The requirements for developing an app

TL;DR:

Building an app in 2026 means covering five bases: a validated business case, a technical plan, a design, a legal and compliance checklist, and a team and budget to execute it. Compliance is the category to watch most closely right now. Android developer verification kicks in September 30, 2026. Facebook Login on iOS requires SDK 17.0.0 or later to support Apple's privacy changes. New age verification laws mean a standard app rating doesn't satisfy account creation rules for minors in several states and countries.

What are the requirements for developing an app from scratch?

Developing an app from scratch requires a defined tech stack, a backend, API infrastructure, and a team maintaining separate iOS and Android codebases, since they don't share code. You also need ongoing DevOps capacity because every OS update, every new device size, and every platform policy change becomes your team's job to track and fix.

Try it for free!

Enter any URL to build your webview app

Right Arrow

What are the business requirements for an app?

Before any code gets written, you need a clear answer to what problem the app solves and for whom, basic validation of who the user is, what they're doing today instead, and why they'd switch.

You may also need to decide on a monetization model early (e.g., subscription, one-time purchase, ads, free with a paid tier, etc.), since it affects technical decisions such as in-app purchase integration and platform-specific billing rules.

We cover this in more detail here: Boost app engagement with push notifications.

What are the technical requirements for an app?

The technical requirements for an app is where the from-scratch versus platform decision matters most. At minimum, you need a platform approach, native iOS and Android, a cross-platform framework, or web to app, a backend for data storage and business logic, and a hosting environment.

Additional integration work may apply for:

  • Location services

  • Camera or microphone access

  • Health or fitness data

  • Financial services or payments

  • AI-generated content

  • Children's apps

  • In-app purchases or subscriptions

  • User-generated content (including moderation and reporting features)

Tip: Decide your platform approach before you scope a timeline. A native build and a web to app build aren't the same project at a different price, they're different requirement lists entirely. Furthermore, you'll need an associated developer account to publish your app.

What are the design requirements for an app?

A unique app name and package/bundle identifier, plus an app icon, screenshots, and a description, are among the requirements. You also need UI design for every screen and every state, loading, empty, error, and UX decisions about navigation and onboarding.

Accessibility isn't optional at this stage either; Apple and Google both weigh accessibility compliance in review, so it's cheaper to design for it up front than retrofit it later.

What team and resources does app development require?

The team requirements for building an app from scratch typically include a product owner, a designer, and either separate iOS and Android developers or a single cross-platform developer who covers both, with trade-offs.

QA and maintenance aren't a one-time thing or phase, either. They're a permanent line item once the app is live, since each of the compliance requirements described below needs to be checked as platforms change.

What budget and timeline does app development require?

The answer depends entirely on scope; specific figures vary too much by project to provide here generically. This app cost breakdown covers budget and timeline in more detail.

What's consistent is that native from-scratch builds carry the highest cost and longest timeline of any approach, cross-platform frameworks reduce both somewhat, and turning an existing site into an app carries neither the native build cost nor the ongoing dual-codebase maintenance burden.

What are the requirements for publishing an app?

You need developer accounts on both Apple's and Google's platforms, app store assets, screenshots, descriptions, privacy labels, and a plan for each store's specific review process.

This is the stage where the legal and compliance requirements above are actually tested; any gaps in your age verification setup or your privacy disclosure surface here, not earlier.

Before you submit, work through Median's app store publishing checklist to confirm your app is ready for both stages.

The legal and compliance requirements for an app currently span four fronts: Android developer verification, Google Play compliance, App Store privacy requirements, and age verification laws.

Android developer verification requirement: The September 2026 deadline

If you distribute your app outside Google Play, direct APK, a third-party store, or any custom internal channel, Android's new developer verification requirement applies to you starting September 30, 2026, on certified devices in Brazil, Indonesia, Singapore, and Thailand, with a global rollout confirmed for 2027.

What does verification require?

Verification means providing your legal name, address, email, and phone number, plus a government-issued ID if you are registering as an individual.

Organizations need a D-U-N-S Number from Dun and Bradstreet, which can take up to 28 days to obtain. There is no registration fee for individuals and no per-app cost.

For developers distributing outside Play, Google has launched the Android Developer Console specifically to handle non-Play registration.

There's no fee for individuals and no per-app cost. Developers distributing to 20 or fewer devices can use a limited distribution account instead, no ID or fee required. Miss the deadline in an affected country and your app won't install through normal flows there, users can technically still sideload through Google's deliberately buried "advanced flow," but that's not a realistic path for a mainstream user.

What if I only share my app with a small group?

