Skip to main content

ABOUT

Certifications & Accreditations

ISO 9001:2015, ISO/IEC 27001:2022, CAC registration under RC 1489223, BPP contractor registration, NITDA indigenous provider registration, and current partner status with Microsoft, Cisco, AWS, Fortinet and Oracle.

Why Certification Matters in Nigerian Public Procurement

In public procurement, a certificate is not decoration — it is an eligibility gate. A tender for a public IT project will typically require evidence of incorporation with the Corporate Affairs Commission, a current tax clearance certificate for three years, pension and industrial training fund compliance, registration with the Bureau of Public Procurement, and, for information technology projects above the prescribed threshold, clearance from the National Information Technology Development Agency. A bid missing any one of these is not scored down; it is disqualified at the opening stage, however good the technical proposal behind it.

Beyond eligibility, certification does work that a reference cannot. ISO 9001:2015 tells an evaluator that our estimating, change control, testing and close-out follow a documented process that an external auditor checks every year, rather than depending on which project manager happens to be assigned. ISO/IEC 27001:2022 tells a bank or a health institution that the way we handle their data is governed by a risk-assessed control set with defined owners, and that we have been audited against it. Both are increasingly requested by private buyers too, particularly in financial services.

We therefore treat compliance as an operational discipline rather than a bid-time scramble. The Director, Public Sector Business maintains a registration and clearance calendar with renewal dates and owners; certificates are renewed ahead of expiry, not after a tender exposes a lapse. Every document in the due diligence pack is version-controlled, and a complete, current pack can be issued to a buyer within one working day of a request.

Certifications, Registrations and Memberships

Current as at the last review. Certified copies are released to buyers on request — see the notice below.

Certification / registration Issuing body Reference / scope Validity
Certificate of Incorporation Corporate Affairs Commission (CAC) RC 1489223 — Brilliant Esystems Limited, private company limited by shares Perpetual; annual returns filed and current
ISO 9001:2015 — Quality Management System Accredited certification body Design, development, integration, supply, support and training in enterprise information technology, across Kano, Abuja and Lagos Certified since 2018; annual surveillance audit, three-year recertification cycle
ISO/IEC 27001:2022 — Information Security Management Accredited certification body Managed services, security operations centre, hosted platform and software development, covering all three offices Certified since 2021; transitioned to the 2022 standard; annual surveillance audit
Bureau of Public Procurement contractor registration Bureau of Public Procurement (BPP) Registered contractor with a current Interim Registration Report (IRR) for information technology goods and services Renewed annually
Indigenous IT service provider registration National Information Technology Development Agency (NITDA) Registered indigenous provider; required for clearance of public IT projects above the prescribed threshold Renewed annually
Tax Clearance Certificate Federal Inland Revenue Service Three consecutive years of clearance available for tender submission Renewed annually
Pension and ITF compliance certificates PenCom / Industrial Training Fund Employer compliance certificates for statutory tender requirements Renewed annually
NDPR data controller registration Data protection regulator Registered data controller; annual data protection audit filed through a licensed compliance organisation Renewed annually
Corporate membership Nigeria Computer Society Corporate member; 96 engineers hold current vendor certification Renewed annually
PECB-accredited training partner PECB Accredited to deliver ISO/IEC 27001 and ISO 9001 training through the ICT Training Academy Current
ITIL 4 and PRINCE2 practitioner base AXELOS-accredited examination institutes Practitioners on staff across service management and project management functions Individual certifications, maintained

Technology Partner Tiers

Partner status is earned through certified headcount, delivered revenue and audited customer references — which is why it is a reasonable proxy for capability.

Microsoft Solutions Partner

Digital & App Innovation; Infrastructure

Designations in Digital and App Innovation (Azure) and Infrastructure (Azure), supporting Microsoft 365, Azure migration, identity and endpoint management across our managed-services base.

Cisco Premier Integrator

Routing, switching, wireless, security

Premier tier with CCNP-certified engineers in Kano, Abuja and Lagos, covering enterprise networking, wireless, collaboration and Cisco security products for head office and branch estates.

AWS Advanced Consulting Partner

Migration and managed cloud

Advanced tier with certified solutions architects and systems operations engineers, delivering assessment, migration, landing-zone design and ongoing managed operations on AWS.

Fortinet Advanced Partner

Perimeter, SD-WAN, secure access

Advanced partner status covering FortiGate deployment, SD-WAN, secure remote access and integration of Fortinet telemetry into our security operations centre monitoring.

Oracle Partner

Database and middleware

Partner status covering Oracle Database, high availability configuration, backup and recovery, and integration with the enterprise applications used by our banking and public-sector clients.

Accredited Training Delivery

PECB and vendor curricula

The ICT Training Academy is a PECB-accredited training partner and delivers vendor curricula with certified trainers, so client teams can be certified on the platforms we install for them.

Learn more

How the ISO Management System Actually Works in Delivery

Certification is only useful if it changes what engineers do on a Tuesday. Here is where the management system touches an engagement.

