UAE · Dubai priority · 2026 edition

Best external penetration testing companies in the UAE

Verify
Compare
Then shortlist

Ten providers active in the UAE market for external penetration testing, ordered by how closely each one's core practice matches a senior-led, manual external test — and checked, one by one, against the registers that can actually confirm an accreditation claim.

Last updated: September 2026 Registries checked: September 2026 Coverage: UAE, Dubai priority

How to read this page. The order reflects specialisation and engagement model, not accreditation. Accreditation is reported separately on every row, because the two are genuinely different questions. If you are buying for a Dubai government, semi-government or critical-infrastructure entity, ignore the order and filter on the DESC column first — for you that certification is mandatory, not preferable.

This is editorial research, not legal, regulatory or procurement advice.

6/10

On the DESC pentest register

Confirmed directly on the Dubai Electronic Security Center's own certified-provider list, each with its expiry date shown on its card.

2

Accreditation claimed, not found

Two providers name an accreditation on their own site that does not appear on the certifying body's register. Both are flagged, not omitted.

1 Jul 2024

When DESC certification became mandatory

Dubai government, semi-government and critical-infrastructure entities must buy penetration testing only from certified companies. Private-sector buyers are not covered.

What the evidence shows

Four things worth knowing before you read a single vendor page.

  • No single provider fits every buyer. A crypto exchange scoping an API and wallet-adjacent test needs a different firm than a bank satisfying an annual perimeter requirement. Read the "best for" line before the position number.

  • Accreditation is checkable in about a minute. DESC publishes its certified providers, with expiry dates, and CREST publishes its members. Any vendor claiming either can hand you a register link. Two on this list cannot.

  • DESC certification is mandatory only for some buyers. It binds Dubai government, semi-government and critical-infrastructure entities. Treating it as a universal filter will exclude capable private-sector firms for no reason.

  • Manual depth, not tool count, separates a pentest from a scan. The fastest way to tell them apart is a redacted sample report. A firm that will not share one has answered the question.

How we ordered them

Five criteria, published in priority order rather than as weighted percentages. We do not assign point scores: inventing numbers that happen to produce a chosen order would be a trust signal we cannot substantiate. The order below is an editorial judgement you can disagree with, and the evidence to disagree with it is on every card.

  1. Specialisation & engagement model

    01

    Is external penetration testing the core practice — manual-first, senior-led — or one line item inside a broad managed-security and consulting portfolio? Includes sector fit for fintech, crypto and SaaS.

  2. External attack-surface depth

    02

    Documented testing of external network, web application, API and cloud scope with human validation, rather than automated scanning presented as a penetration test.

  3. Independent evidence

    03

    Claims confirmable outside the vendor's own marketing: an official register such as DESC's certified-provider list or the CREST Marketplace, a regulator, or press with a named and checkable source.

  4. UAE delivery & compliance fit

    04

    A verifiable UAE entity or UAE-timezone delivery capability, and demonstrated relevance to the frameworks that actually apply to the buyer — DESC, NESA/SIA, CBUAE or PCI DSS.

  5. Retest & remediation

    05

    Whether a retest of fixed critical and high findings is inside the base statement of work or billed separately — the detail most often discovered after signing.

Read the full methodology, source audit and update policy.

Provider comparison

Every provider gets the same fields. "Registry evidence" reports what a primary register says as of September 2026 — not what the vendor says about itself.

