Creuto is now an OpenAI Select Partner Read More
Search "software development company dubai" and you get agency pages. Here are the four local questions that separate them, plus two we find uncomfortable.

A search for "software development company dubai" returns agency pages almost all the way down, and ours is one of them. So do not judge the market by that page. Judge it by the answers vendors give to four local questions — and to two more that we would rather you did not ask us.
By the end of this you will know which answers point at a schedule risk and which point at a real route. One disclosure first, because it changes how you should read the rest: we have not delivered a project in the UAE. We are a studio that works across India, the United Kingdom and the United States, reading the published UAE rules carefully. Every regulatory claim below is linked to the body that issued it.
| Ask | Who the rule actually binds | A weak answer sounds like |
|---|---|---|
| Whose name goes on the UAE Pass service provider agreement? | The licensed UAE entity whose service it is — not its developer | "We'll handle UAE Pass for you" |
| Where does each class of data physically sit? | Health data has its own localisation rule; Dubai government workloads have their own cloud standard | "It's on AWS, so it's compliant" |
| Who integrates the accredited service provider, and who reconciles? | Businesses above AED 50 million in revenue, on a Ministry of Finance timetable | "Our partner is on the Ministry's list" |
| Who holds the repository and the deployment credentials on the last day? | Nobody but your contract | "We transfer everything at handover" |
The head term is owned by pages built to rank for it, and those pages compete on team size, technology logos and years in business — the easiest things to assert and the hardest to disprove. None of them tell you whether the vendor has a route to the identity, residency and invoicing requirements your product will hit.
The strongest case against reading any of this is that it is procurement theatre: a competent team works the rules out as it goes, and a shortlist filtered on paperwork can exclude the better engineers. That case is fair for a marketing site. It stops being fair the moment your build touches government identity, patient records or tax documents, because those three have gatekeepers who publish their requirements and do not negotiate on your timeline.
If your product needs UAE Pass sign-in, the first question is not "can you integrate it" but "who is the service provider". The official onboarding documentation has the service provider raise the integration request through the developer portal, declare itself government or private, and — for private entities — produce a "valid UAE Trade license", after which the onboarding team assigned by the emirate of registration takes it forward.
That licence attaches to the entity whose service it is. A development studio cannot hold your UAE Pass registration on your behalf, and a vendor promising to "handle UAE Pass" is either describing the engineering work or describing something it cannot do. In the development phase the same documentation has private service providers sign a Service Provider Agreement, with a memorandum of understanding in its place for government entities. Ask which of your two companies signs that agreement, and ask early, because the answer determines who is accountable to the operator afterwards.
Then ask what the integration deviates from. Before any code runs, the service provider submits feature questionnaires, a workflow diagram of the user journey and UI wireframes, and the onboarding team approves the use case. The documentation is explicit that use cases "that deviate from the standard guidelines" need management approval and that "obtaining this approval may extend the overall processing time". A novel sign-in flow is therefore not a design choice you can make in sprint four.
One correction worth making, because this is a figure buyers arrive with: there is no published UAE Pass approval timeline. The documentation sets out four phases — initiation, development, assessment and go live — and attaches no duration to any of them, and the only timing statement in the whole process is the warning above about non-standard use cases. So treat any promised UAE Pass date as your vendor's estimate rather than the operator's commitment, and ask what it is based on.
The assessment phase matters for a different reason. The service provider has to demonstrate every scenario and share video recordings with the onboarding team, which takes them to management for approval. Production credentials arrive only after that, followed by a production assessment and the handover of service desk credentials. If your contract ends at "launch", check which of those steps it covers.
"Are you compliant with the UAE data protection law?" is a weaker question than it sounds. The Personal Data Protection Law came into force on 2 January 2022 and governs processing "inside or outside the country", including cross-border transfer. Its executive regulations are the part that would make a yes-or-no answer possible, and we could not find them published on any official UAE source as of October 2026 — the vendor pages asserting both that they exist and that they do not are citing each other. Ask instead where each class of data lives, which account owns that region, and what the documented basis for any transfer out is.
