Skip to main content
    PENETRATION TESTING/UNITED ARAB EMIRATES
    ·By Budget Security

    VAPT and Penetration Testing in the UAE: Dubai and Abu Dhabi

    Penetration testing for UAE companies, delivered the way the market orders it: VAPT, meaning a vulnerability assessment of everything in scope followed by manual penetration testing by OSCP-certified testers. Budget Security serves companies in Dubai, Abu Dhabi and the free zones remotely from The Hague. Start within 7 days of booking, findings in your dashboard, and a report shaped for PDPL, ISO 27001, SOC 2 or PCI DSS evidence.

    Scope it yourself and see the tester-day estimate before anyone talks to you. Sign up or try the calculator.

    Not sure whether a tender asking for "VAPT" means something different from a pentest? Read VAPT vs penetration testing first. This page is where you order one.

    What we test for UAE companies

    UAE buyers come to us with a document in hand: a supplier security questionnaire from a bank, a free-zone authority's data protection checklist, an ISO 27001 certification body's request for evidence, or a government tender that lists VAPT as a condition. The platform is built to answer the document rather than start a sales cycle.

    You register the assets once. For each engagement you pick the asset, the goal and a tester-day limit, and the scoping engine returns the plan: which assets get manual exploitation depth, which get assessment coverage, and what a shorter plan would leave untested. If the shorter plan no longer satisfies the goal you named, the plan says so before you book.

    Scope options for UAE engagements:

    Every test is manual work by an OSCP-certified tester. Tooling handles discovery; a person handles exploitation and attack chains.

    Penetration testing in Dubai

    Dubai sends us the broadest mix of any city in the region: fintech and payments firms in the DIFC, logistics and trade platforms, property and hospitality groups with large customer databases, and the technology vendors that supply Dubai Government entities. Two regulatory contexts show up again and again in their scoping conversations.

    The first is the Dubai Electronic Security Center's Information Security Regulation (ISR). DESC states that the regulation applies to "all Dubai Government Entities, including but not limited to employees, consultants, contractors and visitors who are not government employees but are engaged with it through various means", and that it "applies to any government information regardless of its type and medium". Source: DESC, Standards and Policies. If your company is a contractor to a Dubai Government entity, that scope statement reaches you through your contract, and the entity's security team will ask how you test the systems that touch its information. The DESC page does not name penetration testing, and we do not claim the ISR mandates one; what a VAPT report does is answer that question with evidence.

    The second is DIFC. The UAE Government's data protection page names the "Data Protection Law, DIFC Law No 5 of 2020" as the regime for the free zone. Source: u.ae, Data protection laws. DIFC firms usually arrive with their own regulator's expectations already written into a policy, and the engagement is scoped to produce the evidence that policy requires.

    A typical Dubai engagement is a grey-box test of a customer-facing web application plus its API, 3 to 5 tester-days, with the cloud account added when the goal is ISO 27001.

    Penetration testing in Abu Dhabi

    Abu Dhabi engagements skew toward three groups: companies registered in ADGM, suppliers to federal and emirate government entities, and energy and industrial groups with corporate IT that has never been tested from the inside.

    For ADGM-registered companies, the Office of Data Protection states that the Data Protection Regulations 2021 apply to "all ADGM registered entities that process personal data". On breaches, data controllers "must inform the Office of Data Protection of a data breach" "not later than 72 hours after becoming aware of them", under Article 32 of the regulations. Sources: ADGM, Office of Data Protection and Data Breach Notifications. The ADGM pages do not require a penetration test, and the page notes that demonstrating "adequately implementing measures to mitigate the risk and prevent future occurrences" can lead to no further action. A dated VAPT report with closed findings is that demonstration, prepared before the 72-hour clock ever starts.

    For government suppliers, it helps to know what the federal regulator means by the term. TDRA offers penetration testing to government entities as a service, described as evaluating security "by searching for security vulnerabilities and trying to use them to access data and internal environment, and then providing a report to the entity about the vulnerabilities that have been discovered, in order to close them before attackers exploit them". Source: TDRA, Penetration Testing. That service is for the government sector only. For the private companies that sell to those entities, our engagement is built to the same definition: find, exploit, report, close.

    Abu Dhabi buyers ask for internal network tests more often than Dubai buyers do. The question is what an attacker reaches from one compromised laptop: Active Directory, file shares, internal applications and the cloud identities tied to them.

    Federal Decree-Law 45 of 2021: the UAE Personal Data Protection Law

    The federal Personal Data Protection Law "came into force on 2 January 2022". It applies to "the processing of personal data, whether in full or part through electronic systems, inside or outside the country", and it "defines the controls for the processing of personal data and the general obligations of companies that have personal data to secure it and maintain its confidentiality and privacy". It also "sets out the requirements for the cross-border transfer and sharing of personal data". Source: u.ae, Data protection laws.

