The Pakistan Information Security Framework 2026 (PISF 2026) is the national baseline of information security controls for federal and provincial government bodies, autonomous entities, corporations, CERTs, and designated Critical Information Infrastructure (CII) in Pakistan. PISF 2026 was issued by the National Cyber Emergency Response Team (PKCERT), under the oversight of the National Telecommunication and Information Security Board (NTISB), in line with the National Cyber Security Policy 2021 and the CERT Rules 2023.
Cabinet approval changes information security compliance in Pakistan from a voluntary internal practice into a mandatory, audited government standard. This article covers 8 core areas: what PISF 2026 requires, who must comply, its 13 control domains, its 4-phase implementation roadmap, its compliance scoring method, its audit process, CII protection, and its relationship to ISO 27001 and NIST CSF.
What Is PISF 2026?
PISF stands for Pakistan Information Security Framework. It is a set of 13 mandatory control documents that define the minimum information security requirements for government and critical-sector organizations in Pakistan.
PKCERT, the National Cyber Emergency Response Team under the Government of Pakistan, issued PISF 2026 as the national baseline for information security. NTISB (National Telecommunication and Information Security Board) provides oversight, and nCERT (the national CERT function) supports incident coordination and compliance verification.
PISF 2026 is grounded in two legal instruments:
- National Cyber Security Policy 2021: the policy document that first established the need for a unified national security baseline.
- CERT Rules 2023: the regulatory rules that formalized CERT reporting, oversight, and enforcement structures.
The framework applies the term “organization” throughout its 13 documents to refer collectively to federal and provincial ministries, divisions, departments, autonomous bodies, corporations, CERTs, and designated CIIs.
Why Did the Federal Cabinet Approve PISF 2026?
The federal cabinet approved PISF 2026 to close a long-standing gap in Pakistan’s public-sector cybersecurity: the absence of one unified, mandatory security baseline across government entities. Before PISF, information security practices varied widely between ministries, departments, and state corporations, with no standardized reporting or audit requirement.
Cabinet-level approval signals three things:
- National priority: Information security has moved from a department-level IT issue to a whole-of-government policy matter.
- Enforcement authority: NTISB and PKCERT now have a cabinet-backed mandate to audit and report on compliance.
- Budget legitimacy: Organizations gain formal justification to allocate funds for information security solutions, training, certification, and audits, as PISF explicitly requires.
What Problem Does PISF 2026 Solve?
Government systems in Pakistan handle citizen data, financial records, and critical services. Fragmented security practices increase the likelihood of breaches, service outages, and non-compliance with sector regulators such as the State Bank of Pakistan (SBP) or the Pakistan Telecommunication Authority (PTA). PISF 2026 addresses this by standardizing controls across 13 domains, from governance to Critical Information Infrastructure protection.
Key Objectives of PISF 2026
PISF 2026 establishes 5 core objectives:
- Define mandatory baseline security controls for federal and provincial organizations.
- Standardize compliance reporting through NTISB, nCERT, and sectoral CERTs.
- Reduce cyber incident response time through defined reporting timelines.
- Protect Critical Information Infrastructure (CII) with dedicated, higher-tier controls.
- Build long-term security capability through mandatory training and governance structures.
What Is the Difference Between PISF 2025 and PISF 2026?
PISF 2025 and PISF 2026 refer to the same national framework at different stages of development. PKCERT’s earlier consultation material referred to the revised framework as “PISF-2025,” while the finalized, cabinet-approved version is officially labeled “PISF 2026.”
This naming transition creates confusion for organizations searching for the framework online. The table below clarifies the distinction.
| Aspect | PISF 2025 (Draft/Consultation) | PISF 2026 (Current, Official) |
|---|---|---|
| Status | Draft under consultation | Finalized and cabinet-approved |
| Naming | Referred to as “PISF-2025” in early PKCERT material | Officially titled “Pakistan Information Security Framework (PISF) 2026” |
| Authority | Consultation-stage, PKCERT-led | Approved framework, backed by federal cabinet |
| Applicability | Not enforceable | Mandatory baseline for covered organizations |
| Structure | Early draft of control domains | 13 finalized “Essential Controls” documents |
Organizations should treat PISF 2026 as the current, authoritative version. Any reference to “PISF 2025” in older material describes the same underlying framework before its final approval and rename.
Who Needs to Comply With PISF 2026?
PISF 2026 applies to all federal and provincial government ministries, divisions, and departments, along with autonomous bodies, corporations, CERTs, and designated Critical Information Infrastructure (CII). The framework uses the umbrella term “organization” to describe any entity within this scope.
Organizations Covered by PISF 2026
- Federal government ministries and divisions
- Provincial government departments
- Autonomous bodies
- State-owned corporations
- CERTs (organizational, sectoral, and national)
- Designated Critical Information Infrastructure (CII) entities
- Regulators overseeing CII sectors
- Service providers and third parties that design, manage, or operate CII systems
Is PISF Mandatory in Pakistan?
