
A practical guide to licensing, building, securing and launching an e-commerce company in Ethiopia with INSA review, logistics and Telebirr payments.
Related guides in this journey
To start an e-commerce company in Ethiopia, begin with the business license. Do not build the complete mobile app first and then ask which documents are required. Use the simple order below so the company, software, security inspection, payment integration, and e-commerce activity support each other.
Step 1: obtain the business license
Register the company, obtain a TIN and commercial registration, and secure a trade or business license that covers what the company will sell or provide. A direct online shop, a multi-seller marketplace, and a delivery platform may need different activities.
Follow the complete process in How to Start a Company in Ethiopia.
Step 2: build the mobile app or system
Build the customer experience and the systems needed to operate it. Depending on the model, this can include a customer app, seller portal, website, admin dashboard, inventory, order management, delivery tracking, refunds, customer support, tax records, and payment reconciliation.
Keep the source code, domain, cloud account, app-store accounts, signing keys, database, and administrator credentials under the company’s control. Prepare test accounts and safe test data before requesting inspection.
Step 3: design the logo and protect the work
Create the company and product logo before the final app release. Keep the editable design files, font and image licenses, brand colors, and ownership agreement.
Copyright can cover original source code, documentation, graphics, and other creative work. The Ethiopian Intellectual Property Authority accepts voluntary registration of computer programs and other eligible works. Trademark registration is a separate process for protecting the name and logo used in the market.
Step 4: submit the system for INSA security inspection
Prepare the software and documentation before submitting the audit request. Submit the required information and files through the INSA Cyber Audit portal. Ask INSA for the current checklist and submit each platform in its correct scope. A mobile app, website, and API do not use one identical requirements document.
Documents required for INSA submission
- A copy of the valid business license.
- The copyright certificate for the mobile app or system.
- The Software Requirements Specification (SRS) file for the system being inspected.
Mobile-application documentation requested
- A mobile SRS describing features, roles, data, permissions, authentication, payments, and error handling.
- Architecture and data-flow diagrams, API details, third-party services, and security controls.
- An Android APK or the Android installation method accepted by the assessor.
- An iOS IPA, TestFlight link, or other installation method specifically accepted by INSA.
- Test accounts for customer, seller, delivery, support, and administrator roles where applicable.
- Company documents and the ownership or copyright evidence requested in the current checklist.
Web-application documentation requested
- A web-specific SRS, site map, roles, workflows, deployment architecture, and data-flow diagram.
- The test or production URL approved for assessment, together with safe test accounts.
- Hosting, domain, TLS, database, backup, logging, privacy, and access-control information.
API documentation requested
- The full endpoint list, HTTP methods, request and response formats, status codes, and error handling.
- Authentication, authorization, token lifecycle, roles, rate limits, and sensitive-data handling.
- Third-party integrations, payment callbacks, webhooks, network boundaries, and test credentials.
Use a Software Requirements Specification (SRS) template as a starting point, then keep separate mobile, web, and API sections.
Step 5: receive and check the INSA certificate
After the assessment, correct the reported security findings and provide the evidence requested for closure. If the system is approved, keep the certificate and final report with the company records.
Field information describes a six-month certificate for some app assessments, but the public INSA requirements reviewed for this guide do not state one universal validity period. Use the start date, expiry date, covered application versions, and conditions printed on the certificate you actually receive.
Step 6: request Telebirr and call-center services
Once the business and technical documents are ready, request the Telebirr product that matches the payment flow. If the service also needs call-center, SMS, or OTP API support, prepare those requests at the same stage.
See How to process Telebirr integration for your app or system for the application and integration process.
Required documents for Telebirr, SMS, and call center
- Renewed business license.
- Registration certificate.
- Tax Identification Number (TIN).
- VAT certificate, if registered.
- Memorandum and articles of association, where applicable.
- Request letter and website or app security inspection approval from INSA.
Proposal for Telebirr, SMS, and call center
- Company profile that clearly states the main service you need to integrate and how the current business or platform works.
- Business readiness, including time to market and whether the service is already live.
- Technical readiness of the app, website, or both.
- Specific integration channel: app, web, or both.
- How you work with clients and how the payment strategy works.
- User manual or flow chart.
Take the company stamp when you go to sign documents. Also prepare the company bank account that will receive transferred money.
Step 7: confirm activity code 85125 or 85126
Add activity code 85125 or 85126 to the company TIN number. Go with the original TIN document, not a copy, because the office changes it during the update. Also bring your business license and company stamp. The update usually takes a few minutes when the documents are ready.
Step 8: check the current MInT e-commerce-license process
Field information says the Ministry of Innovation and Technology stopped issuing an e-commerce-related paper or license for a period. A current public page confirming that the service has restarted was not found during this review.
Ask MInT whether the service is currently active and request the latest checklist. Bring the TIN, business license, confirmed activity code, company documents, and INSA inspection certificate or report. Do not describe the business as fully licensed until the responsible office confirms which approval is currently required.
Step 9: go live legally
Launch only after the company has the approvals that currently apply to its model and every system has passed production testing. Keep the customer terms, privacy notice, refund policy, seller or logistics agreements, tax invoice process, support channel, and daily payment reconciliation ready.
- Business and trade licenses complete
- App, website, admin, and API tested
- Logo, source code, and company ownership documented
- INSA findings closed and certificate conditions checked
- Telebirr payment and callback reconciliation tested
- Activity code and current MInT requirement confirmed
- Tax invoices, delivery, refunds, privacy, and customer support ready
Frequently asked questions
Should I build before getting the business license?
Plan the product early, but confirm the company and activity first. This prevents expensive development for a model the license or regulator does not support.
Does INSA use one SRS for every system?
No. Keep the overall architecture consistent, but document mobile, web, and API scopes separately because their builds, interfaces, risks, and testing methods differ.
Is the INSA certificate always valid for six months?
A universal six-month period was not confirmed in the public requirement documents reviewed. Follow the validity and conditions printed on the certificate issued for the system.
Must every company use both 85125 and 85126?
That was not confirmed. Ask the Revenue and Trade offices to identify the current code that matches the actual platform model.
Can I apply for Telebirr before INSA approval?
Ask the Telebirr onboarding team for its current sequence. Prepare the business and technical documents early, but expect production approval to depend on the complete onboarding and security evidence requested.













