Most guides treat Dubai's cybersecurity regulations as a burden you have to satisfy. That is the wrong way round. The DESC Information Security Regulation, the UAE Information Assurance Standard, the Critical Information Infrastructure Policy and the data protection law do not just bind you. They force your customers to buy what you sell. Dubai government entities, semi-government bodies, banks and critical infrastructure operators are legally required to run compliant security, assess their suppliers, and in two specific service lines use only accredited providers. Regulation here is not overhead. It is the pipeline.
There is one place that cuts the other way, and it decides who can even bid for the best work. Since 31 July 2024, delivering penetration testing or incident response to Dubai government requires the provider itself to be accredited under the DESC Cyber Force programme, run with CREST [3]. That is a real barrier, and knowing exactly what it takes is the difference between a business plan and a wish.
This guide covers the regulatory demand stack, the Cyber Force accreditation in detail, the licence and the product-reselling rules people conflate, the tax position the tech free zones oversell, how to zero-rate work for foreign clients without falling into the trap that undoes it, and honest day rates and margins. Since 2013, our team has set up technology and professional services companies across Dubai, so the traps here come from real files.
Why is regulation your sales pipeline?
Because Dubai has built one of the densest cyber regulatory stacks of any market its size, and almost all of it creates paid work for services firms.
| Framework | Who it binds | Why it pays you |
|---|---|---|
| DESC ISR v3 | Dubai government, semi-government, and their service providers | Mandatory security controls across 13 domains; failed audits remove vendors from procurement [1] |
| UAE IA Standard | Government and operators of critical information systems | Technical and management controls for designated critical entities |
| CIIP Policy (2023) | Critical infrastructure across finance, energy, transport, health, telecom and more | Requires annual risk assessments and pushing security due diligence onto suppliers [7] |
| PDPL (FDL 45/2021) | Anyone processing UAE residents' personal data | Encryption, breach notification, safeguards; enforced by the UAE Data Office [8] |
| CBUAE rules | Banks | Independent security assessments, outsourcing approval, 24-hour incident reporting |
Read that as a demand map. The CIIP Policy in particular requires critical entities to extend cybersecurity due diligence to their suppliers by contract, which is how a services firm with no critical-entity status of its own still gets pulled into regulated work as a subcontractor to a bank or a utility.
Pro Tip: Do not build your go-to-market around cold outbound. Build it around a regulation. "We do PDPL gap assessments and DPO-as-a-service" or "we deliver DESC ISR readiness for entities that supply Dubai government" is a sharper pitch than "we do cybersecurity," because it names the obligation the buyer already has to meet. The buyer is not deciding whether to spend. A regulator decided that for them.
What is the DESC Cyber Force accreditation, and do you need it?
For penetration testing and incident response into Dubai government, yes, and this is the single most important thing on this page.
The Dubai Electronic Security Center partnered with CREST to run the Dubai Cyber Force programme, and from 31 July 2024 it is mandatory for anyone, including freelancers, delivering penetration testing or incident response to Dubai government, semi-government and critical information infrastructure entities [3]. Note the two covered service lines are penetration testing and incident response, taken directly from CREST's own programme page. Some early coverage said vulnerability assessment; the accrediting body lists penetration testing.
Company eligibility, verbatim in substance from CREST [3]:
- A valid UAE trade licence that includes cybersecurity activities in its scope
- CREST company accreditation, either already held or obtained through the process
- Individual consultants who meet the standard and hold Dubai Police security clearance
There is no DESC application fee, but you bear the cost of the CREST company accreditation and the individual certifications, and the accreditation renews annually [3]. Those certification costs are not publicly published, so we are not going to invent a figure. Budget for CREST membership plus certified staff plus the clearance process, and treat it as a project of months, not days.
Real Talk: This barrier is exactly why it is worth crossing. The firms already through it are named publicly, including Help AG, KPMG, Crowe, DTS Solution and others [3]. That tells you two things. First, the club is real and reachable, not a closed shop. Second, if you are not in it, you cannot legally sell those two services into the highest-value client segment in the market, no matter how good your team is. Decide at setup whether Dubai government pen testing is your business, because if it is, the accreditation is not optional and it shapes your hiring from day one. Talk to us about structuring for accredited work→
If your business is GRC consulting, managed detection, SME security or product work, you do not need Cyber Force to operate. It is specific to those two government-facing service lines.