External penetration testing providers active in the UAE, ordered by specialisation and engagement-model fit. Registry status verified September 2026.
# Provider Best for Focus Registry evidence (checked Sep 2026) Why shortlisted
01 Paranoid Security Fintech and crypto teams wanting a senior-led boutique engagement Manual web, mobile and network pentest, red teaming, crypto-wallet forensics Not on DESC register The only provider here pairing external testing with blockchain incident forensics; senior-led delivery is the whole model
02 DTS Solution Regulated enterprises needing an auditor-proof report Black/grey/white-box pentest, red teaming, OT and ICS DESC pentest & IR · exp 22 Oct 2026 Best-evidenced provider on the list: DESC-certified for both disciplines and a CREST member, with offensive testing as a core practice
03 PentestME SMEs and startups wanting a Dubai firm that only does pentesting Web, mobile, internal and external infrastructure pentest Cyber Force claim not on DESC register Narrowest service focus after Paranoid Security, with a verified Dubai entity — but its headline accreditation claim is unconfirmed
04 Microminder Cyber Security Buyers wanting one CREST-accredited offensive and defensive vendor Pentest, social engineering, red and blue team CREST penetration testing CREST accreditation confirmed on the Marketplace; UK-headquartered, so UAE delivery is the open question
05 Haumaru Labs Buyers wanting a DESC-certified small team, not a consultancy Penetration testing as sole specialism DESC pentest · exp 23 Jul 2027 DESC-certified through a UAE company with a Dubai line, and CREST-listed; ownership sits partly in New Zealand
06 ValueMentor SMEs and mid-market buyers who also need compliance advisory Pentest, vCISO, PCI DSS / ISO 27001 / SWIFT CSP advisory DESC pentest · exp 21 Sep 2026 Strongest firmographic evidence among the SME-focused candidates, with a decade-plus documented UAE record
07 Obrela Buyers wanting testing from the same vendor running their detection MDR and managed risk, with pentest and IR practices DESC pentest & IR · exp 30 Apr 2027 DESC-certified for both disciplines with a Dubai office, though managed detection is the core business
08 Help AG Large enterprises and telcos already buying managed security from e& Red teaming inside a broad MSS and consulting portfolio DESC pentest & IR · exp 8 Apr 2027 Longest-standing brand here and DESC-certified for both disciplines; offensive testing is one line item of many
09 CPX Government and large enterprise wanting a single broad vendor Consulting, Cyber Test & Evaluation, OT, managed security DESC pentest & IR · exp 4 Feb 2027 Largest UAE-headquartered, government-backed provider here; external-pentest methodology is not publicly documented
10 Wattlecorp Mid-market buyers wanting multi-surface VAPT in one engagement Network, web, mobile, API and cloud testing CREST claim not found on register Broad surface coverage claimed from a Dubai office, but the accreditation that would support it is unverified

Provider profiles

Same template for every entry: verdict, who it suits, confirmed services, what a register actually says, and the questions to put to them. Nothing appears here as fact unless a primary source supports it.

01

Paranoid Security

Best for: fintech and crypto teams wanting a senior-led boutique engagement

Not on DESC register · checked Sep 2026

A boutique offensive-security team built around senior specialists running the engagement personally rather than delegating to a project team, and the only provider on this list that pairs external penetration testing with crypto-wallet forensics and blockchain tracing. That combination is why it leads on our first criterion: for a crypto or fintech buyer, testing the perimeter and tracing a wallet incident are usually two separate procurements. Its documented markets are Russia and the wider MENA region; a UAE-registered legal entity was not independently confirmed.

Confirmed services
Web and mobile application audits; external and internal network penetration testing; red teaming; Wi-Fi audits; social engineering; crypto-wallet forensics and blockchain incident response.
Questions to ask
Is there a UAE legal entity or a local partner that can contract the engagement? How many senior testers work on it, and does anyone review the report before it ships? What CVSS version, proof-of-concept standard and reporting format do you use? Is a retest of fixed critical findings inside the base scope?

02

DTS Solution — A Beyon Cyber Company

Best for: regulated enterprises needing a report an auditor will accept without pushback

DESC pentest & IR · checked Sep 2026

Dubai-headquartered since 2011 and acquired by Bahrain's Beyon Cyber in 2023, this is the best-evidenced provider on the list: certified under the Dubai Cyber Force programme for both penetration testing and incident response, and separately a CREST member company. Offensive testing and red teaming are core practices rather than line items in a managed-services catalogue, which is why it sits second on specialisation despite being the strongest on evidence.

