UiPath Achieves DESC Certification, Unlocking Dubai Government as an Eligible Customer Base
UiPath has achieved certification under the Dubai Electronic Security Center Cloud Service Provider Security Standard for its Automation Cloud UAE region, removing the regulatory barrier that previously prevented Dubai government and semi-government entities from deploying UiPath cloud services.

UiPath achieves DESC Cloud Service Provider Security Standard certification, enabling Dubai government agentic automation deployments
UiPath has achieved certification under the Dubai Electronic Security Center Cloud Service Provider Security Standard for its Automation Cloud Commercial UAE region, clearing the most significant regulatory hurdle for any cloud provider seeking to serve Dubai's public sector.
The DESC, operating under the Digital Dubai Authority, serves as the primary regulatory authority for cybersecurity and digital infrastructure protection in Dubai. Its Cloud Service Provider Security Standard is grounded in international frameworks including ISO 27001, with additional controls designed specifically for the UAE's regulatory and data sovereignty requirements. Under Dubai law, government and semi-government organisations are prohibited from engaging cloud service providers that have not achieved DESC certification, making this designation a mandatory prerequisite rather than a competitive differentiator. For enterprise technology and procurement leaders, the distinction matters: this is not a badge. It is a legal threshold.
Understanding where DESC sits within the broader UAE compliance architecture is useful context. As covered in MCW's guide to the UAE NESA cybersecurity framework, the UAE operates one of the most structured cybersecurity compliance regimes in the region, with federal and emirate-level frameworks running in parallel. DESC governs Dubai specifically, while NESA sets federal baseline controls. Organisations operating across the UAE must navigate both layers, and cloud service providers seeking public sector access must satisfy each.
With the certification in place, UiPath becomes an eligible automation platform for Tier 1 enterprises and government entities across the UAE, enabling them to deploy agentic automation at scale with confidence that their data handling, identity management, encryption, and business continuity protocols meet the most stringent local standards. For organisations that have previously been unable to deploy UiPath's cloud services due to regulatory constraints, the certification removes that barrier entirely.
The DESC certification covers the full breadth of automation and artificial intelligence capabilities in the UiPath platform. UAE government and enterprise customers can now leverage end-to-end agentic automation capabilities, from intelligent document processing and AI-powered decision-making to orchestration, testing, and citizen development, all within a fully certified, compliant cloud environment.
Scott Roberts, Chief Information Security Officer at UiPath, described the certification as a direct reflection of the rigorous security standards to which UiPath holds itself, stating that it sends a clear message to customers across Dubai and the broader UAE that data is protected, compliance obligations are met, and organisations can move forward with confidence.
Karl Crowther, Vice President for Middle East and Africa at UiPath, framed the certification within the broader direction of UAE public sector AI adoption. As the UAE accelerates toward a future where agentic AI powers a significant proportion of government services and operations, effective business orchestration becomes critical to ensuring that AI agents operate within governed, secure, and compliant workflows. The DESC certification provides the compliant foundation for that next phase of deployment. That framing aligns directly with the infrastructure-level sovereign AI work underway across the country, including the UAE Government Cybersecurity Summit convening in Abu Dhabi on 9 June, where data sovereignty and AI governance are expected to feature prominently on the agenda.
For enterprise security and procurement leaders in Saudi Arabia and the broader GCC, the UiPath DESC certification is a reference point worth noting. As individual GCC markets develop their own cloud service provider security standards, the DESC framework, with its ISO 27001 foundation and UAE-specific data sovereignty controls, represents a template for how regulatory certification is likely to evolve across the region. Enterprises that begin mapping their cloud vendor portfolios against emerging local certification requirements now will be better positioned as those frameworks become mandatory across other Gulf markets.
Layla Haddad
Cyber Policy & Digital Risk CorrespondentLayla Haddad covers cybersecurity regulations, data protection laws, and digital transformation initiatives across GCC and North Africa. She has worked closely with compliance teams, fintech startups, and government advisory groups. Her articles explore how cyber policy, AI governance, and privacy frameworks shape the region’s digital future.