What licence do you need?
A professional services licence for pure consulting and services, and a commercial element if you also resell hardware.
Advisory work, risk assessment, GRC, security architecture, managed services and training sit under a professional licence. If you also import and resell appliances such as firewalls or SIEM hardware, that is trading physical goods and needs a commercial activity added, because a pure professional licence does not cover it.
On activity codes, business-setup sources cite 6209.12 for cybersecurity consultancy, 6202.98 for managed security services, and others. We could not verify these against DET's own activity list, which blocks automated access, so treat them as reported and confirm on application. What is better corroborated is that DESC worked with DET to create cybersecurity-specific activity codes rather than leaving cyber under generic IT consultancy, and that some mainland cyber activities require DESC approval at the licensing stage [2].
Mainland or free zone:
- Mainland (DET) lets you contract directly with any Dubai entity including government, and is where DESC activity approval is most relevant. 100% foreign ownership has been available for most professional and commercial activities since the 2020 reform, so the old "you need a 51% Emirati partner" claim that some setup pages still repeat is out of date.
- Free zones commonly used are Dubai Internet City, Dubai Silicon Oasis, IFZA and DMCC. A free zone company cannot directly serve mainland government or critical-infrastructure clients without a mainland branch or an NOC, which matters because that segment is where the regulated money is.
Common Mistake: Choosing a free zone for the tax pitch and then discovering you cannot sell to the clients you set up to serve. If Dubai government and critical infrastructure are your market, the mainland friction is worth taking on. Compare structures on our mainland company setup and free zone company setup pages, and our free zone versus mainland guide.
What if you resell security products?
Then you cross two separate approval regimes that setup guides constantly confuse.
TDRA type approval governs telecom and radio equipment connecting to public networks. A network appliance with radio or telecom connectivity needs type approval before you import or sell it, though TDRA generally accepts existing CE or accredited-lab test reports, which shortens the process.
Dual-use and encryption export controls are a separate and more consequential regime under Federal Decree-Law 43 of 2021, administered by the Executive Office for Control and Non-Proliferation, not TDRA. The UAE National Control List mirrors the Wassenaar Arrangement, and its Category 5 Part 2 covers information security items with encryption above a low threshold, which captures most modern enterprise security products. Importing, exporting or re-exporting controlled items needs a permit through the Ministry of Economy strategic goods route.
Common Mistake: Budgeting for TDRA and forgetting encryption controls. A firm reselling encryption-capable security appliances needs both approvals from two different authorities. A pure services firm using cloud tooling largely avoids both. Decide which you are before you write the plan.
Does the tech free zone 0% tax actually apply?
No, not the unlimited version, and the tech free zones market it hard.
A free zone company pays 0% only on Qualifying Income as a Qualifying Free Zone Person, and Ministerial Decision 229 of 2025 sets a closed list of Qualifying Activities. IT and cybersecurity services are not on that list [4]. So a cybersecurity firm cannot get the unlimited 0% that Dubai Internet City and Dubai Silicon Oasis put in their marketing.
But the correction runs both ways, and this is the part people get wrong in a panic. Not qualifying does not mean 9% on everything. A free zone company that is not a Qualifying Free Zone Person is simply taxed as an ordinary person under the standard regime: 0% on taxable income up to AED 375,000 and 9% above it, identical to mainland [4].
Pro Tip: So for a cybersecurity services firm, free zone versus mainland stops being a tax decision. Both land on the same standard rates. Decide on client access instead, which for this business usually points toward mainland if government and critical infrastructure are your market. See our corporate tax filing guide, and compare the identical logic in our AI and tech consultancy guide.
Small Business Relief is worth using while it lasts: under AED 3 million of revenue you elect to be treated as having no taxable income, but Ministerial Decision 73 of 2023 limits it to tax periods ending on or before 31 December 2026 [5], so 2026 is the final year under current rules.
Can you zero-rate work for foreign clients?
Often yes, and for a cybersecurity firm this is a genuine advantage, because so much of the work is delivered remotely. But there is a trap that undoes it.
