# AOSP

Source: https://ordergroup.co/glossary/aosp/
Last updated: 2026-10-10

> AOSP explained for teams that ship devices: what the Android Open Source Project contains, how it differs from Android with GMS and what you must build yourself.

[IoT & Devices](https://ordergroup.co/glossary/iot/)
4 min read

# AOSP

Android Open Source Project
Also known as: Android Open Source Project

Definition

AOSP (Android Open Source Project) is the open-source code base of the Android operating system, published by Google. Device makers can build their own Android variants from it. Google apps and services (GMS) are not part of AOSP and are licensed separately.

Cite this entry

Text
"AOSP". Order Group, Software glossary, 10 October 2026. https://ordergroup.co/glossary/aosp/
HTML
`<a href="https://ordergroup.co/glossary/aosp/">AOSP</a> - Order Group`

Reviewed by [Maciej Sułek](https://ordergroup.co/authors/maciej-sulek/), Co-founder & CTO
Last reviewed 10 October 2026

## How AOSP works

AOSP is the source code and documentation of Android, which Google makes available to anyone. Google describes it as a full, production-quality developer product, open for customization and porting. You can use it to create custom variants of the Android operating system for your own devices. The code covers the operating system itself, from the Linux kernel and the hardware abstraction layer to the Android framework, the runtime and the system apps.

Most of AOSP is licensed under Apache 2.0, which the project names as its preferred license. Exceptions are handled case by case; the Linux kernel patches, for example, are under GPLv2.

What AOSP does not contain is Google Mobile Services (GMS), which the documentation defines as a collection of Google apps and APIs that can be pre-installed on devices. Google Play belongs to that layer. A device is eligible for potential licensing of Google Play and GMS only when it is Android-compatible: it must meet the requirements of the Compatibility Definition Document (CDD) and pass the Compatibility Test Suite (CTS). Compatibility makes a device eligible; it does not grant the license automatically. So the Android on most consumer phones is AOSP plus GMS plus the manufacturer's own changes, while a device built on AOSP alone runs Android without Google's apps and services.

Google changed how it publishes the code. Since 2026, it publishes source code to AOSP in Q2 and Q4, and the android-latest-release manifest branch always points to the most recent release pushed to AOSP. Security fixes follow their own rhythm: the Android Security Bulletins come out on the first Monday of each month, and platform security fixes are merged into AOSP 24 to 48 hours after the quarterly bulletins in March, June, September and December.

## What AOSP means for your software

Building on AOSP gives you control over the whole system, and with it every job Google's layer normally does for a phone maker. Requirements for a team that plans its own AOSP-based system:

- App distribution is yours. Without Google Play, apps reach devices through your own store, a managed channel or [sideloading](https://ordergroup.co/glossary/sideloading/). Someone has to review apps, sign them and publish updates.
- Updates are yours. The fleet needs an [OTA update](https://ordergroup.co/glossary/ota-update/) backend, release keys, full and incremental packages and staged rollouts. AOSP gives you the update mechanism on the device; it does not give you the server.
- Security patches arrive on a schedule. Each monthly bulletin has to be assessed, and with source drops in Q2 and Q4 your own changes have to be merged onto a moving base. Plan who does that and how often.
- Board support is hardware work. Drivers, the kernel and vendor components come from the chip and board supplier. Without a maintained board support package, a new Android version may not reach your hardware.
- Fleet management may need to live in the system. On company devices you may need [MDM](https://ordergroup.co/glossary/mdm/) functions, network controls such as [deep packet inspection](https://ordergroup.co/glossary/deep-packet-inspection/) and remote wipe, and in a custom OS they can be built into the operating system rather than added as an app.
- The build needs serious hardware. Google lists at least 400 GB of free disk space to check out and build the code (250 GB for the checkout and 150 GB for the build) and at least 64 GB of RAM on 64-bit x86 Linux. A full build takes about 40 minutes on a 72-core machine and about 6 hours on a 6-core machine.

Writing the specification?

Add AOSP to your requirements checklist

Collect the terms your project touches and get their system requirements in one e-mail, ready for an RFP.

Android with GMS vs a system built on AOSP alone
AreaAndroid with GMSAOSP-based system

Google Play and Google appsAvailable after licensing GMSNot included; you need your own distributionCompatibilityDevice meets the CDD and passes CTSOptional; needed only if you seek GMS licensingUpdatesPhone maker ships them, built on Google's releasesYou build, sign and deliver every updateSecurity patchesPhone maker integrates the monthly bulletinsYou integrate them into your own code baseSystem changesLimited by compatibility requirementsAny change, including removing featuresLicenseApache 2.0 code plus GMS license termsMostly Apache 2.0; kernel under GPLv2

## Rules and standards

AOSP itself is a code base with licenses, not a regulation. A device that wants Google's apps has to follow the Android compatibility program: the CDD lists the hardware and software requirements, and CTS is a free test suite available as a binary or as source in AOSP. A device that does not seek compatibility can use the source for any legitimate purpose, but it is not part of the Google Play ecosystem. A connected device built on AOSP and placed on the EU market is also a product with digital elements, so the update obligations of the Cyber Resilience Act described under [OTA update](https://ordergroup.co/glossary/ota-update/) apply to it as to any other device.

