DEV Community

Tim
Tim

Posted on

Google's Android developer-verification enforcement is live (first wave) — what sideloading devs should do now

On September 30, 2026, Google's developer-verification enforcement went live in the first wave: Brazil, Indonesia, Singapore, and Thailand. Here's the scope, straight from Google's own documentation: right now it covers apps downloaded from participating stores (Google Play, Samsung Galaxy Store, Xiaomi GetApps, OPPO App Market, vivo V-Appstore, HONOR App Market, Transsion Palm Store) on certified Android devices in those four countries. Google says the same requirement expands globally to all install sources in 2027.

What does that mean if you distribute Android APKs outside Google Play — direct downloads, F-Droid, GitHub Releases, your own site? Your exact deadline depends on your distribution:

  • If your app is on Google Play (even alongside other channels): you're in the participating-store set everywhere. Check Play Console now — unregistered apps are at risk of removal from Play globally.
  • If your users install via Galaxy Store / GetApps / etc. in BR, ID, SG, or TH: they're hitting the block today.
  • If you distribute via F-Droid or direct APK download: F-Droid is not a participating store, so the September wave doesn't block those installs — but the 2027 global rollout covers all install sources, which is when your distribution falls in scope. The rules are already written; the only question is your timeline.

A few facts worth knowing: verification means a $25 full-distribution Play Console account plus government photo ID (organizations additionally need a D-U-N-S number, which can take ~28 days — that's the long pole). When an install is blocked, users get a one-time bypass in settings — high-friction by design, not a viable distribution strategy. ADB installs are unaffected.

The checklist for this week

  1. Check your Play Console status. If your app is on Play, confirm it's registered — that's the urgent one.
  2. Decide your deadline honestly. Users in the four launch countries installing via participating stores: you're already affected. Everyone else distributing outside Play: your enforcement date is the 2027 global rollout — start the process now while review queues are short.
  3. Verify your identity. $25 Play Console account with full distribution, government photo ID. Start now — review takes time and rejections happen.
  4. Back up your signing key. Export it, store it offline in two places, record the SHA-256 fingerprint. If you lose the key you lose the ability to update your app, verification or not.
  5. Register your package names + key fingerprints once verification clears.
  6. Orgs: request D-U-N-S today. ~28 day turnaround.

Who should act first

  • Apps on Google Play that were published years ago under accounts nobody actively maintains — check registration status today.
  • Devs with users in Brazil, Indonesia, Singapore, or Thailand installing via participating stores.
  • F-Droid and direct-APK devs — your scope date is the 2027 global rollout; getting verified now means you're covered for both.

Pure Play Store devs who registered years ago: you're likely already verified through your existing Play Console account. Check anyway.

Free audit

I built a free 2-minute audit that takes 7 answers and generates a prioritized action plan for exactly this situation: https://8286544375711.gumroad.com/l/ffqtov

Disclosure: I also sell a $19 printable Readiness Kit with the complete walkthrough (registration steps, signing-key backup guide, package registration, recovery path): https://8286544375711.gumroad.com/l/rwqasc. The audit above is free and standalone.

(Scope per Google's official support documentation as of September 2026; enforcement details are evolving — verify against the current docs.)

Top comments (0)