    Nothing on that page names penetration testing, and this page does not claim the law requires one. The obligation it does name is to secure personal data and keep it confidential. When a regulator, a customer or your own board asks how you know the systems holding that data are secure, a VAPT report answers in the language they expect: what was tested, what was found, what was exploitable, what was fixed and when the fix was verified. In the platform, set "personal data systems" as the goal and the scoping engine puts the tester-days there first.

    ISO 27001, SOC 2 and PCI DSS for UAE companies

    ISO 27001 is the certificate UAE buyers ask us about most, because it is the one enterprise and government procurement teams across the Gulf recognise. SOC 2 follows for companies selling into the US, and PCI DSS applies to anyone handling card data.

    Set the framework as the goal at scoping time and the report cross-references every finding to it. One engagement, one report, as many mappings as you sell into. If you also operate in Singapore, the MAS-specific scope is on penetration testing in Singapore.

    How an engagement runs from The Hague

    Budget Security has no office, staff or entity in the UAE. Testing is delivered from the Netherlands by OSCP-certified testers over authorised, logged connections.

    • Your afternoon is our morning. Central European Time is 3 hours behind Dubai and Abu Dhabi (2 hours during European summer time). Our testers start at around noon UAE time and work into your evening. Verified findings land in the dashboard as they are confirmed, so your team sees the first results the same working day and the full day's set the next morning.
    • Start within 7 days of booking. A start within 24 hours is possible only when a tester is available, carries an urgency fee, and is never guaranteed.
    • The report arrives within 48 hours after the test ends: executive summary, technical findings with evidence, remediation per finding and the compliance mapping for the goal you set.
    • Payment is due after report delivery. Nothing is charged at booking.
    • A confirmed start date can be moved, but not for free, because the tester-days were reserved for you.
    • Retests of fixed findings are ordered from the dashboard and close the finding in the same tracker your auditor sees.

    What we need before the start date: scope sign-off, credentials for authenticated testing, and a signed authorisation letter. The platform collects all three.

    What you receive

    The engagement lives in a dashboard, and the report is exported from it. Each finding carries its severity, proof, remediation guidance and current status, so a DIFC or ADGM compliance officer, a certification auditor or a government client's security team can trace a finding from discovery to verified closure. Findings are tagged as assessment-discovered or penetration-confirmed so the two halves of the VAPT are evidenced separately in the same document.

    VAPT in the UAE FAQ

    What does a penetration test cost in the UAE?
    Budget Security charges $985 per tester-day for US clients (€849 per day for EU clients). Clients outside the US and EU, including the UAE, are quoted in USD. A first engagement covering a web application and its API runs 3 to 5 tester-days, so $2,955 to $4,925, report and one retest included. At the dirham's fixed rate that is roughly AED 3,620 per tester-day, approximate and invoiced in USD. The figure for your scope is on the [pentest pricing calculator](/pentest-pricing/).
    Do you have an office in Dubai or Abu Dhabi?
    No. Testing is delivered remotely from The Hague, Netherlands, and we have no local staff or entity in the UAE. Web, API, cloud, external and VPN-connected internal network scopes are delivered remotely. Scopes needing a tester physically on site are outside what we offer in the UAE.
    Does the UAE Personal Data Protection Law require a penetration test?
    The UAE Government's page on the law, as fetched for this article, does not mention penetration testing. It describes a general obligation on companies to secure personal data and keep it confidential. A VAPT report is evidence of how you met that obligation for the systems that hold the data.
    Does the DESC Information Security Regulation apply to private companies?
    DESC states the ISR applies to all Dubai Government Entities, including consultants and contractors engaged with them. Private companies supplying a Dubai Government entity meet the ISR through that relationship. The DESC page does not name penetration testing; the entity's security team decides what evidence it needs, and a VAPT report is the usual answer.
    What is the ADGM breach-notification deadline?
    Data controllers registered in ADGM must inform the Office of Data Protection of a data breach not later than 72 hours after becoming aware of it, under Article 32 of the Data Protection Regulations 2021. A VAPT report with closed findings is evidence of the mitigating measures already in place.
    Can the report be used for ISO 27001 certification?
    Yes. Choose ISO 27001 as the goal when scoping and the report maps each finding to the Annex A control it relates to, with the retest status visible to the certification body in the dashboard.
    How fast can you start?
    Within 7 days of booking in most cases. A faster start within 24 hours is possible when a tester is available and carries an urgency fee. It is never guaranteed.
    When do I pay, and what if I need to move the date?
    Payment is due after the report is delivered, within 48 hours after the test ends, not at booking. Moving a confirmed start date is possible but not free, because the tester-days were reserved for you.
    NEXT STEP

    VAPT for your UAE company, scoped by you, priced before you commit.

    OSCP-certified testers. Start within 7 days. Findings in your dashboard the same day. Report within 48 hours after the test ends.