Android is tightening its security: what app developers need to know
TL;DR: Google is rolling out mandatory developer verification for all Android apps, including sideloaded ones (apps installed outside of an official app store, directly from a file or third-party source), on certified devices. Starting September 2026 in Brazil, Indonesia, Singapore, and Thailand, any app that isn't registered by a verified developer simply won't install. If you distribute apps outside of Google Play, this changes how your users get to you.
Android developer verification links each app to a real, identity-verified publisher so Android can block anonymous malware distribution without fully closing sideloading—the practice of installing apps outside of an official store. Google is doing this because sideloaded abuse remains disproportionately high, and identity plus package registration adds accountability across Play and off-Play channels. The immediate milestones to track are March 2026 (registration opens to all developers), April 2026 (Android Developer Verifier appears on devices), and September 30, 2026 (enforcement begins in the first four regions).
What is Google changing about Android app security?
Google is requiring every Android app—including sideloaded ones—to come from an identity-verified developer. On certified Android devices, apps from unverified developers will fail to install.
Developer verification, announced in August 2025 on the Android Developers Blog, ties every Android app to a registered, identity-verified developer. To install an app on a certified Android device, the developer behind that app must be verified first.
"Play Protect certified" devices are those that ship with Google Mobile Services and meet Google's security and compatibility requirements—this includes nearly all mainstream Android phones and tablets from major brands like Samsung, Google Pixel, Motorola, and Xiaomi. Devices running AOSP-only builds or custom ROMs are not Play Protect certified. The rule applies to app installs from any source: Play Store, third-party stores, or direct downloads.
Why is Google requiring Android developer verification?
Android has always been the more open mobile platform. Users could download apps from the Play Store, third-party stores, or directly from a developer's website—flexibility that made Android powerful, and, for bad actors, exploitable.
Google's own analysis put a hard number on the problem: there is over 50 times more malware in apps sideloaded from the internet than in apps distributed through Google Play. Malicious actors hide behind anonymity, impersonate legitimate developers, and ship convincing fake apps that steal data or deploy banking trojans and spyware.
That's what developer verification is built to stop—alongside existing device-level risks like rooted Android phones.
Why should you care, and when should you start caring?
The rollout is already underway. March 2026 marked a key milestone that has now passed—global developer registration opened on both the Play Console and Android Developer Console, meaning the window to get verified before enforcement is already open. April 2026 is when the on-device Android Developer Verifier system service launched, putting the enforcement infrastructure directly on certified devices. Further milestones follow in June and August 2026, expanding the limited distribution tier and the advanced sideloading flow globally. Then comes September 30, 2026—hard enforcement begins in Brazil, Indonesia, Singapore, and Thailand, with a global rollout to follow.
If you ship apps outside of Google Play and haven't registered yet, the clock is already running.
Google is rolling this out in phases, deliberately:
- October 2025: Early access for developers begins
- March 2026: Global registration opens to all developers on Play Console and the Android Developer Console
- April 2026: The on-device Android Developer Verifier system service launches
- June 2026: Early access opens for limited distribution (student/hobbyist) accounts
- August 2026: Limited distribution accounts and the "advanced sideloading flow" launch globally
- September 30, 2026: Hard enforcement begins in Brazil, Indonesia, Singapore, and Thailand
- 2027 onwards: Enforcement rolls out globally
An unverified app in an enforcement region may not install at all without the user navigating the advanced flow. For any team relying on sideloaded distribution, getting verified early isn't just about compliance—it's about staying installable.
How does this affect your Median apps?
If your app lives exclusively on Google Play and your developer account is already in good standing, the practical impact is minimal. Play Store developers will move through a streamlined verification process that builds on existing account infrastructure—similar in spirit to Google's recent app testing updates.
The bigger question is for teams who distribute apps directly—enterprise apps rolled out via MDM, beta builds sent to testers, or apps shipped through private distribution channels. These pipelines will need to account for developer verification before September 2026 if you serve users in the initial enforcement regions.
If you build your mobile app with Median.co, your web-to-native setup already sidesteps one common pain point with changes like this. You don't have to push a new native release every time a platform policy shifts—ship app behavior updates through the web layer, and let Median handle the native build, signing, and store submission (developer verification included) as part of your normal workflow.
Frequently asked questions
What is Android developer verification?
Developer verification, announced in August 2025 on the Android Developers Blog, ties every Android app to a registered, identity-verified developer. To install an app on a certified Android device, the developer behind that app must be verified first.
"Play Protect certified" devices are those that ship with Google Mobile Services and meet Google's security and compatibility requirements—this includes nearly all mainstream Android phones and tablets from major brands like Samsung, Google Pixel, Motorola, and Xiaomi. Devices running AOSP-only builds or custom ROMs are not Play Protect certified. The rule applies to app installs from any source: Play Store, third-party stores, or direct downloads.
What happens if I'm not verified by the September 2026 deadline?
In the initial enforcement regions—Brazil, Indonesia, Singapore, and Thailand—users on certified Android devices will be unable to install your app through the normal flow. They would need to navigate the multi-step "advanced sideloading flow," including a mandatory 24-hour delay, to get it installed. Outside those regions, enforcement follows later in 2027, but waiting is a risk.
Ready to get your Android build ahead of the 2026 deadlines? Start a free trial or talk to our team about your distribution setup.