Pakistan Cabinet Approves Cybersecurity Framework (PISF 2026)

ISLAMABAD — Pakistan’s federal cabinet on Monday (Aug. 10) approved the Pakistan Information Security Framework 2026 (PISF 2026), which officials describe as the country’s first unified, mandatory cybersecurity baseline for government institutions and critical infrastructure operators.

The framework was cleared at a cabinet meeting chaired by Prime Minister Shehbaz Sharif in Islamabad. It requires federal and provincial government bodies to adopt standardized incident-response procedures, undergo regular security audits, and migrate any government websites or applications currently hosted on servers outside Pakistan to data centres located inside the country.

The same meeting also cleared the unrelated National Housing Policy 2026, which directs new housing developments to comply with zoning rules, prioritize vertical construction and meet energy-efficiency codes. Ministers were told that banks have approved roughly Rs220 billion in loans under the prime minister’s Apna Ghar housing scheme, of which more than Rs32 billion has been disbursed. The cabinet also reversed a notice to terminate a 1981 investment treaty with Sweden and endorsed amendments to the Pakistan Oil Refining Policy 2023.

It is the cybersecurity framework, however, that carries the most direct consequences for Pakistan’s public-sector technology operations and for the private companies that host, build or manage government digital systems.

What the Framework Requires

The Ministry of Information Technology and Telecommunication placed the draft PISF 2026 before the cabinet, describing it as a foundational document meant to unify information-security standards under one national baseline with central oversight. The cabinet approved it on those terms and directed that implementation be ensured within a prescribed timeframe, though the government’s public readout of the meeting did not spell out specific compliance deadlines for individual requirements.

The framework, developed by National CERT — Pakistan’s National Cyber Emergency Response Team — introduces mandatory controls spanning eight areas:

Control AreaWhat It Covers
GovernanceCybersecurity oversight structures inside each organization
Risk ManagementRegular, documented risk assessments
Incident ResponseStandardized detection, escalation and reporting procedures
Data ProtectionSafeguards for personal and sensitive information
Physical SecurityProtection of facilities that house IT infrastructure
Supply Chain SecurityVetting of vendors, software developers and cloud providers
Secure Software Development“Security-by-design” requirements for new systems
Data Centres & HostingMinimum technical standards for servers, hosting and email providers

The rules apply to federal and provincial ministries, divisions, departments, autonomous bodies and corporations, sectoral and National CERTs, and any organization the government designates as Critical Information Infrastructure, or CII — a category covering systems whose disruption could threaten public safety, the economy or essential services. Organizations covered by the framework must also classify their critical digital assets, run resilience testing, coordinate with sectoral and National CERTs, and put staff through regular cybersecurity awareness training.

Reporting Deadlines and Local Hosting Rules

PISF 2026 sets fixed clocks for reporting confirmed cyber incidents. Entities designated as critical infrastructure must alert their sector regulator, their sectoral CERT and the National CERT as soon as an incident is verified, then file a full report within 72 hours. Other government organizations have up to 120 hours to submit a detailed report once an incident is confirmed.

Organization TypeInitial NotificationDetailed Report
Critical Information Infrastructure (CII)ImmediateWithin 72 hours
Other government organizationsNot specifiedWithin 120 hours

Vendors that run data centres, hosting platforms or email services for government clients take on a heavier compliance load: continuous monitoring of their networks, systematic vulnerability management, redundant backup systems, multi-factor login controls, and an independent security audit every year. Software vendors, cloud providers and hosting companies working with government agencies will also need cybersecurity clauses written directly into their contracts.

Separately, any government website or application currently hosted on servers outside Pakistan will need a documented plan to move that hosting to data centres inside the country — a data-localisation requirement that digital rights researchers in Pakistan have been tracking as part of a broader trend toward tighter national control over government data.

From CERT Rules to a National Baseline

PISF 2026 builds on groundwork Pakistan laid in 2023. The federal cabinet approved the CERT Rules that year under Section 51 of the Prevention of Electronic Crime Act, 2016, and in line with the National Cyber Security Policy 2021, creating the legal basis for a National CERT and sector-specific CERTs. National CERT — also known as PKCERT, and housed under the Cabinet Division — was formally established in March 2024 under Director General Dr. Haider Abbas and has since built out a National Security Operations Centre to monitor government networks around the clock.

PISF 2026 is the compliance layer built on top of that structure. Rather than simply creating response teams, it sets the specific technical and procedural standards those teams — and the organizations they protect — are now expected to meet. The framework followed consultations with federal and provincial governments, sector regulators, critical-infrastructure operators and other stakeholders that National CERT completed before submitting the draft for cabinet review in July.

A Parallel Deadline for Security Operations Centres

Cabinet approval follows a separate directive PKCERT issued in early July, giving both public and private sector organizations across Pakistan six months to stand up fully operational, continuously staffed cybersecurity operations centres, or SOCs, to monitor their own networks. The two measures are complementary: PISF 2026 sets the standards organizations must meet, while the SOC mandate builds the round-the-clock monitoring capacity needed to meet them. Businesses and government bodies already working through that six-month window will now need to align their build-out with PISF 2026’s specific controls.

Part of a Broader Digital Policy Push

The cybersecurity framework arrives alongside a series of other Pakistani digital-governance measures moving through the same institutions. Earlier in 2026, the federal cabinet approved a National AI Policy built around infrastructure, innovation, skills training and secure, ethical AI deployment, with provisions addressing misinformation and children’s online safety. That policy, together with the Digital Nation Pakistan Act 2025, established the Pakistan Digital Authority and a National Digital Commission chaired by the prime minister, which is expected to approve a national digital master plan covering AI and broader technology policy.

Taken together, the measures point to a broader effort to modernize and secure government technology systems as Pakistan’s digital footprint expands. Digital rights researchers, who separately track internet-governance and press-freedom cases in the country, have logged PISF 2026 under data-localisation and digital-sovereignty concerns in their public monitoring, though no major industry body or rights group had publicly issued formal objections to the framework itself as of this writing.

What Happens Next

With cabinet approval secured, implementation now shifts to individual ministries, provincial governments and the CII entities the framework designates — a list that has not been made public in full. Covered organizations will need to stand up governance structures, complete risk assessments and, where applicable, submit migration plans for any offshore-hosted government systems.

Several practical questions remain open. Official statements on the cabinet meeting did not detail enforcement mechanisms, penalties for non-compliance, or a specific master timetable for when each category of organization must meet the new standards. It is also unclear how the framework’s audit and reporting requirements will be resourced across smaller provincial departments, or how compliance will be verified beyond organizations’ own reporting. Neither the Ministry of Information Technology nor National CERT has published a full implementation calendar to date.

Leave a Reply

Your email address will not be published. Required fields are marked *