Qualysec
Blog

What Is DESC Cyber Force? Requirements & Compliance Guide

Discover the DESC Cyber compliance guidelines, key security controls, & steps UAE organizations can take to achieve and maintain compliance.

Published on August 19, 2026
Read Time: 20 min
CONNECT WITH US

Dubai has built one of the most structured cybersecurity oversight systems in the region. At the center of this system is the Dubai Electronic Security Center, known as DESC, which is a government authority that operates under Digital Dubai. Its mandate comes from Dubai Law No. 11 of 2014.

Many people use the term DESC Cyber Force to describe DESC’s cybersecurity rules in general. This is not accurate. DESC Cyber Force actually refers to something more specific, and understanding that difference can save an organization from preparing for requirements that do not apply to it.

This guide explains what DESC Cyber Force really is, who it applies to, and what the requirements actually are. It also explains how Cyber Force connects to DESC’s larger compliance framework, the Information Security Regulation, since many people searching for DESC Cyber Force are really trying to understand their overall cybersecurity responsibilities in Dubai. Every claim in this guide has been checked against official DESC and CREST documentation to keep the information accurate and current.

What Is DESC Cyber Force?

DESC Cyber Force (officially the Dubai Cyber Force Program) is a mandatory accreditation program created by DESC in partnership with CREST, the international body that sets standards for the cybersecurity services industry. Its main purpose is to certify qualified organisations and professionals to deliver two specific services to Dubai’s public sector: 

Penetration testing and incident response.

Before this program existed:

  • There was no reliable way for a government entity to judge whether a penetration testing or incident response provider had the skills it claimed to have. This created a gap between what cybersecurity providers claimed and what they actually delivered.
  • During this time, testing methods varied widely across the market. Providers could follow different approaches when conducting penetration tests or responding to incidents.
  • The scope and quality of assessments also differed significantly from one provider to another.
  • Technical reports were not uniform; either they were too technical or too vague to act upon.

DESC Cyber Force was created to solve this problem by setting one clear benchmark that every provider is measured against.

The program became mandatory from 31.07. 2024. From this date, Dubai government entities, semi-government entities, and Critical Information Infrastructure (CII) operators must use DESC Cyber Force-registered providers when they require penetration testing or incident response services. Simply put, these organisations cannot choose just any cybersecurity service provider for these two services. The provider must first be registered under the DESC Cyber Force Program.

Why is DESC Cyber Force Important for UAE Organisations?

The importance of this program depends on which side of the relationship an organisation is on.

For a cybersecurity service provider, Cyber Force registration is the main entry point into Dubai’s public sector market. Without it, a company cannot be engaged by a Dubai government entity for penetration testing or incident response work. This makes registration a business requirement rather than an optional credential.

For a government entity, a semi-government body, or a critical infrastructure operator, the program provides a reliable way to verify a provider’s competence before signing a contract. Every accredited provider has been measured against the same CREST standard, which ultimately removes much of the guesswork from choosing a vendor.

The program also supports a larger goal set out in the Dubai Cyber Security Strategy. Part of that strategy focuses on building what DESC calls a Cyber Smart Society, a market where the professionals delivering cyber services are skilled and where local practice aligns with recognised international standards.

DESC Cyber Force Requirements

Cybersecurity Governance

  • Mandatory procurement for service consumers: Dubai government entities, semi-government entities, and critical organisations under Dubai’s Critical Information Infrastructure (CII) are required to procure cybersecurity services covered by the program from Cyber Force Certified Service Providers
  • Local presence for service provider companies: A service provider company must have a local presence in the UAE.  The organisation must hold a valid UAE trade licence, either in the mainland or in a free zone. The company must also have performed the relevant discipline’s services under its own name for at least six months.
  • Compliance with UAE laws: Service provider companies must comply with applicable UAE laws, including the requirements referenced in the Dubai Government Information Security Regulation (ISR V3). The Cyber Force Program also requires systems and data to be handled safely in accordance with the specified ISR V3 controls and within the legal jurisdiction and geographical boundaries of the UAE.
  • Requirements for individual practitioners: Individuals working under the program must have the skills and competencies specified for their discipline and must comply with the DESC Terms of Service and any mandated DESC-approved methodologies. If they are physically operating in Dubai, they must have the right to work in Dubai and must present a valid Dubai Police security clearance when applying for certification.
  • Codes of Conduct and Ethics: Companies and individuals providing in-scope services must agree to and comply with the applicable Codes of Conduct and Ethics. The requirements state that these codes are applicable to both companies and individuals.
  • Legal name changes: If a certified service provider changes its legal name, the contract with the service consumer must require the provider to notify the consumer within 14 working days

