Table of Contents
Frequently Asked Questions
1. Is penetration testing mandatory in the UAE?
Yes. VAPT is mandated across UAE regulated sectors under NESA, TDRA and CBUAE frameworks, per Raidefend, with non-compliance carrying fines up to AED 5 million and operational restrictions on regulated entities.
2. How much do UAE penetration testing engagements cost?
UAE VAPT engagements typically range from AED 35,000 for basic SME assessments to AED 180,000-plus for comprehensive enterprise red team engagements, per ITSEC, scaled by scope, testing depth and compliance requirements.
3. Do I need Dubai Cyber Force accreditation to run VAPT?
Yes, for government and semi-government entities. Companies providing penetration testing to Dubai government or semi-government clients must be accredited Cyber Force providers through Dubai Electronic Security Center, per Raidefend documentation.
4. Do I need third-party approval to open a VAPT firm?
No third-party approval is required for activity 6202.95 at the trade license stage. Sector-specific accreditations like Dubai Cyber Force may be required depending on the client base you serve.
5. What frameworks does cyber audit and testing cover in the UAE?
UAE cyber audit and VAPT services support submissions under NESA IA Standards v2.1, CBUAE IAR, DESC Dubai Cyber Force, ISO 27001, PCI DSS, ADHICS for healthcare, PDPL and SCA guidelines for capital markets clients.
How to Start an Auditing, Reviewing and Testing Cyber Risks Business in Dubai
A UAE bank cannot pass its annual CBUAE audit without one. A Dubai government entity cannot renew a contract without one. A hospital cannot certify against ADHICS without one. A retailer cannot accept card payments without one. Vulnerability assessment and penetration testing (VAPT) has become a UAE regulatory line item, with non-compliance fines reaching AED 5 million and engagement pricing running AED 35,000 to AED 180,000-plus depending on scope.
Mordor Intelligence1 values the UAE cybersecurity market at USD 0.82 billion in 2025, forecast to USD 1.51 billion by 2031 at 10.66% CAGR, with banking, financial services and insurance holding the largest end-user share at 19.56% of 2025 outlays and audit-driven compliance a primary spending driver. ITSEC2 reports UAE penetration testing engagements typically range from AED 35,000 for basic SME assessments to AED 180,000-plus for comprehensive enterprise red team engagements, with pricing scaled by scope, testing depth and compliance framework requirements. Raidefend3 reports VAPT is mandated across UAE regulated sectors under NESA, TDRA and CBUAE frameworks, with non-compliance carrying fines up to AED 5 million and operational restrictions, and Dubai Cyber Force accreditation required for testing government and semi-government entities. Finesse Cyberhub4 reports its VAPT services support regulatory submissions under NESA, CBUAE Information Assurance Regulations, DESC Dubai Cyber Force, ISO 27001 and PCI DSS, with the firm serving 80%-plus of UAE banks and 70%-plus of UAE insurers as recurring clients.
Whether you are running a VAPT firm serving UAE banks and financial institutions, a red team practice for enterprise adversarial simulation, a compliance audit firm supporting NESA, CBUAE IAR and ISO 27001 certification programmes, or a niche penetration testing consultancy for cloud, mobile applications or IoT and OT environments, this activity covers auditing, reviewing and testing of cyber risks for enterprise clients.
A Testing Market Anchored by Regulatory Mandate
A Dubai-licensed cyber audit and VAPT firm operates in a UAE market where 188 IA Standard controls, CBUAE regulations and Dubai Cyber Force accreditation drive mandatory testing, with typical engagements running AED 35,000 to AED 180,000-plus and non-compliance fines reaching AED 5 million.

Sources: Mordor Intelligence (2026), ITSEC (2026), Raidefend (2026), Finesse Cyberhub (2026)
Who is this activity for?
- VAPT & PENETRATION TESTING FIRMS: You run a vulnerability assessment and penetration testing firm serving UAE banks, insurers, government entities, healthcare and critical infrastructure. You conduct external, internal, web application, mobile and cloud penetration tests with CREST-certified engineers and deliver audit-ready reports supporting NESA, CBUAE and PCI DSS submissions.
- RED TEAM & OFFENSIVE SECURITY FIRMS: You run adversarial simulation, red team engagements, purple team exercises and threat-informed testing for enterprise clients. You emulate advanced persistent threats, nation-state adversaries and sophisticated attack chains, delivering realistic attack narratives to CISO and board audiences seeking beyond-compliance security validation.
- COMPLIANCE AUDIT & GRC ASSESSMENT FIRMS: You run compliance audit programmes for NESA IA Standards v2.1, CBUAE Information Assurance Regulations, DESC Dubai Cyber Force, ISO 27001, PCI DSS and ADHICS certification. You conduct gap assessments, internal audits, evidence collection and pre-external-audit reviews for regulated UAE enterprises.
6202.95 — Auditing, Reviewing & Testing Cyber Risks
Under this activity, you can run a cyber risk auditing, reviewing and testing business serving enterprise and regulated clients. Service range covers vulnerability assessment and penetration testing (VAPT), red team and adversarial simulation, compliance audit and gap assessment against NESA, CBUAE IAR, DESC and international frameworks, application security testing, cloud and mobile penetration testing, and OT and ICS security assessment services.
This activity covers auditing, reviewing and testing of cyber risks. It does not cover the separate sale of computer hardware or software (4651, 4741), the separate installation of mainframe and similar computers (3320), separate installation of personal computers (6209) or separate software installation (6209).
In short: if you are running a VAPT, red team, penetration testing or compliance audit firm assessing cyber risks, this is your activity.
Third-party approval
No third-party approval is required.
Anti-money laundering compliance
This business activity is exempt from AML compliance requirements.
Footnotes
¹ Mordor Intelligence, "UAE Cybersecurity Market Report Industry Analysis, Size & Forecast", March 2026.
² ITSEC, "Penetration Testing & VAPT Services Dubai UAE", 2026.
³ Raidefend, "Vulnerability Assessment and Penetration Testing in UAE", May 2026.
⁴ Finesse Cyberhub, "Penetration Testing Dubai & UAE | VAPT Services", June 2026.














