To become a UAE eInvoicing Accredited Service Provider (ASP) in 2026, apply to the Ministry of Finance (MoF) under Ministerial Decision No. 64 of 2025, hold ISO/IEC 27001 (Article 9) and ISO 22301 (Article 6) certifications, and be an active OpenPeppol-certified Service Provider. You must also meet minimum capital, insurance, and operational-history thresholds and pass FTA accreditation testing.

Eligibility requires: valid ISO/IEC 27001 certification for your PSP Product (Article 9), ISO 22301 certification for business continuity (Article 6), and active Peppol certification with passed OpenPeppol conformance testing. Applicants must also maintain a minimum paid-up capital of AED 50,000, at least two years of PSP Product operational history, and three UAE-issued insurance policies with combined coverage of AED 12.5 million.

Once these conditions are met, applicants must successfully complete pre-approval and accreditation testing with the Federal Tax Authority (FTA). The MoF issues a decision within 90 business days of application, and accreditation, once granted, remains valid for 2 years.

Key facts for 2026–2027:

  • Voluntary pilot phase: opened 1 July 2026.
  •     ASP appointment deadline: businesses with annual revenue of AED 50 million or more must appoint an ASP by 30 October 2026.
  •     Mandatory issuance date: structured eInvoicing begins 1 January 2027.
  •     Legal basis: Ministerial Decision No. 244 of 2025, as amended by Ministerial Decision No. 66 of 2026; ASP eligibility is governed by Ministerial Decision No. 64 of 2025, as amended by Ministerial Decision No. 56 of 2026.
  •     Exchange standard: Peppol network using PINT AE v1.0.1, the UAE’s official localized specification.

What Is an Accredited Service Provider (ASP) in the UAE?

An Accredited Service Provider (ASP) is a company formally accredited by the UAE Ministry of Finance to connect businesses to the UAE Electronic Invoicing System. 

ASPs validate and exchange eInvoices over the Peppol network in the PINT AE format and report invoice tax data to the Federal Tax Authority on behalf of their clients.

Companies that typically pursue ASP status include eInvoicing platforms, ERP and accounting-software providers, fintech companies, SaaS vendors and established IT service providers with multi-year transaction-processing operations.

The Five-Corner DCTCE Model

The UAE operates a Decentralized Continuous Transaction Control and Exchange (DCTCE) model — commonly described as a five-corner model:

  • Corner 1 — Supplier: submits invoice data to its ASP.
  •     Corner 2 — Supplier’s ASP: validates the data, converts it to the UAE standard XML format where needed, and transmits it onward.
  •     Corner 3 — Buyer’s ASP: receives the validated eInvoice.
  •     Corner 4 — Buyer: receives the eInvoice from its ASP.
  •     Corner 5 — FTA platform: receives a Tax Data Document (TDD) reported by each ASP, with Message Level Status (MLS) confirmations exchanged in parallel.

This architecture makes the ASP a regulated gatekeeper: it performs technical validation and statutory reporting on every transaction it carries.

Who Is Legally Accountable for Invoice Accuracy?

Legal accountability for invoice accuracy remains with the supplier — or the buyer in a self-billing scenario — not the ASP. The MoF’s June 2026 UAE Electronic Invoicing Guidelines confirm this allocation. Accreditation therefore certifies technical, security and operational capability; it does not transfer tax liability.

Is ASP an ISO Certification?

No. ASP accreditation is a regulatory status granted by the UAE Ministry of Finance; it is not an ISO certificate. 

This distinction is the single most common point of confusion in the market, and it matters commercially.

The two instruments differ in issuer and purpose:

  • ASP accreditation: granted by the UAE Ministry of Finance under Ministerial Decision No. 64 of 2025, following application review, pre-approval testing and accreditation testing.
  •     ISO/IEC 27001 and ISO 22301 certifications: management-system certifications issued by independent, accredited ISO certification bodies after conformity audits. ISO — the International Organization for Standardization — publishes the standards but does not certify anyone.

The relationship is one of eligibility inputs to a regulatory decision. Holding the specified ISO certifications is among the conditions an applicant must satisfy, but the Ministry’s accreditation decision also depends on Peppol conformance, experience, capital, insurance, security requirements, self-declarations and successful testing. ISO certification alone does not grant ASP status, and no ISO standard creates ASP status. Searches such as “ASP certification UAE” or “ISO certification for ASP” are really searches about this eligibility relationship — certification and accreditation are separate instruments issued by separate authorities for separate purposes.

