How It Works Pricing Blog Docs Login Sign Up
Guide

Missing Compliance in TestFlight: what it means and how to fix it for good

Every new build shows Missing Compliance until you answer Apple's encryption questions. Two lines in your Info.plist answer them once, for every build after.

By Martin Lasek · Oct 8, 2026 · 4 min read

Missing Compliance in TestFlight

The short answer

Missing Compliance means App Store Connect doesn't know yet whether your build uses encryption, which US export law asks about. To fix one build, open it in the TestFlight tab, click Manage and answer the questions. To fix it for every build, add the key ITSAppUsesNonExemptEncryption to your Info.plist: set it to NO if your app only uses encryption built into iOS, like HTTPS, and YES if it uses other encryption, which can also mean uploading documents.

Why Apple asks about encryption

"When you submit your app to TestFlight or the App Store, you upload your app to a server in the United States. If you distribute your app outside the U.S. or Canada, your app is subject to U.S. export laws, regardless of where your legal entity is based."

Apple, Complying with encryption export regulations, accessed October 8, 2026

So every new build needs an answer. Until it has one, App Store Connect marks it Missing Compliance, which Apple's TestFlight help describes as the state you avoid by specifying "encryption use for your build".

Fix it for one build

  1. Open your app in App Store Connect and switch to the TestFlight tab.
  2. In the sidebar under Builds, click the platform, for example iOS.
  3. Find the build marked Missing Compliance and click Manage next to it.
  4. Answer the encryption questions and click Save. If documents are required, App Store Connect sends you to the App Encryption page to upload them.

That works, but you'll answer the same questions again with the next build.

Fix it for every build

"If you don’t have the ITSAppUsesNonExemptEncryption key in your app’s Info.plist file, App Store Connect walks you through an export compliance questionnaire every time you upload a new version of your app. Including the key streamlines the app submission process."

Apple, ITSAppUsesNonExemptEncryption, accessed October 8, 2026

Add the key to your app's Info.plist, or to the Info tab of your app target in Xcode. For an app that only uses encryption built into iOS, the value is NO:

1 <key>ITSAppUsesNonExemptEncryption</key>
2 <false/>

The next build you upload carries its answer, so App Store Connect doesn't ask again. The key covers your whole app, including third-party SDKs: Apple's definition of NO is that your app, "including any third-party libraries you link against", uses no encryption or only exempt encryption.

NO or YES: is your encryption exempt?

Apple's documentation splits apps into three cases:

Missing Compliance and export compliance paths: encryption built into iOS like HTTPS with URLSession needs no documents and ITSAppUsesNonExemptEncryption NO, a standard algorithm not provided by Apple's OS needs a French declaration if sold in France, a proprietary algorithm needs CCATS

Apple gives HTTPS through URLSession as the typical example of encryption built into the operating system, which is exempt from uploading documents, while proprietary encryption is not. Two things to keep in mind:

  1. The decision is yours. Apple's overview says you're "responsible for all liabilities associated with misinterpretation of export regulations or claiming exemption inaccurately". If you're unsure whether a library brings its own encryption, answer the questions in App Store Connect, which tell you which documents you need.
  2. Exempt doesn't always mean nothing to do. Apple notes that apps using exempt encryption might instead need to submit a year-end self-classification report to the US government.

When you need documents

If your app uses a standard algorithm that iOS doesn't provide, Apple asks for a French encryption declaration, and only if you distribute the app in France. Proprietary algorithms, ones not accepted by standards bodies like IEEE, IETF or ITU, also need a US classification called CCATS.

  1. Upload them in App Store Connect, under App Information, App Encryption Documentation. Apple asks you to fill in the app description and availability first, so it can judge the documents.
  2. Wait for Apple's review. With complete information, Apple "expects to review and clear apps in approximately two business days".
  3. Add the code to Info.plist. Apple gives you a key value next to the approved documents. It goes into a second key, so future builds need no questions:
1 <key>ITSAppUsesNonExemptEncryption</key>
2 <true/>
3 <key>ITSEncryptionExportComplianceCode</key>
4 <string>the value from App Store Connect</string>

Then test and ship

With compliance answered, the build is ready for TestFlight testing, and the key also answers the encryption questions App Store Connect asks when you submit a version for review. It's one of the small stops in publishing an app on the App Store. And once testers are in, WishKit gives them a place inside the beta to request and vote on features.

Frequently asked questions

What does Missing Compliance mean in TestFlight?

App Store Connect needs to know whether the build uses encryption, because apps uploaded to Apple's US servers fall under US export law. Until you answer, the build is marked Missing Compliance.

How do I fix Missing Compliance?

Click Manage next to the build in the TestFlight tab and answer the questions. To stop it for future builds, add ITSAppUsesNonExemptEncryption to your Info.plist.

Does HTTPS count as encryption?

It is encryption, but Apple names HTTPS through URLSession as typically exempt from uploading documents, because it's built into the operating system.

Should ITSAppUsesNonExemptEncryption be YES or NO?

NO if your app, including its third-party libraries, uses no encryption or only exempt encryption. YES otherwise, usually together with ITSEncryptionExportComplianceCode once Apple approves your documents.

Do I have to answer the questions for every build?

Only without the Info.plist key. With it, App Store Connect takes the answer from your build.

How long does Apple take to review encryption documents?

About two business days with complete information, according to Apple. Reviews are case by case.

Ready to build the features users pay for?

Setup takes less than a minute. Free plan included, no credit card required.

Try WishKit for free