We value your privacy

We use cookies to analyse site traffic and improve your experience. You can accept all cookies or reject non-essential ones. See our Privacy Policy for details.

GR IT SERVICES
  • Contact
Get a quote
  1. Audit and compliance
  2. ISO 27001
ISO 27001 certification, UAE

ISO 27001 certification, and whether you actually need it.

The 2013 edition stopped being current on 31 October 2025, so a certificate issued against it is no longer a valid certificate. The standard today is ISO/IEC 27001:2022 with Amendment 1:2024. We prepare UAE organisations for assessment by an accredited body, and we tell you when certification is the wrong answer.

Book an ISO 27001 gap assessmentSee what is involved
ISO 27001 certification preparation for UAE organisations
  • 2022 editionPlus Amendment 1:2024
  • 93 controlsAnnex A, in four themes
  • Deadline passed2013 certificates are not current
  • Not a certifierWe prepare, an accredited body audits
What certification actually involves

Eight things ISO 27001 asks for, and only one of them is a control list.

The most common misconception we correct is that ISO 27001 is a checklist of security controls. It is a management system standard. The clauses that carry the most weight at assessment are about how you decide, review and improve, and the Annex A controls are selected on the back of that reasoning rather than adopted wholesale.

A scope you have defined deliberately

Scope decides the cost, the effort and the credibility of the certificate. Too narrow and a client reads the certificate, sees it covers one office and not the service they buy, and treats it as worthless. Too broad and you spend a year certifying parts of the business nobody asked about. For most UAE organisations the right scope is the service the customer is actually assessing, plus the infrastructure and people behind it.

A risk assessment that drives everything else

The standard requires a defined, repeatable information security risk assessment and treatment process, and the output of that process is what justifies your control selection. This is the clause auditors probe hardest, because a risk register that was written once to satisfy a consultant and never revisited is visible immediately. It should look like something the business actually uses.

A Statement of Applicability that reasons rather than lists

You do not implement all 93 Annex A controls. You implement the controls your risk assessment identifies as necessary, and you justify any exclusions. The Statement of Applicability is where that reasoning lives, and it is usually the first document an assessor reads. A well-argued exclusion is a sign of a working management system. An unexplained gap is a finding.

Ninety-three Annex A controls across four themes

The 2022 edition reorganised the old 114 controls in 14 domains into 93 controls in four themes: 37 Organizational, 8 People, 14 Physical and 34 Technological. If your existing documentation is still structured around the 2013 domains, it is not wrong in substance but it will make the assessment slower, because the assessor has to map your evidence onto the current structure themselves.

Amendment 1:2024, the climate change clause

Amendment 1 added to clause 4.1 that the organisation shall determine whether climate change is a relevant issue, and added a note to 4.2 acknowledging that interested parties can have climate-related requirements. The 4.2 addition is a note rather than a requirement. In practice this is a short, documented consideration rather than an environmental programme, and certification bodies have been checking for it since 2024.

Evidence that the system is operating, not merely designed

Internal audits, management review, corrective actions, competence records, and evidence that your controls have actually run over a period. This is where organisations that buy a documentation pack come unstuck. The templates satisfy the clauses on paper and produce nothing an assessor can sample, because no activity ever happened behind them.

Assessment by an accredited certification body, not by us

Certification is issued by an accredited certification body following a two-stage audit, and it is maintained through surveillance audits with recertification on a three-year cycle. We prepare you and support you through it. We do not issue certificates, and you should be wary of anyone who offers to both consult and certify, because that is a conflict of interest an accreditation body would not permit.

Reuse against your other UAE obligations

An ISO 27001 management system carries a great deal of the evidence needed for UAE sector requirements, and the reverse is true too. If you already hold national standard alignment, DESC ISR work, or ADHICS controls in Abu Dhabi, a substantial share of your risk, asset, access and incident evidence transfers. We map that first, because paying twice for the same control set is the most common waste in UAE compliance budgets.

