DESC ISR v3 in Dubai: What the Information Security Regulation Requires
What DESC's Information Security Regulation (ISR v3) requires, who is in scope, and why it matters commercially in Dubai.
What security a UAE crypto exchange must demonstrate for VARA — wallets, key management, testing and proof of reserves — before going live.
Launching or operating a virtual-asset exchange in the UAE means meeting the Virtual Assets Regulatory Authority (VARA) — and security is central to what VARA assesses. A crypto exchange holds custody, moves value in real time, and is a permanent target. This guide sets out what “secure” has to mean for a UAE exchange before, and after, you go live.
An exchange is several high-risk systems in one: wallets and key management, a matching and trading engine, deposit and withdrawal flows, APIs, and the customer-facing platform. Each is a target, and a weakness in any one can drain funds or leak data. Security therefore has to be designed across the whole surface — hot and cold wallet architecture, key custody and signing controls, withdrawal approvals, and hardening of the trading and API layers. ITSEC's crypto exchange security practice assesses exactly these layers.
VARA regulates virtual-asset service providers in Dubai under its activity-based Rulebooks, updated to Version 2.0 in 2025, which strengthened custody controls and oversight across licensed activities. For an exchange, that translates into demonstrable controls over custody and key management, independent security testing, incident response, and clear evidence that client assets are protected. Our VARA cybersecurity page maps these expectations to concrete controls.
Beyond keeping attackers out, an exchange increasingly has to prove to users and regulators that customer assets are actually there. A proof-of-reserves audit provides cryptographic evidence that on-chain holdings back customer balances — a trust signal that has moved from nice-to-have to expected. Combined with penetration testing of the platform, it forms the evidence base regulators and counterparties look for.
Treat security as a launch gate, not a post-launch task. Independent testing of wallets, the trading engine and APIs; a tested incident-response plan; and documented custody controls should all be in place before the first real deposit. Retrofitting them after launch is more expensive and far riskier. For the wider market context, see our overview of crypto exchanges in the UAE.
If you are building or running a UAE crypto exchange, security is what stands between you and both the regulator and the headlines. ITSEC provides wallet, trading-engine and API security assessment, proof-of-reserves support and VARA-aligned testing. Visit our crypto exchange security page to scope a review.