AFTA Security Requirements in Iran - A Readiness Checklist
AFTA security requirements in Iran explained - who is affected, common technical expectations and a readiness checklist for critical infrastructure security.
By NetGuardUpdated: 8 min readنسخه فارسی

AFTA security requirements are the security requirements and guidelines issued by Iran's AFTA Strategic Management Center (مرکز مدیریت راهبردی افتا) to protect the country's critical infrastructure. AFTA is the Persian acronym for "security of the information production and exchange space". The center operates under the presidency, is responsible for the cybersecurity of critical infrastructure, and oversees the security assessment of products and systems used in it.
If your organization works in energy, telecommunications, financial services, transport or a similar sector in Iran, you are likely expected to be ready for AFTA requirements. This article is a practical guide, not an official interpretation: it explains the common technical expectations, offers a readiness checklist and shows where on-premises tooling with Persian reporting helps. Always take the exact, current obligations from the latest official documents published by AFTA and your supervising authority.
What is AFTA and its role in critical infrastructure security in Iran?
Critical infrastructure means systems and assets whose disruption could seriously harm public services, the economy or national security, such as the power grid, banking systems or telecom networks. In this space, the AFTA center has three main roles:
- Policy and requirements: developing and issuing security requirements, guidelines and instructions for the organizations in scope.
- Oversight and assessment: following up on organizations' security posture through periodic assessments and audits.
- Product security assessment: overseeing whether products and systems deployed in critical infrastructure have been security-assessed.
AFTA requirements are not static; they are updated over time. Rather than relying on circulated lists or old versions, obtain documents through official channels and make one person responsible for tracking changes.
Who must comply with AFTA requirements?
The primary audience is organizations considered critical or sensitive infrastructure. This typically includes sectors such as oil, gas and petrochemicals, power and water, telecommunications and IT, banks and financial institutions, transport and some public services. Exactly which requirements apply to a given organization should be confirmed through its supervising authority or official correspondence.
Two other groups are affected indirectly:
- Suppliers and contractors that provide software, equipment or services to infrastructure organizations, which are usually asked for security evidence about their product or service.
- Organizations outside the formal scope that adopt the same expectations voluntarily as a security baseline, because they align well with international good practice.
Common technical expectations
Details depend on the organization and the version of the documents, but a handful of technical areas come up almost every time. They overlap heavily with ISO 27001 and the NIST CSF.
Asset inventory
You cannot protect what you do not know about. An inventory of servers, network devices, workstations, databases, software and internet-facing services, with an owner, location and criticality for each, is the foundation for everything else.
Hardening and secure configuration
Every system type needs a secure baseline: unnecessary services disabled, default passwords changed, insecure protocols turned off, and password and lockout policies enforced. Starting from CIS Benchmarks and adapting them locally is the most common approach. Our system hardening guide covers this in depth.
Periodic vulnerability assessment
Scanning should be regular, documented and preferably authenticated so installed versions and patches are seen accurately. The output is more than a findings list; it must show what was assessed, when and with what scope.
Patch management
A written process for obtaining, testing and deploying patches, with timelines based on severity and likelihood of exploitation, is a core expectation. Where immediate patching is impossible, document compensating controls and formal risk acceptance.
Access control and privileged accounts
Least privilege, removal of unused accounts, multi-factor authentication for sensitive access and tight control of administrator accounts are recurring themes.
Logging and monitoring
Logs from systems, security devices and critical applications should be collected, retained long enough and monitored so incidents can be detected and investigated.
Incident response
Organizations should have an incident response plan, defined roles, a reporting path to the relevant authorities and periodic exercises.
Product security assessment
Products and systems used in critical infrastructure may need a security assessment under processes defined by AFTA before deployment. Ask vendors about the assessment status of any product before purchase and coordinate with your security team.
From requirement to evidence
Audits most often fail on missing evidence rather than missing controls. The table shows what is typically worth preparing:
| Area | Suggested evidence | Method or tool |
|---|---|---|
| Asset inventory | Current inventory with owners and criticality | Automated discovery plus periodic review |
| Hardening | Approved baseline and compliance percentage | Configuration audit against CIS and custom baselines |
| Vulnerability assessment | Periodic reports with scope and dates | Authenticated vulnerability scanner |
| Patching | Deployment records and approved exceptions | Patch management system plus verification rescans |
| Access control | Privileged account list and access reviews | Periodic review and MFA |
| Logging and monitoring | Retention policy and sample alerts | Centralized log collection (SIEM) |
| Incident response | Approved plan and exercise report | Tabletop exercises |
A practical AFTA readiness checklist

Use this AFTA checklist as a multi-month work plan for the security team. The order matters, because each step needs the output of the one before it:
- Assign an owner and scope. Name an owner for the compliance project and collect the latest official documents relevant to your organization.
