iOS App Distribution Guide 2026: App Store, TestFlight, Enterprise and EU Options

Last updated 28 September 2026, after Apple opened App Store submissions for iOS 27. We review this guide whenever Apple changes its distribution rules.

There are seven ways to get an iOS app onto someone's iPhone or iPad in 2026. Six of them work worldwide: the public App Store, TestFlight, Ad Hoc, custom apps, unlisted apps and the Enterprise Program. The seventh, alternative distribution outside the App Store, only exists in the EU, Japan and Brazil. This guide covers all seven, what each costs, and how to pick. It's the companion to our Complete Guide to Android App Publishing in 2026.

How many ways are there to distribute an iOS app in 2026?

There are seven. Which one you need depends on who the app is for.

1. Public App Store: anyone, worldwide.

2. TestFlight: beta testing with up to 10,000 external testers.

3. Ad Hoc: direct installs on up to 100 registered devices per device type each membership year.

4. Custom apps: private distribution to named organisations through Apple Business or Apple School Manager.

5. Unlisted apps: on the App Store, but only reachable through a direct link.

6. Apple Developer Enterprise Program: in-house apps for your own employees, and only if you qualify.

7. Alternative distribution: alternative app marketplaces in the EU, Japan and Brazil, and downloads from your own website in the EU.

What changed for iOS app distribution in 2026?

Seven changes this year affect how you ship. Here they are with the date Apple announced each one.

• 3 Feb 2026: from 28 April 2026, every iOS and iPadOS upload to App Store Connect has to be built with the iOS 26 SDK or later, which means Xcode 26 or later.

• 6 Feb 2026: Apple revised the App Store Review Guidelines. Apps with random or anonymous chat now fall under guideline 1.2, User-Generated Content.

• 24 Feb 2026: Apple started blocking users in Australia, Brazil and Singapore from downloading apps rated 18+ unless they've been confirmed as adults.

• 8 Jun 2026 (WWDC26): Apple clarified guideline 4.3(b) and added examples. For saturated categories such as dating, flashlight, wallpaper and simple timer apps, Apple says it "may remove these apps from the App Store going forward if they are not updated, improved, or do not attract customers."

• 18 Jun 2026: alternative app marketplaces and payments outside In-App Purchase arrived in Brazil (from iOS 26.5), following Japan (from iOS 26.2, announced December 2025).

• 9 Jul 2026: the age rating questionnaire gained questions about social media features. Answers are required when you submit new apps or updates from September 2026.

• 18 Aug 2026: new EU business terms, effective 1 October 2026. A 5% Core Technology Commission replaces the per-install Core Technology Fee, and developers no longer need an EU legal entity to run an alternative marketplace or use Web Distribution.

Looking ahead, Apple opened submissions for iOS 27 on 9 September 2026. From April 2027, uploads must be built with the iOS 27 SDK and target iOS 15 or later.

Part 1: What you need before you can distribute anything

How much does the Apple Developer Program cost in 2026?

The Apple Developer Program costs 99 USD a year, and the Enterprise Program costs 299 USD a year. Apple charges both in local currency where it can, so you see the exact UK price during enrolment. You need a paid membership for every distribution method in this guide. A free Apple Account only lets you run your own builds on your own devices from Xcode.

You can enrol as an individual or as an organisation. An organisation needs a D-U-N-S Number from Dun & Bradstreet (free in most places), a work email on the company's domain and a public website. The company name then appears as the seller on the App Store. Government organisations don't need a D-U-N-S Number.

Fee waivers exist, but only for nonprofits, accredited educational institutions and government entities. They're not available to individuals, sole traders or anyone selling digital goods in their apps.

How does code signing work on iOS?

Every iOS app has to be cryptographically signed before it will install. The signature proves who built the app and that nobody has changed it since. Three pieces work together:

• Certificates identify you or your organisation. Distribution certificates sign builds for the App Store and Ad Hoc. Enterprise members get in-house certificates.

• App IDs identify an app (or a group of apps) and list the capabilities it uses, such as push notifications or Sign in with Apple.