Certifications Required to Become a UAE eInvoicing ASP

Two management-system certifications are explicit accreditation conditions under Ministerial Decision No. 64 of 2025 (as amended): ISO/IEC 27001 for the PSP Product and ISO 22301 for the applicant company. ISO 9001 is not required.

ISO/IEC 27001 — Information Security Management

Article 9 of MD 64 of 2025 requires a valid ISO/IEC 27001 certification for the PSP Product — the technology product used to deliver the eInvoicing service. The certification anchors an Information Security Management System (ISMS) covering risk assessment, security controls, and the confidentiality, integrity and availability of invoice data.

The requirement is directly relevant because an ASP continuously processes commercially sensitive transaction data and tax data under statutory reporting obligations. The MoF framework couples ISO/IEC 27001 with specific technical measures: multifactor authentication, encryption of data at rest and in transit, and compliance with UAE data hosting, storage, archival and residency rules, including national cloud-security and critical-information-infrastructure policies. For organizations building this capability, structured information security and ISO 27001 consulting materially shortens the path from gap assessment to audit readiness.

ISO 22301 — Business Continuity Management

Article 6 of MD 64 of 2025 requires the applicant company to maintain ISO 22301 certification to demonstrate business continuity. A Business Continuity Management System (BCMS) evidences that the provider can sustain eInvoicing service through disruption — business impact analysis, continuity strategy, recovery plans, and tested response procedures.

For a statutory reporting channel on which hundreds or thousands of client businesses depend, continuity is not an abstraction: an ASP outage can mean failed invoice exchange and failed tax-data reporting for its entire client base.

Is ISO 9001 Required?

No — ISO 9001 is not an ASP accreditation condition. No provision of MD 64 of 2025, the 2026 amendments, or the MoF guidelines lists ISO 9001 as an eligibility requirement.

ISO 9001 (quality management) is a useful, strategic certification that strengthens governance maturity and enterprise procurement credibility, but it should not be presented as mandatory. Organizations should budget compliance effort first for ISO/IEC 27001, ISO 22301 and the Ministry’s technical conditions, and treat ISO 9001 as complementary.

Other UAE ASP Requirements Beyond ISO Certification

The eligibility criteria in MD 64 of 2025 extend well beyond management systems into legal form, capital, experience, interoperability, insurance, self-declarations and testing. 

The verified conditions are set out below.

Area

Requirement (MD 64 of 2025, as amended)

Legal entity

UAE-incorporated juridical entity, or foreign entity licensed to conduct business in the UAE

Capital

Minimum paid-up capital of AED 50,000; audited financial statements

Experience

PSP Product in operation for minimum 2 years; experience held by the provider or a third-party PSP owner (Art. 5(bis), MD 56 of 2026)

Interoperability

Active Peppol-certified Service Provider; completed OpenPeppol conformance tests

Security

Valid ISO/IEC 27001 for the PSP Product; multifactor authentication; encryption at rest and in transit

Data residency

Compliance with UAE hosting, storage, archival and residency policies (national cloud security, critical information infrastructure)

Continuity

Valid ISO 22301 certification

Tax registration

Corporate Tax registration (Federal Decree-Law 47 of 2022); VAT registration where mandatory

Insurance

Professional indemnity ≥ AED 2.5M; crime ≥ AED 5M; cyber fraud ≥ AED 5M — all from UAE insurers

Self-declaration

No bankruptcy/liquidation, no criminal litigation, no government blacklisting; commitment to 100 free eInvoice exchanges/reports per annum; data confidentiality

Testing

Pre-approval testing, accreditation testing (TDD reporting, OpenPeppol test services, production trial with the FTA)

Procedure

MoF decision within 90 business days of application; accreditation valid 2 years; renewal ≥ 70 business days before expiry

This table doubles as an ASP Readiness Checklist 2026 — a practical self-assessment starting point before any formal application.

Peppol and PINT AE: Why They Matter for UAE ASPs

Peppol conformance is an eligibility precondition for ASP accreditation, and PINT AE defines the exact data structure every ASP must validate and transmit. 

Regulatory accreditation and technical conformance are inseparable: the Ministry accredits providers precisely because they can operate correctly inside the Peppol/PINT AE architecture.

What Is Peppol?

Peppol is the international interoperability framework — governed by the OpenPeppol association — that lets invoice systems exchange documents over a common network using common addressing, security and document rules. The UAE deliberately adopted this proven standard rather than building a proprietary exchange, giving UAE businesses cross-border reach by design.