1

Bid and estimate under a controlled procedure

Estimates follow a documented method with a defined approval path by value. Scope assumptions, exclusions and risks are recorded at bid stage, so what is later called a change really is a change and can be evidenced as one.

2

Risk assessment and security classification

Before work starts, the engagement is assessed under the ISO/IEC 27001 risk methodology. Data classification, access requirements, hosting location and any NDPR obligations are agreed in writing and reflected in the data processing agreement.

3

Design review and sign-off

Solution designs above a defined value go to the Architecture Review Board chaired by the Chief Technology Officer. Departures from the approved technology list require an explicit, minuted decision rather than a quiet substitution on site.

4

Controlled build, test and change

Development follows the secure development lifecycle with peer review and automated regression testing. Infrastructure changes go through change control with a rollback plan. Every change is logged with a requester, approver and outcome.

5

Access control and least privilege

Engineer access to client environments is granted per engagement, least-privilege, time-bounded and logged. Access lists are reviewed quarterly and revoked on reassignment. Privileged actions on monitored estates generate an audit record.

6

Acceptance, handover and documentation

Acceptance is against the documented criteria agreed at design stage. Close-out delivers as-built documentation, configuration, source code where applicable, runbooks and completed training records for the client team.

7

Service operation under measured levels

In-life service runs to agreed service levels with monthly reporting of achievement, incidents and problems. Security events on monitored estates flow to the security operations centre with defined severity and response commitments.

8

Internal audit, management review and corrective action

Internal audits run to a programme covering every process annually. Nonconformities get a root-cause analysis, an owner and a due date. Management review each year feeds the Risk & Security Committee and, through it, the Board’s Audit & Risk Committee.

Buyer and Due Diligence Questions

What documents are in your standard due diligence pack?
Certificate of incorporation and CAC status report, memorandum and articles, three years of tax clearance, pension and Industrial Training Fund compliance certificates, ISO 9001:2015 and ISO/IEC 27001:2022 certificates with scope statements, BPP Interim Registration Report, NITDA registration, NDPR data controller registration, company profile, organisation chart, three years of audited financial statements and a reference list. Request it from [email protected].
Is your tax clearance current, and for how many years?
Yes. We hold Federal Inland Revenue Service tax clearance for three consecutive years, which is the standard requirement in Nigerian public tenders. Certified copies are issued with the due diligence pack. Pension remittance and Industrial Training Fund compliance certificates are maintained on the same renewal calendar.
Do you have a current BPP Interim Registration Report?
Yes. Brilliant Esystems is registered with the Bureau of Public Procurement as a contractor for information technology goods and services and holds a current Interim Registration Report, renewed annually. We can supply the IRR number and a copy against a named tender reference, usually the same working day.
Our project needs NITDA clearance. Can you support that?
Yes. We are a NITDA-registered indigenous IT service provider, which is a precondition for clearance of public information technology projects above the prescribed threshold. We routinely support procuring entities through the clearance process by supplying our registration evidence, the technical specification and the local-content justification the agency asks for.
What is the exact scope of your ISO certificates?
The ISO 9001:2015 certificate covers design, development, integration, supply, support and training in enterprise information technology across Kano, Abuja and Lagos. The ISO/IEC 27001:2022 certificate covers managed services, the security operations centre, the hosted platform and software development across the same three sites. Both scope statements appear on the certificates themselves, which we supply in full rather than as extracts.
Can we audit you, or send a security questionnaire?
Yes to both. We complete client security questionnaires as a matter of course and accommodate on-site or remote audits by clients and their auditors, subject to reasonable notice and a confidentiality agreement. Banks and health institutions audit us regularly; the ISO/IEC 27001 evidence set usually answers most of a standard questionnaire directly.
How do you evidence local content?
Our engineering payroll is in Nigeria, the majority of it in Kano, and 96 of our engineers hold current vendor certification. We can supply headcount by location and discipline, certification schedules, the profile of our graduate trainee intake and ICT Academy training numbers as local-content evidence for a bid.
Do you carry insurance and can you provide bonds?
We maintain the insurance cover customary for this sector, including public liability and professional indemnity, and we can arrange advance payment guarantees and performance bonds through our bankers where a contract requires them. Bond capacity is approved by the Investment Committee, so tell us early in the bid process.

Requesting Certificate Copies for a Tender

Send your request to [email protected], copying [email protected], with the name of the procuring entity, the tender reference and closing date, and a list of the specific documents required. Where the tender demands certified true copies or notarised documents, say so and we will prepare them accordingly.

Standard turnaround is one working day for the electronic pack and two to three working days for certified hard copies delivered to Kano, Abuja or Lagos. For urgent closings, call +234 802 913 8013 and ask for the public sector business desk.

Need the compliance file today?

Tell us the tender reference and the closing date. Our public sector desk will assemble exactly what the evaluation committee asked for.