A Dubai SOC monitoring a client in Saudi Arabia or Europe, or a penetration test delivered to a foreign entity, is a strong candidate for zero-rated export of services under Article 31 of the VAT Executive Regulation, which requires the recipient to have no residence in an implementing state and to be outside the UAE when the service is performed, and the service not to be connected to a UAE establishment of the recipient [6].
The trap is Cabinet Decision 100 of 2024, in force from 15 November 2024. It tightened the "outside the State" test: the recipient is treated as being in the UAE, losing the zero-rating, if it has UAE presence of 30 days or more cumulatively across the preceding 12 months, and the FTA's own example counts the presence of a director, not just staff [6].
Quick Math: You run a managed SOC for a GCC-headquartered client and zero-rate the monthly invoices as an export. Their executives fly into Dubai for board meetings and industry events through the year. Add those visits up and they cross 30 days cumulatively. The recipient is now treated as being in the UAE, the zero-rating falls away, and those invoices should have carried 5%. GCC clients travel to Dubai constantly, so this is not a remote risk for exactly the client base a Dubai cyber firm targets. Get the position reviewed rather than assumed. Get your VAT treatment checked→
Register for VAT once taxable supplies pass AED 375,000, voluntarily from AED 187,500. See our VAT registration guide.
What do you pay your people, and can you find them?
Well, and with difficulty. Talent cost and scarcity is the defining economic fact of this business.
UAE salary data is directional rather than precise, drawn from recruitment aggregators, but the shape is consistent: penetration testers around AED 300,000 to 315,000 a year, senior security engineers around AED 445,000, and CISSP-certified seniors in government and critical-infrastructure roles routinely above AED 45,000 a month. Certifications carry a real commercial premium, with CISSP holders cited as earning materially more than uncertified peers.
But for the accredited work, certifications are not a premium, they are a gate. Under Dubai Cyber Force your penetration testers and incident responders cannot legally sell into Dubai government without the required CREST-aligned certifications and Dubai Police clearance [3]. That changes hiring from "certifications are nice" to "certifications are the licence to bill."
Emiratisation applies, since ICT is one of the targeted sectors. The obligation begins at 20 to 49 employees with skilled Emirati hires, with percentage targets at 50 plus, and the Emirati minimum salary is AED 6,000 a month from January 2026. NAFIS wage support of up to AED 8,000 a month per qualifying hire materially lowers the cost, and a GRC or compliance analyst role is well suited to building an Emirati bench without needing deep offensive-security depth. See our Emiratisation guide and hiring guide.
Pro Tip: Cybersecurity specialists are an explicitly recognised Golden Visa category under the UAE's talent-first shift, covering penetration testers, security engineers and cloud security professionals, typically at around five years of experience with a relevant qualification. That is a genuine recruitment and retention tool for a founder building a senior team in a scarce market.
What are the honest economics?
Strong day rates, expensive people, and a long sales cycle that rewards patience and punishes the undercapitalised.
Service pricing in the UAE, indicative from market sources: an external network penetration test roughly AED 35,000 to 75,000, internal assessments somewhat higher, and enterprise red-team exercises from around AED 250,000 into the millions for large engagements, typically running 10 to 15 business days for mid-size work. Managed SOC and MDR contracts run monthly, with entry offers advertised from a few thousand dirhams a month and full managed detection in the tens of thousands, though the low end is usually a bare-bones service.
The margin killer is not price, it is utilisation and salary. Your senior people are expensive and scarce, and they bill only when engaged. Professional services norms put healthy utilisation at 70% to 85%, and a boutique that cannot keep its seniors billable at that level is losing money on its most expensive line regardless of day rate.
The sales cycle is long and relationship-driven. Government and enterprise work in the UAE runs on trust, referrals, ISO credentials and channel relationships with established primes, not cold outbound. A boutique often reaches government-linked work first as a subcontractor to a larger firm. Budget working capital for a long runway to the first big contract, because the pipeline is real but slow.
On startup capital we are going to be honest rather than precise. We could not find a credible UAE-specific all-in figure, and the ones circulating on template sites are generic and in places nonsensical. Build it bottom up: a licence at roughly AED 12,000 to 30,000, the CREST and certification costs if you are pursuing accredited work, two or three senior hires at AED 25,000 to 45,000 a month each, and office and tooling. The dominant cost is people, and people here are dear.
