Straight answers for Sharjah companies on SOC 2, ISO 27001, local regulation, timelines and cost.
Does Tranquility Cybersecurity have an office in Sharjah?
+
No. We do not have an office in Sharjah or anywhere else in the UAE. Sharjah is part of our UAE service area: we are headquartered in Gurugram, India, and serve Sharjah from there, with on-site visits across the UAE for kick-off, control walkthroughs and audit days. Gulf Standard Time is 1.5 hours behind IST, so the working days overlap almost completely, and Sharjah is a short drive from Dubai, which keeps on-site days easy to plan.
Which privacy law applies to a company licensed in SHAMS or SAIF Zone?
+
The UAE federal Personal Data Protection Law, Decree-Law 45 of 2021, overseen by the UAE Data Office. Sharjah has no financial free zone with its own privacy regime, so DIFC and ADGM rules do not apply to a Sharjah entity directly — although a DIFC or ADGM client will pass processor obligations down to you by contract. We build one privacy programme on the federal PDPL and layer those client-side duties, and GDPR where you have European customers, on top.
We are a fifteen-person software company in SHAMS. Is ISO 27001 or SOC 2 the right first step?
+
Start from who is asking. If your customers are UAE enterprises, banks or government-linked entities, ISO 27001 is the certificate their procurement teams name, and it is the more common ask across the UAE. If your customers are in the US or you sell through global SaaS partners, SOC 2 Type II is what they expect. A fifteen-person team can carry either with a right-sized control set; if both are on the horizon we build one set and sequence the audits so evidence is collected once.
A UAE bank has asked our SAIF Zone logistics company for a business continuity certificate. Is this normal?
+
Yes, and it is spreading. UAE banks have translated CBUAE continuity and outsourcing expectations into ISO 22301-aligned BCMS clauses for critical vendors, including logistics and service providers, with the first contract deadlines reported from December 2025. They typically expect a business impact analysis, defined RTO and RPO for the services you provide them, tested plans and, in many cases, certification by an accredited body. TCSA builds the BCMS and prepares you for that audit; our consultants have prepared Gulf banks themselves for ISO 22301.
Is there a Sharjah equivalent of Dubai’s DESC ISR or Abu Dhabi’s ADHICS?
+
Not a widely applied emirate-level standard of the same kind, as far as we see in practice. Sharjah companies more often meet the federal layer — the UAE IA Standard for critical sectors and their suppliers, and the federal PDPL for personal data — plus whatever a Dubai or Abu Dhabi client pushes down by contract, which can include ISR or ADHICS expectations. In every case the formal assessment is done by an approved assessor; we align your ISO 27001 ISMS to the relevant control expectations so that assessment goes smoothly.
Do you deliver policies and reports in Arabic?
+
Engagements run in English — policies, reports, working sessions and audit-facing documents — which is the working language of UAE compliance, vendor-risk and audit teams. This site has Arabic pages for the Gulf, but we do not promise Arabic-language deliverables; where a counterparty or regulator requires Arabic artefacts, we plan translation into the engagement schedule with you.
We have no security lead. Can a vCISO replace a full programme?
+
A vCISO complements a programme rather than replacing it. For a lean Sharjah company the retainer gives you a named senior practitioner who owns the security policy, answers customer questionnaires, handles federal PDPL obligations and runs the audit cycle. When a customer then asks for ISO 27001 or SOC 2, the same person scopes and leads that engagement, so nothing is rebuilt. Many clients start with the retainer and add the certification when the first big contract requires it.
How is pricing structured and in which currency do you invoice?
+
Fixed fee, agreed in writing after a scoping call. Typical bands are USD 3,000 – 8,000 for ISO 27001 implementation and USD 2,500 – 6,000 for SOC 2 readiness consulting, with most Sharjah scopes at the lower end; VAPT web-application tests start from about USD 1,000 and vCISO is a monthly retainer scoped to hours. We invoice in USD or INR, with AED available on request. Certification-body and CPA fees are quoted separately by those firms, and we help you scope them so there are no surprises.