Confirmed services
Black-box, grey-box and white-box penetration testing; red teaming and adversary emulation; web, API, mobile and configuration assessments; OT and ICS security assessment; incident response.
Registry evidence
DESC Cyber Force register, as DTS Solution L.L.C: penetration testing with a listed expiry of 22 October 2026, and incident response expiring 21 July 2026. CREST member company listing also confirmed. Both checked September 2026.
Limitations
Its penetration testing entry carries the second-nearest expiry date on this list, so an engagement scoped in late 2026 could straddle a renewal. Post-acquisition, some delivery and SOC capability sits with Beyon Cyber in Bahrain.
Questions to ask
Which specific CREST service lines cover my engagement type, penetration testing or incident response? Has the DESC penetration testing certification been renewed past October 2026? How does integration with Beyon Cyber's Bahrain operations affect the UAE-based delivery team on my project?
dts-solution.com Sources: DESC certified-provider register; CREST member company listing; company website; acquisition press coverage, January 2023.

03

PentestME — Penetration Testing Middle East

Best for: SMEs and startups wanting a Dubai firm that does only penetration testing

Claim not on DESC register · checked Sep 2026

Established in mid-2023 and registered as Penetration Testing Middle East FZCO at Dubai Silicon Oasis, this is the narrowest service focus on the list after Paranoid Security: penetration testing with no managed-security or consulting bundle attached. The problem is its headline accreditation claim, which we could not confirm and which a buyer should settle before anything else.

Confirmed services
Web application, mobile application, and internal and external infrastructure penetration testing; vulnerability assessment; red teaming; ransomware simulation. Consultants are stated to hold OSCP, OSCE, OSWE, OSED, CREST CCT APP and CREST CRT.
Registry evidence
Flagged. The company's own site states it is "one of the first accredited cybersecurity companies to become a member of the Dubai Cyber Force initiative" and displays a DESC-accredited logo, but gives no certificate reference or register link. Penetration Testing Middle East does not appear on DESC's certified-provider list, checked September 2026. A register cannot distinguish a lapsed entry, an accreditation held by individuals rather than the company, or an overstated claim.
Limitations
Founded in 2023, so a short track record and no published case studies. The named CREST certifications are real credentials, but individual certification is not company accreditation.
Questions to ask
Can you send the DESC Cyber Force certificate reference or register entry? Is the Cyber Force membership held by the company or by named individuals? Which of the listed CREST and Offensive Security certifications are held by the testers assigned to my engagement? Can I see a redacted sample report?
pentest-me.com Sources: company website, including its Cyber Force and About pages; DESC certified-provider register (searched, no listing found); named as a UAE market participant in independent industry research.

04

Microminder Cyber Security

Best for: buyers wanting one CREST-accredited vendor across offensive and defensive work

CREST penetration testing · checked Sep 2026

CREST-accredited for penetration testing, confirmed directly on the CREST Marketplace, and one of only two providers here whose accreditation we verified on CREST's own register. It is headquartered in the United Kingdom with Europe and the Middle East listed as served regions and a listed team size under ten people, so whether your test is delivered from the UAE or remotely from the UK is a question to settle during scoping rather than an assumption to make.

Confirmed services
Penetration testing; social engineering; web application testing; red and blue team operations. Company certifications on its CREST entry: ISO 27001, ISO 9001, UK NCSC Cyber Essentials and Cyber Essentials Plus.
Registry evidence
CREST Marketplace: accreditation listed as Penetration Testing, headquarters United Kingdom, regions served Europe and Middle East. Checked September 2026. Not listed on DESC's Cyber Force register.
Limitations
Absent from the DESC register, so it cannot be engaged for Dubai government, semi-government or CII penetration testing. Small listed headcount relative to the breadth of services advertised, and no UAE office confirmed in the sources reviewed.
Questions to ask
Is Middle East delivery UAE-based, or remote from the UK? Can you provide UAE client references? Which named testers on my engagement hold CREST individual certifications, and at what level? Does the ISO 27001 certification cover the entity that will handle my test data?
micromindercs.com Sources: CREST Marketplace supplier listing; company website.

