NITDA to license tech firms as software testing goes mandatory
The National Information Technology Development Agency (NITDA) will begin licensing technology firms to provide independent software testing services under a new regulatory framework that will make third-party certification compulsory for all Federal Government software projects from the second quarter of 2027.
The initiative, unveiled under the National Software Quality Assurance (SQA) Framework, is designed to standardise software development, reduce costly project failures, strengthen cybersecurity and improve public confidence in digital government services.
According to a statement issued by the agency’s Director of Corporate Communications and Media Relations, Mrs Hadiza Umar, the framework, signed by the Director-General of NITDA, Kashifu Inuwa Abdullahi, under the provisions of the NITDA Act 2007, will require all government software projects to undergo independent testing and certification before deployment as a prerequisite for obtaining IT Project Clearance.
NITDA said it would commence nationwide stakeholder engagements and capacity-building programmes ahead of the rollout while opening the accreditation process for Licensed Software Testing Organisations (LSTOs).
The agency disclosed that it would shortly issue an Expression of Interest (EOI) inviting qualified technology firms to apply for licences to operate as accredited software testing organisations.
According to NITDA, the licensing regime is expected to create a regulated market for independent software testing services, providing new business opportunities for indigenous technology firms while encouraging local companies to obtain internationally recognised certifications.
The agency also said the initiative would generate high-skilled technology jobs, strengthen Nigeria’s software ecosystem, improve confidence in locally developed software and enhance the competitiveness of Nigerian technology firms in global markets.
Abdullahi said software quality remained the foundation of digital trust and was critical to the country’s digital transformation agenda.
“Quality is the foundation of digital trust. With this Framework, every software solution serving Nigerians, whether built for government or the private sector, will meet clear national standards for security, reliability and interoperability. This is how we modernise government technology and position Nigerian software to compete on the global stage,” he said.
The framework consolidates three existing regulatory instruments into a unified national standard, comprising the National Software Development Guideline, the National Software Testing Guideline and the Software Testing Organisations Licensing (STOL) Guideline.
Under the new regime, software developers will be required to adopt structured software development life cycles, secure coding practices based on Open Web Application Security Project (OWASP) standards, standardised documentation and compliance with WCAG 2.1 AA accessibility standards for citizen-facing digital services.
The framework also establishes national benchmarks for software functionality, cybersecurity, system performance under peak operating conditions and interoperability before deployment.
To ensure appropriate oversight, NITDA introduced a three-tier risk classification model covering high-risk critical infrastructure systems, moderate-risk enterprise platforms and lower-risk internal applications.
Critical systems, including core banking switches, national identity management platforms and electricity grid control systems, will undergo the highest level of security assessment, including comprehensive penetration testing and specialised cybersecurity audits conducted by top-tier accredited testing organisations.
NITDA said the framework recognises that different software systems pose varying levels of operational and cybersecurity risks and therefore require different levels of regulatory scrutiny.
The new quality assurance framework follows concerns over the persistent failure of government technology projects.
According to NITDA, 56 per cent of Information Technology projects executed by Federal Public Institutions (FPIs) failed because of poor compliance with the agency’s IT Project Clearance Guidelines.
