Quick answer: Mobile app development in Malaysia usually runs through eight stages: discovery, planning and architecture, UX/UI design, development, testing, app store release, launch monitoring, and ongoing maintenance. A typical business app takes about 3 to 5 months to reach the App Store and Google Play, simple apps take 2 to 3 months, and complex platforms take 6 to 12 months. Budgets start around RM20,000 for a simple app and pass RM200,000 for complex ones, with maintenance adding roughly 15 to 20 percent of the build cost each year.
This guide walks through each stage the way a development team actually runs it: what happens, how long it takes, what you should receive, and what you need to approve before the next stage starts. It also covers the 2026 rules from Apple, Google and Malaysia’s PDPA that catch many first-time app owners out.
What mobile app development covers
Mobile app development is the work of planning, designing, building, testing and publishing software that runs on phones and tablets, plus the server side (the backend) that stores data and connects the app to payments, logins and your other systems.
There are three main ways to build an app:
- Native apps are written separately for each platform, in Swift for iOS and Kotlin for Android. They give the best performance and full access to device features, but you pay for two codebases.
- Cross-platform apps use one codebase for both platforms, most often Flutter or React Native. This suits most business apps and costs noticeably less than building twice.
- Progressive web apps (PWAs) are websites that behave like apps. They cost the least and need no app store approval, but they have weaker access to device features and less visibility than a store listing.
If you are still deciding, read native app vs hybrid app vs PWA before you brief anyone.
The process at a glance
|
Stage |
Typical duration |
Share of build budget |
Main output you approve |
|
1. Discovery and validation |
2 to 3 weeks |
8 to 12% |
Requirements document and MVP scope |
|
2. Planning and architecture |
1 to 2 weeks |
5 to 8% |
Platform choice, tech stack, milestone plan |
|
3. UX/UI design |
3 to 4 weeks |
15 to 20% |
Clickable prototype and final screens |
|
4. Development |
6 to 16 weeks |
35 to 45% |
Working builds at the end of each sprint |
|
5. Testing and QA |
2 to 4 weeks (overlaps development) |
10 to 15% |
Test report and user acceptance sign-off |
|
6. App store release |
1 to 2 weeks |
3 to 5% |
Live listings on the App Store and Google Play |
|
7. Launch and first 30 days |
4 weeks |
5 to 8% |
Crash, retention and review report |
|
8. Maintenance and growth |
Ongoing |
About 15 to 20% of build cost per year |
Update plan and feature roadmap |
The percentages are shares of the one-off build budget and move with the project. A booking app with a simple backend spends more of its budget on design. A fintech app spends more on architecture, security and testing.
Overall timelines by complexity:
|
App type |
Examples |
Typical time to launch |
|
Simple |
Information app, loyalty card, simple booking form |
2 to 3 months |
|
Medium |
Ecommerce, membership, booking with payments and user accounts |
3 to 5 months |
|
Complex |
Marketplace, on-demand delivery, fintech, live chat or video |
6 to 12 months |
Before you start: do you actually need an app?
An app is a bigger commitment than a website. You pay to build it, you pay to keep it working through every iOS and Android release, and people have to choose to install it. Before you start, check whether your goal needs an app at all.
An app usually makes sense when:
- Customers use your service repeatedly, for example weekly orders, bookings or account checks.
- You need device features such as push notifications, camera, GPS, biometrics or offline access.
- A loyalty or membership programme is central to your business.
- Staff in the field need a tool that works on patchy mobile data.
A mobile-friendly website or PWA is often the better first step when:
- Most visitors come once, for example to read, compare or enquire.
- Your main goal is new customers from Google, which apps cannot rank for in normal search results.
- The budget is under the simple-app range.
If a website fits better, a web design and development project or an ecommerce website will reach customers faster.
Stage 1: Discovery and validation
Goal: confirm the app is worth building and agree what goes into version one.
Most budget overruns start here, when a vague idea goes straight to design. Discovery turns the idea into a scope that designers, developers and testers can all work from.
