Security & Compliance

NESA, ISR and PDPL —
on the build side.

NESA, DESC ISR v3 and PDPL now bite on architecture, not policy. We map them onto your actual services and data stores, then close the engineering half — with residency boundaries designed in, not retrofitted.

188
NESA controls, 128 of them technical
13
ISR v3 domains, on top of ISO 27001
AED 5m
Maximum PDPL penalty
Trusted by 32+ teams shipping remote engineering, today
Razorpay
Naamly
Tekdoors
SimAgro
Enzen Technologies
Greenlink Health
R360
SharafDG
Concourse Solutions
YOptima
ReMarketplace
Desisiv
Dealflow
LIAISON
Stealth Connect
Car Concierge Pro
Dinner Daddy
Heal Me Fit
Heather Hakes
Kegelbell
Laina
MogiFit
Visag
YouthRenewal
OC Weight Loss
USPTO Lawmatics
Delegata
AZCap
Mindbase
WeBuyUglyBuildings
One Collab Space
Epifinder
Razorpay
Naamly
Tekdoors
SimAgro
Enzen Technologies
Greenlink Health
R360
SharafDG
Concourse Solutions
YOptima
ReMarketplace
Desisiv
Dealflow
LIAISON
Stealth Connect
Car Concierge Pro
Dinner Daddy
Heal Me Fit
Heather Hakes
Kegelbell
Laina
MogiFit
Visag
YouthRenewal
OC Weight Loss
USPTO Lawmatics
Delegata
AZCap
Mindbase
WeBuyUglyBuildings
One Collab Space
Epifinder
Why it matters

Most UAE compliance advice stops at a policy set. The obligations that actually bite are architectural: which data may leave the country, which processing must happen in-country, and whether your free-zone entity is subject to a stricter transfer regime than the federal one. Those are design decisions, and they get very expensive to retrofit.

Benefits

Why teams choose us.

Mapped To Your Architecture

NESA and ISR controls traced onto your actual services, data stores and pipelines — not a spreadsheet of control text with your logo on it.

Residency Designed In

We establish what must stay in-country before you build around an assumption you cannot keep. Health data and Dubai government data have hard localisation.

Free Zone vs Federal

DIFC and ADGM are stricter than the federal regime and neither lists India as an adequate jurisdiction. We work out which regime you are actually in — most clients have not.

Dubai-Fronted Delivery

Our MENA office fronts the engagement and the account management. Engineering is delivered from Mumbai, and we tell you that up front because your regulator will ask.

What we offer

The full menu.

NESA / UAE IA Mapping

  • 60 management and 128 technical controls
  • Traced to services and owners
  • Priority ordered by regulatory exposure
  • Gap register with engineer-day costings

DESC ISR v3

  • 13 domains assessed against your estate
  • Mapped onto existing ISO 27001 controls
  • In-country processing boundaries identified
  • Dubai government pipeline requirements flagged

Data Residency Architecture

  • Data classification and flow mapping
  • In-country processing boundary design
  • Health and financial localisation checks
  • Cross-border transfer inventory

Free Zone Transfer Position

  • DIFC or ADGM applicability assessment
  • Recipient-jurisdiction assessment where required
  • Article 42 safeguards where India is in the chain
  • Federal PDPL position documented

Remediation Plan

  • Every gap costed in engineer-days
  • Sequenced by regulatory exposure
  • Build-vs-buy called per item
  • Deliverable as a Remediation Pod if you want us to ship it
How it works

Our process.

01

Establish The Regime

Mainland, DIFC or ADGM — and whether any sectoral localisation applies. This determines everything downstream and is frequently misunderstood.

02

Map Data & Controls

Data classification, flow mapping, then NESA and ISR controls traced onto real architecture with owners attached.

03

Design The Boundary

What stays in-country, what may transfer and under which safeguard. Documented so it survives a regulator asking.

04

Cost & Sequence

Every gap in engineer-days, ordered by exposure. You fund it, we ship it, or you take it in-house.

Tech stack

What we build with.

Regimes
UAE IA Standards (NESA)DESC ISR v3UAE Federal PDPLDIFC DP LawADGM DP Regulations
Baseline
ISO/IEC 27001:2022CIS Benchmarks
Infrastructure
AWS UAE regionsAzure UAETerraformData classification tooling
Right fit?

Choose this if...

