Pakistan Computer Emergency Response Team (PKCERT) · Pakistan

Pakistan Information Security Framework 2026 compliance software

Assess and evidence Pakistan's Cabinet-approved Information Security Framework across 234 controls and 13 domains, with audit-ready reporting.

At a glance
  • Issued byPKCERT (National CERT); approved by the Federal Cabinet, August 2026
  • Legal basisCERT Rules 2023 under PECA 2016; National Cyber Security Policy 2021
  • Controls234 controls (PISFID-001 to PISFID-234), per PKCERT's merged version
  • Domains13 (Governance, CIIP, Data Centre, Supply Chain, and 9 others)
  • Evidence basisDocumented control implementation, auditable by PKCERT
PISF 2026Available
Overview

What PISF 2026 requires

Who it applies to

  • Federal and provincial government ministries, divisions and departments
  • Autonomous bodies and corporations
  • Government, sectoral and other CERTs
  • Critical information infrastructure (CII) operators

The Pakistan Information Security Framework 2026 (PISF) is a Cabinet-approved national baseline for data protection, risk management, and critical infrastructure security. Developed by PKCERT, the National CERT, under the Computer Emergency Response Team Rules 2023 made under PECA 2016, and approved by the Federal Cabinet in August 2026, it applies to federal and provincial government bodies, autonomous bodies, corporations, CERTs and critical information infrastructure.

PKCERT's published merged version numbers 234 controls, PISFID-001 to PISFID-234, across 13 domains: Governance, Asset and Risk Management, Security Training, System and Communication Protection, Identity and Access Management, Data Protection and Privacy, Incident Response, Physical Security, Data Centre and Web Hosting Services, Secure Software Development Lifecycle, Supply Chain Management, Audit, and Critical Information Infrastructure Protection. Critical infrastructure incidents need a detailed report within 72 hours and other incidents within 120 hours, and organisations hosting outside Pakistan are expected to plan migration to data centres in the country.

Organisations already aligned to ISO/IEC 27001 or PK-CTDISR will find significant overlap. GRCLens surfaces those cross-mappings so evidence already captured counts towards PISF rather than being duplicated.

In the platform

How GRCLens supports PISF 2026

PISF 2026 runs on the same shared control model as every other framework in GRCLens, so evidence captured once can satisfy several obligations at the same time.

Full PISF control catalogue

All 234 PISFID controls in PKCERT's published version are pre-loaded across 13 domains, so assessment starts from a structured baseline rather than a blank spreadsheet.

CIIP and Data Centre readiness

PISF's largest domain, Critical Information Infrastructure Protection with 37 controls, and its Data Centre and Web Hosting Services domain receive dedicated assessment tracks with evidence guidance.

Cross-framework mapping

Controls are mapped to PK-CTDISR and ISO/IEC 27001. Evidence already collected for either framework is surfaced against the relevant PISF controls, eliminating duplication.

Regulator-ready reporting

Produce assessment reports and evidence packs formatted for PKCERT audit and Cabinet-level review.

Questions

PISF 2026 frequently asked questions

Is PISF 2026 mandatory?

For the bodies it names, yes. PISF 2026 was approved by the Federal Cabinet in August 2026 and rests on the National Cyber Security Policy 2021 and the Computer Emergency Response Team Rules 2023 made under PECA 2016. A Cyber Security Act has been proposed but not enacted, and a formal gazette notification of PISF had not been published as of September 2026, so confirm timelines with PKCERT.

Who must comply with PISF?

Federal and provincial government ministries, divisions and departments, autonomous bodies, corporations, CERTs and critical information infrastructure, as set out in PKCERT's published framework.

How many controls does PISF 2026 have?

234, numbered PISFID-001 to PISFID-234 in PKCERT's published merged version, across 13 domains. The largest is Critical Information Infrastructure Protection, with 37 controls.

How quickly must incidents be reported under PISF?

For critical information infrastructure, an initial report and then a detailed report within 72 hours. For other entities, within 120 hours.

How does PISF relate to PK-CTDISR?

CTDISR covers telecommunications licensees specifically; PISF is a broader national baseline. Many controls overlap. GRCLens maps them so a CTDISR-aligned organisation can quickly identify its PISF gaps.

Can GRCLens be hosted in Pakistan?

Yes. The platform can be deployed on-premises in your own data centre, which is the standard arrangement where data residency or PISF data localisation requirements apply.

Talk to us about PISF 2026

Security Solution Consultants provides PISF 2026 readiness and advisory alongside the platform, so you can combine tooling with hands-on expertise.