Yes. PISF establishes mandatory baseline information security controls, and oversight audits are performed by nCERT, NTISB, sectoral CERTs, and relevant regulators.
Is PISF Applicable to Private Companies?
Not automatically. PISF’s scope is defined around government, CII, and CII-adjacent entities. A private company only falls under PISF if it is:
- Formally designated as a Critical Information Infrastructure (CII) organization, or
- A regulator, service provider, or third party that designs, manages, or operates systems supporting a CII, or
- A supplier or contractor bound by PISF-aligned contractual obligations from a covered organization.
Private businesses outside these categories are not automatically required to comply with PISF, though many choose voluntary alignment for contract eligibility with government clients.
What Are the 13 Essential Control Documents in PISF 2026?
PISF 2026 is built from 13 separate “Essential Controls” documents, each covering one security domain. This modular structure lets organizations implement controls in phases and lets regulators audit each domain independently.
The 13 PISF 2026 Control Domains
- Essential Governance Controls : defines roles, responsibilities, and oversight structures for information security.
- Essential Asset and Risk Management Controls : covers asset inventory, classification, and risk assessment.
- Essential Security Training Controls : mandates awareness and role-based training for all staff.
- Essential System and Communication Protection Controls : covers network security, endpoint protection, logging, and backups.
- Essential Identity and Access Management Controls : covers authentication, authorization, and privileged access.
- Essential Data Protection and Privacy Controls : covers data classification, retention, and breach reporting.
- Essential Incident Response Controls : covers incident classification, reporting timelines, and business continuity.
- Essential Physical Security Controls : covers facility access, surveillance, and fire safety.
- Essential Data Centre and Web Hosting Services Controls : covers hosting security and data localization.
- Essential Secure Software Development Life Cycle Controls : covers secure coding and application testing.
- Essential Supply Chain Management Controls : covers third-party and vendor risk management.
- Essential Audit Controls : covers internal and external audit requirements.
- Essential CII Protection Controls : covers additional obligations for Critical Information Infrastructure.
Each document defines requirements at the “shall” level, meaning implementation is not optional for organizations within scope.
How Is PISF 2026 Implemented? (The 4-Phase Roadmap)
PISF 2026 uses a 4-phase implementation roadmap that sequences the 13 control domains from foundational governance to independent audit. This phased structure prevents organizations from attempting all 13 domains simultaneously without the governance foundation in place first.
The 4 Phases of PISF Implementation
- Phase 1 – Essential Governance Controls. Organizations define policies, standards, procedures, roles, responsibilities, and oversight mechanisms. This phase establishes the foundation every later phase depends on.
- Phase 2 – Essential Asset & Risk Management Controls. Organizations identify and evaluate critical assets through a formal risk assessment process, then design controls based on that risk profile.
- Phase 3 – Essential Core Controls. This phase bundles system and communication protection, identity and access management, data protection and privacy, incident response, physical security, and supply chain management. Where applicable, it also includes data centre and web hosting controls, SSDLC controls, and CII protection controls.
- Phase 4 – Essential Audit Controls. Internal and external audits validate compliance, assess control effectiveness, and drive continual improvement.
Security training runs continuously across all 4 phases rather than as a standalone phase.
What Are the PISF 2026 Compliance Criteria?
PISF 2026 measures compliance through 2 linked tables: control applicability and implementation maturity.
Table 1 — Applicability: each control is marked “In Scope” when it addresses a relevant process, asset, or risk, or “Out of Scope” when it does not apply to the organization’s Information Security Management System (ISMS).
Table 2 — Maturity levels: PISF 2026 defines 4 compliance maturity levels: Not Compliant, Partially Compliant, Mostly Compliant, and Fully Compliant. Auditors use this documentation to calculate an overall compliance score during Phase 4 audits.
What Do the Core PISF 2026 Controls Require?
- Governance: Organizations must build an independent information security function, appoint a security lead (CISO, CIO, CRO, or equivalent) reporting to the head of the organization, and form a steering committee that assigns roles through a RACI matrix.
- Asset and Risk Management: Organizations must maintain an asset inventory, classify assets by criticality, conduct formal risk assessments, and maintain a risk register and treatment plan for auditors.
- Security Training: All employees must complete mandatory awareness training before system access is granted, covering password management, phishing, social engineering, secure remote work, mobile device security, data privacy, and incident reporting.
- System and Communication Protection: Organizations must apply network segmentation, perimeter controls, endpoint protection, and centralized logging. Critical event logs require 12-month retention; non-critical logs require 3-month retention.
- Identity and Access Management (IAM): Organizations must enforce multi-factor authentication, least-privilege access, and privileged access controls including session monitoring and just-in-time elevation.
- Data Protection and Privacy: Organizations must classify data by sensitivity, encrypt critical data in transit, and report data breaches within defined timelines 72 hours for critical infrastructure and 120 hours for non-critical infrastructure.
- Incident Response: Organizations must classify incidents by severity, run mock drills, and follow the same 72-hour and 120-hour reporting timelines that apply to data breaches, alongside annual Business Impact Analysis and Disaster Recovery testing.
