Country guide · Pakistan

Cyber security compliance in Pakistan

Pakistan's cybersecurity obligations moved quickly in 2026. The national information security framework, PISF 2026, was reported as approved by the Federal Cabinet in August, and a 90-day implementation plan followed in September. Telecom operators and financial institutions already work to their regulators' rules. A lot of what circulates online states the legal position wrongly, including claims that a Cyber Security Act has been passed. This page sets out what is actually in force.

At a glance
  • Frameworks listed7
  • Issuing bodies5
  • Framework pages2
  • Platform languagesEnglish and Arabic
  • DeploymentSaaS, private cloud or on-premises
PakistanChecked Sep 2026
What applies

Cybersecurity and data protection frameworks in Pakistan

Who issues each one and who must comply. Open a framework for its structure, obligations and how GRCLens runs it.

PKCERT, the National CERT

Pakistan Information Security Framework (PISF) 2026

Federal and provincial ministries, divisions and departments, autonomous bodies, corporations, CERTs and critical information infrastructure

Open the framework page →
Ministry of IT and Telecommunication, under PECA 2016

Computer Emergency Response Team Rules, 2023

Sets up the National, government and sectoral CERTs. Entities regulated by a sector regulator report incidents within one hour

Pakistan Telecommunication Authority (PTA)

Critical Telecom Data and Infrastructure Security Regulations, 2020 (CTDISR)

All PTA licensees

Open the framework page →
State Bank of Pakistan (SBP)

Enterprise Technology Governance and Risk Management Framework

Banks, development finance institutions and microfinance banks (BPRD Circular 05 of 2017)

State Bank of Pakistan (SBP)

Technology Risk Management Framework for Payment Institutions

Payment system operators, payment service providers and electronic money institutions. Compliance due 31 March 2026

Read the guide →
State Bank of Pakistan (SBP)

Framework on Outsourcing to Cloud Service Providers

Banks, microfinance banks, DFIs, digital banks, EMIs, PSOs and PSPs (BPRD Circular 01 of 2023)

Securities and Exchange Commission of Pakistan (SECP)

Guidelines on Cybersecurity Framework for the Insurance Sector, 2020

Insurers regulated by SECP

What is PISF 2026, and is it in force?

The Pakistan Information Security Framework is published by PKCERT, the National CERT, which developed it under the Computer Emergency Response Team Rules 2023. The revised 2026 version was published in March 2026 as a merged document with 13 domains, from governance and asset and risk management to data centre and web hosting services, supply chain management and critical information infrastructure protection.

The Federal Cabinet was reported to have approved PISF 2026 on 10 August 2026, and in September a national committee approved a 90-day plan to implement it at federal and provincial level. We could not find a formal gazette notification as of late September 2026, so treat it as approved, with implementation under way.

Who must comply with PISF?

PISF covers federal and provincial government ministries, divisions and departments, autonomous bodies, corporations, CERTs and critical information infrastructure. Critical infrastructure incidents need a detailed report within 72 hours and other incidents within 120 hours. Organisations hosting websites or applications outside Pakistan are expected to plan migration to data centres inside the country.

Does Pakistan have a Cyber Security Act?

Not yet. A Cyber Security Act that would create a national cybersecurity authority has been announced by the IT ministry, but it does not appear among the bills passed by the National Assembly. The legal base today is the Prevention of Electronic Crimes Act 2016, amended in January 2025, and the CERT Rules 2023 made under it. Pages describing a Cybersecurity Act 2025 as law are wrong.

What do telecom operators have to meet?

PTA's Critical Telecom Data and Infrastructure Security Regulations 2020, gazetted in November 2020, apply to all PTA licensees. They require a steering committee and a licensee CERT, critical patches within 72 hours, multi-factor authentication for critical telecom infrastructure, vulnerability assessment and penetration testing every six months, an annual third-party review and breach reporting to PTA within 72 hours. Data may not be stored outside Pakistan without PTA approval.

What does the State Bank of Pakistan require?

Banks, development finance institutions and microfinance banks work to the Enterprise Technology Governance and Risk Management Framework of 2017. Payment system operators, payment service providers and electronic money institutions have their own Technology Risk Management Framework, issued in October 2025 with compliance due by 31 March 2026. Cloud outsourcing across all of them falls under SBP's 2023 cloud framework, and card issuers and acquirers under the 2016 card security regulations.

Does Pakistan have a data protection law?

Not yet. A Personal Data Protection Bill has been drafted and consulted on but had not been enacted as of September 2026. Data residency obligations come instead from sector rules: CTDISR for telecoms, PISF for hosting, SBP's cloud framework for financial institutions, and the 2022 Cloud First Policy, which keeps community and private clouds for public sector data inside Pakistan.

How GRCLens runs Pakistani frameworks together

PISF 2026, CTDISR and SBP obligations share one control model in GRCLens with ISO/IEC 27001, so a telecom or bank evidences each control once across its regulators. Incident clocks, patching windows and testing cadences are tracked as indicators. GRCLens can run fully on-premises inside Pakistan, which suits PISF's hosting expectations and CTDISR's data rule.

Questions

Cyber compliance in Pakistan: common questions

Is PISF 2026 mandatory?

PISF 2026 was reported as approved by the Federal Cabinet in August 2026 and applies to federal and provincial government bodies, autonomous bodies, corporations, CERTs and critical information infrastructure. A formal gazette notification had not been published as of September 2026.

Has Pakistan passed a Cyber Security Act?

No. A Cyber Security Act has been announced but not enacted. The legal base is the Prevention of Electronic Crimes Act 2016 and the CERT Rules 2023 made under it.

Who issues PISF?

PKCERT, the National CERT of Pakistan, at pkcert.gov.pk. Note that pakcert.org is a private company, not the national CERT.

Which SBP framework applies to payment service providers?

The Technology Risk Management Framework for Payment Institutions (PSP&OD Circular 04 of 2025), with compliance due by 31 March 2026. The 2017 ETGRMF applies to banks, DFIs and microfinance banks.

Can telecom data be stored outside Pakistan?

Not without PTA approval, under the Critical Telecom Data and Infrastructure Security Regulations 2020.

Sources

Checked against the issuing bodies' own publications in September 2026. Regulations change, so confirm current requirements with the relevant regulator before relying on them.

Run Pakistan's frameworks on one platform

See GRCLens with your own frameworks loaded.