Check this today

If your certificate says 2013, it is not a current certificate.

The transition from ISO/IEC 27001:2013 to the 2022 edition closed on 31 October 2025. That date has passed. This catches UAE organisations more often than it should, usually because the certificate sits in a folder and nobody looks at it between tenders.

  • Go and read the edition on your certificate. If it references ISO/IEC 27001:2013, you are not currently certified to the standard, whatever the expiry date on the document says. The practical moment this surfaces is a tender submission or a client due diligence questionnaire, which is the worst possible moment to discover it.
  • The work to move is real but usually smaller than people fear. The clauses are largely unchanged. What changes is the Annex A structure, from 114 controls in 14 domains to 93 controls in four themes, so the Statement of Applicability is rebuilt and the evidence is remapped rather than recreated. For an organisation with a genuinely operating management system this is weeks, not months.
  • Amendment 1:2024 comes with it. The current standard includes the climate action changes, so a transition done now covers both. If you transitioned early in the window and have not addressed the clause 4.1 climate consideration, that is a small documented gap worth closing before your next surveillance audit.
  • If you have let certification lapse entirely, the honest question is whether to resume. Certification costs real money every year, and it is worth it when customers, tenders or regulators ask for it. If nobody has asked you for it in three years, the better answer may be a security programme without the certificate, and we will say so.
Ask us to check your certificate and scope
How we work

Four positions we hold on ISO 27001 work in the UAE.

This market has a lot of providers selling fast certification against templated documentation. That approach produces a certificate and very little else, and it is increasingly being found out by customers who audit their suppliers properly.

We will tell you not to certify when that is right

If nobody has asked you for ISO 27001 and your actual need is to answer client security questionnaires credibly, we will say so, and help you do that instead for a fraction of the cost. Certification is an ongoing annual commitment. It is excellent value when it opens doors and a poor use of budget when it opens none.

We prepare, we do not certify, and we say which bodies we work with

We are not a certification body and cannot issue a certificate. We prepare you, run the internal audit, sit with you through stage one and stage two, and manage findings afterwards. Be cautious of any firm offering to both consult and certify: accreditation rules exist precisely to prevent that, and a certificate from an arrangement like that will not survive customer scrutiny.

We build a system your team can actually run

The measure we hold ourselves to is whether your own people can run the management system twelve months after we finish, without calling us. That means documentation sized for your organisation rather than a two-hundred-page pack, risk assessment integrated with how you already make decisions, and internal audit that finds real things.

We stay for the surveillance audits

Certification is a three-year cycle with surveillance audits in between, and the failure mode is a system that decays quietly between visits. We keep the evidence current through the year rather than assembling it in the fortnight before an audit. Priority response applies throughout, P1 within 5 minutes, P2 within 10, P3 within 30.

Why UAE organisations certify

Six reasons that actually justify the spend.

Certification is worth it when it removes a commercial obstacle. These are the six situations where we have seen it do that reliably in this market.

An enterprise customer has made it a condition

The most common and the most clear-cut. A large client, often a bank, a government entity or a multinational, requires certification from suppliers handling their data. Here the certificate has a direct revenue justification and the scope should be drawn tightly around the service that client buys, rather than around your whole organisation.

A financial services firm in DIFC or ADGM

Regulated firms face supervisory expectations on information security, and while certification is not usually mandated as such, an ISO 27001 management system produces a great deal of the evidence a regulator or an external auditor will ask for. It also answers the outsourcing and third-party questions that come up repeatedly in this sector.

A company bidding for government or semi-government work

Tender requirements in the UAE increasingly reference information security certification, and an expired or 2013-edition certificate has caused real bid disqualifications. If tendering is part of your pipeline, the certificate is best treated as a standing commercial asset that must never lapse, rather than as a project you complete once.

A technology company selling internationally

ISO 27001 is the recognised standard in Europe, the Middle East and much of Asia, and it shortens security review cycles considerably. If your buyers are predominantly American, SOC 2 may serve you better or you may end up needing both. We would rather help you work that out before you commit than watch you certify against the wrong framework.

