Nigeria's New Cloud Policy Puts Government at the Centre of Its Cloud Market
Key Takeaways
- •Federal ministries, departments and agencies must design new digital systems for cloud deployment by default and can only opt out through NITDA-approved exemptions.
- •The policy replaces Nigeria’s 2019 cloud policy and introduces a government-wide procurement and compliance framework led by NITDA, Galaxy Backbone and the Bureau of Public Procurement.
- •A four-level data classification system sets stricter residency rules for sensitive government and regulated data, with the most critical data required to stay on infrastructure physically located in Nigeria.
- •The government wants to attract $250 million in private investment into cloud and data infrastructure within 12 months and $750 million within 24 months.
- •The policy is part of a broader effort to localise digital infrastructure as Nigeria continues work on the $1.6 billion BRIDGE fibre project.

Nigeria's newly released National Digital Cloud Policy will require federal ministries, departments and agencies (MDAs) to prioritise cloud infrastructure when building new digital systems and services, a move that positions the government as a potentially major customer for the country's cloud providers.
On Monday, the Federal Ministry of Communications, Innovation and Digital Economy published the National Digital Cloud Policy, a framework for how Nigeria will build, regulate and use cloud infrastructure.
The policy is the government's latest effort to reduce reliance on overseas systems and bring more of its cloud infrastructure in-country. More than 90% of Nigeria's digital data and enterprise workloads are currently hosted on offshore servers, resulting in an estimated $850 million in annual capital flight. Implementation is expected to expand Nigeria's cloud and data centre market, which is projected to reach $782 million by 2031.
Nigeria is joining a wider continental shift. Kenya's and South Africa's data protection laws already place conditions on cross-border data transfers, Egypt's banking rules require banks to host data in-country, and the African Continental Free Trade Area adopted a digital trade protocol in 2024 that sets continental rules on data flows. At home, the policy extends the National Digital Economy Policy and Strategy 2020–2030, which lists indigenous content development among its eight pillars.
“Nigeria must move from being primarily a consumer of global cloud infrastructure to becoming a competitive location for the infrastructure, investment, skills and digital services that will define the next phase of the global digital economy,” Bosun Tijani, Minister of Communications, Innovation and Digital Economy, said in a statement.
The policy is a bet that collectively moving government systems to the cloud would make them faster and more reliable. The government platforms Nigerians rely on to access public services, manage records and verify their identities could become less prone to disruptions.
What the policy requires
The policy makes cloud the default deployment model for government workloads and requires MDAs to assess their existing systems and develop phased cloud migration plans. It also sets rules for where sensitive government and regulated data can be stored and processed, how the government buys cloud services, how cloud providers are registered, how businesses can move data between providers, and what incentives the government will offer to attract investment in data centres and other digital infrastructure.
The framework supersedes the Nigeria Cloud Computing Policy 2019, which first introduced the Cloud First principle for federal public institutions. The new policy notes that the 2019 principle was implemented unevenly because no single framework coordinated government cloud demand, procurement, funding, security and monitoring. It attempts to close those gaps with aggregated procurement, a government-wide cloud marketplace, cloud provider registration and binding compliance requirements.
“The National Digital Cloud Policy therefore provides a balanced framework — one that promotes investment and competition, strengthens indigenous capability, modernises Government and applies sovereignty requirements only where they are genuinely necessary,” the minister noted.
Under the policy, all MDAs must by default design new digital systems, services and workloads for cloud deployment. An MDA can skip this only by securing a published, time-bound exemption, which must be assessed by the National Information Technology Development Agency (NITDA) under section seven of the policy.
“Applications for exemption will be assessed by NITDA against published criteria and determined within published timeframes,” the policy stated. “Exemptions will be time-bound, subject to periodic review, and recorded in a register maintained by NITDA.”
How procurement will work
Galaxy Backbone Limited (GBB), the agency that builds and runs digital infrastructure for government services, will aggregate cloud demand from multiple registered providers, including domestic and international companies. Rather than each government institution negotiating for capacity separately, GBB will pool that demand and negotiate framework agreements.
The government will manage procurement through a National Digital Marketplace. NITDA will handle provider registration and listing; the Bureau of Public Procurement (BPP) will oversee procurement compliance; and GBB will handle aggregation, framework agreements and commercial arrangements with MDAs.