## From our projects

From 2019 to 2021 we built RAW OS for [Raw Control](https://ordergroup.co/case-studies/raw-cyber-custom-android-os/), a hardened Android-based phone system built on CopperheadOS. Around the system we built a store with only pre-approved apps, packet inspection inside the operating system and device management with an administration panel.

Keeping a custom Android current was a project of its own. The project had an ongoing workstream for keeping RAW OS in line with Copperhead's changes and with new devices: syncing our repositories with Copperhead's and preparing and testing the system for new hardware. When Copperhead moved to Android 11, the team aligned the repositories, built Copperhead's Android in July 2021, fixed compilation errors when merging our changes into frameworks/base, Android's framework repository, and got the Settings app and a release build running in August. Our features then had to be moved to the new base and checked one by one, SIM card detection among them. We closed the task of running RAW OS on Android 11 in September 2021.

For Mudita, our engineers work on the App Store and the OTA platform around Mudita's phones. We did not build Mudita's operating system.

From our projects

[RAW Cyber - Secure Custom Android Operating System
How Order Group and RAW Cyber built a secure mobile operating system: a custom Android-based OS hardened with CopperheadOS for secure communications.](https://ordergroup.co/case-studies/raw-cyber-custom-android-os/)

Where to get it

- [Mudita](https://mudita.com/)
Mudita makes mindful-technology devices, including the Mudita Kompakt phone. We work on its App Store and OTA update platform.

## Related terms

- [Deep packet inspection](https://ordergroup.co/glossary/deep-packet-inspection/)

Deep packet inspection (DPI) is a method of network traffic analysis that reads packet contents, not only IP addresses and ports, to identify the protocol or application behind a flow, extract fields such as host names, and allow, block or log the traffic by policy.
- [MDM](https://ordergroup.co/glossary/mdm/)

Mobile device management
Mobile device management (MDM) is software that lets an organization enroll, configure, monitor, lock and wipe phones, tablets and other devices from a central console, by sending policies to an agent or to the management interface of each device's operating system.
- [OTA update](https://ordergroup.co/glossary/ota-update/)

Over-the-air update
An OTA (over-the-air) update is a software or firmware update that a device downloads and installs over a network, with no cable or service visit. FOTA is the firmware case. The package must be signed, verified on the device and recoverable when the installation fails.
- [Sideloading](https://ordergroup.co/glossary/sideloading/)

Sideloading is installing an app from a source other than the device's official app store, for example an APK file from a website, an email or a cable. Android asks for permission for each source, and a company that manages the device can block it with a device policy.

## Sources

1. [About the Android Open Source Project](https://source.android.com/docs/setup/about) - Android Open Source Project
2. [Android compatibility program overview](https://source.android.com/docs/compatibility/overview) - Android Open Source Project
3. [Content licenses](https://source.android.com/docs/setup/about/licenses) - Android Open Source Project
4. [Hardware and software requirements](https://source.android.com/docs/setup/start/requirements) - Android Open Source Project
5. [Android Security Bulletins overview](https://source.android.com/docs/security/bulletin/asb-overview) - Android Open Source Project

Maciej Sułek reviewed this entry. Ask how it applies to your project.

[Ask an engineer](https://ordergroup.co/contact-us/)

## FAQ

![Maciej Sułek](https://ordergroup.co/media/images/T02DHCC1Z-U04AVB19V-45105f88ff4a-512.format-webp.webp)

Maciej Sułek

Co-founder & CTO

[Talk to an engineer](https://ordergroup.co/contact-us/)

### Is AOSP the same as Android?

AOSP is the open-source base of Android. The Android on most phones is AOSP plus Google Mobile Services and the manufacturer's own changes. A device built on AOSP alone runs Android without Google's apps and services.

### Can I use Google Play on an AOSP device?

Only if the device is Android-compatible, meaning it meets the CDD and passes CTS, and Google licenses GMS for it. Otherwise you need your own way to distribute apps.

### Is AOSP free to use commercially?

The source code is open, and Google says anyone can use it for any legitimate purpose. Most of it is under Apache 2.0, and the kernel is under GPLv2. GMS and Google's apps are licensed separately.

### How often does AOSP get new code?

Since 2026, Google publishes source code to AOSP in Q2 and Q4. Security bulletins still come out monthly, and platform security fixes reach AOSP after the quarterly bulletins.

Building a system that depends on AOSP?

See how we build software for this domain, with case studies and the stack we use.

[See IoT & Device Software Development Services](https://ordergroup.co/iot-software-development/)

Requirements checklist

For each term we send the definition and what it requires from your software. Free, no sales call needed.
Your checklist is empty. Use the plus next to a term to add it.