An organisation already carrying UAE sector obligations

Entities working to ADHICS in Abu Dhabi healthcare, to the national information assurance standard, or to Dubai information security regulation already hold much of the underlying evidence. For them, ISO 27001 is often less additional work than expected, and the resulting management system makes the sector obligations easier to sustain rather than harder.

A growing firm that wants the discipline, not just the badge

A smaller but genuine category: organisations that use certification as a forcing function to build security governance they know they need and would otherwise keep deferring. This works, provided leadership actually wants the discipline. It fails when the objective is the logo and the management system is treated as paperwork.

Three ways organisations approach it

The certificate, the management system, and the difference.

The middle column is the one sold most aggressively in this market: a documentation pack, a fast certificate, and nothing underneath it. It passes an assessment and fails a customer audit, which is the one that costs you the contract.
Certificate from an accredited body
Certified and operating
Certified on paper
Not certified
Risk assessment the business uses
Certified and operating
Certified on paper
Not certifiedSometimes
Statement of Applicability with reasoned exclusions
Certified and operating
Certified on paperGenerated
Not certified
Controls with real operating evidence
Certified and operating
Certified on paper
Not certifiedVaries
Internal audit finding genuine issues
Certified and operating
Certified on paperNominal
Not certified
Survives a customer deep-dive audit
Certified and operating
Certified on paper
Not certifiedNot applicable
Evidence reusable for UAE sector requirements
Certified and operating
Certified on paperBarely
Not certifiedVaries
Surveillance audits are routine, not a scramble
Certified and operating
Certified on paper
Not certifiedNot applicable
Security actually improved
Certified and operating
Certified on paperMarginally
Not certifiedPossibly
Annual cost justified
Certified and operating
Certified on paperOnly if nobody looks
Not certifiedNo cost
Feature
Certified and operating
Certified on paper
Not certified
Certificate from an accredited body
Risk assessment the business uses
Sometimes
Statement of Applicability with reasoned exclusions
Generated
Controls with real operating evidence
Varies
Internal audit finding genuine issues
Nominal
Survives a customer deep-dive audit
Not applicable
Evidence reusable for UAE sector requirements
BarelyVaries
Surveillance audits are routine, not a scramble
Not applicable
Security actually improved
MarginallyPossibly
Annual cost justified
Only if nobody looksNo cost
What changed in the 2022 edition

The 2013 structure against the current one.

For organisations transitioning, this is the shape of the work. The clauses moved very little. Annex A was reorganised substantially, and that is what makes the Statement of Applicability a rebuild rather than an edit.
ISO/IEC 27001:2013ISO/IEC 27001:2022
Annex A control count11493
Annex A structure14 domains4 themes
Organizational controlsSpread across domains37, clauses 5.1 to 5.37
People controlsSpread across domains8, clauses 6.1 to 6.8
Physical controlsSpread across domains14, clauses 7.1 to 7.14
Technological controlsSpread across domains34, clauses 8.1 to 8.34
Climate change considerationNot presentRequired by clause 4.1 via Amendment 1:2024
Statement of ApplicabilityRequiredRequired, rebuilt against new structure
Management system clausesClauses 4 to 10Clauses 4 to 10, largely unchanged
Currently certifiableNo, transition closed 31 October 2025Yes
How we run it

Five stages, typically six to twelve months to certificate.

The timeline is driven by two things: how much evidence you already generate, and how quickly your people can make decisions. Neither is something a consultant can compress by working harder.
  1. 1

    Decide whether to certify, and define the scope

    What is driving the requirement, whether certification is the right response, and if it is, exactly what the certificate should cover. Scope is the single largest cost driver and the hardest thing to change later, so this stage is deliberate rather than quick. We also map what you already hold from other frameworks.