• Provisioning profiles tie a certificate to an App ID and, for Ad Hoc and development builds, to a list of registered devices. A build only runs on a device a matching profile covers.

Xcode's automatic signing handles most of this for small teams. On larger teams or CI pipelines, someone has to own the certificates, and in our experience signing is where new iOS teams lose the most time.

Part 2: The seven iOS distribution methods explained

2.1 Public App Store

The App Store is the default for any app meant for the general public. Every version goes through App Review against Apple's App Review Guidelines before release.

Apple's standard commission is 30% on paid apps and in-app purchases. The Small Business Program cuts that to 15% for developers who earned up to 1 million USD in proceeds the previous year. Four regions have their own payment rules in 2026:

• US storefront: apps may include buttons and links to other ways to pay.

• EU: new terms from 1 October 2026 change commission rates and let App Store apps offer alternative payment options alongside In-App Purchase.

• Japan (from iOS 26.2) and Brazil (from iOS 26.5): apps can process payments for digital goods and services outside In-App Purchase.

In most other storefronts, digital goods and features unlocked inside the app still have to use In-App Purchase (guideline 3.1.1). Physical goods and real-world services don't.

2.2 TestFlight beta testing

TestFlight is Apple's beta testing service. Its limits:

• Up to 100 internal testers: App Store Connect users on your team with the Account Holder, Admin, App Manager, Developer or Marketing role.

• Up to 10,000 external testers, invited by email or through a public link.

• Each build stays testable for 90 days after upload.

• Up to 100 builds shared at once, and each tester can use up to 30 devices.

Internal testers can install a build as soon as it has processed. External testing needs the first build you add to a group to pass TestFlight App Review, and later builds are sent for review automatically when you add them. Public links can have tester criteria, such as device type and OS version, so only suitable testers can join.

What is a TestFlight code?

A TestFlight code is a redemption code from a developer's email invitation. You enter it under Redeem in the TestFlight app when you can't open the invitation link on the device itself; Apple documents this for Apple TV. There's no public directory of TestFlight codes. A code or public link only ever comes from the developer running the beta, so be wary of lists of "TestFlight codes" passed around online, especially for apps you can't find on the App Store.

2.3 Ad Hoc distribution

Ad Hoc installs a build directly onto devices you've registered in your developer account, with no App Review and no TestFlight. It suits hardware testing and client demos on a known set of devices.

The limit is 100 devices per product family per membership year (100 iPhones, 100 iPads and so on). Disabling a device during the year doesn't give the slot back. When the membership renews, Account Holders, Admins and App Managers can remove devices and restore the count to 100. Each device's UDID has to be collected and registered before you build.

TestFlight suits almost every beta better. Ad Hoc is useful when a tester can't install TestFlight, or when a build shouldn't be sent to App Review.

2.4 Custom apps (Apple Business and Apple School Manager)

A custom app is made for specific organisations and never appears on the public App Store. You choose Private under App Distribution Methods in App Store Connect and enter each organisation's ID. Once Apple approves the app, it shows up in the Custom Apps section of that organisation's Apple Business or Apple School Manager account. Their IT team then deploys it through Mobile Device Management (MDM) or with redemption codes.

Custom apps still go through App Review, so provide sample data and a login if the app holds sensitive information. Choose Public or Private before the app is approved, because Apple only offers the option until then. This is the right route for most B2B apps, and for proprietary apps you use inside your own organisation.

2.5 Unlisted apps

An unlisted app is on the App Store but doesn't appear in search, charts, categories or recommendations. People install it through a direct link, and organisations can also get it through Apple Business and Apple School Manager. You request unlisted distribution from Apple, and the app goes through the normal App Review.

Unlisted suits apps with a limited audience that doesn't need device management, such as a members' app or an event app. Anyone with the link can install it, so it isn't a security boundary.