05

Haumaru Labs

Best for: buyers wanting a DESC-certified small team rather than a large consultancy

DESC pentest · exp 23 Jul 2027

Certified under the Dubai Cyber Force programme for penetration testing through a UAE company — Haumaru Lab for Auditing, Reviewing & Testing Cyber Risks Co. L.L.C — with a Dubai landline on the register, while the registered contact address uses a New Zealand domain. So this is neither a purely offshore arrangement nor a straightforwardly local one, and it is worth asking which it is in practice. Penetration testing is its only listed specialism, which is unusual among the certified providers here and counts in its favour on specialisation.

Confirmed services
Penetration testing, listed as its CREST specialism and its DESC certified discipline. ISO 27001 held as a company certification.
Registry evidence
DESC Cyber Force register: penetration testing, listed expiry 23 July 2027 — the longest-dated entry among the providers on this page. CREST service listing also confirmed. Both checked September 2026.
Limitations
Small listed team, and ownership and delivery appear to span two countries, which matters for timezone coverage, incident escalation and where your test artefacts are stored. No published UAE case studies were found.
Questions to ask
Which testers are UAE-based and which are in New Zealand, and what timezone will my engagement run in? Where are findings and evidence stored during and after the test? Given the team size, what is your current lead time and can you commit to my window? Can you provide UAE client references?
haumarulabs.co.nz Sources: DESC certified-provider register; CREST service listing.

06

ValueMentor

Best for: SMEs and mid-market buyers who need testing alongside compliance advisory

DESC pentest · exp 21 Sep 2026

Dubai-headquartered, founded in 2013–2014 by Binoy Koonammavu, with a documented decade-plus record in the UAE market and a dedicated CEO for the Middle East appointed in 2024. It has the strongest firmographic evidence base of the SME-focused candidates and is DESC-certified for penetration testing. Testing sits alongside a substantial governance and compliance practice, so the useful question is which team actually runs the external test.

Confirmed services
Penetration testing; vulnerability assessment; red teaming; cloud security; DevSecOps security; managed detection and response; cyber forensics and incident response; virtual CISO; GRC consulting including PCI DSS, ISO 27001 and SWIFT CSP advisory. Published case studies include penetration testing engagements in Dubai and Kuwait and NESA compliance work for a UAE insurer.
Registry evidence
DESC Cyber Force register, as ValueMentor Cyber Risk Management Services LLC: penetration testing, listed expiry 21 September 2026 — the nearest-term expiry of any provider on this page. Checked September 2026.
Limitations
Its PCI QSA and ISO 27001 claims circulate mainly in third-party comparison content rather than a register lookup we could complete. The imminent DESC expiry is the practical issue: if you need a certified provider, confirm renewal before signing.
Questions to ask
Has the DESC penetration testing certification been renewed past September 2026? Can you send current PCI QSA and ISO 27001 certificate references? Which team delivers external perimeter testing as distinct from internal testing and vulnerability assessment? Is retesting inside the base scope?
valuementor.com Sources: DESC certified-provider register; company website and published case-study index; regional business press coverage of the 2024 leadership appointment.

07

Obrela

Best for: buyers wanting external testing from the same vendor running their detection

DESC pentest & IR · exp 30 Apr 2027

Approved under the Dubai Cyber Force programme for both penetration testing and incident response in June 2024, operating in the UAE as Obrela Security Industries MEA FZ-LLC with a Dubai office. Its core business is managed detection and response and managed risk, so penetration testing is one practice inside a managed-services portfolio rather than the centre of the firm — which is why it ranks mid-list on specialisation despite solid evidence.