What happens:
- Workshops with your team to define the business goal, for example “cut phone bookings by half” or “grow repeat orders”.
- A review of competing apps in Malaysia: their features, store ratings and the complaints in their reviews.
- User research. Even five or six short interviews with real customers show which features matter.
- A feature list sorted into must-have, should-have and later, so version one stays small.
- An early check of legal and platform constraints: personal data under the PDPA, payment rules, and whether Apple requires in-app purchase for what you sell.
Questions to settle before design starts:
- Who is the primary user, and what is the one task they must be able to finish?
- How will the app make money or save money: sales, subscriptions, bookings, or lower operating costs?
- Which languages does the app need? Many Malaysian apps need English and Bahasa Malaysia, and some also need Chinese.
- Which payment methods must work on day one?
- Which of your existing systems must it connect to, such as a POS, ERP, CRM or ecommerce platform?
What you should receive: a requirements document covering users, features, user flows, integrations and acceptance criteria. If you want to see what a good one looks like, use our mobile app documentation example and template.
Stage 2: Planning and architecture
Goal: choose how the app will be built so it can grow without a rebuild.
Key decisions:
|
Decision |
Options |
How to choose |
|
Platform approach |
Native, cross-platform, PWA |
Cross-platform for most business apps; native for heavy graphics, AR or deep hardware use |
|
Launch platforms |
iOS and Android together, or one first |
Launching both is common in Malaysia, where Android and iPhone users are both significant |
|
Backend |
Custom API (for example Node.js or Laravel), or a managed service such as Firebase |
Custom for complex business logic and integrations; managed services for faster, simpler builds |
|
Admin panel |
Custom dashboard or existing CMS |
Depends on who updates content, prices and orders |
|
Hosting |
Cloud provider and region |
Choose a region close to users for speed, and check where personal data will be stored |
Relative cost is a big factor in the platform choice. Building both platforms natively typically costs about 1.7 to 1.9 times a single native build, while one cross-platform codebase usually lands around 60 to 75 percent of the cost of two native apps.
What happens:
- Architecture diagram showing the app, backend, database and third-party services.
- Data model, covering what personal data you collect, where it is stored and who can access it.
- Security plan for logins (password, OTP, social login or biometrics), permissions and encryption.
- A milestone plan with sprint dates, demo dates and payment milestones.
What you should receive: a technical specification and a timeline you can hold the team to. Confirm in writing that you will own the source code, design files and app store accounts.
Stage 3: UX/UI design
Goal: make sure the app is easy to use before anyone writes code.
Changing a wireframe takes minutes. Changing a finished screen in code can take days, so design is where you should spend time on feedback.
UX work:
- User journeys for the main tasks, such as sign up, search, book, pay and reorder.
- Wireframes for every screen, starting in grey boxes, without colours or images.
- A clickable prototype you can test with real users before development.
UI work:
- Visual design that follows your brand, plus a small design system of colours, type, buttons and icons, so every screen stays consistent.
- Final screens for each state: empty, loading, error and success.
- Designs for different phone sizes, including smaller and cheaper Android devices.
Details that matter for Malaysian users:
- Language switching: Bahasa Malaysia text is often longer than English, so buttons and labels need room.
- Local formats: RM prices, Malaysian phone numbers (+60), addresses with postcodes and states.
- Familiar checkout: users are used to fast checkout in apps like Shopee, Grab and Touch ’n Go eWallet, so long forms feel slow.
- Accessibility: readable font sizes, enough colour contrast and touch targets large enough to tap.
One 2026 change for iOS: since 28 April 2026, apps uploaded to App Store Connect must be built with Xcode 26 and the iOS 26 SDK. Builds with that SDK pick up Apple’s new Liquid Glass look on standard controls by default, so designers and developers should check how native components now render.
For more on the design stage, see what is user experience and mobile-first design.
Stage 4: Development
Goal: turn approved designs into a working app and backend.
