Sector guide

R&D tax credits for cybersecurity.

UAE security teams and vendors are advancing detection, cryptography and architecture against threats that outpace off-the-shelf tools. That work often qualifies for the R&D Tax Credit — the discipline is proving precisely which part.

01 · The five criteria, in security

How qualifying R&D shows up in security.

The UAE regime tests every project against the five OECD Frascati criteria. Here is what each looks like in a detector, a cipher, or a security architecture.

1

Novel

A detection or cryptographic method not already available.

2

Creative

Original security engineering, not configuration of known tools.

3

Uncertain

Whether it defeats the threat at scale is uncertain.

4

Systematic

Planned adversarial testing and iteration, documented.

5

Transferable

Results reproducible across environments and threat models.

02 · Example projects

The kind of work that qualifies.

Illustrative projects across upstream, downstream and the energy transition. Eligibility is always confirmed project by project.

Detection

Novel threat detection

Detection methods identifying novel attack classes that signature-based tools miss.

Crypto

Applied & post-quantum crypto

Applied cryptography, including post-quantum, for a real deployment constraint.

Architecture

Security at scale

Security architecture that must hold at a scale or threat model with no proven blueprint.

AI security

AI-driven defence

ML-based defence where the modelling approach itself is uncertain, not rule tuning.

Hardware

Hardware & device security

Securing devices or hardware against attacks with no established countermeasure.

Response

Automated response

Automated containment or response methods that resolve a problem with no proven answer.

03 · Where the line falls

Genuine R&D, not routine engineering.

The value we add is drawing this line correctly — claiming what qualifies, and defending it, while leaving out what does not.

Typically qualifies
  • Advancing underlying security technology where success is uncertain.
  • Developing novel detection, cryptography or architecture with unknown outcomes.
  • Adversarial, experimental work to defeat a threat with no established answer.
  • Systematic testing and iteration to prove the approach.
typically doesn't
  • Configuring or deploying existing security products.
  • Applying known frameworks and controls to specification.
  • Routine monitoring, patching and incident handling.
  • Compliance and audit activity with no technical uncertainty.
Track record

£50M+

claimed across 450+ UK companies with a 100% audit success record — including complex, engineering-heavy claims in energy and industrials. The same chartered method now applies to the UAE.

“We needed a partner who understood deep-tech innovation and could handle complex claims efficiently. RDvault delivered exactly that.”

Hybird — a Techstars company

A UAE cybersecurity case study will feature here as claims complete under the new regime.

04 · Common questions

Configuration and deployment do not qualify. But advancing the underlying technology — where defeating a threat required genuinely uncertain, experimental work — frequently does.

Routine analysis is not. Developing detection methods where the technical approach itself is uncertain and must be proven can qualify.

No — audit and compliance activity carries no technical uncertainty. The qualifying work is the security engineering behind it.

Contemporaneous records: the technical uncertainty, the work done to resolve it, and project-level cost and staff-time allocation. We build this as the work happens — and pre-approval is mandatory before claiming.

Growing in the desert? Let’s find what qualifies.

We assess your projects against the five criteria, handle pre-approval, and build the evidence — before a single figure is claimed.