Sector rules are much sharper, and they bind your vendor as well as you. Under Federal Law No. 2 of 2019 on the use of ICT in health fields, health data relating to health services provided in the UAE may not be stored, processed, generated or transferred outside the country without a decision of the health authority or the Minister, with a fine of AED 500,000 to AED 700,000 for breaching that localisation obligation, and a minimum retention period of 25 years from the last procedure. The law covers free zones, and the entities caught by it include cloud providers and healthcare IT suppliers, not only clinics.
Two caveats on that, because the genre usually drops them. A 2021 ministerial resolution is reported to have created exceptions for certain processing, and we could not read the official English text of either instrument — the UAE legislation portal returned 403 to us — so the exception list is a question for your counsel rather than a claim of ours. What is not in doubt is the architectural consequence: a 25-year floor on retention is a schema and storage-cost decision, not a legal footnote, and it belongs in the estimate.
If you serve Dubai government or semi-government entities, the gate moves to the cloud provider. The Dubai Electronic Security Centre's CSP Security Standard is mandatory for providers serving those bodies, and certification is scoped rather than universal: AWS states that its DESC certification covers the AWS Middle East (UAE) Region, with a yearly verification audit and recertification every three years. Ask for the certificate, its scope and its dates — not the logo. The same pattern shows up inside UAE Pass itself, where the documentation requires a service provider's IP to be whitelisted at DESC before its production signing calls will work.
Businesses with revenue of AED 50 million or more must appoint an accredited service provider by 30 October 2026, extended from 31 July, with the go-live date for the first phase unchanged at 1 January 2027. If your platform issues invoices, that date is your date too, and the appointment deadline is three weeks away as of 8 October 2026.
Here is the distinction that catches buyers out. The Ministry of Finance publishes two tables, not one: 65 accredited service providers with accreditation numbers, and five "Pre-Approved Service Providers Under Final Accreditation Assessment" that have completed pre-approval and are still in the final production assessment stage. "Our partner is on the Ministry's list" is true of both. Ask which table, and ask for the accreditation number.
Accreditation is not a light badge, which is why the distinction matters. The Ministry's published conditions require an active Peppol-certified provider that has passed OpenPeppol conformance testing and has "at least two (2) years of experience in operating and managing an electronic invoicing system". A vendor who proposes to build you a direct integration instead is proposing to work around a system designed around accredited intermediaries.
Then separate transmission from reconciliation, because they fail differently. The accredited provider transmits the document; your finance team still has to tie accepted, rejected and amended documents back to ledger entries. Ask who writes that reconciliation, who gets paged when a document is rejected at 11pm on a filing day, and whether that work is in the fixed price or the change request. Note also who the rule does not bind: taxable persons below the AED 50 million threshold follow a later schedule that we could not confirm against the Ministry's own decision text, so check it with the Ministry rather than with a tracker.
Buyers scoped to the UAE Information Assurance Standards — government entities and critical national infrastructure operators — get asked for control-level evidence, and that question lands on whoever built the system. We are being precise about the limits of our own knowledge here, because this is where the genre invents numbers. We could not reach an authoritative, current copy of the standards: the pages we found were consultancy summaries that disagreed with each other on the version, the owning authority and the control count. Treat any control total you read as unverified until you have the document.
What you can still ask is specific. Which version of the standards was your vendor assessed against, by whom, and when? Which controls are the vendor's responsibility and which are yours? If the answer is a sentence with the word "aligned" in it and no assessor, no date and no document version, the vendor has told you they have not been assessed.
Plainly: these two reduce our leverage, and we think you should ask them anyway. A studio that argues for your reversibility and then quietly engineers against it is worse than one that never raised the subject.
