Nigeria’s new National Digital Cloud Policy will require federal ministries, departments and agencies (MDAs) to prioritise cloud infrastructure when building new digital systems and services, potentially making the government a major new customer for the country’s cloud providers.
On Monday, Nigeria’s Federal Ministry of Communications, Innovation and Digital Economy released the National Digital Cloud Policy, a framework for how Nigeria will build, regulate and use cloud infrastructure.
The policy is the government’s latest effort to reduce reliance on overseas systems and bring more of its cloud infrastructure in-country. Over 90% of Nigeria’s digital data and enterprise workloads are currently hosted on offshore servers, resulting in an estimated $850 million in annual capital flight. The implementation of this policy will expand Nigeria’s cloud and data centre market, projected to reach $782 million by 2031.
“Nigeria must move from being primarily a consumer of global cloud infrastructure to becoming a competitive location for the infrastructure, investment, skills and digital services that will define the next phase of the global digital economy,” Bosun Tijani, Minister of Communications, Innovation and Digital Economy, said in a statement.
The policy is a bet that collectively moving government systems to the cloud would make them faster and more reliable. This means that the government platforms Nigerians rely on to access public services, manage records and verify their identities could become less prone to disruptions.
The policy makes cloud the default deployment model for government workloads and requires MDAs to assess their existing systems and develop phased cloud migration plans. It also sets rules for where sensitive government and regulated data can be stored and processed, how the government buys cloud services, how cloud providers are registered, how businesses can move data between providers, and what incentives the government will offer to attract investment in data centres and other digital infrastructure.
The new policy supersedes the Nigeria Cloud Computing Policy 2019, which first introduced the Cloud First principle for federal public institutions. The new policy noted that the 2019 principle was implemented unevenly because there was no single framework coordinating government cloud demand, procurement, funding, security and monitoring.
The policy attempts to close those gaps with aggregated procurement, a government-wide cloud marketplace, cloud provider registration and binding compliance requirements.
“The National Digital Cloud Policy therefore provides a balanced framework — one that promotes investment and competition, strengthens indigenous capability, modernises Government and applies sovereignty requirements only where they are genuinely necessary,” the minister noted.
Under the policy, all MDAs must, by default, design new digital systems, services, and workloads for cloud deployment. An MDA can only skip this by securing a published, time-bound exemption, which must be assessed by the National Information Technology Development Agency (NITDA) according to section seven of the policy.
“Applications for exemption will be assessed by NITDA against published criteria and determined within published timeframes,” the policy stated. “Exemptions will be time-bound, subject to periodic review, and recorded in a register maintained by NITDA.”
Galaxy Backbone Limited (GBB), the agency that builds and runs digital infrastructure for government services, will aggregate cloud demand from multiple registered providers, including domestic and international companies. Rather than each government institution negotiating for capacity separately, GBB will pool that demand and negotiate framework agreements
The government will manage the procurement through a National Digital Marketplace. NITDA will handle provider registration and listing; the Bureau of Public Procurement (BPP) will oversee procurement compliance; and GBB will handle aggregation, framework agreements, and commercial arrangements with MDAs.
The policy also created a four-level classification system that sorts government and regulated data by sensitivity and the degree of national control required.
Data classified at Level 4, covering national security, defence and critical infrastructure information, must be hosted exclusively on infrastructure physically located in Nigeria. Level 3 data, which includes financial, health, biometric and identity data, must be stored at rest in Nigeria, with processing permitted elsewhere only under strict regulatory safeguards.
Level 2 data, covering internal government operational records, can be deployed in hybrid environments, including approved infrastructure outside Nigeria, but only with prior authorisation. Level 1 data, intended for public access or otherwise low-risk, can be hosted anywhere without residency restrictions.
“Classification takes precedence over data type: the same category of information may attract different treatment depending on the context in which it is held and the consequence of its compromise,” the policy stated.
The policy does not impose a blanket rule that all data generated in Nigeria must remain in the country. The classification and residency requirements apply to data generated by the Federal Government itself, or data generated under a federal regulation, licence, permit or directive that has been formally designated as sovereign data.
For regulated businesses that generate data, including fintechs and healthtechs, being regulated does not automatically mean that every category of data they hold becomes subject to the sovereignty rules. However, a regulator such as the Central Bank of Nigeria or the Nigeria Data Protection Commission can apply to have a category of data it regulates designated as sovereign data, bringing that data category under these residency rules.
The policy creates a division of responsibility among government institutions. The National Information Technology Development Agency (NITDA) will provide regulatory oversight, standards, and assurance. Galaxy Backbone Limited (GBB) will be responsible for operational delivery, shared infrastructure and aggregation, while the Bureau of Public Procurement (BPP) will oversee alignment with public procurement requirements.
Providers and MDAs that fail to comply can face remediation directives, deployment suspensions and, for providers, sanctions or suspension and revocation of registration. Material breaches involving Level 3 or Level 4 data can be escalated to the Office of the National Security Adviser and other competent authorities.
The government now has a 24-month roadmap to move the policy from a framework into implementation. During the first six months, it will focus on activating the policy, conducting baseline assessments, issuing implementation directives, establishing the required institutions and putting investment-facilitation measures in place.
Between the sixth and twelfth month, the government plans to operationalise the National Digital Marketplace, begin migrating priority MDAs, onboard registered cloud providers and start regional market-development activities, according to a statement by the Ministry of Communications, Innovation & Digital Economy.
The final 12 months of the roadmap will focus on scaling government migrations, expanding infrastructure capacity, bringing participating states into the framework, improving regional interconnection and accelerating digital service exports.
The Federal Government has also attached financial and operational targets to the roadmap. It intends to attract $250 million in private investment into Nigerian cloud and data infrastructure within the first 12 months, increasing that figure to $750 million within 24 months, alongside progressive increases in compliant hosting capacity and the development of Nigeria’s regional cloud export market.
“Our approach is deliberately open and investment-oriented. We want Nigerian and international providers to invest, build capacity, develop talent and serve both the Nigerian market and the wider African continent from Nigeria,” said Tijani. “At the same time, the government has a responsibility to ensure that its most sensitive digital assets are governed and secured in a manner consistent with our national interests.”
The policy comes as Nigeria is simultaneously trying to build the physical infrastructure that will make a domestic cloud market possible. The Building Resilient Digital Infrastructure for Growth (BRIDGE) Project is a $1.6 billion digital infrastructure project aimed at expanding the country’s broadband backbone. The project is expected to deploy 90,000 kilometres of open-access fibre across the country, expanding the national fibre backbone to about 120,000 kilometres.
True scale demands moving beyond surface-level integrations to robust execution. We’ve filtered the noise out of Moonshot 2026, optimising the conference strictly for high-calibre connections between startup founders, global financial operators, enterprise leaders and individuals rewiring Africa’s technical frameworks. Get 20% off Early Bird tickets for a limited time.
