence scope. Active testing that simulates real attacks against live systems requires a clearly scoped, written contractual mandate from the client before work begins.

Is written client authorisation legally required before conducting active penetration tests in the UAE

Yes. Conducting active tests against live systems without written authorisation carries criminal liability under UAE cybercrime law, regardless of commercial intent or the tester's qualifications. A clearly scoped contractual mandate from the client is a non-negotiable prerequisite.

This requirement applies even when both parties have an existing commercial relationship. Each active engagement should be covered by its own documented scope of work specifying the systems, timeframes, and methods permitted.

Which regulatory authority oversees cyber risk testing businesses in the UAE

The Telecommunications and Digital Government Regulatory Authority (TDRA) is the primary body overseeing cybersecurity service providers operating in the UAE. It sets the overarching regulatory framework for firms in this sector.

Depending on the nature of your clients — particularly telecommunications operators or government-adjacent entities — sector-specific approvals or formal registration with the TDRA may be required before you commence active engagements. Firms serving critical national infrastructure operators should confirm their registration obligations early in the setup process.

What is the projected size and growth rate of the UAE cybersecurity market

According to Mordor Intelligence, the UAE cybersecurity market is projected to reach USD 1.3 billion by 2029, growing at a compound annual growth rate (CAGR) of approximately 14%. This growth is being driven by mandatory compliance frameworks, the UAE National Cybersecurity Strategy, and a measurable increase in incident frequency across both public and private sectors.

The UAE also ranks among the top three most targeted countries in the Middle East for cyberattacks, which directly intensifies demand for independent testing and assurance services.

Who are the primary target clients for a cyber risk testing business in Dubai

The main client segments include financial institutions, government contractors, healthcare providers, logistics operators, and mid-market SMEs expanding their digital footprint. Banks and insurance firms face regulatory pressure from the Central Bank of the UAE to demonstrate ongoing security assurance, making them reliable buyers of testing services.

Healthcare entities regulated by the Dubai Health Authority are increasingly required to evidence data security controls. Government contractors and entities operating near critical infrastructure also represent a significant and growing segment as compliance obligations tighten across the region.

What revenue models are common for cyber risk testing firms in the UAE

Revenue models typically combine two structures. Project-based engagements involve a defined deliverable — such as a penetration test report or compliance audit — billed as a one-time fee. These are common for new client relationships and specific regulatory deadlines.

Retainer arrangements are equally standard and arguably more valuable commercially. Clients pay a monthly fee for continuous monitoring, quarterly assessments, or on-call advisory support. Retainers produce predictable recurring revenue and are the preferred model among established cyber risk firms looking to build a stable, scalable business.

How does UAE Federal Decree-Law No. 45 of 2021 affect a cyber risk testing business

UAE Federal Decree-Law No. 45 of 2021 on Personal Data Protection imposes compliance obligations on any firm that handles client data during engagements. Because cyber risk testing often involves accessing, reviewing, or processing sensitive organisational data, your business will likely be subject to its requirements as a data processor.

Practically, this means you should have appropriate data handling agreements in place with clients, implement controls to limit data retention, and ensure your team understands their obligations when personal data is encountered during testing activities. Non-compliance can expose both your firm and your clients to regulatory risk.

Why is Meydan Free Zone mentioned as a suitable jurisdiction for setting up a cyber risk testing company in Dubai

Meydan Free Zone is highlighted as a route to establishing a fully-owned entity for cyber risk testing with minimal friction. Free zones in the UAE generally allow 100% foreign ownership, which is a significant advantage for international founders who do not want a local partner.

The activity code 6202.95 for auditing, reviewing, and testing cyber risks can be licensed through Meydan Free Zone, making it a practical starting point for founders targeting the UAE and broader regional market. The free zone structure also typically offers streamlined incorporation processes compared to mainland licensing routes, which can reduce time-to-market for new entrants.

How to Start a Cyber Risk Testing Business in Dubai

Dubai has gone digital fast, and the people who check whether all that new technology is safe are in short supply. Banks, hospitals, government contractors and logistics firms all want someone independent to try breaking into their systems before somebody else does. Demand has run well ahead of the number of qualified testers.

This guide covers what activity code 6202.95 lets you do, who pays for the work, and how to set up a fully owned company through Meydan Free Zone. The rules here are clear once you know them. The hard part is not the license. It is knowing where the line sits between advice and attack.

Key Stats at a Glance

Activity code6202.95
What it coversAuditing, reviewing & testing cyber risks
Main regulatorTelecommunications and Digital Government Regulatory Authority (TDRA) – TDRA
Data protection lawUAE Federal Decree-Law No. 45 of 2021 on Personal Data Protection
Market sizeUAE cybersecurity market set to reach USD 1.3 billion by 2029, growing about 14% a year – Mordor Intelligence
Threat levelUAE sits among the top three most targeted countries in the Middle East
Demand driverDubai's digital hub strategy – Digital Dubai
Typical license timeline5 to 7 working days for simple applications
Foreign ownership100% in Meydan Free Zone

What This License Covers

Infographic: How to Start a Cyber Risk Testing Business in Dubai

Code 6202.95 is titled Auditing, Reviewing and Testing Cyber Risks. It lets you assess how well an organisation is protected. In practice that means penetration testing, vulnerability assessments, security architecture reviews, compliance audits and red-team work.

