Software vendor continuity plan for app owners in 2026

“”

Contents

  1. TL;DR
  2. How often the vendor actually disappears
  3. Three 2026 deadlines that do not wait for your vendor
  4. How we built this checklist
  5. Continuity controls at a glance
  6. Contract clauses that survive the vendor
  7. Accounts and keys that must sit in your name
  8. Documentation a stranger can act on
  9. Source code escrow, and when it is theatre
  10. Which controls fit your product
  11. What our own portfolio says about inheriting code
  12. The continuity test that predicts survival
  13. Your vendor holds the keys? Get a continuity checklist before the next renewal
  14. Frequently asked questions
  15. Sources

TL;DR

A software vendor continuity plan is the set of contract terms and account controls that keep your app shippable when the company building it stops answering. Buyers audit price and portfolio in 2026, and never audit what happens the day the vendor stops existing. These controls are free at signature and costly later.

  • In the US sector that holds software firms, 50.7% of establishments opened in the year to March 2019 were still open five years later.
  • A lapsed Apple Developer Program membership pulls your app from download, and only the current Account Holder can pass that role on.
  • One control returns a pass or a fail: a stranger ships a release from your documentation alone.

How often the vendor actually disappears

Ask a vendor for references and you get their happiest clients. Ask what happens if they stop existing, and the room goes quiet.

The base rate is public. The Bureau of Labor Statistics tracks establishment survival by opening year. In professional and technical services, the sector holding software firms, 50.7% of those opened in the year to March 2019 were still open in March 2024. Of the March 2015 cohort, 34.3% survived a decade.

So a ten year product has better than even odds of outliving its builder. Bankruptcy is the rare version; the common one keeps trading and stops answering.

Three 2026 deadlines that do not wait for your vendor

Your app keeps its own calendar, and it does not pause while you find a new team.

Google Play requires new apps and updates to target Android 16, API level 36, from August 31, 2026, with extensions to November 1, 2026. Apple has required since April 28, 2026 that anything uploaded to App Store Connect is built with Xcode 26 and an iOS 26 SDK. Miss either and you cannot ship, hotfixes included.

Apple's App Store Improvements process flags apps untouched for three years that also miss a download threshold, then allows up to 90 days to respond. Roughly 2.8 million apps went in six years. In June 2026 Apple went further: published apps in crowded categories may be removed if they are not updated, improved or attracting customers.

An app without a vendor does not fail loudly. It ages out.

How we built this checklist

One test for every control below: what breaks in the first 30 days after the vendor stops answering, and can you repair it without them.

  • Can you obtain the current source without their cooperation?
  • Can a replacement team ship to both stores from documentation alone?
  • Is the personal data recoverable once the relationship ends?

Mercury Development is a vendor, so every control here is one a client should apply to us. Several exist because we have rebuilt what somebody else failed to hand over.

Continuity controls at a glance

ControlWho must hold itWhat breaks inside 30 days
Source repositoryYour org accountNo code, no build
Apple Developer ProgramYour legal entityApp leaves the store when membership lapses
Google Play accountYour legal entityNo updates, no transfer
Signing keysYour secret storeNo update users can install
Domain and DNSYour registrar loginBackend unreachable, deep links dead
Data return clauseYour contractPersonal data stranded with a dead company

Contract clauses that survive the vendor

Contracts describe how work starts in detail. Continuity lives in the paragraphs about how it ends.

  • Intellectual property assigns on payment, not on final acceptance. Transfer at project close means an abandoned project leaves you owning nothing.
  • Named triggers. Escode, the NCC Group escrow business, gives bankruptcy and administration plus breach of maintenance as the standard release conditions. Put that list in the development contract, not only in an escrow schedule.
  • Transition assistance in hours. A fixed number of paid handover hours owed after termination, whoever ended it and why, plus a survival clause naming what outlives the contract.
  • Data return on exit. GDPR Article 28(3)(g) makes a processor delete or return all personal data at the controller's choice once services end. For protected health information in the US, 45 CFR 164.504 is harder: return or destroy at termination, retain no copies.
  • A tested exit plan, which EU financial firms have owed since DORA applied on January 17, 2025.

Now the clause nobody expects. Europe wrote a switching regime for cloud and left development contracts outside it. The Data Act applies from September 12, 2025, caps switching notice at two months and the transition at 30 calendar days, and bans switching charges from January 12, 2027. Your vendor is not a data processing service, so copy the shape of it yourself.

