NITDA’s mandatory software testing rules trigger push for risk-based enforcement

Nigeria’s mandatory software testing regime is facing calls for risk-based enforcement as industry professionals warn that applying the same level of compliance to every software system could create unnecessary burdens while failing to adequately protect systems with national consequences.

The Nigerian Software Testing Qualifications Board (NGSTQB), a professional body focused on software testing standards and certification, has endorsed the National Information Technology Development Agency’s (NITDA) National Software Testing Guideline but said enforcement should be proportionate to the potential harm arising from software failure.

NITDA issued the Guideline in April 2026, requiring software developed, modified, integrated or deployed for use in Nigeria to undergo functional and non-functional testing before operational deployment.

The framework covers security, performance, usability, compatibility, reliability, maintainability and portability, with the depth of testing determined by factors including system risk, data sensitivity, public exposure and the potential consequences of failure.

NGSTQB’s position could shape how the new regime is implemented across Nigeria’s technology ecosystem, particularly as software increasingly underpins financial transactions, digital identity, healthcare and government services.

Boye Dare, president of NGSTQB, said the organisation fully supports NITDA’s objective of ensuring that software deployed in Nigeria is secure, reliable and fit for purpose.

‘Software has become the invisible infrastructure of Nigeria’s economy; it sits behind every bank transfer, every hospital record, every government portal. When that infrastructure is not properly tested, the cost is not abstract; it is failed transactions, exposed data and public services that let people down,’ Dare said.

However, NGSTQB said the testing burden should increase with the risk associated with a system rather than being applied uniformly across all software.

‘A defect in a brochure website is not the same as a defect in a payment switch or a national identity platform,’ Dare said.

The distinction is significant because the consequences of a software failure vary widely. A malfunctioning corporate website may inconvenience users, while a defect in a payment, identity or other critical platform could disrupt services for millions of people, expose sensitive data or create significant financial losses.

The Board therefore supports universal minimum testing requirements but wants enhanced assurance requirements reserved for systems where failure could have material consequences for citizens, organisations or critical infrastructure.

Under NITDA’s framework, software must be assessed by a NITDA-licensed testing organisation and certified compliant before it can be put into operational use. Acceptance criteria require systems to have no unresolved critical or high-risk defects.

The rules also provide for renewed testing and certification where significant modifications are made to already certified software.

The approach effectively moves software testing from being primarily an internal development practice to a formal compliance requirement for software deployed in Nigeria.

For developers and organisations, this could introduce additional costs and time into software development and deployment, particularly where systems require independent testing and certification.

NGSTQB’s risk-based proposal seeks to prevent those requirements from becoming a blanket compliance burden, while maintaining stronger assurance for applications where failures could cause significant harm.

The Board said its support for the framework is based on five priorities: backing the Guideline’s objectives and implementation; aligning with NITDA’s quality, security and performance standards; supporting independent and competent testing for systems whose failure could materially affect citizens or critical infrastructure; promoting proportionate, risk-based regulation; and encouraging companies to view compliance as an investment rather than a final-stage certification exercise.

The group also wants software testing to be integrated earlier into development processes rather than treated as a final hurdle before deployment.

This could become increasingly important as Nigerian companies and government agencies deploy more digital services and rely on software for functions previously handled through physical or manual processes.

NGSTQB said effective implementation will also require more testing professionals and organisations capable of meeting the new standards.

The Board plans to support the implementation through education and awareness programmes for industry, academia and the public sector, capacity development for testing professionals and organisations, implementation guidance and best-practice resources.

It also plans continued engagement with NITDA to gather feedback from industry as the Guideline is implemented.

‘We are not approaching this as regulators looking in from outside. We are committing to sit with industry, train the professionals who will do this testing, and take feedback back to NITDA so the Guideline works in practice, not just on paper,’ Dare said.

The debate over enforcement comes as Nigeria seeks to build greater trust in its digital economy, where reliability and security have become increasingly important to financial services, public-sector platforms and locally developed technology products.

For software companies, the new regime could raise the cost of deployment in the short term, but NGSTQB argues that stronger testing could reduce the much larger costs associated with system downtime, fraud exposure, security vulnerabilities and failed digital services.

The broader implication is that Nigeria’s software market is moving towards a model where technical quality is increasingly treated as a condition for market readiness, rather than an optional engineering practice.

The challenge for NITDA will be ensuring that the testing framework strengthens digital trust without creating a compliance regime that disproportionately affects smaller developers or slows the deployment of lower-risk applications.

A risk-based enforcement model would allow regulators to apply the heaviest scrutiny where software failure could cause the greatest harm, while maintaining basic quality requirements across the wider technology ecosystem.

Leave a Reply

Your email address will not be published. Required fields are marked *