One split matters more than any other. Passive work sits comfortably inside the license. You read policies, look at how systems are configured, and write up the gaps you find. Active testing is a different thing. The moment your team simulates a real attack on a live system, you need a written, clearly scoped mandate from that client first. Test without it and you face criminal liability under UAE cybercrime law. Good intentions do not save you, and neither do your qualifications.

Who Your Clients Will Be

Your buyers fall into five groups:

  • Banks, insurers and other financial institutions
  • Government contractors and entities working near critical infrastructure
  • Healthcare providers regulated by the Dubai Health Authority
  • Logistics operators
  • Mid-market SMEs growing their digital footprint

Banks and insurers are under pressure from the Central Bank of the UAE to show ongoing security assurance, so they buy testing again and again rather than once. Healthcare entities under the Dubai Health Authority increasingly have to evidence their data security controls too.

Money comes in two shapes. Project work is a one-off: a penetration test or a compliance audit with a defined report at the end. It is how most new client relationships start, and it is what people buy when a regulatory deadline is coming. Retainers are the better business. The client pays monthly for continuous monitoring, quarterly assessments or on-call advice, and you get income you can predict. That is the model established firms build on.

Mainland or Free Zone

FactorMainland (DET)Free Zone (Meydan Free Zone)
Who you sell toOpen UAE marketCorporate, regional and international clients
Foreign ownershipSet by DET rules for the activity100% yours, no local sponsor
OfficePhysical premises normally neededFlexi-desk covers the registered address
Setup routeApply through DETApply online, remote setup possible
TDRA dutiesApplyApply

A free zone license suits most testing firms, because the work travels to the client and the overheads stay low. A mainland license from the Department of Economy and Tourism makes more sense if you plan to sell straight into the local UAE market. Let your clients decide it, not the price.

[blockCTACostCalculator]

Step by Step Setup Guide

  • Step 1, book your trade name: Pick a name and check it does not clash with reserved terms or a company already on the register.
  • Step 2, confirm your activity code: Set 6202.95 as your main activity. If your service mix needs it, add related codes such as IT consulting now rather than later.
  • Step 3, send in your setup documents: You need passport copies for every shareholder and director, a short business plan, and the completed application forms.
  • Step 4, get the license issued: Simple applications usually come back in 5 to 7 working days once the documents are approved.
  • Step 5, sort visas and banking: Your package sets how many employment and investor visas you can apply for. Meydan Free Zone packages run from sole operators up to small teams. Take the license to the bank and open the corporate account.

Meydan Free Zone does not make you take a physical office to begin. A flexi-desk covers the registered address for a professional license, and the whole setup can be done remotely.

Compliance and What You Need in Place

TDRA oversight

The Telecommunications and Digital Government Regulatory Authority is the main body watching cybersecurity service providers in the UAE. If your clients are telecom operators or entities close to government or critical national infrastructure, you may need to register with TDRA or get sector approvals before you start active work. Check your client profile against current TDRA rules before you sign your first contract in those sectors.

Written scope of work

Every active testing job needs a written contract that names the systems in scope, the testing window, the methods you are allowed to use, and the limits on liability. An existing commercial relationship does not carry over. Each engagement gets its own signed scope.

Data protection

UAE Federal Decree-Law No. 45 of 2021 on Personal Data Protection applies to you directly. Your team will see or handle client data on almost every job, which makes you a data processor. You need data handling agreements with clients, controls that limit how long you keep anything, and a team that knows what to do when personal data turns up mid-test. Breaking the rules here puts both you and your client at risk.

Security clearances

Jobs with government entities or critical infrastructure operators may need individual consultants cleared before they can start. Build that into your timeline, because it can stretch onboarding by weeks.

Market Opportunity

Mordor Intelligence puts the UAE cybersecurity market at USD 1.3 billion by 2029, growing around 14% a year. Three things are pushing it: compliance frameworks that are now mandatory, the UAE National Cybersecurity Strategy, and a measurable rise in the number of incidents across public and private sectors.

The threat picture helps as well. The UAE sits among the top three most targeted countries in the Middle East for cyberattacks, and that fact alone sells independent testing to boards who used to treat it as optional. Digital Dubai keeps pushing the emirate as a regional technology hub, which widens the pool of organisations that need someone to check their work.

Conclusion

Cyber risk testing is a high-margin service with real demand and a client base that is still growing. The license itself is simple to get. What separates a firm that lasts from one that does not is discipline around scope, authorisation and data handling.

Three things decide how smoothly this goes: your written mandate on every active job, your TDRA position for regulated clients, and your data protection paperwork. Sort those and the rest is routine.

[blockCTAContact]

References

On-Demand Video
Live Chat
Call Us
WhatsApp