Each UAE participant is identified on the network by a Peppol ID in the structure 0235:{TIN} — a detail businesses must collect from their buyers to issue valid eInvoices.

What Is PINT AE?

PINT AE is the UAE’s localized Peppol International (PINT) billing specification, published by OpenPeppol’s Post Award Coordinating Community. It defines the semantic model, syntax binding, code lists and validation rules for UAE invoices, credit notes and self-billing scenarios — the concrete data structure an ASP must validate, transmit and (where received in another format) convert into the UAE standard XML.

PINT AE v1.0.1 was released as the UAE’s official specification ahead of the 2026–2027 mandate. For an ASP, this is the technical heart of accreditation: OpenPeppol conformance testing is an eligibility precondition, and PINT AE conformance shapes the PSP Product’s data model.

How to Become an Accredited eInvoicing Service Provider in the UAE

The official procedure in MD 64 of 2025 follows an eleven-step readiness journey, from eligibility assessment through MoF accreditation to ongoing compliance.

  • Assess eligibility — entity status, AED 50,000 paid-up capital, audited financials, insurance capacity, tax registrations.
  •     Conduct an ASP readiness gap assessment — map current capability against every Article 5–11 condition before committing budget.
  •     Establish ISO/IEC 27001 — ISMS scope covering the PSP Product: risk assessment, Statement of Applicability, controls, documentation, internal audit, certification audit.
  •     Establish ISO 22301 — business impact analysis, continuity strategy, BCMS documentation, recovery plans, exercising and testing, certification audit.
  •     Build or validate the PSP Product — confirming the 2-year operational history requirement (held by you or your technology partner).
  •     Establish Peppol/PINT AE readiness — Peppol service provider certification, OpenPeppol conformance testing, PINT AE validation capability.
  •     Complete security and operational readiness — multifactor authentication, encryption, data-residency alignment, support/maintenance and upgrade handling.
  •     Prepare documentary evidence — trade licence, financials, insurance certificates, self-declarations, technical design documentation.
  •     Complete required testing — pre-approval testing, then accreditation testing including TDD reporting and a production trial run with the FTA (production PKI certificate, EmaraTax API access).
  •     Complete the MoF accreditation process — application review (up to 90 business days), decision, publication in the Central Register.
  •     Prepare for production and ongoing compliance — accreditation lasts 2 years; renewal filing is due at least 70 business days before expiry, with evidence of continued compliance.

Why ISO 27001 and ISO 22301 Matter Beyond Certification

Implemented properly, ISO/IEC 27001 creates cybersecurity governance and ISO 22301 creates operational resilience — capabilities that determine whether ASP accreditation is sustainable at renewal, not just achievable at application. 

Organizations that treat these standards as certificates to “collect” miss most of their value and tend to build fragile systems.

ISO/IEC 27001 establishes named risk ownership, risk-based control selection, incident preparedness and continuous improvement. In an ASP context, that governance protects not just one company but an entire client base’s statutory reporting channel. ISO 22301 establishes tested recovery capability against defined disruption scenarios — precisely what enterprise buyers and regulators look for when an entire invoicing ecosystem depends on a provider’s uptime.

Both certifications also carry commercial weight beyond the MoF file:

  • Enterprise procurement: procurement teams increasingly require both certifications.
  •     International credibility: they support operations across GCC and Peppol-connected jurisdictions.
  •     Insurability: they demonstrate governance maturity to insurers — relevant given the mandatory professional indemnity (≥ AED 2.5M), crime (≥ AED 5M) and cyber-fraud (≥ AED 5M) cover.

Disciplined management-system implementation, rather than certificate-chasing, determines whether accreditation is sustainable at renewal.

QRServes Helps Organizations Prepare for UAE ASP Accreditation

QRServes Global LLC supports organizations on the readiness and management-system side of ASP preparation. QRServes does not grant Ministry of Finance accreditation, and it does not issue ISO certificates — certification is performed by independent accredited certification bodies, and accreditation is decided solely by the Ministry of Finance. QRServes’ role is preparation:

  • ASP readiness assessment — mapping the organization’s position against the MD 64/2025 eligibility framework and identifying gaps before formal steps begin.
  •     ISO/IEC 27001 consulting — gap assessment, risk assessment methodology, ISMS framework, policies and procedures, control implementation, documentation, internal-audit readiness and certification preparation.
  •     ISO 22301 consulting — business impact analysis, continuity strategy, BCMS documentation, recovery planning, exercising and testing, and certification preparation.
  •     Integrated management-system support — operating information security and business continuity as one coherent compliance framework rather than two parallel projects.
  •     Documentation and audit readiness — organizing the evidence package for certification audits and for the Ministry’s documentary requirements.
  •     Regulatory readiness — mapping business processes and controls against UAE eInvoicing/ASP requirements.
  •     Ongoing compliance support — internal audits, corrective action, management review and continual improvement through the 2-year accreditation cycle.

