Skip to content

Guide

How to Set Up a Defence or Dual-Use Technology Company in the UAE

The short answer

In the UAE, defence-adjacent and dual-use technology work sits under export-control permitting, not an ordinary trade licence. The Executive Office for Control and Non-Proliferation (EOCN) decides whether a product, piece of software or technical data appears on the UAE Control List and needs a permit before it can be dealt in, exported, re-exported or transferred to a given end user. Where manufacturing, assembly or industrial premises are involved, the Ministry of Industry and Advanced Technology (MoIAT) adds its own sign-off, and cyber-relevant products can bring in the Cyber Security Council. The one thing that decides the route is classification โ€” what the item or service actually is and does โ€” not what the company calls itself on its trade licence.

The export-control perimeter and who decides

A trade licence describes an activity; it does not grant permission to deal in a controlled item. The EOCN administers the UAE Control List and is the authority that decides whether capability, software, technical data or end use pulls a transaction into the permitting regime. That decision is made on the facts of the product and the customer, not on the applicant's preferred description of the business.

Two businesses offering similar software can land on opposite sides of the line depending on who the customer is, what it is used for, and whether the underlying capability appears on the list. A company selling only general-purpose analytics to civilian buyers may sit outside the regime entirely; a near-identical offering sold with export rights to a government end user may not. That determination has to be made before the structure is fixed, because it decides which authority the business answers to and what evidence it needs to keep.

What the controlling authorities actually require

The EOCN's control-list function is the gate that applies most widely: if an item, technology or piece of software is listed, dealing in it, exporting it, re-exporting it or transferring it to a given end user needs a permit from the EOCN first. Where the plan includes local manufacturing, assembly or an industrial production site, MoIAT's industrial licensing framework sits alongside that permit rather than replacing it. Where the product carries encryption, cyber-defence or information-security functionality, the Cyber Security Council's remit can add a further approval on top of both.

None of the three publishes a single combined checklist for "defence technology companies": each answers for its own piece of the chain, and a company can need all three, two or none, depending on classification. Building the activity description, customer list and product specification before any licence application lets each authority be approached with one consistent file rather than a guess.

How money moves: banking and buyer scrutiny

Banks and payment partners in this sector read the approval story before they read the balance sheet. Before onboarding starts, a bank typically wants to see the product and control classification, the end-user and country screening process behind each customer, and a technology-control plan describing who can access controlled data and components. A company that cannot show this evidence reads as undocumented risk, regardless of trading history.

Preparing a bank-ready file and evidencing the source of funds behind the capital are separate pieces of work; see corporate bank account readiness and source of wealth and funds for what each covers. Cost here is built in layers rather than one headline figure, and the engagement letter itemises the firm's fee against each layer โ€” that is how Velarozone works in practice.

Ownership, substance and the roles that must be filled

Key people are part of the approval, not paperwork around it. Authorities in this space routinely want to know who inside the company can access controlled technical data, who signs off on end-user screening, and who is accountable if a classification turns out to be wrong. Those roles need to exist and be named before an application goes in, not recruited afterwards.

Where regulated and unregulated activity sit in the same company, the approval surface for the whole entity can widen to match the regulated piece, even if most of the revenue is unregulated. Splitting the structure โ€” an operating entity that holds the permit, a separate vehicle for unregulated supply or IP โ€” is a genuine option worth comparing early; the same logic applies to other gated sectors, such as a rail, metro or transit-technology company. Ownership structures that mix multiple nationalities, trusts or nominee arrangements add a further layer of scrutiny; see regulated and complex ownership setup for how that is usually documented.

What commonly goes wrong

  • Assuming a civilian customer automatically takes a product off the control list
  • Sharing technical data with staff or partners before access rules are mapped
  • Signing a premises lease before security or inspection requirements are known
  • Selling through a distributor without visibility of the end user it sells on to
  • Treating the trade licence as the finish line instead of the first of several approvals

Comparing routes on the registration fee alone misses what actually drives the budget and the calendar: the control-list permit, any manufacturing or cyber sign-off, and the people and premises conditions attached to each.

From permit to operations

A granted permit is not the end of the obligation. Export-control permits, industrial sign-offs and any cyber clearance each carry their own renewal cycle, separate from the trade licence renewal, and each can require fresh evidence of the same screening and control measures that supported the first application. Visas for key staff follow the same logic: a role the authority named in the approval usually needs a named, resident person behind it, not a title on an organisation chart.

Premises conditions are frequently the slowest-moving piece, because inspection or accreditation can sit behind the facility before any permit is issued. Building the premises timeline around the authority's clock, rather than the lease signing date, keeps the rest of the plan from waiting on a step nobody scheduled.

Modern Dubai office meeting room overlooking the city skyline

General guidance here; the detail that matters depends on your activity and markets.

Questions

Frequently asked

Does this business definitely need regulatory authorisation?
Usually the real question is which approvals apply and how many, not whether any apply at all. The trigger to test is whether the product, software or technical data appears on the UAE Control List, and whether the end user or use case brings in further sign-off. Some models genuinely sit outside the regime โ€” a determination to make on the facts before structuring, not something to assume either way.
Does a civilian customer make a product exempt from control?
Not on its own. Classification looks at the capability itself and the end use, not the marketing label on the customer. A product with civilian and military applications can still need a permit for a shipment to a particular customer or country, even where the same product moves freely to others.
Who inside the company can access controlled technical data?
That has to be a named, limited group, not "the technical team." Authorities expect a documented technology-control plan setting out who can see or handle controlled data and components, and why each person on that list needs access to do their job.
What happens if a shipment or customer turns out to be misclassified?
Treat a wrong classification as a live risk to plan for, not an edge case. Screening the end user and the end use before a transaction, and keeping records of that screening, is what gives the company and its bank something to point to if a classification is later questioned.

Get your UAE setup plan

Defence and dual-use technology ventures rarely fail on the trade licence โ€” they fail on an export-control permit, a manufacturing sign-off or a cyber clearance that nobody sequenced early enough. Velarozone maps every approval gate, works out which authority owns each one, and prices the full path to operation before anything is filed.

Apply this to your own situation

Guides describe the general position. Send us your facts and an adviser will tell you which parts actually apply to you.

Free assessment โ€” current figures are confirmed within your adviser-reviewed route comparison. Your details are not shared with third parties.

Start with a structure assessment

In an initial consultation you receive a plain-language decision summary, a document-preparation list, and the next actions for your situation. Current figures are confirmed within your adviser-reviewed route comparison.

Get my UAE setup planSend the details through the contact form

This guide provides general information, not legal, regulatory, tax, investment or financial advice. It does not guarantee a licence, authorisation, visa, bank account, funding or tax outcome.

This page is general information about UAE business setup, not legal, tax, immigration, or banking advice. Rules, fees, permitted activities, and bank policies can change. Final eligibility depends on your facts and the applicable rules at the time of application.