How big is the market, and who owns it?
Growing fast, reported with a wide spread, and led by a few large integrators with real room underneath them.
Estimates for the UAE cybersecurity market cluster around USD 0.6 to 0.8 billion for 2025 depending on source, growing at low double digits, with the wider GCC around USD 5.9 billion. Treat any single figure with caution, because the numbers diverge by methodology, and one free zone page's much lower figure is an outlier. Regional MEA figures range so widely, from a few billion to over twenty, that they are a scope artifact rather than a usable number.
The demand is real and policy-driven: a national cybersecurity strategy with major government spending behind it, DESC ISR v3, the IA Standard and PDPL all forcing regulated spend.
The large players include CPX, backed by G42, and Help AG, part of the e& group, alongside global vendors operating regionally. The genuine white space for a new entrant is underneath them:
| Opening | Why it exists |
|---|---|
| SME and mid-market | The big integrators chase enterprise and government and largely ignore it |
| Sector specialists | Healthcare, fintech and property need tailored compliance, not generic MDR |
| GRC-as-a-service | SMEs need DESC, PDPL and ISO help they cannot afford as a full engagement |
| Boutique offensive security | Competing on expertise density rather than scale |
Real Talk: Do not try to out-integrate the integrators. A new firm wins by being narrower and deeper than they can be bothered to be, on a segment or a regulation they do not prioritise. The SME market in particular is underserved on price and largely unserved by the names above, and it is where a disciplined boutique can actually build a book.
What are the steps?
- Decide your service lines. Government pen testing and incident response means the Cyber Force path from day one; GRC, MDR or SME work does not.
- Choose mainland or free zone on client access, not on the tax pitch.
- Register the company with cybersecurity activities in scope, taking DESC approval where a mainland activity requires it.
- Pursue CREST company accreditation and staff certifications if you are doing accredited government work.
- Arrange Dubai Police security clearance for the relevant consultants.
- Register for VAT if over the threshold, and get your export-of-services position reviewed for foreign clients.
- Build your Emirati bench early, using NAFIS support, ideally in GRC roles.
- Add TDRA and strategic goods approvals only if you resell hardware.
- Line up channel relationships with larger primes for a route into government-linked work.
- Capitalise for a long sales cycle, because the first enterprise contract is slow.
What documents do you need?
- Passport and Emirates ID of shareholders and manager
- Trade name reservation and initial approval, with cybersecurity activities in scope
- DESC activity approval where required for a mainland licence
- Memorandum of Association
- CREST company accreditation and individual certifications, for accredited work
- Dubai Police security clearance for relevant staff
- VAT registration certificate where applicable
- TDRA type approval and strategic goods permits, for hardware resale
Real Client Stories
The firm that set up in the wrong place for its clients. A founder incorporated in a tech free zone specifically for the 0% tax pitch, planning to sell into Dubai government. The 0% did not apply to security services anyway, so the tax benefit was illusory, and the free zone licence could not contract directly with the government entities that were the entire business plan. We restructured onto a mainland footing. He lost nothing but time, which in a slow-sales-cycle business is the expensive thing to lose.
The pen-test shop that could not bid. A capable team started delivering penetration testing and won interest from a semi-government client, then discovered they could not be engaged because they were not accredited under Dubai Cyber Force, mandatory since July 2024 for exactly that work. They spent the following months getting CREST company accreditation and putting their testers through certification and Dubai Police clearance. Good business, delayed by a requirement that should have shaped the setup from the start.
The SOC that owed VAT on an export it thought was zero-rated. A managed SOC provider zero-rated a year of monthly fees to a GCC client as an export of services. The client's executives had been in Dubai repeatedly across the year for meetings and events, comfortably past 30 days cumulatively under the tightened test. Those invoices should have carried 5%. We regularised it. His comment: "I was applying a rule about where the company is registered. The rule is about where their people have been."