QRServes can support this preparation; accreditation decisions rest with the Ministry of Finance.

Who Should Consider Becoming a UAE eInvoicing ASP?

Realistic ASP candidate profiles are organizations with existing transaction-processing operations, UAE client bases and the governance infrastructure to meet security and continuity requirements. 

Suitable profiles include:

  • ERP providers with UAE client bases.
  •     Accounting software and fintech companies.
  •     Established eInvoicing platforms expanding into the GCC.
  •     SaaS companies with transaction-processing heritage.
  •     Digital transformation and IT managed-service providers.
  •     Established business service providers with deep finance-function relationships.

Suitability depends on technical capability, operational maturity, regulatory readiness and organizational capacity. The 2026 third-party provisions (MD 56 of 2026) widen the field, but accreditation still demands genuine security, continuity and governance infrastructure. It is not an opportunity suitable for every company, and the gap assessment should come before the business case.

Common Mistakes Companies Make When Preparing for ASP Accreditation

The ten most frequent failure points in ASP preparation are:

  • Treating ISO certification as the entire requirement — it is two conditions among roughly a dozen.
  •     Ignoring Peppol conformance — an eligibility precondition, not an afterthought.
  •     Starting platform development before regulatory mapping — requirements should drive architecture, not vice versa.
  •     Weak information-security governance — policies without operating controls fail audits.
  •     Paper-only business continuity — ISO 22301 expects exercised, tested recovery capability.
  •     Incomplete evidence packages — insurance certificates, audited financials and self-declarations stall applications.
  •     Misunderstanding the process timeline — up to 90 business days for review alone; late starts compress testing windows.
  •     Relying on outdated 2024/2025 material — the May 2026 amendments (MD 56 and 66 of 2026) changed the third-party rules and the first-phase appointment deadline.
  •     Confusing certification with accreditation — different instruments, different authorities.
  •     Unclear third-party allocations — permitted now, but responsibility stays with the accredited provider.

Frequently Asked Questions

1. What is an Accredited Service Provider in UAE eInvoicing?

A company accredited by the UAE Ministry of Finance to connect businesses to the UAE Electronic Invoicing System — validating and exchanging eInvoices over Peppol in the PINT AE format and reporting tax data to the Federal Tax Authority.

2. Is ASP accreditation the same as ISO certification?

No. ASP accreditation is a Ministry of Finance regulatory status. ISO/IEC 27001 and ISO 22301 are management-system certifications issued by accredited certification bodies. The certifications are eligibility inputs; they do not confer ASP status.

3. Is ISO 27001 required for UAE eInvoicing ASPs?

Yes — a valid ISO/IEC 27001 certification for the PSP Product is an explicit condition under Article 9 of Ministerial Decision No. 64 of 2025.

4. Is ISO 22301 required for UAE eInvoicing ASPs?

Yes — Article 6 of MD 64 of 2025 requires the applicant company to maintain ISO 22301 certification demonstrating business continuity.

5. Is ISO 9001 required to become an ASP?

No. ISO 9001 is not listed in the accreditation framework. It is a complementary quality-management certification, not a mandatory condition.

6. Does an ASP need Peppol certification?

Yes. Applicants must be active Peppol-certified Service Providers who have successfully completed OpenPeppol conformance testing.

7. What is PINT AE?

PINT AE is the UAE’s localized Peppol International (PINT) specification — the official data structure and validation rules for UAE eInvoices, credit notes and self-billing, published by OpenPeppol.

8. Can an ASP use a third-party PSP Product?

Yes. Ministerial Decision No. 56 of 2026 expressly permits third-party PSP Products and outsourcing of development, operation or management — provided the accredited provider retains full responsibility and oversight.

9. Who accredits eInvoicing ASPs in the UAE?

The UAE Ministry of Finance, under Ministerial Decision No. 64 of 2025, with accredited providers published in the Central Register.

Picture of Sulakshana Sawarkar

Sulakshana Sawarkar

WhatsApp