Government agencies in Nigeria operate under a combination of pressures that make IT readiness more demanding than it might appear from the outside. Technology must meet the accountability standards of public-sector procurement, serve citizens reliably across working hours, comply with data protection and classification obligations, and remain maintainable by teams whose primary expertise is in their service area rather than in technology.
This checklist is structured to help IT leads, heads of department, and permanent secretaries assess and address the IT readiness of a government agency, whether for a new agency launch, a significant upgrade, or a formal readiness review.
Why government IT readiness is its own category
The failure modes in government IT are distinct from those in the private sector. It is rarely a shortage of ambition, most agencies understand what technology they want. The common problems are procurement decisions made without technical rigour, infrastructure deployed without a support model, security controls specified but not verified, and continuity arrangements that exist on paper but have never been tested.
An agency that has the technology but cannot account for how it was procured, who can access what, or what happens if the primary system fails, is not IT-ready. Readiness is about the whole system, not just the devices.
Section 1, Procurement governance
IT procurement in government is a process with specific requirements under public financial management regulations, and the documentation must reflect this.
- An approved IT plan or budget exists for the current fiscal year, covering planned acquisitions and maintenance costs.
- All IT specifications are written to function and performance standards, not to specific brand or model numbers, unless there is a justified and documented reason for sole-source.
- For any procurement above the threshold requiring competitive selection, at least three verifiable quotations or a full tender process is documented.
- Evaluation criteria for any tender or quotation exercise were set and documented before responses were received.
- All Local Purchase Orders (LPOs) are authorised at the appropriate level and matched to an approved budget line.
- A goods-received note exists for every IT delivery, with serial numbers, quantities, and condition recorded and signed.
- All IT assets are entered into an asset register at the point of receipt.
The government sector's procurement obligations do not slow down good IT, they make it defensible. A well-run IT procurement process produces its own audit trail as a by-product.
Section 2, Physical infrastructure and power
- Server room or data room has adequate physical access control, a lock and a visitor log at minimum, biometric access for more sensitive environments.
- Server room has dedicated, reliable power (UPS and generator) with automatic transfer on power failure.
- UPS runtime has been verified under actual load, not estimated from unit ratings.
- Cooling in the server room is active and has been verified as adequate for the current and planned equipment load.
- Structured cabling is terminated, tested, and documented, a cabling schedule exists and reflects the current installation.
- Each network point is labelled and matches the cabling schedule.
- Core network equipment (firewall, switches, routers) is in a locked rack with inventory and configuration records on file.
Section 3, Network and connectivity
- Connectivity is from an approved or contracted carrier and the service level (uptime, bandwidth) is specified in writing.
- A failover connectivity arrangement exists, single-link dependency is a risk that should be documented if it is accepted.
- All network equipment is on a current firmware version and has been patched within the last six months.
- The network is segmented: at a minimum, staff systems and public-facing services (if any) are on separate segments.
- Remote access for authorised staff is via a VPN or approved secure remote access solution, not via open remote desktop.
- All network devices are managed centrally and no device has a default credential.
Section 4, End-user computing
- An accurate device inventory exists, including make, model, serial number, assigned user, and location for every government-issued device.
- Devices are domain-joined or enrolled in a mobile device management (MDM) platform that allows central policy enforcement.
- All devices are running a current, supported version of the operating system and are within the OS vendor's support lifecycle.
- Security patching is applied centrally and the patch status of the fleet is visible from a management console.
- Antivirus or endpoint protection is installed and reporting to a central console, not just installed and assumed to be working.
- Default admin accounts have been renamed or disabled, and local administrator rights are not granted to standard users.
- A device refresh schedule exists, so that the agency is not operating end-of-life equipment indefinitely.
Section 5, Data management, backup, and continuity
- An inventory of systems and data that the agency depends on for its mandate exists, what are the mission-critical systems?
- Data in critical systems is backed up at least daily, with the backup stored in a separate physical or logical location from the primary.