Start your Dubai cybersecurity company the right way
Since 2013, BusinessDubai.ae has completed 700+ company registrations across the UAE, including technology and professional services companies. We will structure you for the clients you actually intend to serve rather than a tax benefit that does not apply, take you through the licence with the right cybersecurity activities and any DESC approval, tell you honestly what the Cyber Force accreditation path involves before you commit to government work, set your VAT up so your foreign-client work is treated correctly, and build your Emiratisation plan with NAFIS support, with clear itemised pricing. Talk to a setup expert→ for a plan built around your service lines. Our AI and tech consultancy and software development company guides cover adjacent tech setups, and post-setup services covers what comes after the licence.
Frequently Asked Questions
What licence do I need for a cybersecurity company in Dubai?
A professional services licence for consulting, advisory, GRC, managed services and training. If you also import and resell hardware such as firewalls or SIEM appliances, you need a commercial activity added, because a pure professional licence does not cover trading physical goods. DESC approval may be required for certain mainland cyber activities at the licensing stage [2].
What is the DESC Cyber Force programme?
An accreditation run by the Dubai Electronic Security Center with CREST. Since 31 July 2024 it is mandatory for anyone delivering penetration testing or incident response to Dubai government, semi-government and critical infrastructure entities [3]. Without it you cannot legally sell those two services into that segment.
Do I need CREST accreditation to start a cybersecurity company?
Only if you want to deliver penetration testing or incident response to Dubai government. Company eligibility requires a UAE trade licence with cybersecurity activities, CREST company accreditation, and consultants who hold Dubai Police security clearance [3]. For GRC consulting, managed detection or SME work you do not need it to operate.
How much does the Cyber Force accreditation cost?
There is no DESC application fee, but you bear the cost of CREST company accreditation and the individual certifications, and the accreditation renews annually [3]. Those certification costs are not publicly published, so plan for CREST membership plus certified staff plus the clearance process, and treat it as a project of months.
Which service lines does Cyber Force cover?
Penetration testing and incident response, per CREST's own programme page [3]. Some early coverage referred to vulnerability assessment, but the accrediting body lists penetration testing and incident response as the two covered disciplines.
Is regulation good or bad for a cybersecurity business here?
Mostly good, and this is the point competitors miss. DESC ISR, the UAE IA Standard, the CIIP Policy and PDPL all impose mandatory security obligations on government, semi-government, critical infrastructure and any business handling personal data, which creates compelled demand for compliant services. Regulation is your pipeline, not just your overhead.
Can I do cybersecurity work from a free zone?
Yes for private-sector and international clients, but a free zone company cannot directly serve mainland government or critical-infrastructure clients without a mainland branch or an NOC. Since that segment is the highest-value work, many cyber firms targeting it choose mainland.
Does the free zone 0% corporate tax apply to cybersecurity services?
Not the unlimited version. IT and cybersecurity services are not on the closed list of Qualifying Activities in Ministerial Decision 229 of 2025 [4], so the tech free zones' 0% pitch does not apply. But failing to qualify means you fall back to the standard regime of 0% up to AED 375,000 and 9% above, the same as mainland, not 9% on everything.
So is a free zone pointless for a cybersecurity firm?
Not pointless, just not a tax play. Since both routes land on the same standard rates, choose on client access, cost and visa allocation. For a firm targeting government and critical infrastructure, that usually favours mainland.
Can I zero-rate cybersecurity work for foreign clients?
Often, yes. Remote work such as a Dubai SOC monitoring a foreign client, or a penetration test for a foreign entity, is a strong export-of-services candidate under Article 31, zero-rated where the recipient is outside the UAE and not connected to a UAE establishment [6]. It is a real advantage for a remotely delivered service.
What is the 30-day trap on export zero-rating?
Cabinet Decision 100 of 2024 treats a foreign recipient as being in the UAE, losing the zero-rating, if it has UAE presence of 30 days or more cumulatively over the preceding 12 months, counting directors as well as staff [6]. GCC clients whose executives travel to Dubai often can cross this without you realising, making an invoice you zero-rated actually standard-rated at 5%.
Do remote security services count as electronic services for VAT?
Probably not, because pen testing, SOC monitoring and incident response involve substantial human analyst work rather than being automatically delivered over a network, so they should fall under the general export-of-services test rather than the electronic-services place-of-supply rule. We flag this as a reasoned position rather than a settled one, so confirm it for your specific service.
