Capital Market Authority — formerly the Securities & Commodities Authority (SCA)
In January 2026 the SCA became the Capital Market Authority — a wider federal remit, tougher supervision, and the one licence that opens ADX, DFM and the national investor base. We place your business in the right activity category and carry the application through the CMA's new framework, so the reform works for you instead of against you.
Confidential & non-binding · Same-day response in UAE hours
ACTIVITIES
The CMA — the Capital Market Authority, successor to the SCA since 1 January 2026 — is the UAE's federal regulator of securities and commodities activity across the onshore market, outside the DIFC and ADGM free zones.
It doesn't licence by label; the activities you carry out determine which of five financial-activity categories you fall into, and the heavier the activity, the heavier the capital and scrutiny. Picking the right category, then evidencing the controls behind it, is where most applications succeed or fail.
Trading securities and commodities on the firm's own account and market-making — the top-tier permission.
Executing and arranging trades for clients on ADX, DFM and Nasdaq Dubai, on a discretionary or advisory basis.
Managing portfolios and collective investment funds on a discretionary or advisory basis for clients.
Safekeeping and administration of financial instruments, with clearing and registry services.
Financial consultancy, investment advice, issuance & listing advisory and findings — no client money held. The most popular entry point.
Security and asset-backed tokens, exchange and custody services — layered on the core category that best matches your model, with proof-of-reserves and technology-governance obligations.
MARKET
The CMA is the UAE's federal capital-markets regulator, overseeing the Abu Dhabi Securities Exchange (ADX), the Dubai Financial Market (DFM) and Nasdaq Dubai, and every broker, dealer, fund and market intermediary operating onshore. Its 2026 reconstitution from the SCA came with an expanded mandate — covering virtual assets, ESG products and market infrastructure — and broader supervisory and enforcement powers. This is the licence that opens the full onshore UAE market and its national investor base.
WHY ONSHORE
The UAE has federal and free-zone regulators, and the right choice depends on who you serve and where. The DFSA (DIFC) and ADGM's FSRA are common-law free-zone regulators; VARA covers Dubai's virtual assets. But if you need the onshore UAE market — ADX, DFM and retail and institutional clients nationwide — the CMA is the regulator that gives it to you. Here's how it sits against the alternatives.
CAPITAL
The CMA sets minimum paid-up capital by activity category, then requires you to hold it — plus risk-based and liquidity resources — on an ongoing basis, not just at filing. Client-money and client-asset activities carry the heaviest requirements; arranging and advice the lightest. Select a category to see the layers.
*Capital requirements are set by activity category. We confirm the figures applicable to your specific activities against the CMA's current published framework during scoping.
PROCESS
CMA authorisation runs in two stages: you earn initial approval before you build and deposit capital, then satisfy the conditions to get the final licence — so problems surface early, not after you've committed.
We confirm your activities fall within the CMA's remit and map them to the correct financial-activity category before a dirham is spent.
Submit the business plan, financial projections, AML/CFT and risk frameworks, and fit-and-proper questionnaires for shareholders and approved persons.
The CMA reviews the file, holds meetings, and issues In-Principle approval setting the conditions you must satisfy. No financial services yet.
Incorporate onshore in the UAE, secure a physical office, put systems and controls in place, make key hires, and deposit the required paid-up capital.
The CMA confirms your approved persons, controls and capital are genuinely in place, and every condition has been met.
Final Authorisation is issued for your category and permitted activities — and your live supervisory obligations begin.
You're authorised to operate — live supervisory obligations begin from day one.
Most applicants lose months in Stage 2 — underestimating the systems, controls and approved-person evidence the CMA expects to see genuinely in place. Preparing that package properly, the first time, is the core of what we do.
The four things the CMA pushes back on most — and the four we harden before you file.
Boards and approved persons without genuine financial-services track record.
Evidence that doesn't cleanly meet base capital, the risk-based figure and liquidity together.
Off-the-shelf policies not tailored to your specific category and risk profile.
Infrastructure and controls below the CMA's technology and resilience expectations.
WHAT IT TAKES
The category sets your capital. But authorisation turns on a wider set of requirements — the ones applicants most often underestimate. Here's the full checklist, in the CMA's own terms.
A UAE-incorporated company — mainland, or a recognised free-zone entity where the free-zone law permits — holding a commercial licence. Financial activities must be carried on onshore under the CMA's remit.
The paid-up capital for your category, plus risk-based and liquidity resources held on an ongoing basis. Client-money and client-asset activities carry the heaviest floors; figures are confirmed per activity in scope.
Fit-and-proper approved persons — a general manager resident in the UAE, plus a Compliance Officer and MLRO. A CISO and dedicated finance function are expected for tech-intensive and client-asset firms.
Genuine local substance is expected: a real UAE office, secured as part of satisfying your initial-approval conditions — not a flexi-desk afterthought.
