NITDA unveils National Software Quality Assurance Framework to strengthen digital governance

To eliminate costly IT failures, strengthen cybersecurity, and build public trust in digital governance, the National Information Technology Development Agency (NITDA) has officially launched the National Software Quality Assurance (SQA) Framework.

The framework was signed by NITDA Director-General and Chief Executive Officer, Kashifu Inuwa Abdullahi, under the authority of the NITDA Act 2007.

The National Software Quality Assurance Framework will officially take full effect in the second quarter of 2027.

According to the agency, the regulatory framework establishes nationwide standards for how software is designed, tested, and deployed across Federal Government institutions, regulated industries, and the broader digital ecosystem.

NITDA said the SQA Framework brings together three complementary regulatory instruments: the National Software Development Guideline, the National Software Testing Guideline, and the Software Testing Organisations Licensing (STOL) Guideline.

The agency explained that the National Software Development Guideline mandates structured software development lifecycles, adherence to OWASP secure coding practices, standardised system documentation, and compliance with WCAG 2.1 AA accessibility standards for citizen-facing digital services.

It added that the National Software Testing Guideline establishes rigorous pre-deployment testing benchmarks covering functionality, cybersecurity, performance under peak loads, and system interoperability. Meanwhile, the STOL Guideline regulates and accredits independent Licensed Software Testing Organisations (LSTOs) to evaluate and certify software before deployment.

According to NITDA, all government software projects must undergo independent third-party testing and obtain official certification before going live, making compliance a mandatory requirement for securing IT Project Clearance.

The framework also introduces a tiered classification model based on the level of operational risk. Software will be categorised into Class A (high-risk/critical infrastructure), Class B (moderate-risk enterprise platforms), and Class C (low-risk internal tools). High-impact Class A systems, including core banking platforms, identity management systems, and power grid control systems, will be subject to the most stringent security standards, comprehensive penetration testing, and specialised audit oversight by top-tier accredited testing organisations.

blank
blank

Related Articles

Back to top button