About this site
A comparison of external penetration testing providers in the UAE built on evidence a reader can check, published by an editorial desk that says plainly where the evidence runs out.
Why it exists
Search for a penetration testing provider in Dubai and most of what comes back is one of two things: a vendor ranking itself first in its own comparison article, or a roundup recycling the same unverified claims about the same handful of firms. Neither answers the question a CISO actually has.
There is a better answer available, and it is public. The Dubai Electronic Security Center publishes the companies certified to deliver penetration testing under its Cyber Force programme, with an expiry date against each one. CREST publishes its accredited members on the CREST Marketplace. Between them, the single most load-bearing claim a vendor makes about itself can be checked in about a minute — and when we did that for the ten providers most often named in UAE roundups, four of them did not come back the way their marketing suggested.
That gap is what this site is for.
What we do
- Research providers active in the UAE market for external penetration testing.
- Check every accreditation claim against the certifying body's own register, searching the registered legal entity rather than the trading name, and record the date of the check.
- Publish a ranking order with the criteria that produced it stated in the open, so a reader can disagree with the judgement rather than just accept a number.
- Say explicitly what we could not verify, on the card where it matters, instead of smoothing it over.
The methodology page carries the current state of that verification work, including a per-company table of what is confirmed and what is still open.
Who writes it
Content is produced and maintained by the site's Editorial Team, working as a Security Research Desk. Bylines are a shared editorial role. We do not publish individual staff biographies, photographs or personal profiles for this project, and we do not invent them either — a fabricated expert persona is a trust signal, and this site does not manufacture those. What we offer instead is a method you can audit and sources you can open.
What we do not do
- We do not sell penetration testing, and we are not a reseller, broker or lead-generation service for any provider listed here.
- We do not accept payment for a ranking position, and we carry no affiliate links. See the editorial policy for the full disclosure position.
- We do not publish star ratings, aggregate scores, testimonials or review schema for any company.
- We do not give legal, regulatory or procurement advice. Statements about UAE frameworks are background, linked to primary sources so you can read them directly.
- We do not audit anyone's technical testing quality. This is a comparison of documented capability and accreditation, and it belongs alongside reference checks and a sample report, not instead of them.
Corrections and additions
If something here is wrong, we want to know, and that includes companies correcting their own profiles. Use Submit a company for a listing change or addition, or the contact page for anything else. Evidence gets assessed the same way whoever sends it.
Don't take our word for it
Every registry status on this site links to the register it came from and shows the date we looked. That is deliberate: the point is not that you trust this site, it is that you do not have to.