NITDA Launches National Software Quality Assurance Framework to Strengthen Cybersecurity, Digital Trust

The National Information Technology Development Agency (NITDA) has unveiled the National Software Quality Assurance (SQA) Framework, a landmark regulatory initiative aimed at eliminating costly software failures, strengthening cybersecurity and enhancing public confidence in Nigeria’s digital governance ecosystem.

The framework, approved by the Director-General and Chief Executive Officer of NITDA, Kashifu Inuwa Abdullahi, CCIE, under the provisions of the NITDA Act 2007, establishes nationwide standards for the design, testing and deployment of software across Federal Government institutions, regulated industries and the broader digital economy.

According to NITDA, the new framework harmonises three key regulatory instruments into a unified quality assurance regime.

These include the National Software Development Guideline, which prescribes structured software development life cycles, secure coding practices based on the Open Web Application Security Project (OWASP), standardised system documentation and compliance with Web Content Accessibility Guidelines (WCAG) 2.1 AA for citizen-facing digital platforms.

The framework also incorporates the National Software Testing Guideline, which introduces mandatory pre-deployment testing standards covering functionality, cybersecurity, performance under peak operational loads and interoperability with existing systems.

In addition, the Software Testing Organisations Licensing (STOL) Guideline establishes a regulatory regime for accrediting independent Licensed Software Testing Organisations (LSTOs) responsible for evaluating and certifying software before deployment.

Under the new policy, all government software projects will be required to undergo independent third-party testing and obtain official certification before they can go live, making compliance a mandatory condition for securing IT Project Clearance.

To ensure regulatory oversight reflects varying operational risks, the framework introduces a three-tier software classification model.

High-risk Class A systems—including core banking platforms, national identity management infrastructure and power grid control systems—will be subjected to the most stringent cybersecurity requirements, comprehensive penetration testing and specialised audits by top-tier accredited testing organisations.

Moderate-risk enterprise platforms will fall under Class B, while lower-risk internal applications will be classified as Class C, each subject to compliance standards proportionate to their level of operational risk.

NITDA said the framework is expected to deliver significant benefits to the country’s digital ecosystem by improving the reliability and security of public digital services, reducing costly system failures and safeguarding government investments from cyber threats.

The agency also said the initiative would stimulate the growth of a regulated software testing industry, creating new opportunities for indigenous technology companies, encouraging international certification and generating high-skilled employment for Nigerian software engineers.

It added that the framework would strengthen international confidence in Nigerian-developed software by ensuring locally built digital solutions meet globally recognised standards for quality, security and interoperability.

Speaking on the initiative, NITDA Director-General Kashifu Inuwa Abdullahi described quality assurance as the cornerstone of digital trust.

> “Quality is the foundation of digital trust. With this Framework, every software solution serving Nigerians—whether built for government or the private sector—will meet clear national standards for security, reliability and interoperability. This is how we modernise government technology and position Nigerian software to compete on the global stage,” he said.

 

The agency disclosed that the National Software Quality Assurance Framework will become fully operational in the second quarter of 2027.

Ahead of its implementation, NITDA said it would embark on nationwide stakeholder engagement and capacity-building programmes, while commencing the accreditation process for software testing organisations.

The agency also announced plans to issue an Expression of Interest (EOI) for prospective software testing firms seeking licensing, providing technology companies with an opportunity to strengthen their technical capacity and align with the new national quality assurance standards.

The statement was signed by Mrs. Hadiza Umar, Director of Corporate Communications and Media Relations at NITDA.

Bank Recapitalization-abacha-university-ad