The national baseline for information security across federal and provincial governments, autonomous bodies, regulators, and designated Critical Information Infrastructure β 234 individually numbered controls across 13 control documents, published by Pakistan's National CERT (PKCERT).
PISF turns Pakistan's National Cyber Security Policy 2021 (intent) and the CERT Rules 2023 (legal authority) into 234 individually auditable controls. Each control is scored, evidenced, and reviewed. It is the most detailed cybersecurity instrument Pakistan has issued.
Federal ministries, provincial departments, autonomous bodies, SOEs, regulators, CERTs, and designated Critical Information Infrastructure (CII). Private sector adoption is voluntary but MSSP-driven.
CERT Rules 2023 (Cabinet Division) and National Cyber Security Policy 2021. Audit evidence is mandatory. Non-conformities must be remediated before the next cycle.
Designated CII breaches β sectoral CERT within 72 hours post-verification (same cadence as EU GDPR). Non-CII gets 120 hours.
"Organizations hosting websites/applications outside Pakistan shall plan migration to data centers within Pakistan's geographical boundaries." Plus a DC audit bar that pushes workloads out of any facility that fails.
Click any domain to filter the full 234-control list below. Counts are live from PKCERT's official sheet.
Filter by domain, search by ID / name / sub-area / description. Click any row for the full description and cross-mapping.
| Control ID | Domain | Name & Sub-area |
|---|
PISF adds the hosting layer to a stack that already had data, compute, and network. Each layer has its own regulator and its own enforcement mechanism. Together they are the architecture of Pakistan's digital sovereignty.
CII Protection is the largest domain by control count (37) and the most structurally rigorous. It classifies assets into four tiers based on the impact of compromise.
| Level | Impact of compromise |
|---|
The federal government approved a 90-day cybersecurity action plan in September 2026. This is the practical sequence to move from zero to audit-ready.
The merged PISF document names specific government categories, CERTs, and designated CIIs. The cabinet-level proposal used broader language covering all public and private entities β the final notification will clarify private-sector applicability.
| Sector | Applicability | Notes |
|---|