VAPT and Penetration Testing in the UAE: Dubai and Abu Dhabi
Penetration testing for UAE companies, delivered the way the market orders it: VAPT, meaning a vulnerability assessment of everything in scope followed by manual penetration testing by OSCP-certified testers. Budget Security serves companies in Dubai, Abu Dhabi and the free zones remotely from The Hague. Start within 7 days of booking, findings in your dashboard, and a report shaped for PDPL, ISO 27001, SOC 2 or PCI DSS evidence.
Scope it yourself and see the tester-day estimate before anyone talks to you. Sign up or try the calculator.
Not sure whether a tender asking for "VAPT" means something different from a pentest? Read VAPT vs penetration testing first. This page is where you order one.
What we test for UAE companies
UAE buyers come to us with a document in hand: a supplier security questionnaire from a bank, a free-zone authority's data protection checklist, an ISO 27001 certification body's request for evidence, or a government tender that lists VAPT as a condition. The platform is built to answer the document rather than start a sales cycle.
You register the assets once. For each engagement you pick the asset, the goal and a tester-day limit, and the scoping engine returns the plan: which assets get manual exploitation depth, which get assessment coverage, and what a shorter plan would leave untested. If the shorter plan no longer satisfies the goal you named, the plan says so before you book.
Scope options for UAE engagements:
- Web application penetration testing: authenticated testing of customer portals, tenant isolation, role boundaries and the checkout and onboarding flows that carry personal data.
- API penetration testing: the interfaces behind mobile apps, open-banking connections and the integrations your partners call.
- Cloud penetration testing: IAM, configuration and privilege paths in AWS, Azure and Google Cloud, including the UAE regions many Dubai and Abu Dhabi workloads now live in.
- External and internal network penetration testing: the perimeter as the internet sees it, then lateral movement from inside over an authorised VPN.
- Mobile penetration testing: iOS and Android apps for consumers and field staff, plus their backends.
Every test is manual work by an OSCP-certified tester. Tooling handles discovery; a person handles exploitation and attack chains.
Penetration testing in Dubai
Dubai sends us the broadest mix of any city in the region: fintech and payments firms in the DIFC, logistics and trade platforms, property and hospitality groups with large customer databases, and the technology vendors that supply Dubai Government entities. Two regulatory contexts show up again and again in their scoping conversations.
The first is the Dubai Electronic Security Center's Information Security Regulation (ISR). DESC states that the regulation applies to "all Dubai Government Entities, including but not limited to employees, consultants, contractors and visitors who are not government employees but are engaged with it through various means", and that it "applies to any government information regardless of its type and medium". Source: DESC, Standards and Policies. If your company is a contractor to a Dubai Government entity, that scope statement reaches you through your contract, and the entity's security team will ask how you test the systems that touch its information. The DESC page does not name penetration testing, and we do not claim the ISR mandates one; what a VAPT report does is answer that question with evidence.
The second is DIFC. The UAE Government's data protection page names the "Data Protection Law, DIFC Law No 5 of 2020" as the regime for the free zone. Source: u.ae, Data protection laws. DIFC firms usually arrive with their own regulator's expectations already written into a policy, and the engagement is scoped to produce the evidence that policy requires.
A typical Dubai engagement is a grey-box test of a customer-facing web application plus its API, 3 to 5 tester-days, with the cloud account added when the goal is ISO 27001.
Penetration testing in Abu Dhabi
Abu Dhabi engagements skew toward three groups: companies registered in ADGM, suppliers to federal and emirate government entities, and energy and industrial groups with corporate IT that has never been tested from the inside.
For ADGM-registered companies, the Office of Data Protection states that the Data Protection Regulations 2021 apply to "all ADGM registered entities that process personal data". On breaches, data controllers "must inform the Office of Data Protection of a data breach" "not later than 72 hours after becoming aware of them", under Article 32 of the regulations. Sources: ADGM, Office of Data Protection and Data Breach Notifications. The ADGM pages do not require a penetration test, and the page notes that demonstrating "adequately implementing measures to mitigate the risk and prevent future occurrences" can lead to no further action. A dated VAPT report with closed findings is that demonstration, prepared before the 72-hour clock ever starts.
