We are an 18-person digital marketing and data analytics agency in Dubai. We are about to close a 600,000 AED per year data processing and campaign management deal with an Abu Dhabi-based financial group. In the final round of negotiations, their procurement department made providing a "cybersecurity compliance certificate" a contractual requirement.
We hold an ISO 27001 certificate obtained two years ago, but it has been suspended because we missed this year's surveillance audit. One local consultancy we spoke with claims renewing our existing ISO 27001 certification will suffice. Another auditor insists that in the financial sector, a third-party independent compliance report based on the local regulators' cybersecurity compliance framework is strictly required.
The quoted consultancy and audit fees range from 40,000 AED to 120,000 AED, with timelines between 2 and 5 months. We are struggling to understand what the client actually means and which certification we should pursue without burning our budget needlessly. What is the practical difference between the two?