HomeBlogPCI DSS
PCI DSS

SBP Payment Security Rules vs PCI DSS: 2026

Sep 2026 · 9 min read

Isometric illustration of a mobile wallet, a fingerprint scanner, a bank building and a merchant card terminal linked to a security hub

Pakistani banks, payment service providers and electronic money institutions answer to two sets of expectations at once: the State Bank of Pakistan's own rules, and the card schemes' PCI DSS. They overlap heavily but are not the same, and much of what is written about them either overstates what SBP mandates or cites sections that have since been superseded. In October 2025 SBP issued a new technology risk framework for payment institutions with a compliance deadline of 31 March 2026, which makes this a good moment to set out how the pieces fit.

Does SBP require PCI DSS?

Not as a blanket certification mandate. The 2016 Regulations for Payment Card Security say that card service providers shall preferably comply with PCI DSS and PA-DSS. That is a strong expectation, not a hard requirement.

PSD Circular 09 of 2018 went further for digital payments, directing banks and microfinance banks to assess the feasibility of PCI DSS and PA-DSS for their digital payment systems and third-party providers.

The 2025 Technology Risk Management Framework for payment institutions requires them to adhere to PCI DSS guidelines when storing payment card data. That is a firm requirement for stored card data, but it is still not a requirement to hold a PCI DSS attestation. In practice the card schemes and acquirers will usually require validation anyway, so most card-handling institutions end up doing both.

Who do SBP's Regulations for Payment Card Security apply to?

They were issued on 10 June 2016 under the Payment Systems and Electronic Fund Transfers Act 2007 and took effect on 1 January 2017. They apply to all financial institutions and payment system operators and providers that issue, acquire or process payment cards, excluding social transfer cards.

They require a board-approved card security framework, reviewed at least annually, covering security risk assessment and control implementation. Card data breaches must be reported to SBP's Payment Systems Department in detail within a fortnight, and payment card systems require an annual external audit.

What is the 2025 Technology Risk Management Framework?

PSP&OD Circular 04 of 2025, dated 3 October 2025, applies to payment system operators, payment service providers and electronic money institutions. Compliance was due by 31 March 2026, and non-compliance attracts penal action.

It supersedes the outsourcing, security and risk management sections of the 2023 EMI Regulations and of the 2014 PSO and PSP Rules. Guides that still cite those older sections as current are out of date.

It applies in stages: written assurances at in-principle approval, baseline readiness at pilot, and full compliance at commercial launch.

What cyber controls does SBP expect from PSPs and EMIs?

Multi-factor authentication for privileged and remote access, network segmentation, security monitoring through a SIEM or security operations centre, and annual penetration testing of externally facing services and after significant changes. Critical patches must be deployed immediately, and the framework sets API security requirements including token expiry and logging of third-party sessions.

Governance requirements include a Head of IT and a separate Head of Information Security, and independent technology audits by firms on SBP's panel or PTA's approved list.

What digital fraud controls and liability rules apply?

The framework requires NADRA biometric verification at channel activation, new device registration and contact detail changes, device binding, and a cooling-off period of at least two hours after a device switch.

It also allocates liability with tight clocks. The sending institution is liable if a dispute is not lodged within 30 minutes of the customer's complaint. The receiving institution is liable if it does not block funds within 30 minutes of the case being lodged. Delayed alerts also shift liability.

For banks, SBP's 2023 digital fraud measures introduced a similar liability shift and a hold on cash-out of incoming wallet transfers. PCI DSS has nothing equivalent to any of this, which is one reason SBP compliance cannot be treated as a PCI DSS subset.

How must payment institutions manage third-party and fintech risk?

Material non-cloud outsourcing must be notified to SBP in writing seven business days in advance, and offshore outsourcing needs SBP's prior approval. Contracts must give SBP direct access, on-site assessment rights and the right to appoint an independent reviewer. The framework also lists tools for monitoring critical third parties, including nth-party supply chain details.

Cloud outsourcing sits under BPRD Circular 01 of 2023, which covers banks, development finance institutions, microfinance banks, EMIs, PSOs and PSPs.

What does the ETGRMF require of banks?

The Enterprise Technology Governance and Risk Management Framework, BPRD Circular 05 of 2017, applies to banks, development finance institutions and microfinance banks. It is not the framework for PSPs and EMIs, which now have the 2025 framework.

It is risk-based, requires board review of implementation at least quarterly, and requires established cyber breaches involving financial loss, data theft or major disruption, and outages of more than two hours, to be reported to SBP within 48 hours.

How fast must incidents be reported to SBP?

It depends on who you are. Banks report within 48 hours under the ETGRMF. Payment institutions report immediately under the 2025 framework, using its incident template. Card data breaches under the 2016 regulations require a detailed report within a fortnight, and the 2018 circular requires customers to be informed within 48 hours.

The widely repeated line that everyone reports to SBP within 48 hours is only true for banks.

What card-specific controls did SBP mandate?

PSD Circular 09 of 2018 required SMS and email alerts on all digital transactions, real-time fraud monitoring, a 3-D Secure implementation plan, and replacement of magnetic stripe cards with EMV chip and PIN. Later SBP instructions required issuers to block magnetic stripe fallback at the host.

How does PCI DSS map onto SBP's rules?

Broadly, SBP's asset inventory, segmentation, MFA, patching, penetration testing, logging and third-party oversight requirements map to PCI DSS requirements 1, 6, 8, 10, 11 and 12.8. An institution with a mature PCI DSS program will find much of the technical baseline already in place.

What SBP adds, and PCI DSS does not cover: NADRA biometric verification, device binding and cooling-off, 30-minute dispute liability, SBP outsourcing notifications and approvals, and regulator incident reporting. What PCI DSS adds: detailed cardholder data environment scoping, payment page script controls and formal validation to the schemes.

One housekeeping point: SBP's older texts still cite PA-DSS, which the PCI Security Standards Council has retired in favour of its Secure Software standards. Treat references to PA-DSS as references to the current software security standards.

How GRCLens supports SBP and PCI DSS together

GRCLens maps SBP obligations and PCI DSS v4.0.1 onto one control model, so a single MFA, patching or penetration testing control carries evidence for both, while SBP-only obligations such as dispute clocks and outsourcing notifications are tracked as their own controls. It is available in English and Arabic, and can run fully on-premises for institutions that keep regulated data in-house. It sits alongside PISF 2026 and PK-CTDISR for groups with wider Pakistani obligations.

Primary sources

State Bank of Pakistan: Regulations for Payment Card Security (2016); PSD Circular 09 of 2018; BPRD Circular 05 of 2017 and the ETGRMF; BPRD Circular 01 of 2023 on cloud outsourcing; PSP&OD Circular 04 of 2025 and the Technology Risk Management Framework for Payment Institutions. PCI Security Standards Council: PCI DSS v4.0.1.

This article is general information. Confirm your obligations directly with SBP and your acquirer.

This article is general information, not legal advice. Regulations change, so confirm current requirements with the relevant regulator before relying on them. Questions?info@grclens.net.

← All articles