Most teams build in two-week sprints. At the end of each sprint you should get a demo and a test build on your own phone (through TestFlight for iOS and internal testing on Google Play). If you only see progress at the end, you lose the chance to correct direction cheaply.
App side (front end):
- Screens, navigation and animations from the approved designs.
- Login and account management.
- Push notifications for reminders, order updates and promotions.
- Offline handling so the app behaves sensibly on weak mobile data.
- Analytics and crash reporting, set up from the first build.
Backend:
- APIs that connect the app to the database and to your other systems.
- An admin dashboard for content, users, orders and reports.
- Integrations such as payment gateways, delivery partners, CRM, POS or accounting software.
Payments in Malaysian apps:
|
Payment method |
Why it matters |
|
FPX online banking |
Widely used for direct bank payments |
|
DuitNow QR and DuitNow transfers |
National real-time payment network |
|
Touch ’n Go eWallet, GrabPay, Boost |
Popular e-wallets, especially for smaller purchases |
|
Credit and debit cards |
Still expected, especially for subscriptions |
These are usually connected through a payment gateway such as iPay88, Razer Merchant Services, Billplz, senangPay or Stripe. Choose based on the methods you need, fees, settlement time and how well the gateway’s SDK works in apps.
Check the app store payment rules early. Apple requires in-app purchase for digital goods and services unlocked inside an iOS app, such as premium features or digital subscriptions. Physical goods and real-world services, such as retail orders, food delivery or clinic appointments, can use your own payment gateway. Getting this wrong is a common reason for rejection late in a project.
What you should receive: sprint demos, test builds, access to the code repository, and a record of what changed in each build.
Stage 5: Testing and quality assurance
Goal: find problems before your customers do.
Testing should run alongside development, not only at the end.
|
Test type |
What it checks |
|
Functional |
Every feature works as described in the requirements |
|
Device and OS |
Layout and behaviour across phone sizes, brands and OS versions |
|
Network |
Behaviour on slow, unstable or lost connections |
|
Payment |
Successful, failed, cancelled and refunded payments in sandbox mode |
|
Performance |
Launch time, screen load speed, battery and memory use |
|
Security |
Data storage, login flows, API access and encryption, often checked against the OWASP Mobile Application Security (MASVS) standard |
|
User acceptance (UAT) |
Your team and a few real users confirm the app works for real tasks |
Device coverage tip: test on at least one lower-priced Android phone as well as current flagship devices. Apps that feel fine on a new iPhone can be slow on the budget Android phones many customers use.
What you should receive: a test report listing issues found, fixed and accepted, and a UAT sign-off form. Do not approve release while any payment or login bug is still open.
Stage 6: App store release
Goal: get both store listings approved and live.
Plan at least one to two weeks for this stage, longer for a first-time developer account.
Apple App Store:
- The Apple Developer Program costs US$99 per year.
- Enrol under your company, not the developer’s account. Organisation enrolment requires a D-U-N-S number, which can take time to obtain, so start early.
- Apple says 90 percent of submissions are reviewed in less than 24 hours on average.
- According to Apple, over 40 percent of unresolved review issues fall under guideline 2.1, App Completeness: crashes, broken links, placeholder content and missing information.
- You must provide a working privacy policy link, a support link, and a demo login if the app requires sign-in.
- Apps that let users create an account must also let them delete it from inside the app.
Google Play:
- A Google Play developer account costs a one-time US$25 fee.
- Personal developer accounts created after 13 November 2023 must run a closed test with at least 12 testers who stay opted in for 14 continuous days before applying for production access. Organisation accounts are exempt, which is another reason to register the app under your company.
- From 31 August 2026, new apps and app updates must target Android 16 (API level 36) or higher.
- You must complete the Data safety form, describing what data the app collects and shares.
Store listing (app store optimisation):
- An app name and subtitle that include the main words people search for.
- Screenshots that show benefits, not just screens.
