Nigeria’s Identity Law Sparks Digital Signature Debate

Nigeria’s newly signed identity law has handed sweeping new powers to the National Identity Management Commission. As a result, the shift is raising fresh questions about who actually regulates digital signatures and online authentication going forward.

SEE ALSO:Digital Lenders Lead Consumer Complaints in Kenya Despite Reforms

President Bola Tinubu signed the amended National Identity Management Commission Act into law in June 2026. One of its most consequential provisions has nothing to do with the physical identity card most Nigerians associate with NIMC. Instead, the law designates the commission as Nigeria’s Root Certification Authority. This places it at the top of the country’s Public Key Infrastructure and Digital Public Infrastructure framework.

In practice, NIMC now issues and manages the cryptographic certificates, digital signatures and authentication systems that verify identities. These systems secure transactions across both government and private platforms.

Until now, that role sat with the National Information Technology Development Agency. Last month, however, NITDA formally handed over its PKI framework to NIMC. The ceremony took place at the agency’s Abuja headquarters. NITDA Director General Kashifu Inuwa Abdullahi said the agency had done extensive foundational work on PKI and Digital Public Infrastructure. He added that NITDA would continue supporting NIMC through the transition. Meanwhile, NIMC Director General Abisoye Coker-Odusote described the handover as a major milestone. She noted that the process would roll out in phases to protect citizens’ data and preserve public trust in digital services.

The two agencies insist the arrangement is complementary rather than competing. NIMC will manage the country’s foundational identity infrastructure. It will also issue the digital certificates that authenticate who someone is online. NITDA, on the other hand, says it will concentrate on regulation, ecosystem development and broader technology adoption. Officials frame this as consolidation. They argue it reduces the duplication that came from two agencies working on overlapping digital trust functions.

Still, that division of labour is exactly what has stakeholders asking who is actually in charge. Public Key Infrastructure is often described as the invisible backbone of the digital economy. It is the system that lets a bank, a government portal or a fintech app confirm that a login, a signed contract or an online payment genuinely came from the person it claims to.

Handing operational control of that backbone to an identity agency creates an unusual split, especially while broad technology regulation stays with a separate body. NIMC now controls the technical machinery of digital signatures and encryption. Yet NITDA retains the wider mandate for regulating how technology is adopted and governed across the economy. Consequently, businesses and legal experts are watching closely. They want to see how disputes over certificate authority, liability for compromised signatures, or fraud investigations get resolved when responsibility is shared between two institutions.

The law also strengthens enforcement in ways that matter for anyone relying on digital identity systems. For instance, NIMC has been granted investigative powers it never had before. These include court-authorised search, seizure and arrest powers against identity fraud syndicates, illegal enrolment centres and data traffickers. In addition, identity fraud now attracts tougher penalties, including prison terms and multi-million naira fines. Citizens’ consent has also been written into how identity data can be shared with third parties.

For everyday Nigerians, little will change immediately. Digital signatures, secure logins and encrypted transactions will keep functioning as before. Officials say the transition is being managed gradually to avoid disruption.

The bigger test still lies ahead: how NIMC and NITDA coordinate when something goes wrong. Nigeria is pushing NIN enrolment toward 180 million by the end of the year and leaning further into digital public services. So the question of clear, singular accountability over the country’s digital trust architecture is not going away anytime soon.

Leave a Reply

Your email address will not be published. Required fields are marked *

Previous Post

Shoprite’s Sixty60 Sales Hit $1.6 Billion

Next Post

Yellow Card Raises $40M to Expand Global Dollar Accounts

Related Posts