How to choose a pentest provider in the UAE
Most vendor-selection mistakes in this market share one cause: buyers compare marketing pages instead of evidence. Seven checks, in the order they are worth doing, before you sign a statement of work.
Seven checks, in the order worth doing them
-
Define scope before you talk to a single vendor
"External penetration testing" can mean network perimeter only, or perimeter plus web applications, APIs and cloud configuration. Quotes are only comparable if the scope is identical, so write down which assets, environments and testing types you need before requesting proposals.
Be specific about counts: how many domains, how many applications, how many API endpoints, whether staging is in or out, and whether cloud configuration review is included. Vendors price off those numbers, and a proposal built on a vague scope will be re-priced after kick-off — which is when you have the least leverage.
-
Ask for a redacted sample report first
This is the fastest way to separate a real manual-testing shop from a relabelled scanning service, and it costs you one email. A genuine external pentest report shows reconnaissance findings, manually validated vulnerabilities with proof-of-concept evidence, a narrative explaining business impact rather than only a CVSS number, and remediation ordered by actual risk.
A vendor who cannot or will not share a redacted sample has told you something. Read what arrives, too: a 60-page document that is 50 pages of tool output and appendices is not a stronger report than a 20-page one with five well-evidenced findings and a clear impact narrative.
-
Ask who will actually test, not the company headcount
A firm with 500 employees can still assign your engagement to one junior tester. Ask for the certifications of the specific people who will work on your project — OSCP, CREST Registered Tester or CCT, GPEN, OSWE — and whether a senior tester reviews the findings before the report ships.
This matters most with vendors whose penetration testing sits inside a large managed-security business, where offensive specialists may be shared with service-delivery work. Several entries on our ranking carry exactly that caveat.
-
Verify the accreditation claim yourself
Both certifying bodies that matter here publish public registers, and checking takes about a minute. Do it before the accreditation influences your shortlist — see the section below for exactly how.
-
Then match accreditation to what your regulator actually requires
Do not over-buy. DESC's Cyber Force accreditation is mandatory for vendors serving Dubai government, semi-government and critical-information-infrastructure entities, and has been since 1 July 2024. It is not a requirement for private-sector engagements. CREST accreditation is commonly requested by regulated-sector buyers, particularly in finance, as a quality signal rather than a legal obligation.
If neither applies to your sector, do not let a vendor price the accreditation as though it were mandatory for you. If one does apply, it is a hard filter and the editorial order of any comparison — including ours — is the wrong tool: filter the register first.
-
Get retest terms in writing before you sign
Ask explicitly whether retesting of fixed critical and high findings is included in the base statement of work, or is a separate billable engagement. Pin down the window, too: "retest included within 30 days of report delivery" is a very different commitment from "retest included", when your remediation will realistically take a quarter.
This detail is easy to skip during scoping and expensive to discover afterwards, which is why it is one of the five criteria in our methodology.
-
Ask about data handling — especially in fintech, crypto or regulated data
Testing necessarily means the vendor accessing sensitive systems and sometimes touching sensitive data. Establish where test artefacts — findings, evidence, anything captured during testing — are stored, in which jurisdiction, for how long, who has access, and how they are disposed of when the engagement closes.
Ask which legal entity signs the contract and where its staff are located. Two providers on our ranking are certified in the UAE while having ownership or delivery capability in another country, which is not a problem in itself but is something you should know before data starts moving.
How to read the DESC register yourself
DESC publishes its certified providers in two tables, one for penetration testing and one for incident response, under the Cyber Force programme it runs with CREST as certifying body. Four things are worth knowing before you use it:
- Search the registered legal entity, not the trading name. This is the single most common reason a real certification appears to be missing. Providers appear as, for instance, "Help Information Technology Consultancy LLC" rather than the brand a buyer would recognise. If a name is not there, ask the vendor what entity it is certified under before concluding anything.
- Every entry carries an expiry date. Read it against your engagement timeline. Certifications lapse, and a provider certified when you shortlisted them may not be when you sign. Two entries on our current ranking expire within twelve months.
- The two tables are separate. A firm certified for incident response is not thereby certified for penetration testing. Check the table you actually need.
- Company accreditation is not individual certification. A team holding CREST individual certificates is a genuine credential and a different claim from the company being accredited. Vendor marketing frequently blurs the two; ask which is meant.
For CREST claims, the equivalent register is the CREST Marketplace, which lists member companies, their accredited service areas and the regions they serve. When we ran these checks across ten commonly-listed UAE providers in September 2026, two advertised an accreditation we could not find on either register — which is a useful reminder that the check is worth doing rather than assumed.
The complete vendor question checklist
-
What methodology do you follow — PTES, the OWASP Testing Guide, NIST SP 800-115?
-
Can I see a redacted sample report from a comparable engagement?
-
How many hours of manual testing are in this engagement, as distinct from tool runtime?
-
Who specifically performs the testing, what are their certifications, and who reviews the report?
-
Are those testers dedicated to offensive work, or shared with your managed-services delivery?
-
Is retesting of fixed critical and high findings inside this statement of work, and within what window?
-
How is my data protected during the engagement, in which jurisdiction is it stored, and how is it disposed of afterwards?
-
Do you hold CREST or DESC accreditation relevant to my sector — and can you send the register link and expiry date so I can verify it?
-
Which legal entity contracts the work, and where are the assigned staff located?
-
What is the timeline from kick-off to final report for this scope, and what do you need from us to start?
One more decision: format
A team shipping weekly will get more from continuous coverage than from a single annual engagement that goes stale the week after delivery; a team meeting one annual compliance date will usually get more depth from a dedicated engagement window. If you are unsure which applies, see PTaaS vs. point-in-time.
And if you are still weighing whether you need a penetration test at all or a vulnerability assessment would do, start with the difference between the two — it is the cheapest mistake on this page to avoid.
Applicability is not our call
Whether DESC, NESA/SIA, CBUAE or PCI DSS applies to your organisation is a question for your compliance team or counsel. This guide links the primary sources so you can take them the actual text; it is not legal or procurement advice. See our editorial policy.