NITDA has given government institutions, software developers and technology service providers until the second quarter of 2027 to comply with a new national software quality regime that will make independent testing and certification mandatory before government software can be deployed, in one of the most significant regulatory overhauls of Nigeria’s public sector technology ecosystem.
The enforcement timeline was announced as the National Information Technology Development Agency (NITDA) unveiled the National Software Quality Assurance (SQA) Framework, a new regulatory framework that introduces mandatory third-party software testing, risk-based quality standards and licensing requirements for software testing organisations.
Signed by Kashifu Inuwa Abdullahi, Director-General of NITDA, under the authority of the NITDA Act 2007, the framework establishes national standards governing the design, development, testing and deployment of software across Federal Government institutions, regulated industries and Nigeria’s broader digital economy.
The agency said the phased implementation is intended to allow stakeholders sufficient time to prepare before enforcement begins in the second quarter of 2027.

A key provision of the framework requires all software projects developed for government institutions to undergo independent third-party testing and certification before they can be deployed.
Government software to require independent certification
A key provision of the framework requires all software projects developed for government institutions to undergo independent third-party testing and certification before they can be deployed.
Under the new rules, compliance with the certification process will also become a mandatory requirement for obtaining IT Project Clearance, effectively making software quality assurance a prerequisite for government technology projects.
According to NITDA, the new regime is designed to reduce costly software failures, strengthen cybersecurity, improve the reliability of digital public services and ensure greater value from government investments in information technology.
The agency said the framework seeks to improve public confidence in digital government platforms by ensuring software meets nationally defined standards for quality, security and interoperability before going live.
Software Testing: Three regulatory instruments unified
NITDA said the National Software Quality Assurance Framework consolidates three complementary regulatory instruments into a single national framework.
The National Software Development Guideline introduces structured software development life cycles, mandates secure coding practices based on the Open Web Application Security Project (OWASP), standardises software documentation and requires citizen-facing digital services to comply with Web Content Accessibility Guidelines (WCAG) 2.1 AA.
The National Software Testing Guideline establishes comprehensive testing requirements covering software functionality, cybersecurity, performance under peak demand and interoperability before deployment.
Meanwhile, the Software Testing Organisations Licensing (STOL) Guideline creates a licensing regime for independent Licensed Software Testing Organisations (LSTOs), which will be responsible for evaluating and certifying software before deployment.

According to NITDA, Class A systems, including core banking switches, national identity management platforms and power grid control software, will be subject to the most rigorous testing requirements, including enhanced cybersecurity assessments, penetration testing and specialised evaluation by accredited testing organisations.
Critical national systems face stricter oversight
The framework introduces a risk-based classification model that aligns software quality assurance requirements with the operational risks posed by different applications.
Software will be categorised into Class A for high-risk and critical national infrastructure, Class B for moderate-risk enterprise systems and Class C for lower-risk internal applications.
According to NITDA, Class A systems, including core banking switches, national identity management platforms and power grid control software, will be subject to the most rigorous testing requirements, including enhanced cybersecurity assessments, penetration testing and specialised evaluation by accredited testing organisations.
The agency said the tiered approach recognises that applications supporting critical national infrastructure require more stringent quality assurance than lower-risk systems.
NITDA targets stronger digital trust
Beyond improving software reliability, NITDA said the framework is expected to strengthen digital trust, protect taxpayer-funded technology investments and improve resilience against cyber threats.
The agency also expects the licensing of independent software testing organisations to stimulate a new segment of Nigeria’s technology industry by encouraging indigenous innovation, promoting international software quality standards and creating high-skilled employment opportunities.
NITDA added that the framework could enhance international confidence in software developed in Nigeria, helping local technology companies compete more effectively in global markets while attracting foreign direct investment.
“Quality is the foundation of digital trust. With this Framework, every software solution serving Nigerians whether built for government or the private sector will meet clear national standards for security, reliability, and interoperability,” Abdullahi said.
“This is how we modernise government technology and position Nigerian software to compete on the global stage.”
Industry given transition period before enforcement
Ahead of the 2027 enforcement deadline, NITDA said it will embark on nationwide stakeholder engagement and capacity-building programmes while commencing the accreditation of independent software testing organisations.
The agency also announced plans to issue an Expression of Interest (EOI) inviting qualified organisations to apply for licences as independent software testing bodies, giving technology companies time to prepare for the new regulatory requirements.
According to NITDA, the phased rollout is intended to provide government institutions, software developers and technology service providers with adequate time to align their software development and testing processes with the new national standards before compliance becomes mandatory in the second quarter of 2027.




























Home