On June 26, 2026, President Bola Tinubu signed the National Identity Management Commission (NIMC) Act 2026 into law, repealing the 17-year-old NIMC Act 2007 and naming NIMC as Nigeria's Root Certification Authority for the National Public Key Infrastructure (PKI) and Digital Public Infrastructure (DPI) (NALTF). On July 17, 2026, the National Information Technology Development Agency (NITDA) formally handed its PKI assets, technology and operations to NIMC at a ceremony in Abuja, with NITDA Director-General Kashifu Inuwa Abdullahi calling it a move "beyond theoretical policy into immediate, practical execution" (Leadership).
What a Root CA Actually Controls
A Root Certification Authority sits at the top of a trust chain: every digital certificate used to verify a website, sign a document, authenticate a login, or encrypt a transaction traces back to it. Handing that role to NIMC means the same agency that issues the National Identification Number (NIN) — the credential now required for banking, tax filing, pensions, land transactions and consumer credit under the "One Person, One Identity, One Number" mandate — also becomes the entity certifying the cryptographic trust layer underneath Nigeria's banking, government and private-sector digital systems (TechCabal). NIMC's identity database has enrolled more than 136 million Nigerians and legal residents as of July 2026, and Tinubu has ordered universal enrollment completed by the end of the year (Vanguard).
The Case For Consolidation
The strongest argument for this design is coherence. Nigeria's PKI had been fragmented between NITDA (infrastructure operator) and NIMC (identity issuer) for years, with a formal partnership on "building and implementing" a robust PKI dating back to at least 2024 — a division of labor that created ambiguity over who actually certified what. A single root authority tied to a verified national identity is the architecture most digital-ID systems converge on eventually, because a signature is only as trustworthy as the identity behind it. The Act also brings NIMC — for the first time — squarely under the Nigeria Data Protection Act 2023, requiring consent for third-party access to identity data with only narrowly defined exceptions for court orders and criminal investigations, and imposing minimum penalties of five years' imprisonment or ₦10 million for unauthorized access (TechCabal). That is a real improvement on a 2007 law that predated Nigeria's data protection regime entirely, and the data-protection authority itself has an institutional stake in enforcing those limits (NDPC).
Where the Design Strains
The problem is not that NIMC issues certificates. It is that the same Act also grants NIMC court-authorized powers to search, seize evidence, and decrypt data in connection with identity fraud — meaning the agency that controls the cryptographic keys underpinning the entire economy is also the agency empowered to break into encrypted material using access derived from that same infrastructure. Regionally, this is a recognizable pattern, not a Nigerian anomaly: CIPESA has documented how Morocco shifted encryption-authorization power from a civilian telecoms regulator to the military's information-security directorate in 2015, and how Algeria requires encryption approval from its Ministry of Defence alongside its telecoms regulator — both cases where governments folded cryptographic gatekeeping into security-facing institutions rather than independent technical bodies (CIPESA). Nigeria has not gone that far — NIMC is a civilian identity agency, not a security service, and its investigative powers require court authorization. But the structural risk CIPESA flags generalizes: when the entity that certifies trust and the entity that can compel decryption are the same body, the ordinary technical safeguards against key misuse (revocation audits, independent certificate transparency logs, external review of who requested what) depend entirely on that single institution policing itself.
A Proportionate Fix, Not a Reversal
None of this is an argument against digital identity infrastructure or against consolidating a previously fragmented PKI — Nigeria's $1-trillion-economy ambitions genuinely require a coherent trust layer, and 136 million enrolled identities represent real state capacity that shouldn't be discarded. The fix is narrower: publish certificate-issuance and revocation logs independently auditable by the Nigeria Data Protection Commission, require NIMC's court-authorized decryption requests to be logged and periodically disclosed in aggregate (as several democracies now require of lawful-intercept regimes), and keep the NDPC's oversight role functionally separate from NIMC's operational one rather than nominal. Root CAs fail quietly, through a single compromised or coerced key, not loudly — which is exactly why the institution wielding both the certificate and the subpoena power needs a watcher that isn't itself.