Guide
How to Set Up a Defence or Dual-Use Technology Company in the UAE
The short answer
In the UAE, defence-adjacent and dual-use technology work sits under export-control permitting, not an ordinary trade licence. The Executive Office for Control and Non-Proliferation (EOCN) decides whether a product, piece of software or technical data appears on the UAE Control List and needs a permit before it can be dealt in, exported, re-exported or transferred to a given end user. Where manufacturing, assembly or industrial premises are involved, the Ministry of Industry and Advanced Technology (MoIAT) adds its own sign-off, and cyber-relevant products can bring in the Cyber Security Council. The one thing that decides the route is classification โ what the item or service actually is and does โ not what the company calls itself on its trade licence.
The export-control perimeter and who decides
A trade licence describes an activity; it does not grant permission to deal in a controlled item. The EOCN administers the UAE Control List and is the authority that decides whether capability, software, technical data or end use pulls a transaction into the permitting regime. That decision is made on the facts of the product and the customer, not on the applicant's preferred description of the business.
Two businesses offering similar software can land on opposite sides of the line depending on who the customer is, what it is used for, and whether the underlying capability appears on the list. A company selling only general-purpose analytics to civilian buyers may sit outside the regime entirely; a near-identical offering sold with export rights to a government end user may not. That determination has to be made before the structure is fixed, because it decides which authority the business answers to and what evidence it needs to keep.
What the controlling authorities actually require
The EOCN's control-list function is the gate that applies most widely: if an item, technology or piece of software is listed, dealing in it, exporting it, re-exporting it or transferring it to a given end user needs a permit from the EOCN first. Where the plan includes local manufacturing, assembly or an industrial production site, MoIAT's industrial licensing framework sits alongside that permit rather than replacing it. Where the product carries encryption, cyber-defence or information-security functionality, the Cyber Security Council's remit can add a further approval on top of both.
None of the three publishes a single combined checklist for "defence technology companies": each answers for its own piece of the chain, and a company can need all three, two or none, depending on classification. Building the activity description, customer list and product specification before any licence application lets each authority be approached with one consistent file rather than a guess.
How money moves: banking and buyer scrutiny
Banks and payment partners in this sector read the approval story before they read the balance sheet. Before onboarding starts, a bank typically wants to see the product and control classification, the end-user and country screening process behind each customer, and a technology-control plan describing who can access controlled data and components. A company that cannot show this evidence reads as undocumented risk, regardless of trading history.
Preparing a bank-ready file and evidencing the source of funds behind the capital are separate pieces of work; see corporate bank account readiness and source of wealth and funds for what each covers. Cost here is built in layers rather than one headline figure, and the engagement letter itemises the firm's fee against each layer โ that is how Velarozone works in practice.
Ownership, substance and the roles that must be filled
Key people are part of the approval, not paperwork around it. Authorities in this space routinely want to know who inside the company can access controlled technical data, who signs off on end-user screening, and who is accountable if a classification turns out to be wrong. Those roles need to exist and be named before an application goes in, not recruited afterwards.
Where regulated and unregulated activity sit in the same company, the approval surface for the whole entity can widen to match the regulated piece, even if most of the revenue is unregulated. Splitting the structure โ an operating entity that holds the permit, a separate vehicle for unregulated supply or IP โ is a genuine option worth comparing early; the same logic applies to other gated sectors, such as a rail, metro or transit-technology company. Ownership structures that mix multiple nationalities, trusts or nominee arrangements add a further layer of scrutiny; see regulated and complex ownership setup for how that is usually documented.
What commonly goes wrong
- Assuming a civilian customer automatically takes a product off the control list
- Sharing technical data with staff or partners before access rules are mapped
- Signing a premises lease before security or inspection requirements are known
- Selling through a distributor without visibility of the end user it sells on to
- Treating the trade licence as the finish line instead of the first of several approvals
Comparing routes on the registration fee alone misses what actually drives the budget and the calendar: the control-list permit, any manufacturing or cyber sign-off, and the people and premises conditions attached to each.
From permit to operations
A granted permit is not the end of the obligation. Export-control permits, industrial sign-offs and any cyber clearance each carry their own renewal cycle, separate from the trade licence renewal, and each can require fresh evidence of the same screening and control measures that supported the first application. Visas for key staff follow the same logic: a role the authority named in the approval usually needs a named, resident person behind it, not a title on an organisation chart.
Premises conditions are frequently the slowest-moving piece, because inspection or accreditation can sit behind the facility before any permit is issued. Building the premises timeline around the authority's clock, rather than the lease signing date, keeps the rest of the plan from waiting on a step nobody scheduled.

