Android developer verification starts 30 September: how should businesses check registration?
Event summary: the first enforcement phase of Android developer verification starts on 30 September 2026. On certified devices running Android 7 or later in Brazil, Indonesia, Singapore and Thailand, developer-verification protections begin for installations from seven participating stores. Google Play developers must also have every Play package registered by that date; an unregistered app may be removed from Google Play globally. Companies should audit developer identity, package name, signing key and distribution route app by app rather than assuming Google's 99% automatic-registration figure proves their own completion.
What is happening
Google announced the implementation plan on 18 June 2026 and added Play requirements in July. The initial participating stores are Google Play, HONOR App Market, OPPO App Market, Samsung Galaxy Store, Transsion Palm Store, vivo V-Appstore and Xiaomi GetApps. The first four countries are Brazil, Indonesia, Singapore and Thailand.
Google says approximately 99% of Play apps were registered automatically, but developers must review the remaining apps on the Play Console home page before 30 September. Play Console Help is explicit that all Play package names must be registered by the deadline and that an unregistered app will be removed from Play under the Play Console Requirements policy.
Companies distributing exclusively outside Google Play use Android Developer Console for the applicable verification and package-registration route. Google plans broader coverage across certified Android devices in 2027, although subsequent scope may continue to respond to implementation feedback.
Who is affected and where
An immediate review is appropriate for organisations that:
- have live, dormant, regionally unavailable or planned relaunches on Google Play;
- distribute through a participating store in Brazil, Indonesia, Singapore or Thailand;
- have used multiple signing keys, developer accounts, publishing agencies or legacy suppliers for one package;
- distribute the same product through Google Play and a website, enterprise channel or another store; or
- are managing a company acquisition, account migration, app transfer or signing change.
The first phase does not mean every mainland China Android store adopts an identical policy on 30 September. However, the Play package requirement can lead to global removal, and Google plans wider certified-device coverage in 2027. Any China-based company operating Google Play or overseas Android distribution should therefore complete the check.
Six actions before 30 September
1. Build a complete application register
For every package name, record product name, legal entity, developer account, stores, distribution countries, current status, signing certificate, public-key fingerprint, accountable owner and last release date. Include test variants, retired brands and dormant apps that remain downloadable; these are common sources of omissions.
2. Confirm account identity
In Play Console, check identity-verification status, account type, organisation details and contact information. Google's current Play policy requires specified financial, health, VPN and government services to use an organisation account. Legal name, address, D-U-N-S information where required and the actual operating entity should be consistent.
Do not use an employee's or supplier's account to bypass an organisation-data problem. Incorrect ownership affects package registration, updates, payments, appeals and eventual transfer.
3. Verify each package status in the console
An app marked successfully auto-registered generally needs no duplicate action, but retain evidence of that state. A package that was not registered automatically must follow the Play Console process: select an eligible signing key, provide the signed verification artifact or submit a package-use request as directed.
If another developer registered the name first, a key is ineligible or historical installation ownership is unclear, do not imitate the original app under a similar name. Assemble ownership, signing and release evidence and use the official request process.
4. Audit distribution outside Google Play
Include website APKs, customer-specific builds, MDM, third-party stores and channel variants. Play Console can register apps that the same developer distributes outside Play; developers distributing exclusively outside Play use Android Developer Console. Choose the route that matches the real account and distribution model.
ADB and the advanced flow for power users may remain possible in some circumstances, but they are not a sound default installation experience for customers or a normal commercial delivery plan.
5. Secure signing and supplier handover
Verification connects developer identity, package name and signing relationships. Confirm Play App Signing, upload keys, historical release certificates, recovery contacts and supplier-exit arrangements. If a former supplier controls the only key or primary account, start the formal transfer or recovery process before the deadline and retain approval and completion evidence.
6. Test a real update and installation
For each critical app, test an existing-user update and a new-user installation in a target market, then verify listing, sign-in, payment or another core business path, crash monitoring and customer-support lookup. A registered status is necessary evidence; it does not replace release and business acceptance.
Acceptance checklist
- Every production package maps to a legal entity, developer account and accountable business owner.
- Play Console or Android Developer Console evidence records identity and package status.
- Every exception is completed or has an official case owner and deadline.
- Signing certificates, fingerprints, Play App Signing and upload-key records agree.
- Website, third-party-store and customer-specific distributions are included.
- Priority apps are sampled for install and update in Brazil, Indonesia, Singapore and Thailand.
- Dormant, acquired, supplier-managed and paused apps have a retain-or-exit decision.
- Account recovery, key recovery, appeal and supplier-exit contacts are controlled by the company.
- Console status and store availability are scheduled for review after 30 September.
Common mistakes
“Google registered 99%, so there is nothing to check.” That is an ecosystem-wide figure, not evidence for an individual account. The remaining exceptions are precisely what businesses must address.
“Only four countries are affected.” Device-level protections begin in four countries, but Play Console Help says an unregistered Play app can be removed globally.
“A new build uploads successfully, so verification is complete.” Identity, package registration, signing relationship, store availability and real installation are separate controls.
“Our publishing supplier owns this task.” A supplier may operate the workflow, but the business still needs sustainable ownership and recovery of its account, package name and signing assets.
Teams preparing a new release can also use the Google Play submission readiness guide for listing, policy and testing scope.
Sources
- Android Developers Blog: Android developer verification — Building a safer ecosystem together (published 18 June 2026; updated 15 July 2026; accessed 7 September 2026)
- Android Developers: Android developer verification (accessed 7 September 2026)
- Google Play Console Help: Registering Play package names (accessed 7 September 2026)
This update reflects public information available on 7 September 2026. Enforcement markets, participating stores and console procedures may continue to change; the current official guidance and live account state govern.