Nigeria signed three cloud instruments on 5 August. The framework sorts government data into four levels, and the top two have to stay inside the country. If that sounds familiar, it should. This is Europe’s own cloud sovereignty argument, written by someone else and pointed the other way.
What Nigeria signed on 5 August
Kashifu Inuwa Abdullahi, Director General of the National Information Technology Development Agency, signed three instruments. They are the National Cloud Computing Guideline, the National Cloud Technical Guideline and the National Digital Infrastructure Assurance Framework. NITDA presented a National Cloud Investment Strategy alongside them, under the National Sovereign Cloud Initiative.
Abdullahi described cloud infrastructure as “a strategic national asset that underpins digital government, financial services, artificial intelligence, digital public infrastructure, innovation and digital trade”. He framed the signing as a move from writing digital policy to implementing it.
Two things carry dates. NITDA will set up a Sovereign Cloud Governance Committee for oversight. By October 2026 it intends to operationalise a national digital regulatory platform, which will onboard, assess, certify and regulate the providers serving Nigerian government workloads.
That last one is the part with teeth. Certification is where a cloud sovereignty framework stops being a document.
The four levels
The cloud sovereignty classification sits in the National Cloud Policy 2025, which the new instruments build on. It sorts government data into four tiers.
- Level 1, open data. Public cloud is fine, residency flexible, transfers permitted.
- Level 2, sensitive personal, financial or health data. Nigeria or abroad, residency highly recommended, transfers lawful under the NDPA.
- Level 3, highly sensitive records. Primarily hosted in a private or secure hybrid cloud within Nigeria’s territorial boundary, with cross-border transfer permissible only under NDPA-compliant conditions and subject to NITDA approval, where applicable.
- Level 4, classified. Data must reside exclusively on premises within the federal public institution, in a collocated private data centre or in a government-certified private cloud inside Nigeria’s territorial boundary, with migration requiring explicit written authorisation.
Note the difference between the top two. Level 4 keeps the data in the country and puts an authorisation step in front of any move. Level 3 leaves a gate and puts the regulator beside it, which is the more consequential design, because a gate has a keeper and a keeper has discretion.
Where these cloud sovereignty rules came from
Read Level 4 again and you are reading the cloud sovereignty argument Brussels has been making for two years.
The Cloud and AI Development Act proposes its own four-level framework. Level 1 puts infrastructure and data in the Union. Level 2 adds independence from third-country legal control and software supply chain transparency. Levels 3 and 4 require EU ownership and control, restrictions on personnel and no interference from a third country.
Same architecture. Same instinct. Four tiers, rising restriction, the top of the scale reserved for whatever a state decides it cannot afford to lose.
Europe has also shown what the argument looks like when it bites. Earlier Future Prep coverage of the Dutch decision on DigiD traced the reasoning. The concern there was not a breach. It was who might lawfully compel disclosure later, which is a claim about jurisdiction rather than about security. We looked at what the sovereign cloud label actually means for much the same reason.
None of that reasoning is uniquely European. It was always going to travel.
What changes when cloud sovereignty rules point at you
Cloud sovereignty stops being an abstraction the moment you are the one being assessed. For an EU provider selling into the Nigerian public sector, the position has inverted. You are the third country now. Your legal exposure to a foreign government is the risk they assess, and somebody else holds the pen.
Three things follow in practice. Higher-tier workloads need infrastructure inside Nigeria rather than in a regional hub, which is a capital decision rather than a contractual one. Certification through the October platform becomes a condition of eligibility, so the timeline belongs to the regulator and not to your sales cycle. And the sovereignty questions your own procurement team puts to American vendors now come back at you, from a regulator who has written them down.
There is a data protection layer underneath as well. Levels 2 and 3 both route through the NDPA, so the transfer analysis is a Nigerian one, on Nigerian lawful bases, rather than a GDPR analysis with the names changed.
The mirror test
Here is the uncomfortable part, and it is worth sitting with rather than skipping.
If foreign legal control over infrastructure is a genuine sovereignty risk, it is a risk in Abuja for the reasons it is a risk in The Hague. If it is protectionism dressed as security, that judgement lands on CADA too. Cloud sovereignty does not become principled or cynical according to who wrote the rules.
It is not a position EU organisations have had to hold before. It is a useful test of whether your cloud sovereignty stance is a policy or a preference.
What to watch
October 2026 is the date that matters, because certification is when the regulator decides eligibility and vendors learn what the framework costs them.
Watch the Sovereign Cloud Governance Committee too, since committees are where exceptions get written. Level 3 already allows cross-border transfer with NITDA approval, and how readily that approval comes will tell you more about the regime than the policy text does.
Then watch who copies it. Nigeria is not the first state outside Europe to build cloud sovereignty tiers and pin the top ones to its own soil. The architecture is now easy to lift, and the political argument for lifting it writes itself.
The European conversation has treated cloud sovereignty as something Europe grants or withholds. It is turning into something Europe is also granted or refused.
If your cloud strategy assumes the localisation questions only run one way, the Future Prep assessments and checklists are a reasonable place to test that before a tender does it for you.