What Is PISF? Pakistan Information Security Framework Explained (2026) | Sahl
What Is PISF (Pakistan Information Security Framework)? The Complete Guide
PISF (Pakistan Information Security Framework) is Pakistan’s national cybersecurity and information-security framework, published by PKCERT (National CERT), that sets mandatory, auditable security controls for government bodies, critical infrastructure operators, financial institutions, and their technology vendors. Sahl helps organizations map, implement, and evidence PISF controls automatically instead of building compliance from spreadsheets.
This guide covers everything a compliance lead, CISO, or IT manager in Pakistan needs to know about PISF in 2026 — what it is, who published it, who must comply, how it’s structured, and how it compares to frameworks like ISO 27001 and NIST CSF.
Who Publishes PISF?
PISF is published by PKCERT — Pakistan’s National Computer Emergency Response Team — which operates under the Cabinet Division and was established in 2024. PKCERT’s mandate was further strengthened by the Cybersecurity Act 2025, which also created the National Cybersecurity Authority (NCA) to oversee national-level cyber governance. PISF is the control framework organizations are expected to align to, while PKCERT and the NCA handle incident response, national advisories, and threat intelligence.
The framework went through a formal consultation cycle — a revised version (PISF 2025, later updated toward a 2026 version) was briefed to stakeholders in Islamabad and put through public feedback before submission to the federal cabinet, following consultation with federal and provincial governments, regulators, and critical infrastructure operators.
Who Must Comply With PISF?
PISF applies to:
- Federal and provincial government ministries, divisions, and departments
- Autonomous bodies and corporations under public-sector control
- CERTs operating at sector or organizational level
- Designated Critical Information Infrastructure (CII) — energy, telecom, transport, and similar sectors
- Financial institutions — banks and fintech, alongside existing State Bank of Pakistan(SBP) security expectations
- Technology suppliers and vendors who build, host, or operate systems and applications for any of the above
In short, PISF applies directly to organizations that handle government data, support critical infrastructure, or operate in financial services. Technology, hosting, and IT service providers may also need to meet PISF requirements when their clients require it contractually.
How is PISF Structured?
PISF organizes requirements into domains, each containing individually numbered, auditable controls — the current version spans 13 mandatory control documents covering 238+ individually numbered controls. This is a much more granular structure than most people expect from a “government framework” — it reads closer to a hybrid of ISO 27001 Annex A and NIST CSF, purpose-built for the Pakistani regulatory context.
Key domains organizations consistently need help with include:
| Domain area | What it covers |
| Governance & Risk Management | Board-level accountability, formal risk assessment cycles, policy ownership |
| Data Protection | Classification, handling, and protection of sensitive/personal data |
| Incident Response | Standardized detection, escalation, and CERT coordination procedures |
| Business Continuity & Disaster Recovery | BCM/DR plans, resilience testing, recovery time objectives |
| Physical Security | Facility, hardware, and access controls |
| Supply Chain / Third-Party Risk | Vendor risk assessment and contractual security requirements |
| Secure Software Development (Domain 11) | Secure SDLC, threat modelling, code review, CI/CD security testing |
| Web Application Security (Domain 11) | Testing against the OWASP Top 10, session/API security, input validation |
| Data Center & Hosting | Data residency — organizations hosting outside Pakistan are expected to plan migration to compliant in-country data centers |
| Awareness & Training | Recurring cybersecurity awareness training for staff |
Two of the most cited application-security controls are EDC-WAS-07.6 (Web Application Security) and ESSDLC-SDLC-2.1 (Secure Software Development Life Cycle) — both fall under Domain 11 and are the controls most technology vendors get audited against first.
Is PISF Mandatory?
PISF is the national baseline cybersecurity standard organizations in scope are expected to adopt and be audited against — this is confirmed and formalized through the framework’s cabinet submission process and its grounding in the Cybersecurity Act 2025 and CERT Rules 2023. It is mandatory for public-sector organizations and designated CII entities specifically; financial institutions layer it on top of existing SBP requirements.