Risk Management

  • Risk assessment before engagement: Cybersecurity service consumers should conduct a thorough cybersecurity risk assessment before engaging a service provider.
  • Documented service methodologies: Service providers must show their technical methodologies as part of the assessment process. The assessment may cover their policies and operating procedures, technical methodologies, data assurance processes, individual competencies, and relevant engagements.
  • Technical input and contractual requirements: A technical expert should be involved when the service consumer and provider draft the contractual agreement so that roles, responsibilities and relevant Service Level Agreements (SLAs) are properly defined. 
  • Non-Disclosure Agreement: The cybersecurity service consumer and service provider must sign a Non-Disclosure Agreement aligned with the Cyber Force Program Terms and the Dubai Data Law No. 26 of 2015.

Security Controls

  • Data must remain within the UAE: Classified data must remain within the geographical boundaries of the UAE during and after the engagement, with reference to the applicable ISR V3 requirements. 
  • Technical and organisational safeguards: Service providers must maintain sufficient technical and security measures to protect confidential information, access controls, data encryption, controls for data transfer and transmission, software patching, and backup, retention and recovery procedures against potential security incidents and data breaches
  • Secure removal of data: Confidential information should be retained only for as long as it is necessary to administer the Cyber Force Program, provide the relevant services, or comply with legal and regulatory obligations. Once the information is no longer required for these purposes, it must be securely removed from the service provider’s systems in a way that protects it from unauthorised disclosure.
  • Security breach notification: If there is a security incident, data security breach or unauthorised access to confidential information, the applicant or certified service provider must notify DESC, the certification body, the requesting entity and any other affected individuals or entities immediately in writing, and in any event no later than 24 hours after becoming aware of the incident. The provider is also mandated to take the remedial actions required under applicable laws and regulations.

Vulnerability Management

The Cyber Force Program’s first phase focuses on Penetration Testing and Incident Response. The guidelines state that the scope may expand as the program develops and may include additional cybersecurity services such as vulnerability assessment, cybersecurity governance, risk management, cybersecurity audit, cybersecurity architecture, digital forensics and malware analysis, Security Operations Centre (SOC) analysts, and threat hunting and intelligence. 

During the assessment of a service provider, DESC may examine whether the company has quality and information security management policies and processes for each service offering. These policies and processes must be actively reviewed and updated to ensure that they remain fit for purpose.

Penetration Testing

  • Use of the CREST Defensible Penetration Test: Penetration testing providers must follow the CREST Defensible Penetration Test standard.
  • Registration of technical staff: Companies providing penetration testing services must complete the Skilled Person Register and register their technical staff on the CREST Skilled Persons Register. 
  • Team Leader qualifications: Individuals serving as Team Leaders in penetration testing must hold one of the certifications recognised by the Cyber Force Program for that role, such as CREST CCT APP, CREST CCT INF, OffSec OSEP, OffSec OSWE and GIAC GXPN.
  • Team Member qualifications: Individuals serving as Team Members must hold one of the certifications recognised for that role, including CREST CRT, OffSec OSCP, EC-Council ECSA or LPT, and GIAC GPEN or GWAPT. 
  • Codes of Conduct and Ethics: Penetration testing companies must sign the applicable Codes of Conduct and Ethics, and the enforceable codes bind both the company and its individual practitioners.
  • Reporting major security gaps: Approved service providers conducting penetration tests must disclose any major gaps identified during the security assessment directly to DESC within five working days of issuing the penetration testing report to the client. 

Incident Management

  • Authorised incident response activities: The Cyber Force Program allows approved incident response providers to carry out authorised activities relating to the cybersecurity service consumer’s assets when responding to incidents. These providers may respond to incidents, provide reports and provide remediation assistance.
  • Team Leader qualifications: Individuals acting as Team Leaders for Incident Response must hold one of the certifications recognised for the relevant role. These include CREST CCIM, CREST CCNIA, CREST CCHIA, CREST CCTIM and GIAC GREM.
  • Team Member qualifications: Individuals acting as Team Members must hold recognised certifications including CREST CRIA, GIAC GCFR or GIAC GCFA. The role assigned to an individual depends on the certification they hold.
  • Same-day reporting of critical incidents: Approved Incident Response service providers must disclose any critical incidents to which they respond directly to DESC. The information must be sent to cyberforce@desc.gov.ae on the same day the incident is discovered. The required information includes the service provider’s details, the names of the individuals who provided the service, a detailed report on the engagement results, and a summary of the next steps discussed with the in-scope entity.