Shareholders, directors and approved persons must pass the CMA's fit-and-proper assessment — competence, experience, financial soundness and integrity. The CMA screens the people, not just the paperwork.
An adequate governance framework, clear division of responsibility, conflicts-of-interest management and internal controls proportionate to your scale and complexity — evidenced, not asserted.
Compliance with UAE federal AML/CFT law and the CMA's market-conduct rules: AML/CFT procedures, the FATF Travel Rule, sanctions screening, client-money and client-asset segregation, and — for virtual assets — proof-of-reserves.
The CMA expects technology risk, resilience and cyber controls proportionate to your business — penetration testing, business-continuity and incident-response — with professional indemnity and other insurance on top.
THE KOLL GROUP DIFFERENCE
Getting the licence is one thing. Staying licensed — with compliance that holds up to supervision and security that holds up to attack — is another. We're the only Dubai advisor that carries all three in-house.
We don't coach from the sidelines. We run the whole file — category selection, entity structuring, the full application and every round of regulator questions — through to authorisation.
Client-money reconciliation, market-conduct monitoring and regulatory reporting on our own platform — so the controls you're approved on are the controls you actually run.
Trading systems and client-asset custody live or die on security. Our sister firm ITSEC delivers the penetration testing, cyber controls and audit evidence in-house.
Three disciplines competitors outsource to three vendors. With KOLL Group it's one engagement, one accountable team — advisory, RegTech and cybersecurity under one roof.
END TO END
CMA authorisation runs in two stages — initial approval before capital and controls are deployed, then final authorisation once every condition has been verified.
We map your business to the correct CMA category and confirm what is — and isn't — in scope before you commit capital or time.
We prepare the business plan, AML/CFT policy pack and approved-person documentation, defend it through review — then keep you compliant after authorisation: AML, KYC, governance, reporting and audit.
The CMA expects technology risk and cyber resilience proportionate to your business. As part of ITSEC, we bring penetration testing, CISO and incident-response into the application from day one — where others outsource it later.
LIGHTER ENTRY
Two routes sit outside the full category framework — lighter registration for narrower activities, worth checking before you scope a full application.
Referring clients to a licensed CMA firm without executing trades, advising or holding client money — a materially lighter registration than a full dealing category.
Providing investment advice on a non-discretionary basis, tied to a single principal firm — a narrower permission than independent discretionary management.
STAYING LICENSED
Authorisation isn't the finish line — it's the start of ongoing supervision. Here's what continues after your licence is issued.
Refusals, conditions and enforcement decisions can be challenged through the CMA's internal grievance process, and beyond that through the UAE courts. We prepare the file and represent your case at every stage.
Where KOLL takes it from here
Licensing is one part of the engagement. We also handle regulatory and compliance advisory across the application, RegTech implementation for KYC, transaction monitoring and reporting, cybersecurity assurance for licensed firms, and ongoing compliance after your licence.
FAQ
Brokerage, advisory, fund management, custody, market-making and related securities and commodities activities. We confirm your category up front.
Capital requirements vary by activity. We size them against your model as part of the structuring work before you apply.
The CMA is the SCA's direct successor — reconstituted as the federal capital-markets regulator on 1 January 2026 with an expanded mandate covering virtual assets, ESG products and market infrastructure. Existing SCA licences carried over automatically, with no re-application required.
Conduct, reporting and AML obligations begin. We stay on as your compliance partner so nothing slips after go-live.
Yes — since its 2026 expansion, the CMA's mandate covers virtual-asset and tokenised-instrument activity onshore, layered on top of the core category that best matches the underlying model, with proof-of-reserves and technology-governance obligations attached.
Typically 6–12 months end to end — in-principle approval first, once your application, capital and controls are in order, then final authorisation once build-out is verified and every condition is met.
THE FULL PICTURE
Every regulated business in the UAE fits under one of these six regimes. Here's the full picture, and where CMA sits within it.
Federal regulator for securities, commodities and onshore capital markets.
The world's first dedicated virtual-asset regulator, covering all of Dubai.
Read the guide →Financial services in the DIFC — common-law, institution-facing, firm-led crypto.
Read the guide →Abu Dhabi's common-law free zone with a pioneering virtual-asset framework.
Read the guide →Banking, payments, e-money and exchange — the Central Bank of the UAE.
Read the guide →GO FURTHER
Some models span more than one framework, or need support that goes beyond the licence itself.
If your CMA activity carries a virtual-asset or tokenised-instrument component, VARA may also come into scope. We map both frameworks together.
Explore virtual assets →Advisory, RegTech and cybersecurity in one engagement — the same team that built your licence keeps you compliant after.
See the ecosystem →Building trust in a regulated market
Tell us your goals. In one confidential call we'll confirm the activities you need, the right structure, a realistic timeline and the exact next steps.