Who owns the repository and the deployment credentials on the last day? Not "who owns the IP" — that is a clause everyone signs. Ask who holds the owner role on the Git organisation, the root account and billing on the cloud tenancy, the Apple Developer and Google Play accounts, the domain registrar and DNS, the secrets manager, and the UAE Pass production credentials, which the operator issues per channel and use case and does not expect to see reused elsewhere. "We transfer at handover" and "it is yours from day one" are different promises. If it is the first, ask what event triggers the transfer and what happens to it if an invoice is in dispute. We have written before about treating vendor lock-in as a reversibility problem rather than a vendor one, and this is the same test pointed at us.
What happens to support if the relationship ends? Ask for the notice period in both directions, the rate after the retainer stops, and who answers at 2am in month 13 when nobody is on a retainer at all. In this market the question has concrete local edges: the UAE Pass service desk credentials are issued to the service provider, your accredited provider contract names a party, and both outlive the build. Ask whether a runbook exists that an engineer who has never met your vendor could follow, and ask to see one page of it.
We would rather not be asked either question, because a studio that is cheap to replace has less pricing power. That is exactly why the answer is informative.
We have not delivered a software project in the UAE, and nothing on our site should be read as saying we have. Our Dubai page describes what we do and the market we are building a practice for; if it ever reads as a local delivery record, hold us to this paragraph.
What does transfer is engineering pattern, with the deployment market stated honestly. Our aquaculture platform runs across Odisha, Andhra Pradesh and West Bengal in India, not the Gulf, and the parts of it a UAE buyer should care about are structural: per-role data separation, a retention model that survives a long statutory floor, and an operations panel someone other than us can run. Ask any vendor to show you that layer rather than a logo wall, and ask which jurisdiction it was deployed in.
That is also the honest frame for choosing us or not choosing us for custom software development in this market: we will do the engineering and read the rules with you, and we will not pretend to a local delivery history we do not have. If local delivery history is the deciding factor for your board, a vendor with one should win, and you should ask them for the client reference rather than the case study page.
Send the four local questions to every vendor on your shortlist in writing, before pricing, and read the shape of the replies rather than their confidence. A vendor who answers "the service provider agreement is in your name, here is our DESC-scoped region, here is our accredited provider's accreditation number, and here is the credential list we hand over" has told you how the project will be run. A vendor who answers all four with reassurance has told you something too.
Ask four local questions before pricing: whose name goes on the UAE Pass service provider agreement, where each class of data will physically sit, who integrates the accredited e-invoicing service provider and who reconciles it, and what security evidence the vendor can produce if you serve government.
The trade licence requirement attaches to the entity registered as the UAE Pass service provider, which is normally your own licensed UAE company rather than your developer. UAE Pass documentation asks private entities for a valid UAE trade licence and has them sign the service provider agreement themselves.
Whoever your contract says, which is why the useful question is about custody rather than intellectual property. Ask who holds the owner role on the Git organisation, the cloud root account, the app store accounts, the domain registrar and the production credentials on the last day of the engagement.
Businesses with revenue of AED 50 million or more must appoint an accredited service provider by 30 October 2026, extended from 31 July 2026, with the first phase go-live date unchanged at 1 January 2027. Smaller taxable persons follow a later schedule published by the Ministry of Finance.
Not by default. Under Federal Law No. 2 of 2019, health data relating to health services provided in the UAE may not be stored, processed, generated or transferred outside the country without a decision of the health authority or the Minister, and the law extends to free zones.
Ready to take the first step towards unlocking opportunities, realizing goals, and embracing innovation? We're here and eager to connect.
11th Floor, O-Hub, Chandaka Industrial Estate, Infocity, Bhubaneswar, Odisha 751024
Level 4, 11 York Street Sydney Startup Hub Sydney, NSW – 2000
30 N. Đinh Nghệ, Phước Mỹ Sơn Trà, Đà Nẵng / Da Nang City – 550000
Level 25, AIDP Business Tower, Dubai Marina, United Arab Emirates
50 Beauchamp Street, Wellington, WGN 5028, New Zealand