Confirmed services
Penetration testing; incident response; managed detection and response; managed risk and controls; digital forensics and incident response; continuous threat exposure management; professional advisory services.
Registry evidence
DESC Cyber Force register, as Obrela Security Industries MEA FZ-LLC: penetration testing and incident response, both with a listed expiry of 30 April 2027. Checked September 2026. Independently reported in regional trade press at the time of accreditation.
Limitations
Penetration testing is not the core practice, and a firm organised around continuous monitoring may reach for automated exposure management where a manual deep-dive is what you asked for. No UAE-specific pentest case studies were found in the sources reviewed.
Questions to ask
Are penetration testers a dedicated offensive team, or shared with the SOC and exposure-management practice? Can I see a sample external penetration test report, separate from MDR reporting? Where are the assigned testers based? How much of the engagement is manual versus tool-driven?
obrela.com Sources: DESC certified-provider register; company accreditation announcement, June 2024; regional consulting trade press.

08

Help AG, an e& enterprise company

Best for: large enterprises and telcos already buying managed security from e&

DESC pentest & IR · exp 8 Apr 2027

One of the longest-established cybersecurity brands in the Gulf, Dubai-headquartered and owned by e&, formerly Etisalat. It holds the first-listed entries on both of DESC's Cyber Force registers, for penetration testing and incident response. Offensive testing exists as one service line inside a large managed-security and consulting business, and that is the thing to probe: the certification belongs to the company, but the people on your engagement may or may not be dedicated offensive specialists.

Confirmed services
Red teaming; managed security operations; digital forensics; advisory and consulting services. Its register entries are held under Help Information Technology Consultancy LLC.
Registry evidence
DESC Cyber Force register: penetration testing with a listed expiry of 8 April 2027, and incident response expiring 8 May 2027. Checked September 2026. This corrects a widely repeated claim that Help AG's current accreditation status could not be confirmed — it is on the register, first in both lists.
Limitations
Penetration testing is a small part of a very large services business, so scoping discipline matters more here than with a boutique. Public material describes red teaming and managed security in more detail than it does external penetration testing methodology.
Questions to ask
Are the assigned red-team and pentest staff dedicated offensive specialists, or shared with managed-security delivery? Can I see a sample external penetration test report, distinct from managed-security reporting? What are the named certifications of the testers on my engagement? What is the named methodology — PTES, OWASP or NIST SP 800-115?
helpag.com Sources: DESC certified-provider register; company website; third-party company profile for ownership and firmographics.

09

CPX

Best for: government agencies and large enterprises wanting one broad vendor

DESC pentest & IR · exp 4 Feb 2027

Abu Dhabi–headquartered, founded in 2022 and majority-owned by G42, CPX is the largest UAE-headquartered provider on this list and is DESC-certified for both penetration testing and incident response. Penetration testing sits inside an unusually broad portfolio spanning consulting, managed security, OT and even physical security, and its external-testing methodology is the least documented of any certified provider here — which is what places it ninth on specialisation rather than on evidence.

Confirmed services
Cyber consulting; Cyber Test and Evaluation; cyber resilience services; OT and ICS cybersecurity; cloud security; managed detection; physical security.
Registry evidence
DESC Cyber Force register, as CPX Holding LLC: penetration testing and incident response, both with a listed expiry of 4 February 2027. Checked September 2026.
Limitations
Public sources do not describe the external penetration testing methodology, scope boundaries or reporting format, so the certification is the only hard signal available. A portfolio and client base oriented to large government programmes may not suit a mid-sized private-sector scope.
Questions to ask
Is external penetration testing delivered by a dedicated in-house offensive team, or subcontracted? What named methodology do you follow, and can I see a redacted sample report? What is the minimum engagement size? Which entity contracts the work and where is test data held?
cpx.net Sources: DESC certified-provider register; company website; industry award and acquisition press coverage for firmographics.

