HomeFrameworksQatar NIAS v2.1
National Cyber Security Agency (NCSA) · Qatar

National Information Assurance Standard, Version 2.1 (NIAS) compliance software

NCSA's current certifiable information assurance standard for Qatar — 356 controls across 26 domains, 166 baseline controls tracked as mandatory, superseding the NIA v2.0 Policy for new applications.

At a glance
  • RegulatorNational Cyber Security Agency (NCSA)
  • VersionNIAS v2.1 — reviewed and approved May 2023
  • Structure26 domains, unchanged from v2.0
  • Controls356, of which 166 are baseline and mandatory
Qatar NIAS v2.1Available
Overview

What Qatar NIAS v2.1 requires

Who it applies to

  • Qatar government ministries, agencies and public bodies applying for NIAS certification
  • Operators of critical information infrastructure required to hold current NIAS certification
  • Service providers accessing or processing information assets for a NIAS-certified organisation
  • Organisations re-certifying an expiring v2.0 certificate against v2.1

The National Information Assurance Standard, Version 2.1 (NIAS), reviewed and approved by Qatar's National Cyber Security Agency in May 2023, supersedes the NIA Policy v2.0 it replaces: v2.0 applications closed 31 December 2023, existing v2.0 certificates run to their own expiry, and any new application or re-certification is against v2.1 only.

v2.1 keeps every v2.0 control code and domain — 26 domains across the same governance and security-control structure — while widening several requirements: data classification labels extend from three tiers to four (Internal, Restricted, Secret, Top Secret), critical incident notification to NCSA tightens from a one-hour to a two-hour window with a wider trigger, minimum log retention rises from 90 to 120 days, and audits move to an NCSA-accredited audit organisation rather than the retired Certification Body. 166 of the 356 controls are baseline and mandatory regardless of an agency's business impact assessment.

GRCLens carries v2.1 as its own catalogue beside the v2.0-based Qatar NIA page, so an agency already assessed against v2.0 sees exactly what changed control by control, and a new application starts directly on the standard NCSA will certify against.

In the platform

How GRCLens supports Qatar NIAS v2.1

Qatar NIAS v2.1 runs on the same shared control model as every other framework in GRCLens, so evidence captured once can satisfy several obligations at the same time.

Baseline tier tracked as mandatory

166 baseline controls carry the standard's own marker, reported as a separate tier so a mandatory-control gap cannot hide behind a healthy overall average.

What changed from v2.0, control by control

The controls v2.1 reworded — wider data classification labels, the two-hour incident window, 120-day log retention, NCSA-accredited audit — are carried with the change visible, for an agency migrating a live assessment.

The current certifiable standard

New applications and every re-certification run against v2.1; agencies still holding a v2.0 certificate see it flagged as it nears expiry, so re-certification starts on the standard NCSA will actually assess.

Arabic and English

Every control, category and guidance note carried in both languages, reusing verified Arabic from the v2.0 catalogue and freshly authored Arabic wherever the text changed.

Questions

Qatar NIAS v2.1 frequently asked questions

Does NIAS v2.1 replace the NIA Policy v2.0?

For new applications and re-certification, yes. NCSA closed v2.0 applications on 31 December 2023; existing v2.0 certificates remain valid to their own expiry, but every re-certification is against v2.1.

What actually changed between v2.0 and v2.1?

No controls were added, removed or renumbered. A small set were reworded for real content changes — data classification widened to four tiers, critical-incident notification tightened to two hours, minimum log retention rose to 120 days, and audits moved to an NCSA-accredited organisation — the rest are terminology-only updates.

Can GRCLens run both the v2.0 and v2.1 catalogues?

Yes. The Qatar NIA page carries the v2.0-based catalogue for agencies with a live certificate; this page carries v2.1 for new applications and re-certifications, so nothing forces a migration before the agency needs one.

Talk to us about Qatar NIAS v2.1

Security Solution Consultants provides Qatar NIAS readiness and advisory alongside the platform, so you can combine tooling with hands-on expertise.