ABOUT
Certifications & Accreditations
ISO 9001:2015, ISO/IEC 27001:2022, CAC registration under RC 1489223, BPP contractor registration, NITDA indigenous provider registration, and current partner status with Microsoft, Cisco, AWS, Fortinet and Oracle.
Why Certification Matters in Nigerian Public Procurement
In public procurement, a certificate is not decoration — it is an eligibility gate. A tender for a public IT project will typically require evidence of incorporation with the Corporate Affairs Commission, a current tax clearance certificate for three years, pension and industrial training fund compliance, registration with the Bureau of Public Procurement, and, for information technology projects above the prescribed threshold, clearance from the National Information Technology Development Agency. A bid missing any one of these is not scored down; it is disqualified at the opening stage, however good the technical proposal behind it.
Beyond eligibility, certification does work that a reference cannot. ISO 9001:2015 tells an evaluator that our estimating, change control, testing and close-out follow a documented process that an external auditor checks every year, rather than depending on which project manager happens to be assigned. ISO/IEC 27001:2022 tells a bank or a health institution that the way we handle their data is governed by a risk-assessed control set with defined owners, and that we have been audited against it. Both are increasingly requested by private buyers too, particularly in financial services.
We therefore treat compliance as an operational discipline rather than a bid-time scramble. The Director, Public Sector Business maintains a registration and clearance calendar with renewal dates and owners; certificates are renewed ahead of expiry, not after a tender exposes a lapse. Every document in the due diligence pack is version-controlled, and a complete, current pack can be issued to a buyer within one working day of a request.
Certifications, Registrations and Memberships
Current as at the last review. Certified copies are released to buyers on request — see the notice below.
| Certification / registration | Issuing body | Reference / scope | Validity |
|---|---|---|---|
| Certificate of Incorporation | Corporate Affairs Commission (CAC) | RC 1489223 — Brilliant Esystems Limited, private company limited by shares | Perpetual; annual returns filed and current |
| ISO 9001:2015 — Quality Management System | Accredited certification body | Design, development, integration, supply, support and training in enterprise information technology, across Kano, Abuja and Lagos | Certified since 2018; annual surveillance audit, three-year recertification cycle |
| ISO/IEC 27001:2022 — Information Security Management | Accredited certification body | Managed services, security operations centre, hosted platform and software development, covering all three offices | Certified since 2021; transitioned to the 2022 standard; annual surveillance audit |
| Bureau of Public Procurement contractor registration | Bureau of Public Procurement (BPP) | Registered contractor with a current Interim Registration Report (IRR) for information technology goods and services | Renewed annually |
| Indigenous IT service provider registration | National Information Technology Development Agency (NITDA) | Registered indigenous provider; required for clearance of public IT projects above the prescribed threshold | Renewed annually |
| Tax Clearance Certificate | Federal Inland Revenue Service | Three consecutive years of clearance available for tender submission | Renewed annually |
| Pension and ITF compliance certificates | PenCom / Industrial Training Fund | Employer compliance certificates for statutory tender requirements | Renewed annually |
| NDPR data controller registration | Data protection regulator | Registered data controller; annual data protection audit filed through a licensed compliance organisation | Renewed annually |
| Corporate membership | Nigeria Computer Society | Corporate member; 96 engineers hold current vendor certification | Renewed annually |
| PECB-accredited training partner | PECB | Accredited to deliver ISO/IEC 27001 and ISO 9001 training through the ICT Training Academy | Current |
| ITIL 4 and PRINCE2 practitioner base | AXELOS-accredited examination institutes | Practitioners on staff across service management and project management functions | Individual certifications, maintained |
Technology Partner Tiers
Partner status is earned through certified headcount, delivered revenue and audited customer references — which is why it is a reasonable proxy for capability.
Microsoft Solutions Partner
Digital & App Innovation; Infrastructure
Designations in Digital and App Innovation (Azure) and Infrastructure (Azure), supporting Microsoft 365, Azure migration, identity and endpoint management across our managed-services base.