- A backup restoration test has been conducted within the last six months and the results are documented.
- A business continuity plan for IT exists, covering the scenarios most likely to affect operations: power failure, connectivity failure, primary system failure, and hardware fault.
- The continuity plan has been reviewed by relevant department heads, not just produced and filed by IT.
- If cloud or hosted services are used, the data residency (where data is stored) and the agency's rights to export or migrate that data are confirmed in the contract.
Section 6, Information security and data protection
Government agencies hold significant volumes of sensitive citizen data, and obligations under the Nigeria Data Protection Act (NDPA) and relevant security classification guidelines apply.
- All staff have received basic information security awareness training in the last 12 months.
- A data classification scheme is in use, staff understand which data is sensitive and what handling restrictions apply.
- Access to systems holding sensitive data is role-based: staff access only what their role requires.
- Shared logins are not in use, every user account is individually assigned and attributable.
- A process exists for revoking access promptly when a staff member departs or changes role.
- Disk encryption is enabled on laptops and portable devices that carry government data.
- A procedure for reporting suspected data incidents exists and staff are aware of it.
- An agency-level data protection policy has been approved and is accessible to all staff.
Section 7, Support and vendor management
- A named IT support arrangement is in place, with a documented escalation path and committed response time.
- The response time commitment is calibrated to the agency's operational needs, for mission-critical systems, the maximum acceptable downtime should be specified and the SLA should reflect it.
- Contracts with technology vendors are current, signed, and retained, expired or unsigned contracts are a procurement and audit risk.
- Warranty status for all major equipment is tracked and expiry dates are known.
- A preventive maintenance schedule exists for server and network equipment, and maintenance is being carried out on that schedule.
Section 8, Governance and documentation
- An IT policy covering acceptable use, data handling, security, and procurement exists and is current (reviewed within the last two years).
- A network diagram exists and reflects the current state of the network.
- Configuration records for critical systems (servers, firewalls, key applications) are documented and stored securely.
- The agency head or accounting officer is formally briefed on the IT risk profile at least annually.
Using this checklist
Work through each section and assign a status to each item: compliant, partially compliant, or not in place. Items marked not in place are action items. Items marked partially compliant should have a note on what is missing and who is responsible for closing the gap.
The purpose of this checklist is not to produce a perfect score on paper, it is to identify the real gaps before they become operational failures or audit findings.
Frequently asked questions
How often should an agency conduct an IT readiness review?
Annually is the minimum for a functioning review cycle. For agencies undergoing significant change, new leadership, a major system implementation, a budget increase that includes significant IT spend, an ad hoc review is advisable before the change begins and after it is complete. The checklist is most useful as a living document, updated as each item is addressed.
Who should lead an IT readiness review?
Ideally, the IT lead or Director of ICT conducts the self-assessment, with sign-off by the Permanent Secretary or Director General. For agencies without internal IT capacity, an independent review by a qualified third party provides more credibility, particularly when the output will be used for budget justification or external reporting. The critical point is that sign-off comes from someone with accountability, not just from the IT team.
What happens if the review reveals significant gaps?
The output of a gap-identified review is a remediation plan with prioritised actions, owners, timelines, and cost estimates. Prioritise by risk: items that could cause loss of data, service interruption, or compliance failure take precedence over items that affect convenience or efficiency. A realistic remediation plan, honestly costed and with genuine commitment from leadership, is far more valuable than a glossy readiness report that papers over real problems.
Should a government agency manage its IT internally or use a managed service?
The answer depends on the scale and complexity of the agency's IT environment and the availability of qualified IT staff in the agency. Smaller agencies often lack the internal depth to manage complex systems effectively, and a managed service arrangement that provides monitoring, response, and scheduled maintenance can be more cost-effective than maintaining an internal team. Larger agencies typically need both: internal IT capacity for governance and day-to-day management, and an external partner for specialist support and capacity.



