Editorial method

How we build and update this ranking

What gets a company onto this list, how the order is decided, what we verified against a primary register, and what we could not verify and therefore did not publish as fact.

Last updated: September 2026 Next review: December 2026

Why this page exists

Most "best pentest company UAE" content online falls into two buckets: unlabelled vendor self-promotion, and thin roundups repeating the same unverified claims about the same handful of companies. Neither tells a buyer who is actually certified, whose certification expires in six months, or who is simply good at search.

This page is the record of how we tried to do better, including where the record is still incomplete.

Which companies enter the pool

A company is researched if it meets both of these:

  • It is named as a UAE-relevant external penetration testing provider by at least one credible source.
  • It offers services inside our stated scope — external penetration testing — rather than only SOC and MSSP services, antivirus or EDR products, or compliance certification.

We do not rank managed SOC providers, EDR or WAF vendors, ISO 27001 certification bodies, free scanning tools, training providers or procurement platforms, even when a listed company also sells those things.

How the order is decided

The list is ordered by fit for this site's primary reader: a fintech, crypto or SaaS team commissioning a senior-led, manual external penetration test. It is not ordered by accreditation status. Those are two different questions, and collapsing them into one number would hide the more useful of the two.

Five criteria, in priority order:

  1. Specialisation and engagement model. Is external penetration testing the core practice — manual-first, senior-led — or one line item inside a broad managed-security and consulting portfolio? Includes sector fit for fintech, crypto and SaaS.
  2. External attack-surface depth. Documented testing of external network, web, API and cloud scope with human validation.
  3. Independent evidence. Claims confirmable outside the vendor's own marketing — an official register, a regulator, or press with a named and checkable source.
  4. UAE delivery and compliance fit. A verifiable UAE entity or UAE-timezone delivery, and relevance to the frameworks that actually apply to the buyer.
  5. Retest and remediation. Whether retesting fixed critical and high findings sits inside the base statement of work.

Why there are no scores or percentages

We publish the criteria as a ranked list, not as weighted percentages with per-company point totals. Producing numbers that happen to yield a particular order would look rigorous while being unfalsifiable, and it is close kin to the fabricated star ratings this site refuses to publish. An ordinal priority is an editorial judgement stated plainly, which you can examine and reject. The evidence you would need to reject it is on every card.

What position 1 does and does not mean

Paranoid Security is first because it leads on criterion 1: senior-led manual offensive work is its entire practice, and it is the only provider here that also does crypto-wallet forensics and blockchain tracing, which matters specifically to this site's named priority segment. It is last on criterion 3 — it holds no DESC or CREST accreditation, and its service detail is vendor-sourced. Both facts are on its card, in the same template as everyone else.

If you are procuring for a Dubai government, semi-government or critical-information-infrastructure entity, the editorial order is the wrong tool for you. Filter on DESC certification first, because since 1 July 2024 you are required to. Four of the ten entries here are not eligible for that work at all.

What we verified, and what is still open

Checked in September 2026 against DESC's own certified-provider register and the CREST Marketplace.

Source audit, September 2026. Every registry status on the ranking carries the date it was checked, because certifications lapse.
Company Independently confirmed Still open
Paranoid Security Nothing via a third party. Service list and positioning come from the company's own materials. UAE legal entity or local partner; any third-party certification; client references.
DTS Solution DESC Cyber Force for penetration testing and incident response; CREST member company; Dubai HQ, founding year, 2023 acquisition. Renewal status of the pentest entry after 22 October 2026.
PentestME Official domain, legal entity (Penetration Testing Middle East FZCO), Dubai Silicon Oasis address, 2023 founding, service list. The Dubai Cyber Force membership it claims — not present on DESC's register; whether the claim refers to the company or to individual testers.
Microminder Cyber Security CREST accreditation for penetration testing, UK headquarters, regions served, ISO 27001 / ISO 9001 / Cyber Essentials, all on its CREST entry. Whether Middle East delivery is UAE-based or remote; UAE client references.
Haumaru Labs DESC Cyber Force for penetration testing through a UAE L.L.C. with a Dubai landline; CREST service listing; ISO 27001. Split of UAE-based versus New Zealand-based testers; where test artefacts are stored.
ValueMentor DESC Cyber Force for penetration testing; Dubai HQ, founding year, founder, 2024 leadership appointment, published case studies. PCI QSA and ISO 27001 certificate references; renewal after 21 September 2026.
Obrela DESC Cyber Force for penetration testing and incident response; UAE FZ-LLC entity; Dubai office; June 2024 accreditation reported in trade press. Whether testers are a dedicated offensive team or shared with the SOC; UAE pentest case studies.
Help AG DESC Cyber Force for penetration testing and incident response, first-listed in both; Dubai HQ; ownership by e&. Whether assigned testers are dedicated offensive specialists; external-pentest methodology and reporting format.
CPX DESC Cyber Force for penetration testing and incident response; founding year, Abu Dhabi HQ, G42 ownership. External-pentest methodology, scope boundaries and reporting format — not documented in any public source reviewed.
Wattlecorp Dubai office and service scope, from the vendor's own site only. The CREST claim — no company listing found on CREST's register or Marketplace, and none on DESC's register.

How vendor-published comparisons are treated

Several sources encountered during this research are self-published by companies writing about their own competitors. Where a source is a vendor writing about itself or a rival, we treat it as a lead to verify, never as evidence for a position. Aggregator and lead-generation directories are treated the same way.

Conflicts of interest

This site carries no paid placements and no affiliate links, and no company can buy a position on this page. The publisher has no ownership, commercial or client relationship with any company listed here.

If that ever changes — for any company, at any position — the relationship will be disclosed on this page, on the editorial policy page, and directly on the affected company's card, and the card will state how the relationship bears on its position. It will not be buried in general marketing copy. One disclosure already applies: some of Paranoid Security's service and positioning detail was provided by the company for this review rather than gathered from third parties. The source-audit table below records it.

No fabricated trust signals

This site publishes no star ratings, no aggregate scores, no testimonials, and no Review or AggregateRating structured data for any company. If we ever publish client feedback it will be attributable, dated, and clearly separated from editorial judgement.

Sources we use

Update and correction policy

Reviewed at least quarterly, and immediately on a credible correction request. Registry statuses are re-checked at every review, and the check date is shown next to each one. Two entries on the current list expire within twelve months, so those are re-checked first.

Anyone, including a listed company, can request a correction through Submit a company. Evidence is assessed against the same primary-source standard described above. Material corrections are logged with a visible updated date on the affected page. The full process is in the editorial policy.

Check it yourself

Nothing on this page asks for your trust. DESC and CREST both publish searchable registers, linked above. Search a vendor's registered legal entity rather than its trading name — several appear under a different one — and compare what you find with what we published. If they disagree, tell us.