For government suppliers, it helps to know what the federal regulator means by the term. TDRA offers penetration testing to government entities as a service, described as evaluating security "by searching for security vulnerabilities and trying to use them to access data and internal environment, and then providing a report to the entity about the vulnerabilities that have been discovered, in order to close them before attackers exploit them". Source: TDRA, Penetration Testing. That service is for the government sector only. For the private companies that sell to those entities, our engagement is built to the same definition: find, exploit, report, close.
Abu Dhabi buyers ask for internal network tests more often than Dubai buyers do. The question is what an attacker reaches from one compromised laptop: Active Directory, file shares, internal applications and the cloud identities tied to them.
Federal Decree-Law 45 of 2021: the UAE Personal Data Protection Law
The federal Personal Data Protection Law "came into force on 2 January 2022". It applies to "the processing of personal data, whether in full or part through electronic systems, inside or outside the country", and it "defines the controls for the processing of personal data and the general obligations of companies that have personal data to secure it and maintain its confidentiality and privacy". It also "sets out the requirements for the cross-border transfer and sharing of personal data". Source: u.ae, Data protection laws.
Nothing on that page names penetration testing, and this page does not claim the law requires one. The obligation it does name is to secure personal data and keep it confidential. When a regulator, a customer or your own board asks how you know the systems holding that data are secure, a VAPT report answers in the language they expect: what was tested, what was found, what was exploitable, what was fixed and when the fix was verified. In the platform, set "personal data systems" as the goal and the scoping engine puts the tester-days there first.
ISO 27001, SOC 2 and PCI DSS for UAE companies
ISO 27001 is the certificate UAE buyers ask us about most, because it is the one enterprise and government procurement teams across the Gulf recognise. SOC 2 follows for companies selling into the US, and PCI DSS applies to anyone handling card data.
- ISO 27001 penetration testing: the independent test evidence your certification body expects for Annex A technical vulnerability management, with findings mapped to the control each one defeated.
- SOC 2 penetration testing: evidence for the common criteria a US auditor samples.
- PCI DSS penetration testing: external and internal testing of the cardholder data environment and its segmentation.
Set the framework as the goal at scoping time and the report cross-references every finding to it. One engagement, one report, as many mappings as you sell into. If you also operate in Singapore, the MAS-specific scope is on penetration testing in Singapore.
How an engagement runs from The Hague
Budget Security has no office, staff or entity in the UAE. Testing is delivered from the Netherlands by OSCP-certified testers over authorised, logged connections.
- Your afternoon is our morning. Central European Time is 3 hours behind Dubai and Abu Dhabi (2 hours during European summer time). Our testers start at around noon UAE time and work into your evening. Verified findings land in the dashboard as they are confirmed, so your team sees the first results the same working day and the full day's set the next morning.
- Start within 7 days of booking. A start within 24 hours is possible only when a tester is available, carries an urgency fee, and is never guaranteed.
- The report arrives within 48 hours after the test ends: executive summary, technical findings with evidence, remediation per finding and the compliance mapping for the goal you set.
- Payment is due after report delivery. Nothing is charged at booking.
- A confirmed start date can be moved, but not for free, because the tester-days were reserved for you.
- Retests of fixed findings are ordered from the dashboard and close the finding in the same tracker your auditor sees.
What we need before the start date: scope sign-off, credentials for authenticated testing, and a signed authorisation letter. The platform collects all three.
What you receive
The engagement lives in a dashboard, and the report is exported from it. Each finding carries its severity, proof, remediation guidance and current status, so a DIFC or ADGM compliance officer, a certification auditor or a government client's security team can trace a finding from discovery to verified closure. Findings are tagged as assessment-discovered or penetration-confirmed so the two halves of the VAPT are evidenced separately in the same document.
FAQ
VAPT in the UAE FAQ
What does a penetration test cost in the UAE?
Do you have an office in Dubai or Abu Dhabi?
Does the UAE Personal Data Protection Law require a penetration test?
Does the DESC Information Security Regulation apply to private companies?
What is the ADGM breach-notification deadline?
Can the report be used for ISO 27001 certification?
How fast can you start?
When do I pay, and what if I need to move the date?
VAPT for your UAE company, scoped by you, priced before you commit.
OSCP-certified testers. Start within 7 days. Findings in your dashboard the same day. Report within 48 hours after the test ends.