2.6 Apple Developer Enterprise Program

The Enterprise Program lets a large organisation distribute proprietary apps to its own employees outside the App Store, with no App Review. Apple restricts it to use cases the App Store, custom apps and TestFlight can't meet. To qualify, an organisation must:

• have 100 or more employees,

• be a legal entity (Apple doesn't accept trading names, DBAs or branches),

• use the program only for internal apps distributed to employees,

• have systems that stop anyone except employees downloading them, and

• pass Apple's verification interview and ongoing evaluation.

The fee is 299 USD a year. Distributing to customers or the public breaks the terms, and Apple can revoke the certificate, which stops every app signed with it from launching.

2.7 Alternative distribution: EU, Japan and Brazil

In three regions, iPhone users can get apps from outside the App Store.

• EU: under the Digital Markets Act, you can distribute through alternative app marketplaces or directly from your own website (Web Distribution). Web Distribution requires Apple's authorisation, a domain registered in App Store Connect and one of Apple's eligibility criteria. It works on devices running iOS 17.5 or iPadOS 18 or later. From 1 October 2026, you no longer need an EU legal entity to use it.

• Japan: from iOS 26.2, under the Mobile Software Competition Act, with alternative app marketplaces and payments outside In-App Purchase.

• Brazil: from iOS 26.5, following an agreement with the competition regulator CADE, with the same two options.

Apple still checks these apps. Each one has to pass Notarization, a lighter check focused on security and integrity, and needs a developer account, signing and an age rating. For most UK businesses the App Store is still the practical route. Alternative distribution is worth weighing when a large share of your users are in one of these regions and you want to reach them outside the App Store.

Part 3: How do you choose the right iOS distribution method?

Start with who the app is for, then whether it's a test or a release.

• The general public: the App Store. In the EU, Japan or Brazil you can add alternative distribution.

• Beta testers before launch: TestFlight, or Ad Hoc for a handful of registered devices.

• Specific client organisations (B2B): a custom app.

• A limited group you can reach with a link: an unlisted app.

• Your own staff: a custom app for your organisation, or the Enterprise Program if you have 100+ employees and a use case the other routes can't meet.

In our experience, most organisations that think they need the Enterprise Program don't. A custom app deployed through MDM covers nearly every internal use case, and it can't be switched off by a certificate revocation.

How do the seven methods compare?

Distribution method Audience / capacity Best for App review Commission Key limitation
Public App Store Unlimited, global reach Public consumer apps Full App Store review 15-30% Public visibility
TestFlight 10,000 external testers Beta testing TestFlight App Review (external testers) None 90-day build expiry
Ad Hoc 100 devices/year Hardware testing, client demos None None UDID registration required
Custom Apps Specific organisations (unlimited users) B2B / enterprise Full App Store review Standard Private distribution only
Unlisted App Anyone with the link (unlimited) Limited audiences Full App Store review Standard Link-controlled access
Enterprise (ADEP) Employees only Internal enterprise use None None (299 USD/year) Strict eligibility
Alternative distribution EU, Japan and Brazil users only Selling outside the App Store in those regions Notarization Regional terms Regional only; Apple authorisation needed

Part 4: App Store Connect, the distribution hub

4.1 What is App Store Connect?

App Store Connect is Apple's web portal for everything after the build: app records, metadata, TestFlight, pricing and availability, review submissions and sales reports. You upload builds to it from Xcode, Transporter or a CI pipeline.

4.2 Creating an app record

Before the first upload you create an app record. It needs:

• the platform (iOS, iPadOS, macOS, tvOS or visionOS),

• the app name (2 to 30 characters),

• the primary language,

• the Bundle ID, which is registered in your developer account and can't be changed later, and

• a SKU, an internal reference that only you and Apple see.

4.3 App Store listing: what each metadata field does

• Name (30 characters): your most valuable search field. Brand first, then a keyword if it fits.

• Subtitle (30 characters): shows under the name and is used for search. Use it for a second keyword or a clear benefit.

• Promotional text (170 characters): sits above the description and can be changed without a new version.

• Description (4,000 characters): written for people deciding whether to download. The first three lines matter most.