Developers distributing to 20 or fewer devices can use a limited distribution account, which doesn’t require a government ID or a fee. This is Google's solution for students, hobbyists, and internal testing scenarios.

Can users still sideload unverified apps?

Technically, yes, but Google has made it deliberately difficult.

After enforcement starts, users who want to install an unverified app will need to navigate a buried settings menu, confirm they understand the risks multiple times, and wait 24 hours for the installation to complete.

This is what Google calls the "advanced flow." It exists, but it’s not a realistic path for a mainstream user, and apps distributed only through this method should be considered effectively blocked for most audiences.

Per early reporting on the rollout, the new com.google.android.verifier system service is already being deployed to Android devices running version 8 or higher this month, where it will remain dormant until enforcement goes live in your region.

What are Google Play's compliance and review requirements in 2026?

If you're submitting through Google Play, review typically takes a few hours to a few days for established accounts. Google Play reviews every app submission in two stages before it can go live. An automated system screens for clear-cut policy violations first. Human reviewers then check for compliance with Google's content policies, content rating accuracy, and ad suitability. Apps associated with sensitive data get closer scrutiny at the human review stage.

The three most common rejection triggers are: content policy violations, performance issues present at submission, and intellectual property conflicts.

Google provides feedback on rejections, which means a rejection is a diagnosis, not a dead end. The resubmission path is straightforward once you know what triggered it. 10 ways to avoid app rejection covers the resubmission path once you know what triggered it.

How Apple's privacy rules changed Facebook login on iOS

If your app uses Facebook Login on iOS, Apple's App Tracking Transparency enforcement already changed what data you can access unless you're on SDK 17.0.0 or higher with your login flow updated to request ATT permissions upfront and handle the new AuthenticationToken correctly. This is iOS only. Android users are unaffected because Limited Login was introduced specifically to comply with Apple's ATT policies.

This is part of a broader shift in Apple's App Store privacy requirements, disclosure of what data your app collects and how it's used now shows up directly on your App Store listing, not just buried in a privacy policy link.

If Facebook login is breaking for you inside an in-app or embedded browser after this change, Facebook Limited Login: Understanding changes to the iOS Facebook Login SDK covers the implementation end to end.

Age verification requirements in 2026: Who they apply to

If minors can access your app or create an account, new age verification laws in several US states and international markets mean an age rating from Apple or Google doesn't satisfy the requirement on its own, an app rated "4+" isn't automatically compliant with, for example, Texas's account-creation rules for minors.

Check the specific laws for where your users are rather than assuming a generic rating covers you.

FAQs about the requirements for development an app

Why does app compliance matter?

Non-compliance blocks your app before it reaches users. A missed Android developer verification deadline means your app won't install through normal flows in the affected regions. A Google Play rejection means it never goes live until the flagged issue is fixed.

An age verification gap can put you on the wrong side of a law, not just a platform policy. Compliance is the difference between an app being reachable and not.

What’s app developer compliance, specifically?

It's the set of requirements a developer has to meet, separate from what the app itself does, to distribute on a given platform. Android's new developer verification is the clearest example, it checks who's publishing the app, not what the app contains. That's different from content review, which checks the app's behaviour against platform policy. A developer can be fully verified and still have an app rejected on content grounds, and an app can pass content review while its developer isn't yet verified.

Do I need to know how to code to develop an app?

Not necessarily. No-code and web-to-app platforms handle the technical build, though the business, design, and compliance decisions are the same either way.

The compliance cost of maintaining a separate mobile codebase

Median’s web to app platform turns your existing website into a native iOS and Android app, which removes several items from the requirements for building an app entirely. When platform requirements change, the things that typically need updating are your website's implementation, your SDK versions, and your store listings, not a separate mobile codebase you have to maintain in parallel.

For compliance changes such as the ones above, the risk surface area you're responsible for is smaller. Age verification compliance lives in your web layer, Facebook Limited Login compliance lives in your authentication implementation, and Android developer verification, where applicable, is a one-time account-level step, not an app rebuild.

If you're building on Median and want a straight answer on how any of this affects your specific setup, Median’s Publishing Service is where Median's team tracks these changes for you and handles the submission work directly.

*DISCLAIMER: This content is provided solely for informational purposes. It is not exhaustive and may not be relevant for your requirements. While we have obtained and compiled this information from sources we believe to be reliable, we cannot and do not guarantee its accuracy. This content is not to be considered professional advice and does not form a professional relationship of any kind between you and GoNative.io LLC or its affiliates. Median.co is the industry-leading end-to-end solution for developing, publishing, and maintaining native mobile apps for iOS and Android powered by web content. When considering any technology vendor we recommend that you conduct detailed research and "read the fine print" before using their services.*