PISF 2026: What Actually Changed From Last Year’s PISF 2025 Draft

In December 2025, we covered the draft Pakistan Information Security Framework (PISF) 2025, a framework put out by the National Cyber Emergency Response Team (National CERT/PKCERT) for public consultation, still unfinished and still a proposal. Eight months later, it isn’t a proposal anymore.

On August 10 to 11, 2026, Pakistan’s federal cabinet, chaired by Prime Minister Shehbaz Sharif, formally approved the Pakistan Information Security Framework 2026 (PISF 2026) as the country’s official cybersecurity baseline for the public sector. National CERT confirmed the approval in an official announcement, describing the framework as “globally aligned and locally tailored.” Here’s what’s actually different, and what’s simply been confirmed.

What Stayed the Same

The core architecture hasn’t been thrown out. PISF 2026 is still organized around the same 13 categories of “Essential Controls” the 2025 draft introduced: Governance, Asset & Risk Management, Security Training, System & Communication Protection, Identity & Access Management, Data Protection & Privacy, Incident Response, Physical Security, Data Centre & Web Hosting, Secure Software Development (SSDLC), Supply Chain Management, Audit, and CII Protection. It’s still built under the CERT Rules 2023, developed by National CERT with support from the Ministry of IT and Telecommunication, and it still applies to the same broad public-sector universe.

So this isn’t a rewrite. It’s the same framework, finalized.

banner-3-implementation-soon

What’s Actually New in the 2026 Version

1. It’s binding, not a draft. This is the single biggest change. PISF 2025 was open for public review; consultation closed December 4, 2025, and it was never formally launched as policy. PISF 2026 has cabinet approval and a directive that its effective implementation be ensured within the prescribed timeframe. That’s the difference between a proposal and a national requirement.

2. A specific control count: 234. According to National CERT’s own PISF 2026 announcement, the framework establishes a national baseline of 234 essential security controls across those 13 categories, described as a unified, scalable, and risk-based approach to information security. That specific number wasn’t public during the draft-stage coverage.

3. Concrete incident-reporting timelines. The 2025 draft talked about incident response controls in general terms. The approved 2026 version, per cabinet-briefing coverage, sets actual clocks: verified incidents involving Critical Information Infrastructure (CII) must be reported to the relevant sectoral regulator or CERT, and to the National CERT, with a detailed report following within 72 hours. Verified incidents involving non-critical infrastructure get 120 hours.

4. A data localization requirement. Organizations currently hosting websites or applications outside Pakistan are now required to plan migration to in-country data centres, a concrete operational obligation that wasn’t part of the draft-stage summary.

5. Explicit third-party and vendor accountability. Government entities must now ensure security requirements are written directly into contracts and service-level agreements (SLAs) with developers, hosting providers, and cloud service providers. This closes a gap where vendor risk often falls through the cracks.

6. A companion audit framework. Alongside PISF 2026, National CERT has also published a separate Audit Engagement & Oversight Framework, setting out how information-security audits against the national baseline will actually be conducted and overseen.

7. Implementation guidance is still pending. To National CERT’s credit, its own announcement is upfront about this: a dedicated Implementation Plan for organizations “will be published soon.” In other words, the what is now official; the detailed how is still being finalized.

banner-2-234-controls

Who This Actually Applies To

Per National CERT’s own announcement, PISF 2026 applies to:

  • Federal and provincial ministries, divisions, and departments
  • Autonomous bodies
  • Public sector corporations
  • CERTs (sectoral and national)
  • Designated Critical Information Infrastructure (CII) entities

Private-sector organizations aren’t directly bound by PISF 2026 unless they fall into one of these categories or operate as a vendor or contractor to one, which is exactly where the new SLA requirement (point 5 above) starts to matter for private IT vendors and cloud providers serving government clients.

Why This Matters, Beyond the Public Sector

If you’re not a government IT officer, this can still read as bureaucratic housekeeping. It isn’t, for two reasons. First, the data-localization and vendor-SLA requirements will ripple into Pakistan’s private hosting, cloud reseller, and dev-agency market, since many of them contract with government bodies. Second, a binding national baseline with real timelines and audit oversight is a meaningful marker of how seriously incident response and CII protection are now being treated at a policy level, something worth watching regardless of what sector you’re in.

What We’re Still Verifying

In the interest of not overstating the comparison: we don’t have machine-readable text of the original December 2025 draft PDFs to run a clean line-by-line diff against the March 2026 “Revised Version” documents now on National CERT’s site. It’s possible some of the items above, like the incident timelines or localization requirement, existed in the draft in some form and simply weren’t surfaced in earlier press coverage, rather than being entirely new additions. We’re treating this piece as “what’s now confirmed and binding” rather than a definitive draft-to-final diff, and will update if National CERT publishes clearer version-comparison notes.

Get notified when we publish

No spam, unsubscribe anytime.

Read our privacy policy for more info.

Leave a Comment

Your email address will not be published. Required fields are marked *