- Physical Security: Organizations must control access to data centers and network cabinets using biometric locks, smart cards, or manned guards, supported by CCTV and fire safety training.
- Data Centre and Web Hosting: Organizations hosting websites or applications outside Pakistan must plan migration to data centers within Pakistan’s geographical boundaries , one of PISF 2026’s most significant new requirements. Email systems require SPF, DKIM, and DMARC validation.
- SSDLC: Organizations that develop software must embed security from requirements analysis through deployment, using SAST, DAST, IAST, and SCA testing proportional to application risk.
- Supply Chain Management: Organizations must assess supplier risk across the full supplier lifecycle and enforce secure offboarding, including data destruction and access revocation.
How Does a PISF Audit Work?
PISF audits combine internal self-assessment with external regulatory oversight, conducted at least annually by independent, certified auditors. Organizations establish an internal audit function and adopt a Control Self-Assessment (CSA) process, while sector regulators and nCERT/NTISB conduct external oversight audits. Audit firms registered with nCERT, sectoral CERTs, or the relevant regulator are the preferred choice for consultancy, internal audits, and external audits.
What Is CII Protection Under PISF 2026?
PISF 2026 applies an additional, higher-tier layer of controls to organizations designated as Critical Information Infrastructure. PISF classifies CII assets into 4 levels based on impact of compromise: Most Critical, Highly Critical, Critical, and Non-Critical.
CII organizations carry 5 special obligations:
- 30-day notification of material changes to CII design, configuration, or operations.
- 72-hour breach reporting to the relevant sectoral CERT.
- Periodic resilience and stress testing of power, cooling, and network components.
- Supply chain risk assessment for procurement of software, hardware, and services.
- Annual internal and external audits, plus audits triggered by material configuration changes.
How Does PISF 2026 Compare to ISO 27001 and NIST CSF?
PISF 2026 is a Pakistan-specific, government-mandated compliance framework, while ISO 27001 and NIST CSF are internationally recognized, voluntary security standards. PISF functions as the national regulatory baseline that Pakistani organizations must meet, independent of any international certification they pursue.
| Aspect | PISF 2026 | ISO 27001 | NIST CSF |
|---|---|---|---|
| Governing body | PKCERT / NTISB | ISO | US NIST |
| Nature | Mandatory | Voluntary certification | Voluntary framework |
| Geographic scope | Pakistan-specific | Global | Originated in the US |
| Structure | 13 Essential Controls | Annex A / ISMS | 5 core functions |
| Audit model | nCERT/NTISB oversight | Accredited certification bodies | Self-assessment |
Organizations already certified against ISO 27001 find substantial control overlap with PISF in governance, risk management, and incident response. PISF adds Pakistan-specific requirements that international standards do not cover, including mandatory data localization and fixed 72-hour and 120-hour CERT reporting timelines.
Which Bodies Oversee PISF 2026?
PKCERT issues PISF 2026, NTISB provides security oversight, and nCERT coordinates incident reporting and compliance verification. Sectoral regulators , including PTA, SBP, SECP, NEPRA, OGRA, HEC, and CAA , operate their own sectoral CERTs in coordination with nCERT and NTISB.
Frequently Asked Questions About PISF 2026
Question 1: What is Pakistan Information Security Framework 2026?
Answer: PISF 2026 is the national baseline of mandatory information security controls issued by PKCERT for federal and provincial government organizations, autonomous bodies, corporations, CERTs, and designated Critical Information Infrastructure in Pakistan.
Question 2: How do you implement PISF?
Answer: Organizations implement PISF through its 4-phase roadmap: governance first, then asset and risk management, then core security controls, then formal audit.
Question 3: How do I get PISF certified?
Answer: PISF does not issue a single certification. Organizations undergo internal and external compliance audits against the 13 Essential Controls documents, scored using the In Scope/Out of Scope and compliance maturity tables.
Question 4: What happens if an organization is not compliant with PISF?
Answer: Non-compliant organizations must document corrective actions, remediate gaps within defined timelines, and, for non-compliant data centers, migrate to compliant infrastructure.
Question 5: Does PISF apply to cloud service providers?
Answer: Yes. Where a cloud provider hosts or processes data for a covered organization, PISF’s supply chain and data centre controls apply, and the covered organization remains accountable through contracts and audit rights.
Getting Support for PISF 2026 Compliance
Organizations without internal information security expertise can outsource consultancy, risk assessment, and audit support to nCERT-registered or sectoral-CERT-registered firms, as PISF’s own governance controls permit. Building a compliant program across 13 control domains, 4 implementation phases, and formal audit requirements represents significant work for teams managing this alongside core operations.
Apprise Cyber supports organizations through the PISF compliance journey, including gap assessments against the 13 Essential Controls, governance and risk management setup, and audit-readiness preparation. Organizations evaluating external support should verify a firm’s registration status with nCERT, sectoral CERTs, or the relevant regulator, in line with PISF’s own guidance on engaging external expertise.