  2. 2

    Gap assessment against the 2022 edition

    A clause-by-clause and control-by-control review producing a findings list with effort estimates, so you can see the shape of the programme before committing to it. For organisations transitioning from the 2013 edition this stage is largely a remapping exercise and moves quickly.

  3. 3

    Build the management system

    Risk assessment and treatment, Statement of Applicability, policies sized for your organisation, and the control implementation the risk work identified. We build documentation your team will maintain rather than a pack that impresses at handover and is never opened again.

  4. 4

    Operate it, then audit it internally

    Controls need to run for a period before they can be sampled, so there is an operating window here that cannot be skipped. During it we run the internal audit and the management review, close findings, and get the evidence into a state where stage two is straightforward.

  5. 5

    Stage one and stage two, then maintain it

    We support you through both audit stages with the certification body, manage any nonconformities to closure, and then keep the system running through surveillance audits and recertification. The objective from here is that audits become routine rather than events.

“We were told by another firm that we could be certified in eight weeks using their documentation pack. We went the longer route instead. Eighteen months later a client ran a two-day audit on us and we passed it comfortably, and I am fairly sure the eight-week version would not have survived the first morning.”
Managing Director
Technology services company, Dubai · Client reference available on request
Straight answers

What UAE organisations ask about ISO 27001.

ISO/IEC 27001:2022, including Amendment 1:2024 which added the climate action changes. The transition period from the 2013 edition closed on 31 October 2025, so a certificate issued against ISO/IEC 27001:2013 is no longer a current certificate regardless of the expiry date printed on it. This is worth checking today rather than at your next tender, because the discovery usually happens at the worst possible moment.

Amendment 1:2024 added a sentence to clause 4.1 requiring the organisation to determine whether climate change is a relevant issue when identifying internal and external issues, and added a note to clause 4.2 acknowledging that interested parties can have climate-related requirements. The 4.2 addition is a note rather than a normative requirement. Practically, this is a documented consideration in your context analysis, not an environmental management programme, and certification bodies have been checking for it during surveillance audits since 2024.

As many as your risk assessment says you need, and no more. Annex A of the 2022 edition contains 93 controls across four themes, 37 Organizational, 8 People, 14 Physical and 34 Technological, and it is a reference set rather than a mandatory list. You select controls based on your risk treatment, and you justify exclusions in the Statement of Applicability. Organisations that implement all 93 regardless of relevance have usually misunderstood the standard and spent a great deal of money doing so.

For an organisation starting from a reasonable security baseline, typically six to twelve months to certificate. The two things that set the pace are how much operating evidence you already generate, because controls have to run for a period before they can be sampled, and how quickly your leadership can make decisions about scope and risk appetite. Anyone quoting eight weeks is selling a documentation pack, and the certificate that results tends not to survive a customer audit.

No, and you should be cautious of any consultancy that says it can. Certification is issued by an accredited certification body, and accreditation rules exist specifically to keep consulting and certification separate, because a firm that audits its own advice is not independent. What we do is prepare you: scope, risk assessment, management system, controls, internal audit, and support through stage one and stage two with the body you appoint. We will help you choose one and tell you what to ask them.

There are two separate costs and it is worth keeping them apart. The certification body charges audit fees based on audit days, which are driven by your scope, headcount and number of sites, and those fees recur annually through surveillance and every three years at recertification. Our preparation work is scoped separately. We do not publish figures because the range across a fifteen-person firm and a multi-site group is very wide, but we will tell you at the outset what drives the number so you can budget realistically before committing.

It depends almost entirely on who is asking. ISO 27001 is the recognised standard across Europe, the Middle East and much of Asia and it certifies a management system, so it is a statement about how you run security. SOC 2 is predominantly what American buyers ask for and it is an attestation report by a CPA firm about your controls over a period, so it reads differently. If your buyers are mixed, you may eventually need both, and there is substantial overlap in the underlying evidence. Establish who is asking before choosing.