The marketplace will launch into infrastructure that international operators have already begun investing in. Equinix acquired Lagos-based connectivity and data centre operator MainOne in 2022, and carrier-neutral operators such as Rack Centre and Africa Data Centres have expanded capacity in Lagos. The three largest global cloud providers — Microsoft, Amazon Web Services and Google Cloud — have so far located their African cloud regions in South Africa, a gap the policy's investment incentives are designed to help close.
A four-level data classification system
The policy creates a four-level classification system that sorts government and regulated data by sensitivity and the degree of national control required.
- Level 4, covering national security, defence and critical infrastructure information, must be hosted exclusively on infrastructure physically located in Nigeria.
- Level 3, which includes financial, health, biometric and identity data, must be stored at rest in Nigeria, with processing permitted elsewhere only under strict regulatory safeguards.
- Level 2, covering internal government operational records, can be deployed in hybrid environments, including approved infrastructure outside Nigeria, but only with prior authorisation.
- Level 1, intended for public access or otherwise low-risk, can be hosted anywhere without residency restrictions.
“Classification takes precedence over data type: the same category of information may attract different treatment depending on the context in which it is held and the consequence of its compromise,” the policy stated.
The policy does not impose a blanket rule that all data generated in Nigeria must remain in the country. The classification and residency requirements apply to data generated by the Federal Government itself, or data generated under a federal regulation, licence, permit or directive that has been formally designated as sovereign data.
For regulated businesses that generate data, including fintechs and healthtechs, being regulated does not automatically mean every category of data they hold becomes subject to the sovereignty rules. However, a regulator such as the Central Bank of Nigeria or the Nigeria Data Protection Commission can apply to have a category of data it regulates designated as sovereign data, bringing that data category under the residency rules.
The designation route also builds on an existing legal baseline: the Nigeria Data Protection Act 2023, which established the Commission, already places conditions on transferring personal data out of the country.
Oversight and enforcement
The policy creates a division of responsibility among government institutions. NITDA will provide regulatory oversight, standards and assurance. GBB will be responsible for operational delivery, shared infrastructure and aggregation, while the BPP will oversee alignment with public procurement requirements.
Providers and MDAs that fail to comply can face remediation directives, deployment suspensions and, for providers, sanctions or suspension and revocation of registration. Material breaches involving Level 3 or Level 4 data can be escalated to the Office of the National Security Adviser and other competent authorities.
A 24-month implementation roadmap
The government has a 24-month roadmap to move the policy from a framework into implementation.
During the first six months, the focus will be on activating the policy, conducting baseline assessments, issuing implementation directives, establishing the required institutions and putting investment-facilitation measures in place.
Between the sixth and twelfth month, the government plans to operationalise the National Digital Marketplace, begin migrating priority MDAs, onboard registered cloud providers and start regional market-development activities, according to a statement by the Ministry of Communications, Innovation & Digital Economy.
The final 12 months of the roadmap will focus on scaling government migrations, expanding infrastructure capacity, bringing participating states into the framework, improving regional interconnection and accelerating digital service exports.
The Federal Government has also attached financial and operational targets to the roadmap. It intends to attract $250 million in private investment into Nigerian cloud and data infrastructure within the first 12 months, increasing that figure to $750 million within 24 months, alongside progressive increases in compliant hosting capacity and the development of Nigeria's regional cloud export market.
The earliest test of the framework will be procedural rather than financial: whether NITDA publishes its exemption criteria and register on schedule, whether the National Digital Marketplace goes live in the roadmap's second phase, how quickly providers register, and whether regulators begin applying to designate new categories of sovereign data.
“Our approach is deliberately open and investment-oriented. We want Nigerian and international providers to invest, build capacity, develop talent and serve both the Nigerian market and the wider African continent from Nigeria,” said Tijani. “At the same time, the government has a responsibility to ensure that its most sensitive digital assets are governed and secured in a manner consistent with our national interests.”
Parallel infrastructure build-out
The policy comes as Nigeria simultaneously works to build the physical infrastructure that will make a domestic cloud market possible. The Building Resilient Digital Infrastructure for Growth (BRIDGE) Project is a $1.6 billion digital infrastructure project aimed at expanding the country's broadband backbone. The project is expected to deploy 90,000 kilometres of open-access fibre across the country, expanding the national fibre backbone to about 120,000 kilometres.