Security Monitoring and Ongoing Compliance

  • Audits and re-evaluations: DESC and approved certification bodies may conduct audits, inspections and re-evaluations of certified service providers. These assessments may be conducted remotely or on-site and can be used to verify continued compliance with the Cyber Force Program requirements.
  • Annual certificate renewal: The Cyber Force Certificate is renewable every year. During recertification, providers must submit relevant updated certifications and any newly acquired certifications. Failure to submit the required documents and apply for renewal results in the certificate expiring and the certification being revoked.
  • Reporting changes affecting compliance: During the certification period, a certified service provider must report any changes, incidents or circumstances that could affect its continued compliance with the Cyber Force Program to DESC and the certification body in writing, and this must be done promptly and no later than 24 hours after the relevant event.

Third-Party Security

  • Security clearance for individuals: Individuals proposed for Cyber Force engagements must undergo Dubai Police security clearance requirements or another form of identity confirmation. 
  • Right to work in Dubai: An individual applying to the Cyber Force Program must have the right to work in Dubai if the individual will be physically operating within the country.
  • Direct contractual relationship: Contracts for cybersecurity services regulated under the Cyber Force Program are entered into directly between the procuring entity and the selected service provider. DESC is not a party to these individual contracts.
  • Subcontractor responsibility: A certified service provider is liable for the performance of its obligations even where subcontractors are involved. Managing third-party cybersecurity risks remains crucial under the Cyber Force Program Terms, and the provider remains liable for the acts and omissions of its subcontractors, including their personnel, representatives and agents, as though those acts and omissions were the acts and omissions of the certified service provider itself.

DESC Cyber Force Penetration Testing Requirements

DESC Cyber Force Penetration Testing Requirements

According to the DESC Cyber Force Program Guidelines (Version 1.1), the Penetration Testing discipline has specific requirements for both service provider companies and the individual professionals working for them. The penetration testing discipline is administered by CREST International, while DESC retains overall accountability for the program.

Requirements for Penetration Testing Companies

A company that is seeking to get certification to provide penetration testing services under the Cyber Force Program must meet the general Cyber Force requirements as well as the discipline-specific requirements.

The company must provide an outline of the penetration testing methodology that it will use for its engagements (such as web application penetration testing or network penetration testing). The company must also complete the Skilled Person Register and register its technical staff on the CREST Skilled Persons Register. This register records information about the staff’s education, training, certifications, industry experience, sector alignment and soft skills, and is used to recognise that they have the appropriate skills and competence.

The company and its individual practitioners must also agree to the applicable Codes of Conduct and Ethics. These codes are enforceable and bind both the company and its individual practitioners.

CREST Defensible Penetration Test Requirement

Penetration testing carried out under the program must follow the CREST Defensible Penetration Test. 

Requirements for Individual Penetration Testers

Individual employees providing penetration testing services must show their competence through recognised professional certifications. The Cyber Force requirements map these certifications to the Dubai Digital Skills Framework and also use internationally recognised certifications.

The role assigned to an individual within the Cyber Force Program, such as Team Member or Team Leader, depends on the certification held by that individual.

Team Leader Certifications

For the Team Leader role, the PDF lists the following recognised certifications:

  • CREST CCT APP
  • CREST CCT INF
  • OffSec OSEP
  • OffSec OSWE
  • GIAC GXPN

These certifications are used to demonstrate the technical competence required for the Team Leader role under the program.

Team Member Certifications

For the Team Member role, the PDF lists the following recognised certifications:

  • CREST CRT
  • OffSec OSCP
  • EC-Council ECSA
  • EC-Council LPT
  • GIAC GPEN
  • GIAC GWAPT

Reporting Major Security Gaps

If a penetration testing engagement identifies a major gap in the system’s software, the approved service provider must disclose it directly to DESC via cyberforce@desc.gov.ae within five working days of issuing the report to the client. 