10

Wattlecorp

Best for: mid-market buyers wanting multi-surface VAPT — once the accreditation is settled

CREST claim not on register · checked Sep 2026

Markets network, web, mobile, API and cloud penetration testing from a Dubai office, with delivery described as mapped to SIA/NESA, ISO 27001, PCI DSS and CREST standards. The breadth is genuine as a service offering, but the accreditation that would substantiate the compliance framing is the issue: a direct search of CREST's own register and Marketplace returned no company listing, and Wattlecorp does not appear on DESC's register either. That combination places it last here.

Confirmed services
Network, web application, mobile application, API and cloud penetration testing, per the vendor's own service pages. No third-party confirmation of scope or methodology was found.
Registry evidence
Flagged. CREST alignment and CREST-credentialled testers are claimed on the company's site. No company listing was found on CREST's register or Marketplace, and none on DESC's certified-provider list, both checked September 2026. Note the distinction that matters here: individual testers holding a CREST certification is a different claim from company accreditation, and the marketing does not separate the two.
Limitations
Everything on record traces to the vendor's own pages or to aggregator and competitor comparison articles. Not eligible for Dubai government, semi-government or CII penetration testing without DESC certification.
Questions to ask
Can you send your CREST Marketplace profile URL or membership number? If the CREST claim refers to individuals, which testers hold which certifications, with numbers? Can I see a sample report showing NESA and PCI DSS mapping? Which legal entity contracts the work?
wattlecorp.com Sources: vendor website; CREST Marketplace and CREST member register (searched, no listing found); DESC certified-provider register (searched, no listing found).

What a proper external pentest includes

A vulnerability scan flags what a tool can see. A penetration test proves what an attacker could do with it. These five stages are what you are paying the difference for.

  1. Reconnaissance and attack-surface discovery

    Mapping domains, subdomains, exposed services and cloud assets before testing begins. Buyers are routinely surprised here: the asset that gets exploited is often one nobody remembered owning.

  2. Manual validation

    A human tester confirms each automated finding is real and reachable in your environment, removing the false positives a scanner reports without apology.

  3. Controlled exploitation, where authorised

    Chaining findings — an exposed API plus a weak authorisation check, say — to demonstrate real business impact, inside a signed rules-of-engagement document that says exactly what is permitted.

  4. Reporting

    Findings mapped to CVSS, with evidence such as screenshots or proof-of-concept code, and remediation ordered by business risk rather than by raw severity score.

  5. Remediation and retest

    Fixes verified rather than assumed. Whether this is inside the base engagement or billed separately is a contract question, and it is the one buyers most often discover too late.

Full comparison: external pentest vs. vulnerability assessment

How to choose a provider in the UAE

Most selection mistakes in this market come from comparing marketing pages instead of evidence. Five checks catch the majority of them.

  • Scope first, vendor second. Decide whether you need external perimeter, web and API, cloud, or a combination before requesting quotes. Prices are only comparable across identical scopes.

  • Ask for a redacted sample report. The single fastest disqualifier. A real report shows manual validation, proof-of-concept evidence and business-impact framing, not a scanner export with a cover page.

  • Ask who actually tests. Get the certifications of the specific people assigned to your engagement — OSCP, CREST Registered Tester, GPEN — not the company's aggregate headcount.

  • Verify accreditation yourself, then match it to your regulator. DESC and CREST both publish registers. Check the claim, then check whether the accreditation is actually required for your sector before paying a premium for it.

  • Get retest terms in writing. Confirm before signing whether retesting fixed critical and high findings is inside the statement of work or a separate billable engagement.

Full guide, including how to read the DESC register and the complete vendor question checklist

PTaaS vs. point-in-time

Neither format is better in the abstract. The right one depends on how often your environment changes and what specifically you need to satisfy.

Comparison of engagement formats. Neither is a compliance shortcut on its own.
Aspect Point-in-time pentest PTaaS
Cadence Scheduled engagement, typically annual or pre-release Continuous or frequent testing, usually subscription-based
Best fit Compliance deadlines, major releases, annual audit cycles Teams shipping API or feature changes more than monthly
Reporting One comprehensive report at the end of the engagement Rolling findings, often pushed into a ticketing tool
Coverage risk Can lapse between engagements as the environment changes Stays current, assuming genuine ongoing manual effort
Manual depth Usually deeper per pass, since the window is dedicated to one scope Varies widely by provider — ask what share of each cycle is manual

Full comparison, including the trade-off most PTaaS pitches leave out

UAE compliance context

Background, not legal advice. Confirm applicability with your compliance team or counsel before requiring any of this of a vendor.

