Pakistan Information Security Framework

The national baseline for information security across federal and provincial governments, autonomous bodies, regulators, and designated Critical Information Infrastructure β€” 234 individually numbered controls across 13 control documents, published by Pakistan's National CERT (PKCERT).

πŸ“„ Source: PKCERT official πŸ›οΈ Cabinet Division Β· CERT Rules 2023 πŸ‡΅πŸ‡° Applies to PK federal + provincial + designated CII
Total Controls
β€”
PISFID-001 β†’ β€”
Control Domains
13
Governance β†’ CII Protection
CII Breach Window
72hrs
120hrs for non-CII
Sovereignty Layers
4
Data Β· Compute Β· Network Β· Hosting
Audit Cadence
1/yr
Independent third-party
Status
Approved
90-day action plan in motion
How to read this page. All 234 controls below come from PKCERT's official PISF Controls Sheet (downloaded Sep 29, 2026). Cross-mapping to ISO 27001:2022 / NIST CSF 2.0 is indicative β€” verify each control against your auditor's checklist. CII tier definitions and sovereignty stack analysis from Waqar Uddin's independent July 2026 deep-dive. The 13-domain structure matches the PKCERT GRC Policies page exactly.

What PISF actually is

PISF turns Pakistan's National Cyber Security Policy 2021 (intent) and the CERT Rules 2023 (legal authority) into 234 individually auditable controls. Each control is scored, evidenced, and reviewed. It is the most detailed cybersecurity instrument Pakistan has issued.

🎯 Scope

Federal ministries, provincial departments, autonomous bodies, SOEs, regulators, CERTs, and designated Critical Information Infrastructure (CII). Private sector adoption is voluntary but MSSP-driven.

βš–οΈ Legal basis

CERT Rules 2023 (Cabinet Division) and National Cyber Security Policy 2021. Audit evidence is mandatory. Non-conformities must be remediated before the next cycle.

🚨 Breach reporting

Designated CII breaches β†’ sectoral CERT within 72 hours post-verification (same cadence as EU GDPR). Non-CII gets 120 hours.

🌐 Hosting mandate

"Organizations hosting websites/applications outside Pakistan shall plan migration to data centers within Pakistan's geographical boundaries." Plus a DC audit bar that pushes workloads out of any facility that fails.

13 control domains

Click any domain to filter the full 234-control list below. Counts are live from PKCERT's official sheet.

All 234 controls

Filter by domain, search by ID / name / sub-area / description. Click any row for the full description and cross-mapping.

Filter by domain β€” All
Control ID Domain Name & Sub-area
Showing 0 of 0 controls

The sovereignty stack

PISF adds the hosting layer to a stack that already had data, compute, and network. Each layer has its own regulator and its own enforcement mechanism. Together they are the architecture of Pakistan's digital sovereignty.

Critical Information Infrastructure β€” 4-tier classification

CII Protection is the largest domain by control count (37) and the most structurally rigorous. It classifies assets into four tiers based on the impact of compromise.

LevelImpact of compromise
CII owner obligations: 30 days to notify sector regulator of any material change to a critical system Β· Recovery measured against RTO, RPO, MTTD, and MTTR together (not uptime alone) Β· Sector coordination required across banking, telecom, energy, health, transport, and government digital infrastructure.

Implementation roadmap (90-day β†’ 12-month)

The federal government approved a 90-day cybersecurity action plan in September 2026. This is the practical sequence to move from zero to audit-ready.

Who does PISF apply to?

The merged PISF document names specific government categories, CERTs, and designated CIIs. The cabinet-level proposal used broader language covering all public and private entities β€” the final notification will clarify private-sector applicability.

SectorApplicabilityNotes

Sources & further reading

Primary sources

  1. PKCERT β€” GRC Policies page Β· The authoritative landing page for all 13 PISF documents
  2. PISF Introduction (Mar 2026) Β· The framework overview
  3. PISF Controls Sheet (xlsx) Β· All 234 controls, this page's data source
  4. PISF Merged Version (PDF) Β· All 13 documents in one file
  5. 13 individual control documents β€” Governance, Asset & Risk Management, Security Training, System & Communication Protection, IAM, Data Protection & Privacy, Incident Response, Physical Security, Supply Chain Management, Audit, Data Center & Web Hosting, SSDLC, CII Protection

Industry analysis

  1. Waqar Uddin β€” PISF Closes the Hosting Layer (Jul 2026) Β· Sovereignty-stack analysis used for CII tiers and stack layer definitions
  2. ProPakistani β€” Framework approval coverage (Aug 2026)
  3. Profit by Pakistan Today β€” 90-day action plan (Sep 2026)
  4. Bloom Pakistan β€” 90-day action plan
  5. FBR β€” National Cybersecurity Handbook Β· Employee-facing handbook tied back to PISF
  6. ImmuniWeb β€” PISF Compliance guide (Jun 2026)
  7. GRC Lens β€” PISF 2026 controls index