A leading product engineering company, creating adaptive software solutions to improve operations, providing businesses with expert development services from across domain.

A leading product engineering company, creating adaptive software solutions to improve operations, providing businesses with expert development services from across domain.

Mobile App Development

Android developer verification: the 30 September cutoff

From 30 September 2026, Android developer verification blocks unregistered apps in four countries across Play and OEM stores. Who is exposed and what to do.

Android developer verification: the 30 September cutoff

On 30 September 2026, certified Android phones in Brazil, Indonesia, Singapore and Thailand start refusing to install apps from developers who have not verified their identity with Google. Android developer verification has been announced for over a year and most teams on Google Play have nothing to do. The teams who do are the ones least likely to have been reading Play Console announcements: companies distributing apps outside Google Play, to field staff, dealers or distributors, through a link or a device management tool.

If that describes any app you own, you have thirteen days in four markets and roughly a year everywhere else.

What actually happens on 30 September

Google's developer verification page sets out the scope precisely. From 30 September 2026, apps must be registered to a verified developer to be installed and updated on certified Android devices in the four launch countries, running Android 7 or later.

The part most coverage underplays is which stores are included. It is not only Google Play. The participating stores are Google Play, Galaxy Store, OPPO App Market, HONOR App Market, Palm Store, V-Appstore and GetApps. In markets where a large share of installs happen through a manufacturer's own store, that list covers most of the phones your users hold.

Google says it will expand the requirement globally to all apps on certified devices in 2027.

Who Android developer verification actually affects

For most Play developers the practical impact is close to nil. Google states that Play automatically registers 99% of apps, and that the Play Console is where you register the remainder or apps you also distribute elsewhere.

The exposure sits in three places.

Apps distributed only outside Google Play. These need the separate Android Developer Console, which exists specifically for developers distributing exclusively off Play. If your distributor app, dealer portal or internal tool ships as an APK from your own website, it is not covered by anything you did in the Play Console.

Enterprise and field apps installed by hand. Many businesses sideload an APK onto company phones — delivery drivers, sales teams, technicians, warehouse staff. Whether those installs are blocked depends on how they are installed and whether the devices are certified, and the only safe position is to register the package.

Apps built by an agency under the agency's account. If a vendor built and signed your app, the developer identity Google checks may be theirs, not yours. That is a governance problem this deadline turns into an operational one. Establishing who owns the signing key and the developer account now is far cheaper than discovering it when the vendor relationship has ended.

What registration involves

The requirement has three parts: identity verification using government-issued identification, registration of each package name, and proof that you hold the app's signing key. Reporting from The Hacker News describes the identity step as legal name, address and contact details, with ownership proven by submitting APKs signed with your private key, and notes a one-time fee for a full account.

The signing key is where this gets difficult for older apps. Proving ownership assumes you still have it. Teams that lost track of a keystore when a developer left, or whose key lives only in a build machine nobody maintains, will find that the hard part of verification is not the form.

There is also a separate, limited lane. Google describes limited distribution accounts that let students, teachers and hobbyists share apps with up to 20 devices without a government-issued ID or registration fee. It is useful for what it is, and not a route for a business app used by a field team larger than twenty people.

Sideloading is not going away, but it is getting harder

Unregistered apps can still be installed through adb, or through what Google calls the advanced flow, intended for power users who deliberately want to install unverified apps. Reporting on the June announcement describes that flow as requiring developer mode, a 24-hour wait and reauthentication.

Read that as a signal about intent rather than as a workaround. A flow with a day-long delay is designed for enthusiasts making an informed choice, not for onboarding a hundred delivery drivers on a Monday. If your distribution depends on users sideloading, it is time to change the distribution model rather than rely on the exception.

A checklist for this week

  1. List every Android app you own, including internal and partner apps nobody thinks of as products.
  2. For each, write down how it is distributed: Play, a manufacturer store, an APK link, or device management.
  3. Confirm who holds the signing key and the developer account. If the answer is a person who has left, or a vendor, resolve that first.
  4. Register anything distributed outside Play through the Android Developer Console, and check the Play Console for any app not automatically registered.
  5. Check whether your users are in the four launch countries. If they are, this is urgent; if not, schedule it before the 2027 global rollout rather than during it.
  6. Move internal apps to managed distribution where possible, so installation does not depend on users bypassing platform protections.

Why Google is doing this, and why it will stick

The stated rationale is fraud and malware: the ability to attribute an installed app to an accountable developer, so that someone distributing malicious apps cannot simply publish under a new anonymous identity the next day. Whatever you think of the trade-off with Android's openness — and it has real critics — the direction is set and the global date is already announced.

It fits a broader pattern across both mobile platforms. Apple has spent the same period tightening what it requires at submission, and the practical effect for businesses is identical: owning a mobile app now means owning an identity, a signing key and a registration that have to stay current, not just a codebase. The apps that break on deadlines like this are rarely the flagship ones. They are the useful internal tools that were built once, work fine, and have no owner.

If you are not sure which of your apps fall into that category, that inventory is quick to do and is where we would start on any Android app engagement — and it is the same discipline that decides whether a mobile app estate survives the next platform change, as it did when teams had to find a new route for over-the-air updates after CodePush.

Frequently asked questions

Android developer verification is enforced from 30 September 2026 on certified devices running Android 7 or later in Brazil, Indonesia, Singapore and Thailand. Google says it will expand the requirement globally to all apps on certified devices in 2027.

No. The participating stores are Google Play, Galaxy Store, OPPO App Market, HONOR App Market, Palm Store, V-Appstore and GetApps, so apps distributed through major manufacturer stores are covered as well as those on Google Play.

Usually very little. Google states that Play automatically registers 99% of apps. Developers should use the Play Console to register any remaining apps and any apps they also distribute outside Google Play.

Register it through the Android Developer Console, which exists for developers distributing exclusively outside Google Play. Registration requires identity verification with government-issued ID, registration of the package name and proof that you hold the app's signing key.

Yes, through adb or Google's advanced flow for power users who deliberately choose unverified apps. That flow is designed for informed individuals rather than business deployment, so internal apps should be registered or moved to managed distribution instead.

Google offers limited distribution accounts that let students, teachers and hobbyists share apps with up to 20 devices without a government-issued ID or registration fee. It is not suitable for business apps used by larger teams.

Written by

Akash Mohapatra

Akash Mohapatra

Co Founder & Director

17 Sep 2026

·

6 min read

Share

LET'S CONNECT

Connect with Creuto!

Ready to take the first step towards unlocking opportunities, realizing goals, and embracing innovation? We're here and eager to connect.

Contact Us

We don't just aim to fit in – we strive to stand out. Experience the perfect blend of innovation, excellence, and trust that makes us truly unforgettable. Discover the difference with Creuto.

© 2026 Creuto All Rights Reserved