DESC Cyber Force

The Dubai Electronic Security Center's accreditation programme, run with CREST as certifying body, covering exactly two disciplines: penetration testing and incident response. It became mandatory on 1 July 2024 for Dubai government, semi-government and critical-information-infrastructure entities, which must procure those services only from certified companies. It does not bind private-sector buyers. The certified-provider list is public and shows an expiry date for every entry.

CREST

A UK-founded, internationally recognised accreditation for penetration testing firms and individual testers. Commonly requested by regulated-sector buyers as a quality signal rather than universally mandated. Company accreditation and individual certification are separate things, and vendor marketing frequently blurs them. Both are searchable on the CREST Marketplace.

Sector frameworks

NESA / UAE Information Assurance Standards, the CBUAE Information Security Standard, PCI DSS and the UAE PDPL each apply to specific sectors or data types — government and critical infrastructure, banking, card payments and personal data respectively. Establish which, if any, apply to you before making them a vendor requirement.

Registers move

Every registry status on this page carries the date we checked it, because certifications expire and lapse. Two entries here expire within twelve months of publication. Before you sign anything on the strength of an accreditation, check the register yourself — it takes about a minute, and the links are above.

Questions buyers actually ask

What is external penetration testing?

Authorised, manual testing of everything an attacker can reach from outside your network — public-facing servers, web applications, APIs and cloud assets. The purpose is to prove real exploitability and business impact, not to list potential weaknesses.

Is CREST or DESC accreditation required for all penetration testing in the UAE?

No. DESC's Cyber Force certification is mandatory for vendors serving Dubai government, semi-government and critical-infrastructure entities, and has been since 1 July 2024. Private-sector buyers may request CREST or DESC as a quality signal, but neither is a blanket legal requirement. Confirm what your own regulator or auditor expects rather than assuming.

How do I check whether a provider's accreditation claim is real?

Both certifying bodies publish registers. DESC lists its certified providers by legal entity name, with an expiry date for each. CREST publishes members and accredited services on the CREST Marketplace. Search the vendor's registered legal entity, not its trading name — several providers appear under a name that differs from their marketing. If a vendor cannot point you at its own register entry, treat the claim as unverified.

What is the difference between a vulnerability scan and a penetration test?

A scan lists what automated tooling detects. A penetration test has a human validate, chain and — with authorisation — exploit findings to demonstrate business impact, and delivers a report built for remediation rather than a list of CVEs. Read the full comparison if you are deciding which you need.

How often should we run an external pentest?

At minimum annually, and after any significant infrastructure or application change. If you ship features weekly, an annual test is stale within weeks of delivery and a continuous format may fit better — see PTaaS vs. point-in-time.

Will an external pentest report satisfy PCI DSS or NESA?

Sometimes, depending on scope and the specific control involved. PCI DSS, for instance, treats vulnerability scanning and penetration testing as two separate obligations with different frequencies. Confirm the required scope and reporting format with your QSA or compliance lead before commissioning the test, not after.

How much does external penetration testing cost in the UAE?

It depends on scope size, methodology depth, and whether retesting is included. We do not publish a figure, because we have no confirmed source for one and a plausible-looking guess would be worse than no number at all. Our editorial policy explains why. Get at least three quotes against an identical written scope.

Editorial note and corrections

Last updated September 2026, with all registry statuses checked that month. This page carries no paid placements and no affiliate links. The order reflects the criteria published above and on the methodology page, which also records what we could not verify. Sourcing rules and the corrections process are in the editorial policy. Found an error, or want a listing reviewed? Send us the evidence.