Considerably, and mapping it first is the best way to control cost. The underlying disciplines are the same: risk management, asset management, access control, incident management, continuity, third-party oversight. Much of your existing evidence transfers directly. What ISO 27001 adds on top is the management system layer, the clauses about leadership, planning, internal audit and management review, which sector standards address less prescriptively. That layer is usually the genuine gap rather than the controls.

The service your customers are actually assessing, plus the infrastructure, locations and people that support it. Two failure modes: a scope so narrow that a client reads the certificate, sees it excludes the service they buy, and dismisses it, which is worse than not certifying; and a scope so broad that you spend a year and a large budget certifying parts of the business nobody asked about. Write the scope statement early and read it as a sceptical customer would.

No. Your cloud provider certifies itself, and you rely on its certificate as part of your third-party assurance. What you do need is to define whether the cloud environment is inside your scope boundary, hold evidence that you have assessed the provider, and manage the parts of the shared responsibility model that fall to you. That last point catches people out: the provider certifies its infrastructure, and your configuration of it remains entirely yours.

The certification body returns, usually annually, and samples parts of the management system rather than reauditing everything: whether internal audits happened, whether management review happened, whether findings were closed, whether the risk assessment has been maintained, and whether the controls it selects are operating. Surveillance audits are straightforward for an organisation that runs its system through the year and stressful for one that assembles evidence in the preceding fortnight. The difference is entirely in the habit.

Failure in the dramatic sense is rare, because a competent preparation process would have caught it. What happens instead is nonconformities: minor ones you correct within an agreed period, major ones that must be closed before a certificate is issued or that can suspend an existing one. The common causes of a major nonconformity are an internal audit that never happened, a management review that was never held, or a control claimed in the Statement of Applicability that has no evidence behind it at all.

You cannot transition an expired position, but you can certify against the current 2022 edition, and for an organisation with a genuinely operating management system this is far less work than starting from nothing. Your clauses, risk process and most of your evidence carry forward. The Statement of Applicability is rebuilt against the new four-theme structure, the clause 4.1 climate consideration is added, and the certification body assesses you against the current standard. Expect weeks of preparation rather than months.

No, and this matters commercially. A certificate is only as credible as the accreditation behind the body that issued it. There are unaccredited certificates in circulation that look convincing and carry no weight with a customer who checks, and the customers most likely to ask for ISO 27001 are exactly the ones who will check. Before appointing a body, confirm its accreditation and confirm it is accredited for your sector and scope, not merely accredited in general.

Treating it as a documentation exercise. The clauses that carry the most weight are about leadership, risk decisions, internal audit and improvement, and none of those can be templated because they are records of things your organisation actually did. When a project fails, it is almost always because the documentation was bought, the activities never happened, and there is nothing for an assessor to sample. The second biggest reason is scope decided by finance rather than by what the customer asked for.
Before you commit to certification

Fifteen questions to answer before the first invoice.

The first group decides whether to certify at all, and it is the group most often skipped. The second is scoping, which drives cost more than anything else. The third is readiness, and it is what separates a nine-month project from an eighteen-month one.

Should you certify at all

  • Has a specific customer, tender or regulator actually asked for it?
    If nobody has, the certificate may not be the right spend.
  • Would a completed security questionnaire satisfy the same request?
    Frequently it would, at a fraction of the cost.
  • Is the request specifically ISO 27001, or would SOC 2 serve better?
    Depends heavily on whether your buyers are European or American.
  • Can you sustain surveillance audits and annual cost indefinitely?
    Certification is a recurring commitment, not a project.
  • Do you have management commitment beyond signing the budget?
    Clause 5 is about leadership, and assessors test it directly.

Scope, which drives the cost

  • Which service or entity does the customer actually care about?
    Certify that, plus what supports it.
  • How many physical locations are in scope?
    Sites drive audit days more than headcount does.
  • Are cloud platforms and third parties inside or outside the boundary?
    Ambiguity here produces findings and awkward client questions.
  • Does the scope statement read sensibly to a customer?
    They will read it. A narrow scope can be worse than none.
  • Have you chosen an accredited certification body?
    Accreditation matters. An unaccredited certificate persuades nobody.

