Becoming a Trust Service Provider in the UAE is a regulated licensing project, not simply a technology or cybersecurity launch. An entity intending to provide trust services must obtain a TDRA licence, and an entity intending to provide qualified trust services must obtain the licence and the applicable qualified status.

Federal Decree-Law No. (46) of 2021 on Electronic Transactions and Trust Services, Cabinet Resolution No. (28) of 2023, and TDRA technical resolutions form the core framework. The legal and operational assessment should cover the service model, governance, technology, customer protection, audit evidence, and exit arrangements before an application is filed.

What services fall within the framework?

The framework covers regulated electronic trust services such as electronic signatures, electronic seals, electronic time stamps, electronic documents, certified electronic delivery, and authentication certificate services. The exact classification depends on the service design and the applicable TDRA technical controls.

A provider should map every proposed service before selecting a licence scope. A product described commercially as a digital-signature, identity, certificate, or delivery platform may contain several regulated functions. Marketing language should not promise a qualified status or legal effect that the licensed service does not have.

TDRA licensing is the starting point

Article 15 of Federal Decree-Law No. (46) of 2021 prohibits providing trust services without a TDRA licence. Qualified trust services require both a TDRA licence and the grant of qualified status. The licensing obligation applies before the service is provided in the UAE; a business plan or technical pilot does not replace the required approval.

Where the service is intended for the government sector or relies on data or services of the Federal Authority for Identity, Citizenship, Customs and Port Security, ICP sets the relevant rules, criteria, and requirements. TDRA verifies compliance and coordinates with ICP. A government-facing product therefore requires an additional scope review.

Application preparation under Cabinet Resolution No. (28) of 2023

The Executive Regulation requires the applicant to use TDRA procedures and forms and provide the information and documents identified by TDRA. The application package may include:

  • the competent-authority trade licence or other authorisation to conduct the business in the UAE;
  • a description of other commercial activities unrelated to trust services;
  • the UAE business-office details and the applicant's organisational structure;
  • a business plan covering objectives, strategy, marketing, and service provision;
  • details of institutional and operational capacity;
  • a recent compliance-assessment report and the documents reviewed for that assessment;
  • a service termination plan;
  • an audited financial report confirming financial resources equivalent to AED 5 million;
  • a bank guarantee or security specified by TDRA, automatically renewed on licence renewal; and
  • proof of payment of the application fees.

The AED 5 million reference is an application requirement stated in the Executive Regulation. It should not be presented as a universal capital requirement for every technology company or as a guarantee that an application will be approved. TDRA may require further information and may determine additional technical or procedural conditions.

Qualified services require a higher control environment

A qualified trust service is not created by adding the word “qualified” to a service description. The applicant must demonstrate that the proposed service and its systems meet the applicable legal and technical controls and that the qualified status is granted for the relevant service.

Before applying, the provider should map the following:

  • subscriber and relying-party onboarding;
  • identity verification and authentication;
  • certificate, signature, seal, time-stamp, or delivery-service lifecycle;
  • key management, secure devices, cryptographic controls, and access rights;
  • records, logs, retention, incident response, and business continuity;
  • customer complaints, revocation, suspension, and service termination; and
  • the evidence needed to appear accurately on the UAE Trust List.

TDRA resolutions cover technical controls for trust service providers and services, conformity-assessment bodies and reports, qualified signature or seal creation devices, and the UAE Trusted List. A licence application should therefore be built against the current technical documents, not only the high-level wording of the Decree-Law.

Conformity assessment and recurring audits

The compliance-assessment body must be approved and registered with TDRA. Its report assesses the applicant or licensee and the services against the Decree-Law, Executive Regulation, TDRA resolutions, and relevant competent-authority requirements. The assessment body must avoid actual or potential conflicts of interest.

TDRA states that both TSPs and QTSPs must submit a Conformity Assessment Report issued by an approved Conformity Assessment Body when applying for a licence and at renewal. TDRA may also request an ad hoc audit. TDRA's published audit guidance describes initial and regular assessments, with the regular assessment renewed at least every two years, subject to the current requirements and decisions.

The audit should be treated as a continuing evidence programme. Maintain version-controlled policies, system diagrams, risk assessments, access reviews, incident records, test results, supplier controls, and proof that identified findings were closed. A report that describes a compliant design without operational evidence may not withstand supervisory review.

Licence term, renewal, and the Trust List

Under the Executive Regulation, the licence term is two years. The renewal application should be prepared at least three months before expiry and should include the required information and documents, together with proof of renewal fees and any further material TDRA requests.

TDRA maintains the UAE Trust List, which records licensed providers, their services, and licence status. It also records qualified providers, qualified services, and qualified status. The Trust List is an authoritative reference for verifying the status of a provider and service; marketing materials should link to the correct listing and avoid creating a broader impression.

A qualified provider may use the qualified trust mark subject to the applicable conditions. The mark must be presented clearly and without misleading claims, identify the qualified service and status, and link to the relevant Trust List information where required.

Supervisory risk during operations

Supervisory exposure can arise from a failure to maintain technical standards, a misleading service description, weak identity controls, poor incident response, inadequate records, failure to support audits, or non-compliance with ICP requirements for government or ICP-dependent services.

TDRA may suspend or revoke a licence in the cases provided by the Decree-Law and Executive Regulation. If a licence is suspended, the provider must stop listing new subscribers to the licensed services while continuing the treatment required for existing subscribers under the applicable decision. If a licence is revoked, the provider may be required to activate the termination plan and update the UAE Trust List. A provider should not shut down a regulated service unilaterally without following TDRA procedures and obtaining any required prior approval.

Suspension or revocation does not erase administrative or criminal exposure. The Decree-Law includes civil liability for damage caused by breach of its obligations and penalties for specified misconduct, including unauthorised use, forgery, incorrect data, and certain confidentiality failures. Cabinet Resolution No. (52) of 2024 also sets administrative penalties for regulatory violations.

Termination planning is part of licensing

The termination plan should explain how the provider will protect subscribers and relying parties if a service is suspended, revoked, or discontinued. It should address certificate and service status, records and evidence, customer notifications, data retention, access to verification information, migration or replacement arrangements, and coordination with TDRA.

Operational continuity matters because trust services can support contracts, government services, authentication, signatures, seals, and time-sensitive transactions. The provider should identify who can activate the plan, which systems are essential, and how the plan will be tested.

Practical application checklist

  1. Map each proposed product to the trust-service categories and TDRA technical controls.
  2. Decide whether the service requires ordinary trust-service licensing, qualified status, or both.
  3. Check whether ICP requirements apply because of government use or ICP data and services.
  4. Appoint an approved Conformity Assessment Body and prepare the compliance evidence.
  5. Build the financial, security, governance, incident, subscriber, and termination documents.
  6. Submit the TDRA application with the required financial report, security, and fees.
  7. Track the two-year licence and the three-month renewal planning deadline.
  8. Maintain audit readiness and monitor the provider and service entries on the UAE Trust List.

How HZ Legal can help

Hossam Zakaria Legal Consultancy can assist with trust-service regulatory mapping, licensing readiness, contractual and governance documents, audit preparation, supervisory responses, incident and termination planning, and review of qualified-service marketing claims. Visit HZ Legal to discuss your proposed UAE trust-service model.

Official sources and verification

Editorial verification before publication: Confirm the current Arabic text, TDRA application forms, applicable technical resolutions, fees, approved Conformity Assessment Bodies, ICP requirements, and any current supervisory notices. Exact service classification and licensing scope depend on the proposed technology, customers, data sources, and sector.

Prepared on 9 October 2026. General legal information, not advice on a particular licensing application.