The federal cabinet has approved the Pakistan Information Security Framework 2026 (PISF 2026), introducing a unified approach to information security and cybersecurity standards across Pakistan.

The framework is designed to establish baseline security controls, strengthen centralized oversight, improve cybersecurity incident response, and enhance protection for critical information infrastructure.

The framework also sets security requirements for government organizations, data centres, web hosting, software development, email services and third-party suppliers. Organizations hosting websites and applications outside Pakistan will be required to plan their migration to data centres within Pakistan, while government entities will have to ensure security requirements are covered through contracts and service-level agreements with developers, hosting providers and cloud service providers.

The federal cabinet approved the PISF 2026 as a key guiding document for cybersecurity and directed that it be implemented effectively within the prescribed timeframe.

The PISF 2026 provides baseline information security controls for federal and provincial ministries, divisions and departments, autonomous bodies, corporations, CERTs and designated Critical Information Infrastructure (CII).

Its requirements cover governance, risk management, incident response, physical security, supply chain security, information security audits, data centres and web hosting, secure software development and the protection of critical information infrastructure.

Organizations will be required to establish formal mechanisms for responding to cybersecurity incidents, and report verified incidents within defined timelines.

Critical infrastructure incidents must be reported to the relevant sectoral regulator or CERT and the national CERT after verification. A detailed report must follow within 72 hours. Verified incidents involving non-critical infrastructure must be reported within 120 hours.

Critical Information Infrastructure entities will also have to maintain incident response plans, conduct resilience and stress testing, test backup restoration and coordinate with sectoral and national CERTs.

The PISF 2026 was developed by the National CERT under the CERT Rules 2023. It was finalized following consultations with relevant stakeholders before being submitted to the federal cabinet.

The Ministry of Information Technology and Telecommunication presented the draft framework during a federal cabinet meeting chaired by Prime Minister Shehbaz Sharif on Monday.

The cabinet was informed that the framework was prepared to create a comprehensive and unified system of baseline information security standards and ensure centralized oversight of information security across the country.

Get the latest tech news, telecom insights, and product launches wherever you prefer.

Add ProPakistani to Preferred Sources and see more of our stories in Google Search and Top Stories.

Shares