Assessment of the Company

The Cyber Force Program assesses the company as well as the individuals providing the service. The assessment can examine the company’s policies and operating procedures, individual competencies, data assurance processes, technical methodologies, significant related engagements, and independent client references. DESC also requires evidence that the company has quality and information security management policies and processes for its service offering, which are actively reviewed and updated to remain fit for purpose.

Secure Your Business with a Expert-Led Security Assessment

Partner with certified security specialists to identify, prioritize, and remediate real-world risks across your systems.

Book a Security Assessment

Security Assessment

Who Needs to Comply With DESC Cybersecurity Requirements?

The DESC Cyber Force Program covers both cybersecurity service providers and the organisations that procure their services.

  • Cybersecurity service providers: Any provider offering cybersecurity services to Dubai government entities, semi-government entities or Critical Information Infrastructure (CII) organisations falls within the program. Providers delivering services covered by the program must comply with the applicable requirements and certification requirements.
  • Government and semi-government entities: Dubai government and semi-government entities are identified as cybersecurity service consumers. They are expected to procure and use certified cybersecurity service providers for services covered by the program.
  • Critical Information Infrastructure (CII) organisations: CII organisations are also treated as cybersecurity service consumers and are expected to procure and use certified cybersecurity service providers.
  • Other entities regulated by DESC: The program also covers other entities that are regulated by DESC. These entities are included within the definition of cybersecurity service consumers and should use certified cybersecurity service providers.

What Services are covered?

The first phase of the Cyber Force Program focuses on two disciplines:

As the Cyber Force Program expands, it also expands to cover additional cybersecurity services:

DESC Cyber Force Compliance Process

For a service provider working toward Cyber Force registration, the process generally follows these steps.

  • Understand requirements. Confirm whether the organization is pursuing penetration testing, incident response, or both, and review the current CREST and DESC guidelines for exact certification and licensing details.
  • Assess current posture. Review the company’s trade license scope, its readiness for CREST accreditation, and whether its consultants already hold certifications on the accepted list.
  • Identify gaps. Look for missing certifications, licensing that does not cover cybersecurity activities, or consultants without a valid security clearance.
  • Remediate. Pursue CREST accreditation if the company does not already hold it, help consultants obtain the right certifications, correct the trade license if needed, and start the police clearance process early since it can take time.
  • Validate. Submit the registration through the CREST partner programme and respond to any evidence requests raised during the review.
  • Maintain. Once registered, keep certifications current, renew the registration annually, and be ready to meet any reporting requirements tied to specific engagements.
  • Government entities and critical infrastructure operators working toward DESC ISR compliance follow a similar cycle. Their process begins with a domain-by-domain applicability review of the ISR controls rather than a service provider accreditation.

Common DESC Cybersecurity Compliance Gaps

  1. A few problems come up repeatedly for organizations working through DESC-related compliance, whether that involves Cyber Force, ISR, or both.
  2. Confusing the two frameworks is the most common issue. Many organizations assume Cyber Force covers governance, risk management, and monitoring in the same way ISR does, and end up building a compliance plan around requirements the program does not actually impose.
  3. Trade license scope is another frequent gap. A company may hold a standard IT license that does not explicitly list cybersecurity activities, which quietly blocks Cyber Force registration until the issue is identified and corrected.
  4. Certification mismatches happen often as well. A team may hold strong and legitimate certifications that simply are not on DESC’s accepted list at the required level, which prevents an otherwise skilled consultant from being registered.
  5. Security clearance timing is a recurring practical challenge. Obtaining a Dubai Police clearance certificate takes time, and organizations often remember this requirement only once it has already become a delay.
  6. On the ISR side, the most common gap is treating regulatory compliance as a one-time exercise rather than an ongoing process. Controls that were appropriate at the time of assessment can become outdated as systems and risks continue to change.

