Skip to content

Guide

How to Set Up a Cloud or Managed-Service Provider in the UAE

The short answer

A cloud or managed-service company usually starts as an ordinary commercial licence, and the question is which authorities have a further say. The ones to test are the Telecommunications and Digital Government Regulatory Authority (TDRA), if any part of the service looks like telecommunications, and the UAE Cyber Security Council, for cybersecurity expectations. Data-protection law applies whatever the licence says.

The thing that most often decides the route is the service boundary: whether the company resells, operates infrastructure, or runs customers' own environments. That answer sets the contracts, insurance, people and approvals. It also decides whether the telecom question is worth a formal check.

Pick the service model before the licence

Most founders describe four models. Each puts different obligations on the company:

  1. Reselling a hyperscaler under a partner agreement.
  2. Operating private or public cloud infrastructure.
  3. Managing operations over customer-owned environments.
  4. Combining hosting, backup, security and support.

A reseller carries partner accreditation, billing and support duties. An operator carries hardware, facilities, uptime and recovery. A managed-service firm carries privileged access to someone else's systems. A bundle carries all of those at once.

If more than one model applies, expect a group rather than a single company. An asset owner, an operator and a customer-contracting entity are often separate. Lenders and anchor customers tend to push for that split. One company holding hardware, debt and customer risk is harder to finance.

Where the regulatory perimeter sits

The risk is a service that drifts across a line without anyone noticing, so the position is confirmed with the authorities rather than assumed. Test these points early:

  • Whether any part of the service is a telecommunications activity rather than an IT service. That is a question for TDRA.
  • Which cybersecurity standards the customer's sector expects of its suppliers, and what the UAE Cyber Security Council has published that bears on the service.
  • Whether the company is a controller or a processor for each data set it touches.
  • Where subprocessors sit, and whether data crosses a border.
  • What the upstream vendor agreement allows, since a hyperscaler partner agreement can limit resale and white-labelling.

A test that finds an issue does not mean authorisation is required. It means the position needs a fact-based check with the authority concerned. Calling a business a technology platform does not take it outside regulation if the customer journey performs a controlled function.

Write the position down: what the company builds and operates, what it does not, which functions sit with approved partners, and which expansion steps would change the answer. Landlords, lenders and banks all ask for it, as do enterprise customers during procurement.

Structure choices that change the answer

Fix these variables before comparing mainland, free-zone and financial-centre routes:

  • Where infrastructure is owned and which regions it serves.
  • Whether the company contracts as principal, agent or reseller.
  • Who is responsible for backup, recovery and security administration.
  • How customer data is segregated and who holds privileged access.
  • How service credits, liability caps and cyber insurance line up.

The entity that signs customer contracts should hold the people, systems and risk needed to deliver them. An asset-owning vehicle, an IP company or an overseas parent can sit elsewhere in the group, but each needs a real role. A structure built to advertise a low setup price tends to come back as bank questions and rework. For compute-heavy models that depend on power and hardware, the AI compute guide covers the extra layer.

Roles, people and substance

A managed-service provider is its people. Engineers hold administrator rights over customer systems, so the company needs a named owner for each of these:

  • Security operations and incident escalation.
  • Data protection, including the processor terms customers will demand.
  • Service delivery against the contracted recovery objectives.
  • Finance and contract management.

Each person needs residence and work status before they touch customer environments. Premises matter too, but less for a reseller than for an operator with racked hardware. Customers read the team page and the org chart as evidence of substance, and so do banks.

How money moves and what a bank looks at

Revenue in this sector is recurring: monthly invoices, usage billing, partner rebates and sometimes pass-through charges. Costs are often paid abroad to hyperscalers and hardware vendors, in foreign currency. A bank looks at who the customers are, where the suppliers sit, and whether the contracts explain the flows.

Be ready to show:

  • Vendor and data-centre agreements.
  • A service catalogue and a responsibility matrix.
  • Information-security policies.
  • Business-continuity and disaster-recovery evidence.
  • Support coverage and incident escalation.

The aim is that the deck, the financial model, the contracts and the bank file tell one story. That is what corporate bank account readiness is built around, and the business plan and documentation usually becomes the reference document. Consistency removes avoidable questions. It does not guarantee an account, financing or approval.

What commonly goes wrong

  • Copying a hyperscaler's service-level terms without the operations to match them.
  • Leaving subprocessor locations undisclosed in customer contracts.
  • Selling regulated-sector hosting before meeting the customer's controls.
  • Bundling telecom-style connectivity with IT services without checking the boundary.
  • Signing a customer contract from an entity that holds none of the delivery capacity.
  • Comparing incorporation fees instead of whole routes, including renewal cost, staffing and the cost of restructuring after contracts are signed.

Cost

Cost is built in layers, and the firm's fee is itemised in the engagement letter; how Velarozone works sets out the approach. For an operator, premises, hardware and people dominate the licence. For a reseller, partner accreditation and engineers do. No regulator figure applies across the sector, so none is quoted here.

Modern Dubai office meeting room overlooking the city skyline

General guidance here; the detail that matters depends on your activity and markets.

Questions

Frequently asked

Does a cloud reseller need a different licence from an operator?
The commercial licence activity may be similar. The difference lies in what sits around it: infrastructure, premises, security administration and data handling. An operator has more to test with TDRA and with customers' sector controls.
Is a managed-service provider treated as a data processor?
Often, when it handles customer personal data on the customer's instructions. The roles are decided by what the company actually does with the data, not by the contract label. Record the role for each service and each subprocessor.
Can we bundle connectivity with our cloud service?
Possibly, but this is the point where the telecom boundary gets tested. Describe the connectivity element precisely and confirm the position with TDRA before it is sold.
Do regulated customers add requirements for us?
Yes, usually through the contract. Banks, health and government customers may require specific controls, audit rights and subprocessor approval. Meeting those controls comes before selling hosting into that sector.
Should we form one company or a group?
If you own infrastructure and also sell managed services, a group is common. Separating the asset owner from the contracting entity eases financing and contains customer risk. A single entity can suit a pure reseller.

Get your UAE setup plan

Velarozone maps the service boundary, the authorities that may have a say, the data and contract position and the bank evidence before anything is filed.

Apply this to your own situation

Guides describe the general position. Send us your facts and an adviser will tell you which parts actually apply to you.

Free assessment — current figures are confirmed within your adviser-reviewed route comparison. Your details are not shared with third parties.

Start with a structure assessment

In an initial consultation you receive a plain-language decision summary, a document-preparation list, and the next actions for your situation. Current figures are confirmed within your adviser-reviewed route comparison.

Get my UAE setup planSend the details through the contact form

This guide provides general information, not legal, regulatory, tax, investment or financial advice. It does not guarantee a licence, authorisation, visa, bank account, funding or tax outcome.

This page is general information about UAE business setup, not legal, tax, immigration, or banking advice. Rules, fees, permitted activities, and bank policies can change. Final eligibility depends on your facts and the applicable rules at the time of application.