- A description that explains what the app does in the first two lines.
- Localised listings in Bahasa Malaysia if your users search in Malay.
Pre-submission checklist:
- Accounts registered under the company, with your team as admin
- Privacy policy published and linked
- Demo account ready for reviewers
- All placeholder text and images removed
- In-app purchase rules checked
- Data safety (Google) and privacy details (Apple) completed accurately
- Final build tested on real devices
Stage 7: Launch and the first 30 days
Goal: catch problems quickly and learn how people really use the app.
Consider a soft launch first, to staff, loyal customers or one city, before promoting the app widely. A small group finds the problems your testers missed without damaging your store rating.
Metrics to watch in the first month:
|
Metric |
What it tells you |
|
Crash-free users |
Stability. Fix any crash affecting a key flow immediately |
|
Day 1, day 7 and day 30 retention |
Whether people come back after installing |
|
Onboarding completion |
Where new users give up during sign-up |
|
Conversion on key actions |
How many users complete a booking, order or payment |
|
Store ratings and reviews |
What frustrates users, in their own words |
|
Uninstalls |
Whether churn follows crashes, notifications or a specific screen |
Tools such as Firebase Crashlytics and Google Analytics for Firebase cover most of this. If you already use GA4 for your website, see how to set up Google Analytics 4 so web and app data can be compared.
An app does not market itself. Plan how people will find it: links from your website, QR codes in store, social media ads and Google Ads campaigns that drive installs.
Stage 8: Maintenance and growth
Goal: keep the app working and improve it based on real use.
Launch is the start of the app’s life, not the end of the project. Apple and Google release major OS versions every year, and both stores raise their technical requirements on a schedule, as the 2026 Xcode 26 and Android 16 deadlines above show. An app that is not updated will eventually stop meeting store requirements.
Ongoing work includes:
- Compatibility updates for new iOS and Android versions and devices.
- Security patches and updates to third-party libraries and SDKs.
- Bug fixes from crash reports and user reviews.
- Server monitoring, backups and scaling as users grow.
- New features and A/B tests, prioritised from usage data.
Budget roughly 15 to 20 percent of the original development cost per year. Our guide to app maintenance cost breaks this down.
PDPA checklist for mobile apps
Apps collect far more personal data than most websites: phone numbers, locations, photos, payment details and sometimes fingerprints or face data. Malaysia’s Personal Data Protection (Amendment) Act 2024 came into force in phases during 2025 and raised the stakes:
- The maximum fine for breaching the data protection principles rose from RM300,000 to RM1,000,000, and the maximum prison term from two years to three.
- Biometric data is now classed as sensitive personal data.
- Data processors, such as outsourced developers and hosting providers, are now directly bound by the Security Principle.
- From June 2025, data controllers and processors must appoint a data protection officer, notify the Commissioner of personal data breaches as soon as practicable, and support data portability requests.
Build these into the app, not afterwards:
- Collect only the data the features need
- Clear consent screens and a privacy notice in the languages the app supports
- Permission requests (location, camera, contacts) asked at the moment they are needed, with a reason
- Encryption for data in transit and stored personal data
- Role-based access in the admin dashboard
- A way for users to access, correct and delete their data
- Logging that helps you detect and report a breach
This is not legal advice. Ask your legal adviser to review how your app handles personal data. For the website side, see how to make your website PDPA compliant in Malaysia.
How much does mobile app development cost in Malaysia?
|
App type |
Estimated cost |
Typical use |
|
Simple app |
RM20,000 to RM60,000 |
Information, basic tools, simple booking |
|
Medium app |
RM60,000 to RM200,000 |
Ecommerce, booking with payments, membership |
|
Complex app |
RM200,000 to RM1,000,000+ |
Marketplace, streaming, fintech, social |
|
Cross-platform business app |
RM80,000 to RM200,000 |
Most SME and corporate apps |
|
Hybrid app or MVP |
RM30,000 to RM80,000 |
Prototypes and early validation |
On top of the build, plan for third-party services, hosting, store fees and push notification services, which usually add around 5 to 10 percent, plus yearly maintenance. For the full breakdown of hourly rates, development hours and ways to reduce cost, read mobile app development cost in Malaysia.