Accounts and keys that must sit in your name

Here is where fitness and wellness products are quietly exposed. Code ownership is drafted properly and the accounts sit on the vendor's credit card.

The Apple Developer Program costs $99 per membership year. When it expires, Apple says your apps are no longer available for download and you cannot submit updates, while installed copies keep running. A vendor who stops paying that invoice takes your product off sale.

Apple's app transfer starts with the Account Holder of the account that holds the app, and the Account Holder role moves only when that person passes it on, with Apple Developer Support required if they have died. Play transfers need the registration transaction ID from both accounts, both accounts active, and a request from the original owner.

Even a friendly move costs you: an Apple Pay merchant ID does not travel with the app, Wallet passes go inactive, and keychain sharing breaks once the app is rebuilt under a new team ID, forcing every user to log in again.

Hold the root of each account and invite the vendor in as a member: both stores, the registrar, DNS, cloud billing, the repository, the payment processor. Keep a quarterly register of signing keys, push keys, third party API keys and root cloud credentials. Can you produce all of it today without emailing the vendor?

Documentation a stranger can act on

Documentation fails predictably. It describes the product and skips the machine that produces it. Aim at one bar: a new engineer goes from a clean laptop to a signed build using only what sits in your repository. That means a runbook with exact tool versions, an environment map naming the source of each secret, the release procedure for both stores with named approvers, and a register of dependencies and accounts with an owner per line.

Source code escrow, and when it is theatre

Escrow is a three way agreement: you, the vendor, and a neutral agent holding the source until a named condition releases it.

Codekeeper puts agents at $89 a month for Software-Escrow.com, $179 for its own plans, $275 for Escrow London and $375 for PRAXIS, with verification sold separately. Verification is where escrow earns or wastes the money. An unrebuilt deposit is a zip file with a legal opinion attached, and Escode warns that verification testing still cannot guarantee everything needed to maintain an application was captured.

Opinion: for a mobile product on a live release cycle, escrow is often the wrong shape. A quarterly deposit is three months stale, and what you need at 2am is a shippable build. A mirror you own, pushed on every merge, plus one rebuild drill a year, costs less and covers more.

Which controls fit your product

Nobody needs all of it at once. Sequence by what you lose first.

Consumer fitness apps start with accounts and keys. The exposure is a store account you do not control and a subscription flow wired to the vendor's credentials.

Connected hardware adds firmware to the deposit. A companion app is recoverable in weeks. A firmware signing chain, a calibration tool, a build environment for an embedded target: those take quarters, if at all.

Studio and franchise software is exposed on data rather than code. Ask where member records live and how a full export is produced without a support ticket. Operators who left a previous platform usually left over exactly this.

What our own portfolio says about inheriting code

Mercury Development has delivered over 1,500 mobile applications since 1999. Fifteen are published as case studies, which is what we counted.

Five of them began with somebody else's code: a legacy Windows 8 application inside the Fitbit engagement that started in 2011, an in-house iOS app picked up for Kensington, legacy Mac and Windows support that became the primary developer role at MiMedia, a media player already shipped by FireCore, and configuration software for Element Labs and Barco handed over by an earlier vendor with no source code.

The oldest, the claims platform for Precision Practice Management, has run since 2006, now on its fourth major release.

The continuity test that predicts survival

The question buyers ask is the wrong one. "Do you have a business continuity plan?" gets a yes and a PDF from every vendor alive.

Ask for a drill instead. In a quarter when nothing is wrong, send one email requesting four things inside five business days:

  1. An archive of the current source from the main branch
  2. The app signing keys and distribution certificates
  3. An export of the DNS zone
  4. The build runbook as it stands today

A vendor with real continuity answers in a day, because none of it has to be created first. A vendor without it sends a meeting invitation.

Continuity is a state of your accounts, never a document about them. Only a vendor who already handed you the keys passes a drill on a random Tuesday.

Written by Rob Devereaux, Chief Operating Officer at Mercury Development. Rob has run the firm's operations from Hudson, Ohio since 2019 and has over 20 years of operational and financial experience. The handover and continuity terms described here are the ones he negotiates into the firm's own contracts, and the engagement histories counted above come from the same records.

Your vendor holds the keys? Get a continuity checklist before the next renewal

You have the controls. What you may not have is the version that matches your contract and stack. Tell us what you run, who holds what today, and where you feel exposed. We will send back a checklist for your vendor.

Check your vendor exposure

Feel free to contact us and we'll respond as soon as possible.

Frequently asked questions

Sources