Readiness

  • Do you have a risk assessment the business actually uses?
    Not one written once for a consultant.
  • Has an internal audit been completed and its findings closed?
    Required before stage two, and commonly the blocker.
  • Has management review happened, with minutes?
    An assessor will ask to see them.
  • Do your controls have three to six months of operating evidence?
    You cannot sample a control that started last week.
  • Have you documented the clause 4.1 climate consideration?
    Amendment 1:2024, and easy to miss on an early transition.
Related reading

The pages around this one.

IT audit services in Dubai

The wider audit practice: what an assessment examines, how findings are evidenced, and which type of engagement your situation actually calls for.

Learn more

ADHICS V2 compliance in Abu Dhabi

The Abu Dhabi healthcare standard, read from the Department of Health source, and how ISO 27001 evidence maps onto its eleven control domains.

Learn more

NESA compliance in Dubai

The national information assurance regime, and how alignment to one framework reduces the work required for the other.

Learn more
Next step

Start by reading the edition printed on your certificate.

If it says 2013, that is today priority and we can tell you quickly what the route back looks like. If you are not certified at all, the first conversation is about whether you should be, and we are perfectly willing to conclude that you should not.

Book an ISO 27001 gap assessmentCall +971 56 613 2743

Related Services

Explore more solutions that work great with this service

CBUAE IT Requirements

Which Rulebook articles actually bind your licence

Learn more

NIST CSF 2.0 Assessment

Know where you stand, without committing to certification

Learn more

SOC 2 Readiness UAE

Type II preparation, and when ISO 27001 fits better

Learn more

Virtual CISO Dubai

Security governance and accountability, not more tools

Learn more

PCI DSS Compliance UAE

Scope reduction first, then the controls that remain

Learn more

IT Audit Services Dubai

Assessment, technical test or certification, scoped properly

Learn more

ADHICS V2 Compliance

The Abu Dhabi healthcare standard, read from the source

Learn more

NESA / IA Compliance

UAE Information Assurance Standards compliance

Learn more
GR IT SERVICES

Leading IT services provider in Dubai,
delivering enterprise-grade solutions
for businesses across the UAE.

Microsoft CSP PartnerCISGuard

Get the Helpdesk app

Raise and track IT tickets from your phone.

Download on the App StoreGet it on Google Play
Learn more about the app

Microsoft 365

  • Microsoft 365 Administration
  • M365 Reporting & Auditing
  • Microsoft 365 Licensing
  • Microsoft Copilot
  • Microsoft 365 Apps
  • Windows 365 Cloud PC
  • Microsoft SharePoint
  • Outlook & Exchange

Security

  • Microsoft Defender
  • Microsoft Purview
  • Microsoft Intune
  • Microsoft Entra
  • Compliance Manager
  • Cybersecurity Audits
  • Copilot for Security
  • Microsoft Sentinel
  • Microsoft Priva

Infrastructure

  • Google Workspace
  • Cloud Migration Services
  • Data Analytics & BI
  • Active Directory
  • Server Management
  • Apple Business
  • Apple Jamf Pro
  • IP Telephone
  • Data Backup
  • Website Development

IT Services

  • Managed IT Services
  • IT Support Dubai
  • IT AMC Dubai
  • New Office IT Setup
  • IT Relocation
  • Remote IT Support
  • On-Call IT Support
  • Startup IT Business Kit
  • Disaster Recovery & BC

Company

  • About Us
  • Careers
  • Contact
  • Blog

Contact

  • Iris Bay Tower, Office 903,
    Business Bay, Dubai, UAE
  • +971 56 613 2743
  • hello@gritservices.ae
  • gritservices.ae

© 2026 GR IT Services. All rights reserved.

Privacy PolicyTerms of UseCookie Policy