You operate in the UAE and hold or are pursuing a mainland licence
You are subject to NESA, DESC ISR or sectoral UAE requirements
You have a DIFC or ADGM entity and have not established your transfer position
You are building or migrating and want the residency boundary decided before it is expensive
Right fit?

Honest about who this is for.

Pick us if

This will be a fit.

  • You are a mainland UAE commercial organisation, or a free-zone entity that knows which regime it is in
  • You want control mapping traced onto architecture, not a policy pack
  • You want the residency boundary decided at design time
  • You are comfortable with Dubai-fronted account management and offshore engineering
Skip us if

Honestly — not our zone.

  • You process health data. It may not be stored, processed or transferred outside the UAE, which closes offshore delivery outright
  • You are a Dubai government entity or run a regulated pipeline under DESC ISR requiring in-country processing — we decline rather than promise a workaround
  • You want certification against ISR or NESA. We do the engineering; assessment and certification come from elsewhere
  • You want Saudi coverage as the primary market. NCA ECC-2 effectively requires an in-Kingdom presence; we take KSA only as pull-through from a UAE client under the UAE contract
FAQ

Common questions, straight answers.

Is the UAE actually a regulated market now?

Yes, and recently. The National Cyber Security Strategy 2025–2031 turned guidance into obligation: security-by-design in technology, operations and vendor relationships, with the perimeter extended to supply-chain participants and cloud providers serving government.

Why do you keep separating free zone from mainland?

Because they are different legal regimes and it changes what we can do. ADGM publishes an adequate-jurisdictions list and India is not on it. DIFC's 2025 amendment added a private right of action in the DIFC Courts plus a mandatory assessment of whether data subjects get adequate protection in the recipient jurisdiction. The federal regime is the opposite — no adequacy list published and the Executive Regulations still unissued — which we treat as under-specified rather than permissive.

Can you handle our health data?

No. UAE law prohibits health data being stored, processed, generated or transferred outside the country, and our engineering is delivered from Mumbai. There is no scoping trick that fixes that, so we decline it.

Do you certify us against NESA or ISR?

No. We do the engineering and the control mapping; assessment and certification come from parties licensed to do it. Nothing we produce is an audit, attestation or certificate.

What about Saudi Arabia?

We take it only as pull-through from a UAE client with a KSA subsidiary, delivered under the UAE contract. NCA ECC-2's tiered model, in-Kingdom presence expectations and localisation make Saudi a Riyadh-entity market, and we do not have one.

How does this relate to ISO 27001?

DESC ISR v3 sits on top of ISO 27001:2022, so if you hold or are pursuing ISO 27001 much of the work carries over. That is usually the efficient order: ISO 27001 as the base, ISR and NESA as the UAE-specific overlay.

From $16,000· NESA, DESC ISR v3 and PDPL, on the build side

Ready to start?

Book a free 25-minute call. We'll scope the work, share examples, and send a plan within a week.

What else we do

One contract covers any of these.

Everything below runs on the same agreement, the same invoice and the same account team as UAE PDPL & ISR Engineering Readiness.

Security & Compliance

Compliance Readiness Assessment

A fixed-fee assessment of where you actually stand against SOC 2 or ISO 27001:2022, ending in a costed, sequenced remediation plan and a warm introduction to an auditor. We are not your auditor and legally cannot be — which is exactly why we can do this work.

From $12,500
Security & Compliance

Compliance Remediation Pod

Your platform lists eighty failing controls and your auditor is legally not allowed to close any of them. We put a security pod on the backlog — IAM, logging, encryption, cloud configuration, CI/CD hardening — and hand your auditor working evidence in the format they ask for.

From $15,000/mo
Tech & Dev

Agentic AI Development

Custom AI agents, LLM integrations, RAG pipelines, and intelligent automation built into your product. On the Secure Build tier, every agent ships with a threat model, tool-permission scoping, guardrails, and an adversarial eval suite running in your CI.

From $5,000/mo
Talent

Direct Hire

We source, vet, and shortlist senior engineers from a 100,000+ pool. You interview, offer, and own the employment.

$1,499 / hire
Marketing

Managed Growth

The whole digital operation for a business people physically visit — website built and maintained, SEO, AEO, GEO, Google Ads, email, campaigns, lead gen, and the automations behind them. One team, one fee, and ad spend passed through to the platforms at cost.

From $5,000/mo
Design

Graphic & Design Services

Brand systems, marketing collateral, and design-on-demand for product, social, and sales.

From $2,500/mo
All 18 services
WhatsApp us