• Keywords (100 characters): comma-separated search terms. Don't repeat words from the name or subtitle.

• Screenshots and app previews: the biggest influence on whether someone downloads.

For iOS 27, Apple added new product page headers and search result assets, and says a product page preview tool is coming to App Store Connect. Check them before your next release.

4.4 What does "Ready for Distribution" mean in App Store Connect?

Ready for Distribution means Apple has accepted your app version and released it for distribution, which is normally when it becomes available on the App Store. Apple's definition is "Your app has been accepted and is ready for distribution. To distribute your app, your agreements must be in effect." Apple used to call this status "Ready for Sale".

If the status is Ready for Distribution and you still can't find the app:

• Your agreements aren't in effect. Only the Account Holder can accept the latest agreements, in the Business section of App Store Connect.

• It's a custom or unlisted app. It will never appear in search. People reach it through Apple Business, Apple School Manager or its link.

• The store hasn't caught up. A newly released version can take a while to appear everywhere.

After approval you may see one of these statuses instead, in Apple's words:

• Pending Developer Release: "Your app was accepted, but you still need to release it for distribution on the App Store." You chose manual release, so release it yourself.

• Processing for Distribution: "Your app is processing and will be ready for distribution within 24 hours."

• Pending Apple Release: Apple "is holding your app version until the corresponding Apple operating system version releases to the public". This happens when a build needs an OS that isn't out yet, which is worth knowing while iOS 27 rolls out.

• Ready for Distribution with "Phased Release": the update is reaching users over seven days (see 6.2).

Before approval, the statuses you'll see most are Prepare for Submission, Waiting for Review, In Review and Rejected.

Part 5: The App Review process

5.1 What does App Review check?

App Review checks your app against the App Review Guidelines, which fall into five sections:

1. Safety: objectionable content, user-generated content moderation, kids' apps and physical harm.

2. Performance: the app must be complete and work, with accurate metadata and no placeholder content (guideline 2.1).

3. Business: In-App Purchase rules, subscriptions and advertising (guideline 3.1).

4. Design: quality, minimum functionality and spam. Guideline 4.2 asks for "features, content, and UI that elevate it beyond a repackaged website".

5. Legal: privacy, data collection, intellectual property and local law (guideline 5.1).

5.2 How long does App Store review take in 2026?

Apple says that "on average, 90% of submissions are reviewed in less than 24 hours". Apps that touch sensitive guidelines, or that need a reviewer to sign in, can take longer. Allow extra time around major OS launches in September and over late December, when many teams submit at once.

You can ask for an expedited review for a critical bug fix (include steps to reproduce the bug in the live version) or for an app tied to a dated event.

5.3 What are the most common App Store rejection reasons?

From the apps we submit for clients, first-submission rejections are usually mundane:

• Guideline 2.1, App Completeness: crashes, broken links, placeholder content, or a reviewer who can't get past the login. Always put a working demo account in the App Review notes.

• Guideline 3.1.1, In-App Purchase: digital content or features sold outside Apple's system, or subscriptions set up wrongly in App Store Connect.

• Guideline 5.1.1, Data Collection and Storage: a missing or vague privacy policy, or App Privacy answers that don't match what the app collects.

• Guideline 4, Design: layouts that are hard to use, especially on iPad if you support it.

• Metadata: screenshots that don't show the real app, or claims the app can't back up.

Guideline 4.2 (minimum functionality) and 4.3 (spam) rejections do happen, but in our experience they're much rarer than the five above. If your app is in a crowded category such as dating, flashlight, wallpaper or simple timers, read 4.3(b) closely: Apple won't accept new ones unless they offer a meaningfully different or improved experience, and says it may remove existing ones that aren't updated, improved or attracting customers.

If you're rejected, read the message in full. Reply in App Store Connect if it's unclear, and fix and resubmit if it's clear. If you believe the reviewer got it wrong, you can appeal to the App Review Board.

Part 6: How do you manage iOS app updates?