Cisco Premier Integrator
Routing, switching, wireless, security
Premier tier with CCNP-certified engineers in Kano, Abuja and Lagos, covering enterprise networking, wireless, collaboration and Cisco security products for head office and branch estates.
AWS Advanced Consulting Partner
Migration and managed cloud
Advanced tier with certified solutions architects and systems operations engineers, delivering assessment, migration, landing-zone design and ongoing managed operations on AWS.
Fortinet Advanced Partner
Perimeter, SD-WAN, secure access
Advanced partner status covering FortiGate deployment, SD-WAN, secure remote access and integration of Fortinet telemetry into our security operations centre monitoring.
Oracle Partner
Database and middleware
Partner status covering Oracle Database, high availability configuration, backup and recovery, and integration with the enterprise applications used by our banking and public-sector clients.
Accredited Training Delivery
PECB and vendor curricula
The ICT Training Academy is a PECB-accredited training partner and delivers vendor curricula with certified trainers, so client teams can be certified on the platforms we install for them.
Learn moreHow the ISO Management System Actually Works in Delivery
Certification is only useful if it changes what engineers do on a Tuesday. Here is where the management system touches an engagement.
Bid and estimate under a controlled procedure
Estimates follow a documented method with a defined approval path by value. Scope assumptions, exclusions and risks are recorded at bid stage, so what is later called a change really is a change and can be evidenced as one.
Risk assessment and security classification
Before work starts, the engagement is assessed under the ISO/IEC 27001 risk methodology. Data classification, access requirements, hosting location and any NDPR obligations are agreed in writing and reflected in the data processing agreement.
Design review and sign-off
Solution designs above a defined value go to the Architecture Review Board chaired by the Chief Technology Officer. Departures from the approved technology list require an explicit, minuted decision rather than a quiet substitution on site.
Controlled build, test and change
Development follows the secure development lifecycle with peer review and automated regression testing. Infrastructure changes go through change control with a rollback plan. Every change is logged with a requester, approver and outcome.
Access control and least privilege
Engineer access to client environments is granted per engagement, least-privilege, time-bounded and logged. Access lists are reviewed quarterly and revoked on reassignment. Privileged actions on monitored estates generate an audit record.
Acceptance, handover and documentation
Acceptance is against the documented criteria agreed at design stage. Close-out delivers as-built documentation, configuration, source code where applicable, runbooks and completed training records for the client team.
Service operation under measured levels
In-life service runs to agreed service levels with monthly reporting of achievement, incidents and problems. Security events on monitored estates flow to the security operations centre with defined severity and response commitments.
Internal audit, management review and corrective action
Internal audits run to a programme covering every process annually. Nonconformities get a root-cause analysis, an owner and a due date. Management review each year feeds the Risk & Security Committee and, through it, the Board’s Audit & Risk Committee.
Buyer and Due Diligence Questions
What documents are in your standard due diligence pack?
Is your tax clearance current, and for how many years?
Do you have a current BPP Interim Registration Report?
Our project needs NITDA clearance. Can you support that?
What is the exact scope of your ISO certificates?
Can we audit you, or send a security questionnaire?
How do you evidence local content?
Do you carry insurance and can you provide bonds?
Requesting Certificate Copies for a Tender
Send your request to [email protected], copying [email protected], with the name of the procuring entity, the tender reference and closing date, and a list of the specific documents required. Where the tender demands certified true copies or notarised documents, say so and we will prepare them accordingly.
Standard turnaround is one working day for the electronic pack and two to three working days for certified hard copies delivered to Kano, Abuja or Lagos. For urgent closings, call +234 802 913 8013 and ask for the public sector business desk.
Need the compliance file today?
Tell us the tender reference and the closing date. Our public sector desk will assemble exactly what the evaluation committee asked for.