Straight answers for Abu Dhabi companies on SOC 2, ISO 27001, local regulation, timelines and cost.
Does Tranquility Cybersecurity have an office in Abu Dhabi?
+
No. We do not have an office in Abu Dhabi or anywhere else in the UAE. Abu Dhabi is part of our UAE service area: we are headquartered in Gurugram, India, and serve Abu Dhabi from there, with on-site visits across the UAE for kick-off, control walkthroughs, BIA workshops and audit days. Gulf Standard Time is 1.5 hours behind IST, so the working days overlap almost completely, and Abu Dhabi is a direct flight from Delhi for on-site weeks.
We are an ADGM-registered firm. Does the federal PDPL apply to us?
+
Generally no — ADGM has its own regime, the ADGM Data Protection Regulations 2021, enforced by the ADGM Office of Data Protection, and DIFC likewise has its own law. The federal PDPL, Decree-Law 45 of 2021, applies to mainland companies and to most other free zones such as KEZAD, Masdar City and twofour54. Groups with both an ADGM entity and a mainland operating company usually run one privacy programme, built on ISO 27701 controls, and document the two sets of obligations on top of it rather than maintaining two programmes.
Can TCSA get us ADHICS-certified?
+
No, and no consultant can. ADHICS compliance is assessed through the Department of Health – Abu Dhabi’s own process and approved assessors, and the decision sits with them. What we do is align your ISO 27001 ISMS to the ADHICS control expectations, build the mapping into your Statement of Applicability, prepare the policies and evidence, and run an internal audit against it — so the formal assessment goes smoothly and you are not maintaining two programmes.
Is ISO 42001 worth it for a Hub71 AI start-up?
+
If your buyers are banks, government-linked entities or healthcare providers, it is becoming worth it early. Those buyers are starting to ask how AI risk is governed, and ISO 42001 gives an auditable answer — AI risk and impact assessments, roles and accountability, data and model governance — that a security questionnaire alone does not. We integrate it with ISO 27001 so that one management system, one internal audit and one certification-body relationship cover both; the certificate itself is issued by the accredited certification body.
Our bank client in Abu Dhabi has asked for ISO 22301 evidence. What do they actually expect?
+
A working business continuity management system, not a policy document. UAE banks have translated CBUAE continuity and outsourcing expectations into ISO 22301-aligned clauses for critical vendors, with the first contract deadlines reported from December 2025. They typically expect a business impact analysis, defined RTO and RPO for the services you provide them, tested continuity and recovery plans, and in many cases certification by an accredited body. Our consultants prepared ADIB for ISO 22301, so we know what the bank side of that assessment looks like.
Do government-linked buyers in Abu Dhabi accept SOC 2 instead of ISO 27001?
+
Rarely as a substitute. Abu Dhabi government-linked entities, energy operators and ADGM institutions overwhelmingly name an accredited ISO 27001 certificate in procurement, and several also reference the UAE IA Standard. SOC 2 is valued by the same firms’ US and global counterparties, so Hub71 and ADGM technology companies often need both. We build one control set and sequence the certification audit and the CPA examination so evidence is collected once.
Do you deliver policies and reports in Arabic?
+
Engagements run in English — policies, reports, working sessions and audit-facing documents — which is the working language of UAE compliance, vendor-risk and audit teams. This site has Arabic pages for the Gulf, but we do not promise Arabic-language deliverables; where a government-linked counterparty or regulator requires Arabic artefacts, we plan translation into the engagement schedule with you.
How is pricing structured and in which currency do you invoice?
+
Fixed fee, agreed in writing after a scoping call. Typical bands are USD 3,000 – 8,000 for ISO 27001 implementation and USD 2,500 – 6,000 for SOC 2 readiness consulting; ISO 22301 is scoped to your sites and critical services, and OT-adjacent scopes are priced after we understand the environment. We invoice in USD or INR, with AED available on request. Certification-body and CPA fees are quoted separately by those firms, and we help you scope them so there are no surprises.