6.1 Version numbers and build numbers

The version number (CFBundleShortVersionString, for example 2.4.1) is what users see. The build number (CFBundleVersion) must be unique and higher than the previous build for every upload. Version 2.4.1 might go through builds 100, 101 and 102 before one ships.

6.2 Phased release

Phased release rolls an update out to users with automatic updates over seven days: 1%, 2%, 5%, 10%, 20%, 50%, then 100%. You can pause for up to 30 days, as many times as you need, which buys time to fix a bug before everyone has the update. Anyone can still download the new version manually from the App Store. We use phased release on every significant update to a production app.

6.3 Emergency fixes

For a crash or security problem in the live version, upload the fix, submit it, and then request an expedited review with the steps to reproduce the bug. Be specific about the impact on users. Apple decides case by case.

Part 7: Enterprise and business app distribution

7.1 Custom apps or the Enterprise Program?

Use a custom app when:

• you're distributing to client organisations (B2B),

• the app is for your own staff and App Review is acceptable, or

• IT wants to push the app silently through MDM.

Use the Enterprise Program only when all of these are true:

• the app is for your own employees only,

• you have 100 or more employees, and

• there's a documented reason the app can't go through App Review or be distributed as a custom app.

7.2 Mobile Device Management (MDM)

MDM is how organisations install, update and control apps on company devices. IT teams use it to install apps silently, enforce passcodes and encryption, and wipe lost devices. Common platforms include Jamf, Microsoft Intune, Kandji and Omnissa Workspace ONE. The choice usually follows the company's existing IT setup. If you're building an app that will be deployed this way, test it on an MDM-enrolled device before launch.

Part 8: Distributing Flutter and other cross-platform iOS apps

To Apple, a Flutter or React Native app is an iOS app. It uses the same signing, TestFlight, App Review and distribution methods as one written in Swift. The differences are in tooling:

• Build: Flutter produces the archive with flutter build ipa. The result is a standard iOS build that you upload like any other.

• SDK deadlines apply to you too. The iOS 26 SDK rule from April 2026, and the iOS 27 rule from April 2027, mean your Xcode version and your framework's iOS toolchain both have to be current.

• Privacy manifests: every plugin that ships native iOS code needs a correct privacy manifest.

• No exemptions: cross-platform apps are reviewed under exactly the same guidelines.

For more on this, see our Flutter app development and native iOS app development services, and our guide on how to create an iOS app.

Part 9: Common iOS distribution problems and fixes

9.1 My iOS distribution certificate is expiring. What happens?

If your membership is current, an expired App Store distribution certificate doesn't affect apps already on the App Store. It only stops you uploading new builds signed with it. Create a new certificate, update your profiles, and re-sign. Enterprise certificates are different: when one expires or is revoked, apps signed with it stop working, so renew well before the date.

9.2 "Missing private key" on a distribution certificate

The certificate is in your keychain, but the private key that created it isn't on this Mac. That usually means it was made on someone else's machine. Either export the certificate with its key (a .p12 file) from the Mac that created it, or revoke it and create a new one. On teams, keep signing identities in one managed place, such as fastlane match or your CI's secure storage, so this stops happening.

9.3 "Provisioning profile doesn't include the entitlement"

The app uses a capability, such as push notifications or Sign in with Apple, that isn't enabled on its App ID. Enable it under Identifiers in your developer account, then regenerate and download the profile. Xcode's automatic signing usually does this for you.

9.4 TestFlight problems

• Build not showing: it's still processing, or it's waiting for export compliance (encryption) information before testers can get it. Check the build's status in App Store Connect.

• External testers can't see it: the build is waiting for TestFlight App Review, or it hasn't been added to their group.

• Testers can't install: their device is below the build's minimum iOS version, they don't meet the public link criteria, or the build has passed 90 days.

Part 10: Keeping an iOS app live for the long term

10.1 App Store Optimisation (ASO)

ASO is SEO for the App Store. The fields Apple uses for search are the name, subtitle and keywords. Downloads are driven by the icon, screenshots, preview video and ratings. We'd review it every quarter.

