Nigeria’s new mandatory software testing regime is drawing support from industry professionals, but stakeholders are calling for enforcement to be based on the level of risk posed by each software system.
The Nigerian Software Testing Qualifications Board (NGSTQB) has endorsed the National Software Testing Guideline introduced by the National Information Technology Development Agency (NITDA), while urging regulators to avoid applying the same compliance requirements to every type of software.
The guideline, issued in April 2026, requires software developed, modified, integrated or deployed for use in Nigeria to undergo functional and non-functional testing before it is put into operation. The testing covers areas including security, performance, usability, compatibility, reliability, maintainability and portability.
Testing requirements to reflect risk
NGSTQB said the level of testing should increase according to a system’s potential impact, data sensitivity, public exposure and the consequences of failure.
The organisation argued that a minor corporate website should not face the same testing burden as a payment platform, national identity system or other critical infrastructure.
Under NITDA’s framework, software must be assessed by a licensed testing organisation and certified as compliant before deployment. Certification must also be renewed when significant changes or modifications are made to the software.
The framework also requires systems to meet defined acceptance criteria, including having no unresolved critical or high-risk defects before deployment.
Three-tier classification
The broader National Software Quality Assurance Framework introduces a three-tier classification system based on software risk.
Class A covers high-risk systems and critical infrastructure, including platforms such as core banking systems, national identity management and electricity grid control systems. These applications face more stringent security testing and specialised audits.
Class B covers moderate-risk enterprise platforms, while Class C applies to lower-risk internal applications.
The classification is intended to ensure that testing requirements are proportionate to the possible consequences of software failure.
New compliance requirements for developers
The new rules move software testing beyond an internal development practice and make it part of Nigeria’s formal regulatory framework.
For government software projects, compliance with the testing requirements will form part of the conditions for obtaining IT Project Clearance. The framework is scheduled to become fully operational in the second quarter of 2027.
NITDA is also establishing a regulated market for independent software testing organisations. Technology companies seeking to provide testing and certification services will need to go through an accreditation and licensing process.
The agency has said the framework is designed to reduce software failures, strengthen cybersecurity and improve confidence in digital services.
Balancing compliance and innovation
While stronger testing could help reduce system failures, security vulnerabilities and costly disruptions, industry stakeholders have warned that excessive compliance requirements could increase development costs and create difficulties for smaller technology companies.
NGSTQB therefore supports universal minimum testing standards but wants more demanding requirements reserved for systems where failures could cause significant harm to citizens, organisations or critical infrastructure.
The organisation also wants testing to be introduced earlier in the software development process rather than treated as a final compliance hurdle before deployment.
It plans to support implementation through training, awareness programmes, capacity development and engagement with NITDA and other stakeholders.
The debate is ultimately about finding a balance between stronger digital safeguards and a regulatory system that does not unnecessarily slow innovation.
A risk-based approach could allow Nigeria to apply the strictest controls to software where failure carries the greatest consequences, while keeping compliance proportionate for lower-risk applications.
SEO Title: NITDA Software Testing Rules Spark Risk-Based Enforcement Push
Meta Description: NITDA’s mandatory software testing rules are prompting calls for risk-based enforcement to protect critical systems without burdening low-risk developers.