Common mistakes that delay app projects
- Building everything in version one. Launch the smallest version that solves the main task, then add features based on usage.
- Skipping the prototype. Feedback on finished code is expensive. Test the clickable prototype first.
- Registering store accounts under the developer. If the relationship ends, you can lose control of your own app.
- Leaving payment rules to the end. Apple’s in-app purchase rules and gateway approval can push a launch back by weeks.
- Testing only on new phones. Many real users have older or cheaper Android devices.
- No budget after launch. Without updates, the app falls behind store requirements within a year or two.
- No launch plan. Downloads rarely arrive on their own. Plan how people will find the app.
How to choose a mobile app development company in Malaysia
Ask these questions before signing:
|
Question |
What a good answer looks like |
|
Can we see apps you built that are live in the stores? |
Links to real, downloadable apps, ideally in a similar category |
|
Who owns the source code, designs and store accounts? |
You do, stated in the contract |
|
How will we see progress? |
Sprint demos and test builds every one or two weeks |
|
How do you handle changes in scope? |
A written change request with cost and time impact before work starts |
|
What testing is included? |
A device list, payment testing, security checks and UAT |
|
How do you handle PDPA? |
Specific answers about consent, data storage and access control |
|
What happens after launch? |
A defined warranty period and a maintenance plan |
Red flags: a fixed price without any discovery, no live apps to show, store accounts registered to the agency, and quotes that leave out testing or the backend.
To compare options, see our list of top mobile app development companies in Malaysia. If you would like us to scope your idea, our mobile app development team builds iOS, Android, Flutter and React Native apps for Malaysian businesses.
Frequently asked questions
What are the stages of mobile app development?
Discovery and validation, planning and architecture, UX/UI design, development, testing, app store release, launch monitoring, and maintenance. Some teams merge stages and describe it as five to seven steps, but the work is the same.
How long does it take to develop a mobile app in Malaysia?
A simple app takes 2 to 3 months, a medium app with payments and user accounts takes 3 to 5 months, and a complex app takes 6 to 12 months or more.
How much does it cost to build an app in Malaysia?
Roughly RM20,000 to RM60,000 for a simple app, RM60,000 to RM200,000 for a medium app, and RM200,000 or more for a complex app, plus about 15 to 20 percent of the build cost each year for maintenance.
Should I build a native or cross-platform app?
For most business apps, cross-platform (Flutter or React Native) gives the best balance of cost and quality with one codebase. Choose native when the app relies on heavy graphics, AR or deep hardware features.
How long does App Store and Google Play approval take?
Apple says 90 percent of submissions are reviewed in less than 24 hours on average. Google Play reviews usually take a few days, but new personal developer accounts must first complete a 14-day closed test with at least 12 testers.
Should the app store accounts be under my company?
Yes. Register the Apple Developer and Google Play accounts under your company and add the developer as a team member. You keep control of the app if you change developers.
Can I use my own payment gateway instead of Apple in-app purchase?
For physical goods and real-world services, yes. For digital content or features unlocked inside the app, Apple generally requires in-app purchase.
Do I need to update my app after launch?
Yes. Apple and Google raise their technical requirements regularly, for example the Xcode 26 build requirement from April 2026 and the Android 16 target from 31 August 2026. Apps that are not updated eventually cannot be updated or reach new users.
The bottom line
A good app project is mostly decided before development starts: a clear scope, the right platform choice, a tested prototype and accounts registered in your name. Build in sprints you can see, test on the phones your customers actually use, plan for the 2026 store requirements, and budget for the years after launch.
Planning an app? Request a quote from our mobile app development team, and we will map your idea into a scope, timeline and budget.