DESC Cyber Force Compliance Checklist

Requirement Area What It Covers
Governance Valid UAE trade license with cybersecurity scope, CREST accreditation, and compliance with codes of conduct and ethics
Risk Assessment Managed under DESC ISR for government entities, informed by findings from Cyber Force testing and incident response work
Vulnerability Management Consistent testing methodology from accredited penetration testers, feeding into the entity’s own remediation process
Penetration Testing CREST company accreditation combined with approved individual certifications at team member or team leader level
Incident Response Approved certifications for incident response consultants, along with a valid Dubai Police clearance
Security Monitoring Covered under DESC ISR’s security operations center domain, supported indirectly through incident response engagements
Third-Party Risk Managed through ISR for suppliers, and reinforced by third-party risk management policies to use Cyber Force accredited providers.
Remediation Annual renewal of Cyber Force registration, ongoing certification maintenance, and regular ISR control updates
Documentation Evidence for CREST accreditation, DESC reporting where required, and a clear audit trail for compliance reviews

DESC Cyber Force vs Other UAE Cybersecurity Requirements

DESC’s Information Security Regulation is the broader instrument in this system. It applies to Dubai government entities and their related suppliers, and it sets baseline controls across governance, operations, and assurance through thirteen separate domains, covering everything from access control to cloud security.

Cyber Force sits alongside ISR rather than beneath it. It is a specialized program built specifically for penetration testing and incident response providers. Registering for Cyber Force does not mean an organization is compliant with ISR, since the two frameworks measure entirely different things.

At the federal level, there is also the UAE Information Assurance framework, sometimes referenced through the earlier National Electronic Security Authority standards, which applies across the wider UAE rather than Dubai alone. Financial institutions face an additional layer as well, since any entity licensed by the Central Bank of the UAE may need to follow its cybersecurity guidelines in addition to whatever DESC requires.

An organization operating in Dubai may find that more than one of these frameworks applies to it at the same time, depending on its sector, its client base, and whether it delivers cybersecurity services directly to government entities.

Prepare for Your Next Cybersecurity Audit with Qualysec

Choose a partner that helps you identify and fix real security risks before attackers do. We are here to help.

Talk to an Expert

Talk to a Cybersecurity Expert

Conclusion

DESC Cyber Force is a focused and well-defined program, and understanding its limits matters just as much as understanding its requirements. It is not a general cybersecurity standard for every business in Dubai. It is a CREST-backed accreditation scheme built specifically for penetration testing and incident response providers working with the public sector, and it sits alongside DESC’s much broader Information Security Regulation rather than replacing it. For service providers, the path forward is clear. Secure CREST accreditation, get the team certified against the approved list, and keep the registration current every year. For government entities and their suppliers, Cyber Force compliance is really about knowing which providers can be trusted. Understanding this distinction from the start saves significant time and effort, and it is the first real step toward meeting Dubai’s broader cybersecurity expectations with confidence.

Frequently Asked Questions

What is DESC Cyber Force?

DESC Cyber Force is a joint program between DESC and CREST that accredits companies and certifies individuals to deliver penetration testing and incident response services to Dubai government, semi-government, and critical information infrastructure entities.

What are DESC Cyber Force requirements?

Organizations need a UAE trade license that includes cybersecurity activities, along with CREST accreditation. Individual consultants need approved certifications at either team member or team leader level, and a valid Dubai Police security clearance certificate.

Who needs to comply with DESC?

Providers delivering penetration testing or incident response to Dubai’s public sector must register under Cyber Force. Government departments, semi-government bodies, and certain suppliers handling government data must meet DESC’s Information Security Regulation instead.

Is penetration testing required?

Penetration testing is one of the two services this program governs, and Dubai government entities are expected to use registered providers for it. The results of this testing also support the vulnerability management requirements under ISR.

How can an organization prepare for DESC compliance?

The first step is identifying which framework actually applies. Service providers should pursue CREST accreditation and get their consultants certified against DESC’s approved list. Government entities and their key suppliers should complete an ISR applicability review and build their controls from there.

What happens if cybersecurity requirements are not met?

Unregistered service providers risk losing access to penetration testing and incident response work with Dubai government entities. Government entities and suppliers that fall short on ISR requirements risk compliance findings, contract complications, and possible removal from government procurement.

Pabitra Kumar Sahoo

About Pabitra Kumar Sahoo

Pabitra Kumar Sahoo is the Co-Founder and Chief Operating Officer (COO) at Qualysec. With a deep commitment to elevating global cybersecurity standards, he directs corporate operations and service strategy, helping enterprises mitigate compliance debt and defend their digital infrastructure through elite, human-led penetration testing.

Leave a Comment.

Your email address will not be published. Required fields are marked *

Related Blogs

Subscribe to Newsletter

Get the latest cybersecurity insights, compliance tips, and vulnerability reports delivered directly to your inbox.