Can I claim Small Business Relief?
If revenue is under AED 3 million, yes, by election, but Ministerial Decision 73 of 2023 limits it to tax periods ending on or before 31 December 2026 [5], so 2026 is the final year under current rules. It is not available to Qualifying Free Zone Persons.
Do I need TDRA approval?
Only if you import or sell telecom or radio-connected equipment such as certain network appliances, which need type approval before sale. A pure services firm using cloud tooling does not. Note that reselling encryption-capable products additionally triggers dual-use and strategic goods controls under a separate authority.
What are the encryption import rules?
Security products with encryption above a low threshold fall under the UAE dual-use control regime under Federal Decree-Law 43 of 2021, administered by the Executive Office for Control and Non-Proliferation, not TDRA. Import, export and re-export of controlled items need a permit through the Ministry of Economy strategic goods route. This is separate from and additional to TDRA type approval.
What do cybersecurity professionals earn in Dubai?
Directional UAE figures put penetration testers around AED 300,000 to 315,000 a year, senior security engineers around AED 445,000, and CISSP-certified seniors in regulated roles routinely above AED 45,000 a month. Certifications carry a real commercial premium, and for accredited government work they are effectively a requirement to bill.
Does Emiratisation apply to a cybersecurity firm?
Yes. ICT is one of the targeted sectors, so the obligation begins at 20 to 49 employees with skilled Emirati hires and rises with headcount. The Emirati minimum salary is AED 6,000 a month from January 2026, and NAFIS wage support of up to AED 8,000 a month per qualifying hire lowers the cost. A GRC or compliance analyst role suits building an Emirati bench.
Are cybersecurity specialists eligible for the Golden Visa?
Yes. Under the UAE's talent-first shift, penetration testers, security engineers and cloud security professionals are a recognised category, typically requiring around five years of experience with a relevant qualification. It is a useful tool for recruiting and retaining a senior team in a scarce market.
What does a penetration test sell for in the UAE?
Indicative market figures put an external network test at roughly AED 35,000 to 75,000, internal assessments somewhat higher, and enterprise red-team exercises from around AED 250,000 into the millions for large engagements, with mid-size work typically running 10 to 15 business days.
Why do boutique cybersecurity firms struggle?
Two reasons. Their senior people are expensive and scarce and only earn when billable, so utilisation below the 70% to 85% norm loses money on the costliest line. And the enterprise and government sales cycle is long and relationship-driven, so undercapitalised firms run out of runway before the first big contract lands.
How big is the UAE cybersecurity market?
Estimates cluster around USD 0.6 to 0.8 billion for 2025 depending on source, growing at low double digits, with the wider GCC around USD 5.9 billion. Figures diverge by methodology, so treat any single number with caution and be sceptical of both the very low and very high outliers.
Where is the white space for a new cybersecurity firm?
Underneath the large integrators. The SME and mid-market segment is underserved on price, sector specialists in healthcare, fintech and property can package tailored compliance, GRC-as-a-service around DESC, PDPL and ISO suits SMEs who cannot afford full engagements, and boutique offensive security competes on expertise density. Do not try to out-integrate the integrators.
References
[1] Dubai Electronic Security Center, Information Security Regulation (ISR) v3, mandatory for Dubai government and their service providers across 13 domains. itsecnow.com
[2] Setting up a cybersecurity company in the UAE, DESC and DET collaboration on cyber activity codes and mainland activity approval. propartnergroup.com
[3] Dubai Cyber Force Programme, CREST International, covered service lines, mandatory date, company eligibility and fees. crest-approved.org and Digital Dubai launch announcement digitaldubai.ae
[4] Ministerial Decision No. 229 of 2025 on Qualifying Activities and Excluded Activities. mof.gov.ae
[5] Ministerial Decision No. 73 of 2023 on Small Business Relief, Article 2. mof.gov.ae
[6] Cabinet Decision No. 100 of 2024 amending the VAT Executive Regulation, including the tightened "outside the State" test for export of services. tax.gov.ae
[7] UAE Cyber Security Council, Critical Information Infrastructure Protection Policy. u.ae
[8] Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (PDPL). securiti.ai
Last Updated: July 2026