- Complete the asset inventory. Discover internal assets and internet-facing services, and assign an owner and criticality to each.
- Define secure baselines. Write and approve baselines for Windows, Linux, network devices and databases.
- Run an initial assessment. Scan for vulnerabilities and audit configurations across the full scope to see the real current state.
- Prioritize remediation by risk. Vulnerabilities with public or known exploitation on critical assets come first.
- Verify fixes with rescans. No finding is closed without evidence.
- Test monitoring and response. Centralize logs and run at least one incident response exercise.
- Keep the evidence file current. Archive reports, meeting minutes and approved exceptions in a single repository.
Common mistakes
- Pre-audit theatre: a one-off scan days before an audit does not show the real picture, and assessors usually look at trends.
- Ignoring configuration: many intrusions start with weak configuration, not just CVEs; scanning without hardening audits is incomplete.
- Careless scanning in industrial networks: in OT and SCADA environments, active scanning can disrupt sensitive equipment. Coordinate with operators, choose the timing and use low-impact methods.
- Relying on unofficial sources: old lists that circulate may not match current requirements.
Why on-premises, air-gapped tooling with Persian reports matters
In infrastructure organizations, many networks are air-gapped, so tools that depend on a foreign cloud service are simply unusable. Vulnerability scan results are also highly sensitive and should not leave the organization. Three properties matter when choosing tools:
- On-premises deployment: all data and reports stay inside the organization's network.
- Offline updates: CVE and CIS content must be updated in a controlled way without a direct internet connection.
- Persian reporting: executive and technical reports in Persian make presenting to managers and assessors easier and reduce misinterpretation.
How NetGuard helps with AFTA readiness
NetGuard can be deployed on-premises and fully air-gapped, with regular CVE and CIS content updates. It performs authenticated and unauthenticated vulnerability scanning of servers, network devices, endpoints and databases, hardening audits against CIS Benchmarks and custom baselines, configuration drift detection, external attack surface discovery and verification rescans, and it produces executive and technical reports in Persian and English to strengthen your evidence file. See the hardening page or contact us to discuss your environment.
Frequently asked questions
What is AFTA in Iran?
AFTA is the Persian acronym for "security of the information production and exchange space". The AFTA Strategic Management Center operates under Iran's presidency and is responsible for the cybersecurity of the country's critical infrastructure. It issues security requirements and guidelines to organizations in scope and oversees the security assessment of products and systems used in that infrastructure.
Which organizations must follow AFTA security requirements?
The main audience is organizations considered critical or sensitive infrastructure, typically in sectors such as energy, telecommunications, financial services and transport. Their suppliers are usually asked for security evidence too. Exactly which requirements apply to your organization should be confirmed with your supervising authority or through official correspondence rather than assumed.
What does an AFTA checklist include?
A practical readiness checklist usually covers a complete asset inventory, secure configuration baselines, periodic vulnerability assessment, a patch management process, access control and privileged accounts, logging and monitoring, an incident response plan and an evidence file for audits. It is a preparation aid, not a substitute for the official text, so always work from the latest AFTA documents.
Is vulnerability scanning enough for AFTA compliance?
No. Vulnerability scanning is one area among several. Assessors also look at configuration hardening, access control, logging and monitoring, incident response readiness and documented processes. Regular scanning combined with hardening audits and verification rescans covers much of the technical evidence well, but it does not replace management documentation and governance.
Where can I find the latest AFTA requirements?
AFTA requirements are updated over time, so the only reliable sources are the official documents published by the AFTA Strategic Management Center and correspondence from your supervising authority. Do not rely on circulated or outdated lists, and assign someone in the organization to track changes and keep your internal checklist current.
- #AFTA security requirements
- #AFTA Iran
- #critical infrastructure security in Iran
- #AFTA checklist
- #Iran cybersecurity compliance
- #افتا




