Cyber security compliance in Pakistan
Pakistan's cybersecurity obligations moved quickly in 2026. The national information security framework, PISF 2026, was reported as approved by the Federal Cabinet in August, and a 90-day implementation plan followed in September. Telecom operators and financial institutions already work to their regulators' rules. A lot of what circulates online states the legal position wrongly, including claims that a Cyber Security Act has been passed. This page sets out what is actually in force.
- Frameworks listed7
- Issuing bodies5
- Framework pages2
- Platform languagesEnglish and Arabic
- DeploymentSaaS, private cloud or on-premises
Cybersecurity and data protection frameworks in Pakistan
Who issues each one and who must comply. Open a framework for its structure, obligations and how GRCLens runs it.
Pakistan Information Security Framework (PISF) 2026
Federal and provincial ministries, divisions and departments, autonomous bodies, corporations, CERTs and critical information infrastructure
Open the framework page →Computer Emergency Response Team Rules, 2023
Sets up the National, government and sectoral CERTs. Entities regulated by a sector regulator report incidents within one hour
Critical Telecom Data and Infrastructure Security Regulations, 2020 (CTDISR)
All PTA licensees
Open the framework page →Enterprise Technology Governance and Risk Management Framework
Banks, development finance institutions and microfinance banks (BPRD Circular 05 of 2017)
Technology Risk Management Framework for Payment Institutions
Payment system operators, payment service providers and electronic money institutions. Compliance due 31 March 2026
Read the guide →Framework on Outsourcing to Cloud Service Providers
Banks, microfinance banks, DFIs, digital banks, EMIs, PSOs and PSPs (BPRD Circular 01 of 2023)
Guidelines on Cybersecurity Framework for the Insurance Sector, 2020
Insurers regulated by SECP
What is PISF 2026, and is it in force?
The Pakistan Information Security Framework is published by PKCERT, the National CERT, which developed it under the Computer Emergency Response Team Rules 2023. The revised 2026 version was published in March 2026 as a merged document with 13 domains, from governance and asset and risk management to data centre and web hosting services, supply chain management and critical information infrastructure protection.
The Federal Cabinet was reported to have approved PISF 2026 on 10 August 2026, and in September a national committee approved a 90-day plan to implement it at federal and provincial level. We could not find a formal gazette notification as of late September 2026, so treat it as approved, with implementation under way.
Who must comply with PISF?
PISF covers federal and provincial government ministries, divisions and departments, autonomous bodies, corporations, CERTs and critical information infrastructure. Critical infrastructure incidents need a detailed report within 72 hours and other incidents within 120 hours. Organisations hosting websites or applications outside Pakistan are expected to plan migration to data centres inside the country.
Does Pakistan have a Cyber Security Act?
Not yet. A Cyber Security Act that would create a national cybersecurity authority has been announced by the IT ministry, but it does not appear among the bills passed by the National Assembly. The legal base today is the Prevention of Electronic Crimes Act 2016, amended in January 2025, and the CERT Rules 2023 made under it. Pages describing a Cybersecurity Act 2025 as law are wrong.
What do telecom operators have to meet?
PTA's Critical Telecom Data and Infrastructure Security Regulations 2020, gazetted in November 2020, apply to all PTA licensees. They require a steering committee and a licensee CERT, critical patches within 72 hours, multi-factor authentication for critical telecom infrastructure, vulnerability assessment and penetration testing every six months, an annual third-party review and breach reporting to PTA within 72 hours. Data may not be stored outside Pakistan without PTA approval.
What does the State Bank of Pakistan require?
Banks, development finance institutions and microfinance banks work to the Enterprise Technology Governance and Risk Management Framework of 2017. Payment system operators, payment service providers and electronic money institutions have their own Technology Risk Management Framework, issued in October 2025 with compliance due by 31 March 2026. Cloud outsourcing across all of them falls under SBP's 2023 cloud framework, and card issuers and acquirers under the 2016 card security regulations.
Does Pakistan have a data protection law?
Not yet. A Personal Data Protection Bill has been drafted and consulted on but had not been enacted as of September 2026. Data residency obligations come instead from sector rules: CTDISR for telecoms, PISF for hosting, SBP's cloud framework for financial institutions, and the 2022 Cloud First Policy, which keeps community and private clouds for public sector data inside Pakistan.
How GRCLens runs Pakistani frameworks together
PISF 2026, CTDISR and SBP obligations share one control model in GRCLens with ISO/IEC 27001, so a telecom or bank evidences each control once across its regulators. Incident clocks, patching windows and testing cadences are tracked as indicators. GRCLens can run fully on-premises inside Pakistan, which suits PISF's hosting expectations and CTDISR's data rule.
Official portals and publications
Cyber compliance in Pakistan: common questions
Is PISF 2026 mandatory?
PISF 2026 was reported as approved by the Federal Cabinet in August 2026 and applies to federal and provincial government bodies, autonomous bodies, corporations, CERTs and critical information infrastructure. A formal gazette notification had not been published as of September 2026.
Has Pakistan passed a Cyber Security Act?
No. A Cyber Security Act has been announced but not enacted. The legal base is the Prevention of Electronic Crimes Act 2016 and the CERT Rules 2023 made under it.
Who issues PISF?
PKCERT, the National CERT of Pakistan, at pkcert.gov.pk. Note that pakcert.org is a private company, not the national CERT.
Which SBP framework applies to payment service providers?
The Technology Risk Management Framework for Payment Institutions (PSP&OD Circular 04 of 2025), with compliance due by 31 March 2026. The 2017 ETGRMF applies to banks, DFIs and microfinance banks.
Can telecom data be stored outside Pakistan?
Not without PTA approval, under the Critical Telecom Data and Infrastructure Security Regulations 2020.
Sources
Checked against the issuing bodies' own publications in September 2026. Regulations change, so confirm current requirements with the relevant regulator before relying on them.

Run Pakistan's frameworks on one platform
See GRCLens with your own frameworks loaded.