If you’re unsure whether your specific entity type falls within the mandatory scope, a proper gap assessment can help clarify your obligations quickly. See our How to Comply With PISF Checklist for guidance.
PISF vs. ISO 27001 vs. NIST CSF vs. SAMA CSF
PISF wasn’t built in isolation — its domain-and-control model deliberately mirrors international standards so organizations already working toward ISO 27001 or NIST don’t have to start from zero.
| Framework | Region | Structure | Best mapped to PISF for |
| PISF | Pakistan | 13 control documents, 238+ controls, domain-based | – |
| ISO/IEC 27001 | Global | Annex A technical + organizational controls |
Governance, risk, ISMS controls |
| NIST CSF 2.0 | Global (US- origin) | 6 functions: Govern, Identify, Protect, Detect, Respond, Recover | Risk management, detection/response |
| SAMA CSF | Saudi Arabia | 4 domains, 32 subdomains, maturity levels 0–5 | Structure/maturity-model comparison for MENA-facing orgs |
| OWASP Top 10 / ASVS | Global | Application vulnerability classes |
Domain 11 web/app security controls |
If your organization already holds ISO 27001 or has done SAMA CSF work (common for Sahl’s Saudi and MENA clients), a large share of that evidence is directly reusable for PISF — the gap is usually in Pakistan-specific requirements like data residency and PKCERT incident-reporting procedures, not in rebuilding controls from scratch.
Why PISF Compliance Matters Right Now
Pakistan has seen a run of high-profile data exposures, and web/mobile applications remain among the most exploited entry points for attackers into government and financial systems. Beyond risk reduction, PISF conformity is fast becoming:
- A prerequisite for government and enterprise contracts
- A due-diligence checkpoint for financial-sector partnerships and audits
- A trust signal for regulators, investors, and enterprise customers evaluating a vendor
How Sahl Helps With PISF Compliance
Sahl is an AI-powered GRC automation platform designed for MENA and South Asian compliance needs. Unlike generic global tools, Sahl includes PISF compliance as a core capability.
Sahl helps organizations:
- Map existing controls (ISO 27001, SAMA CSF, PDPL, NCA ECC) to PISF domains automatically, so you’re not starting evidence collection from scratch
- Run structured gap assessments against all 13 PISF control documents
- Automate evidence collection for governance, risk, incident response, BCM, and Domain 11 application-security controls
- Track remediation with owners, deadlines, and audit-ready reporting
- Stay current as PISF moves through revisions (2025 → 2026 and beyond)
FAQ
1- What does PISF stand for?
PISF stands for Pakistan Information Security Framework — the national cybersecurity control framework published by PKCERT.
2- Who publishes PISF?
PKCERT (Pakistan’s National Computer Emergency Response Team), operating under the Cabinet Division, with its mandate reinforced by the Cybersecurity Act 2025.
3- Is PISF the same as ISO 27001?
No, but they’re closely related. PISF is Pakistan’s own national framework; its domain-and-control structure conceptually mirrors ISO 27001 Annex A, so ISO 27001 evidence is largely reusable for PISF compliance.
4- Who has to comply with PISF?
Government ministries and departments, autonomous bodies, CERTs, designated Critical Information Infrastructure operators, financial institutions, and the technology vendors that serve them.
5- How many controls does PISF have?
The current version spans 13 mandatory control documents with 238+ individually numbered controls.
6- Does PISF apply to private companies?
Directly, it targets public-sector, CII, and financial- sector entities — but private technology vendors and suppliers serving those sectors are pulled into scope contractually.
7- How is PISF different from the Cybersecurity Act 2025?
The Cybersecurity Act 2025 is the legal/regulatory foundation that creates the National Cybersecurity Authority and strengthens PKCERT’s mandate. PISF is the practical control framework organizations implement and get audited against under that legal authority.