10.2 Privacy and age ratings

Three things have to be right on every submission in 2026:

• App Privacy details in App Store Connect, describing every type of data the app collects and whether it's linked to the user.

• Privacy manifests (PrivacyInfo.xcprivacy) in your app and in each third-party SDK that uses sensitive APIs, with an approved reason for each.

• The age rating questionnaire. Apple added 13+, 16+ and 18+ to the 4+ and 9+ ratings in July 2025, with answers to the new questions required from 31 January 2026. The questionnaire covers in-app controls, medical and wellness topics and violence. Since July 2026 it also asks about social media features, which feed the new Time Allowances parental controls in iOS 27. Those answers are required for new apps, updates and notarization submissions from September 2026. Apps rated 18+ face adult checks in Australia, Brazil and Singapore.

10.3 Automating builds and releases

If you release often, automate signing, building and uploading. Your options are Xcode Cloud (Apple's own), fastlane (open source, with match for signing and pilot for TestFlight), or scripts around xcodebuild and the App Store Connect API running on GitHub Actions, Bitrise or Codemagic. The first setup takes a day or so. After that, a release is one command, and nobody has to remember which certificate is current.

10.4 Plan for Apple's calendar

Apple announces new OS versions at WWDC in June, ships them in September, and makes the new SDK compulsory for uploads the following April. Budget for that cycle every year. Apple also removes neglected apps: under its App Store Improvements policy, an app that hasn't been updated in three years and is downloaded very rarely gets an email and 90 days to submit an update. An app that crashes on launch is removed straight away. If you'd like someone to handle releases, SDK updates and review problems for you, that's what our App Care support and maintenance service does. Get in touch to talk it through.

Part 11: Frequently asked questions

What is the cheapest way to distribute an iOS app?

TestFlight. It's included in the 99 USD a year Apple Developer Program and reaches up to 10,000 testers. Public App Store distribution costs the same membership plus Apple's commission on paid apps and in-app purchases. There's no free way to distribute an iOS app publicly.

Can I distribute an iOS app without an Apple Developer account?

No. A free Apple Account lets you run a build on your own device from Xcode, but every distribution method here, including Ad Hoc and TestFlight, needs a paid membership. In the EU, alternative distribution also needs a membership, because apps still have to pass Notarization.

How long does App Store review take in 2026?

Apple says 90% of submissions are reviewed in less than 24 hours on average. Apps that need a login, use sensitive features or are submitted during busy periods can take a few days.

What does "Ready for Distribution" mean?

Apple has accepted the version and released it for distribution, so it's normally live. If you chose manual release, you'll see Pending Developer Release instead until you release it. If a Ready for Distribution app still isn't visible, check that the Account Holder has accepted the latest agreements and whether it's a custom or unlisted app.

What is the difference between TestFlight and Ad Hoc?

TestFlight reaches up to 10,000 external testers by email or link, handles installs through the TestFlight app, and needs a light review for external builds. Ad Hoc needs each device's UDID registered in advance, is capped at 100 devices per product family a year, and needs no review. TestFlight is the better choice for almost every beta.

Can I use the Enterprise Program to distribute to customers?

No. It's only for proprietary apps used by your own employees. Distributing to customers breaks Apple's terms and can get the certificate revoked, which stops every app signed with it from working. Use a custom app or an unlisted app instead.

Can I distribute an iPhone app outside the App Store?

Yes, in the EU, Japan and Brazil, through alternative app marketplaces, and in the EU from your own website with Apple's authorisation. Apps still need a developer account and must pass Notarization. Everywhere else, outside the App Store means Ad Hoc, custom apps or the Enterprise Program, none of which reach the general public.

What happens when a TestFlight build expires?

After 90 days testers can no longer install or open the build. Upload a new build to keep testing. Testers who were invited can keep testing a build after it goes live on the App Store, until it expires.

Meet our CTO, Gareth. He has been involved in mobile app development for over 25 years. Gareth is an experienced CTO and works with many startups

We'd love to show you how we can help

Get in Touch  

Latest Articles

All Articles