NGSTQB Backs NITDA Software Testing Guideline, Seeks Risk-Based Enforcement

The Nigerian Software Testing Qualifications Board (NGSTQB) has formally endorsed the National Software Testing Guideline introduced by the National Information Technology Development Agency (NITDA), while calling for its enforcement to follow a risk-based and tiered model rather than a one-size-fits-all approach.

The position places NGSTQB among the industry stakeholders supporting stronger national standards for software quality, security and reliability, while also highlighting the need for proportional regulation.

According to the testing body, software systems do not carry the same level of risk. Therefore, the intensity of testing and certification should correspond to the potential consequences of failure.

Why Risk-Based Testing Matters

NGSTQB argued that a software application used for a relatively simple purpose should not necessarily face the same testing burden as a platform that handles financial transactions, sensitive personal information or critical infrastructure.

That distinction is central to the National Software Testing Guideline, which links the level and depth of testing to the risk profile of a software system.

Factors such as data sensitivity, exposure to external systems and the potential consequences of failure can help determine the appropriate level of testing.

Consequently, a risk-based framework could allow regulators to maintain strong minimum standards while applying more intensive testing requirements to systems where failure could cause greater harm.

NITDA Framework Sets National Testing Standards

NITDA’s National Software Testing Guideline establishes a framework for testing software before operational deployment.

The guideline covers functional and non-functional testing, including security, performance, usability, compatibility, reliability, maintainability and portability.

It also assigns responsibilities to different stakeholders. NITDA is responsible for establishing and enforcing testing standards, licensing and overseeing testing organisations and monitoring compliance.

Meanwhile, software developers and government institutions are expected to ensure that software undergoes the required testing before deployment and that identified defects are addressed.

This structure is designed to make software quality assurance part of the development and deployment process rather than something considered only after a system has already gone live.

Testing Should Match Potential Harm

NGSTQB’s position focuses particularly on proportionality.

A system supporting a small internal administrative function, for instance, may present a very different risk profile from a payment platform serving millions of customers.

Similarly, software connected to critical national infrastructure could require significantly deeper security assessments because a major failure could affect essential services.

Therefore, NGSTQB wants enhanced testing requirements to concentrate on systems where failure could produce substantial consequences.

The approach could also prevent compliance requirements from becoming unnecessarily burdensome for smaller developers and less critical applications.

Certification and Independent Testing

Under the NITDA framework, software is expected to undergo assessment by licensed testing organisations before operational use.

Testing organisations must maintain independence and objectivity, while certification provides formal confirmation that software has satisfied the required testing standards.

The framework also provides for compliance monitoring and renewed testing where significant changes are made to certified software.

That requirement is important because software does not remain static after its initial deployment. Major modifications, integrations, security changes or new functionalities can introduce fresh vulnerabilities.

Consequently, quality assurance needs to continue throughout a system’s lifecycle rather than end when developers initially receive certification.

Building Confidence in Nigeria’s Digital Economy

NGSTQB’s support also reflects the wider importance of software reliability to Nigeria’s digital economy.

Banks, hospitals, government agencies, educational institutions, businesses and other organisations increasingly depend on digital platforms for essential services.

When these systems fail, the consequences can extend beyond technical inconvenience.

System outages can disrupt transactions, delay public services, expose sensitive information and undermine confidence in digital platforms.

Therefore, stronger testing standards could help organisations identify vulnerabilities before systems reach users.

In addition, consistent national standards could provide Nigerian software developers with clearer expectations for quality, security and performance.

Industry Capacity Will Be Important

However, effective implementation will require sufficient testing professionals, accredited organisations and technical capacity.

A regulatory framework can establish standards, but those standards must be supported by people and institutions capable of applying them effectively.

NGSTQB has indicated that it will support implementation through education and awareness programmes, capacity development, implementation guidance and engagement with NITDA.

That role could become particularly important as organisations adapt to the new requirements.

Furthermore, developers and businesses will need to understand not only what the guideline requires but also how to integrate testing into their development processes without creating unnecessary delays.

From Compliance to Quality Culture

Another important issue is whether organisations view software testing simply as a regulatory requirement or as an essential part of product development.

NGSTQB has urged the industry to treat compliance as an investment rather than a late-stage certification exercise.

This distinction could influence how effectively the guideline works.

If developers incorporate testing from the beginning of a software project, they can identify defects earlier and potentially reduce the cost of fixing them later.

Moreover, early testing can improve system reliability, security and user experience before deployment.

A Tiered Model Could Improve Implementation

The call for tiered enforcement also aligns with the broader risk-based direction of NITDA’s software quality framework.

Such an approach allows regulatory attention to focus where the potential consequences are greatest.

At the same time, minimum quality and security expectations can still apply across the software ecosystem.

Consequently, the challenge will be to maintain a balance between strong oversight and a regulatory environment that allows developers and technology businesses to innovate.

The Road Ahead

Ultimately, NGSTQB’s endorsement strengthens support for NITDA’s effort to establish clearer national standards for software testing.

However, the testing body has also highlighted a practical issue that could shape the success of the framework: enforcement must reflect the different levels of risk associated with different software systems.

A proportionate model could help Nigeria strengthen digital trust without imposing identical compliance burdens on every developer and application.

For NITDA, industry testing professionals and software developers, the next stage will involve turning the guideline from a regulatory document into an operational standard that organisations can consistently implement.

If that balance is achieved, stronger testing could help reduce software failures, improve cybersecurity, protect users and strengthen confidence in Nigeria’s growing digital economy.