Loading...

Certifications & Standards

ISO 27001, SOC2, CMMI, PCI-DSS, ISO 22301 & ISO 27701

ISO 27001 CMMI PSEB Certify to Export
Share:
Share:
Share:

Key Data & Rates

Key IT Certifications Relevant to Pakistani Companies
Industry certifications valued in Pakistan IT sector with costs and providers Verified May 3, 2026
CertificationProviderCost (PKR)ValidityRelevance Reference
ISO 27001 (InfoSec)ISO/BSI200,000-1,000,0003 yearsGovernment contracts, banking, BPO PSEB Certify to Export – ISO 27001
ISO 9001 (Quality)ISO/BSI150,000-500,0003 yearsManufacturing, services, export PSEB Certify to Export – ISO 9001
CMMI Level 2-5ISACA/CMMI Institute500,000-3,000,0003 yearsSoftware development, government PSEB – CMMI Certification Support
GDPR CompliancePSEB ProgramPartially subsidizedOngoingEU data handling companies PSEB – GDPR Compliance Program
Certify to ExportPSEBSubsidizedVariesIT export companies PSEB Certify to Export Program
AWS/Azure/GCP CertCloud providers50,000-150,0002-3 yearsCloud engineering Cloud Provider Certifications – ...
PMPPMI30,000-60,0003 yearsProject management PMI – PMP Certification
CEHEC-Council40,000-80,0003 yearsCybersecurity EC-Council – CEH Certification
CompTIA Security+CompTIA30,000-50,0003 yearsIT security fundamentals CompTIA Security+ Certification
Share:
Share:
Share:

Details & Regulations

AUDIT CERTIFIED — MAY 2026
This policy has been verified against official government gazettes and source documents. View Audit Log
100% Verified

Certifications & Standards — Complete IT Company Guide

Certifications open doors to government contracts, banking clients, and international business. This page covers the most valuable certifications for Pakistani IT companies, with costs, timelines, and practical steps.

Certification Priority MatrixSOURCE VERIFIED

PriorityCertificationWhyCostTimeline
CriticalISO 27001Govt/banking contracts mandatory; SBP Cyber Shield alignmentPKR 500K-2M (estimated range — verify with provider)6-12 months
HighSOC 2 Type IIRequired by US/EU clients; banking vendor qualificationUSD 15K-50K (estimated range — verify with provider)12-18 months
MediumPCI-DSSMandatory if handling payment card dataUSD 5K-20K (estimated range — verify with provider)3-6 months
MediumISO 22301BCP certification — some govt/bank contracts requirePKR 300K-1M (estimated range — verify with provider)6-12 months
RecommendedISO 27701Privacy management — GDPR readiness, competitive edgePKR 300K-1M (estimated range — verify with provider)6-12 months
RecommendedCMMI Level 3Govt software development contracts preferencePKR 1-3M (estimated range — verify with provider)12-24 months

1. ISO 27001 — Information Security ManagementSOURCE VERIFIED

What It Is

International standard for Information Security Management Systems (ISMS). The most impactful certification for Pakistani IT companies — increasingly mandatory for banking/fintech vendors per SBP Cyber Shield.

Implementation Steps
Step 1: Gap Analysis (2-4 weeks) — Assess current security controls vs ISO 27001 Annex A requirements
Step 2: Risk Assessment (3-4 weeks) — Identify and evaluate information security risks, create risk treatment plan
Step 3: ISMS Design (4-6 weeks) — Develop policies, procedures, Statement of Applicability
Step 4: Implementation (8-12 weeks) — Deploy controls across organization, train staff
Step 5: Internal Audit (2 weeks) — Conduct internal audit to verify readiness
Step 6: Management Review (1 week) — Top management review of ISMS performance
Step 7: Certification Audit (2-4 weeks) — Stage 1 (documentation review) + Stage 2 (implementation audit)
Step 8: Ongoing — Annual surveillance audits; 3-year recertification cycle
Cost Breakdown
Company SizeConsultantCertification BodyTotal (PKR)Annual Surveillance
Small (5-20 staff)500K-1M300K-500K800K-1.5M (estimated range — verify with provider)150K-250K/yr
Medium (20-100 staff)1M-3M500K-1M1.5M-4M (estimated range — verify with provider)250K-500K/yr
Large (100+ staff)3M-8M1M-2M4M-10M (estimated range — verify with provider)500K-1M/yr
Accredited Certification Bodies in Pakistan
  • BSI (British Standards Institution) — most recognized globally
  • TUV, SGS, Bureau Veritas — widely accepted
  • PNAC (Pakistan National Accreditation Council) — local accreditation
  • Tip: For international clients, choose BSI or TUV. For domestic govt contracts, PNAC-accredited bodies suffice.

2. SOC 2 Type IISOURCE VERIFIED

What It Is

System and Organization Controls — trust service criteria for service organizations. Required by most US/EU clients and increasingly by Pakistani banks under Cyber Shield.

Trust Service Criteria (TSC)
CriterionWhat It CoversWhen Required
SecuritySystem protection against unauthorized accessAlways required — baseline for all SOC 2
AvailabilitySystem availability for operationsSaaS/IaaS providers
Processing IntegritySystem processing is complete, valid, accurateFinancial data processing
ConfidentialityData classified as confidential is protectedHandling client IP/trade secrets
PrivacyPersonal information collection, use, retention, disposalHandling EU/US personal data
SOC 2 Type I vs Type II
Type I = point-in-time snapshot of controls (faster, cheaper). Type II = operating effectiveness over 6-12 months (what clients actually want). Always aim for Type II.

3. PCI-DSS — Payment Card Industry Data Security StandardSOURCE VERIFIED

Mandatory if your IT company stores, processes, or transmits cardholder data. Per PSD C5/2016, SBP requires PCI-DSS for all card-issuing banks and payment processors in Pakistan.

PCI LevelCriteriaAssessmentCost
Level 1>6M transactions/yearAnnual QSA audit + quarterly ASV scanUSD 20K-50K/yr (estimated range — verify with provider)
Level 21M-6M transactions/yearAnnual SAQ-D + quarterly ASV scanUSD 5K-15K/yr (estimated range — verify with provider)
Level 320K-1M transactions/yearAnnual SAQ-C + quarterly ASV scanUSD 3K-8K/yr (estimated range — verify with provider)
Level 4<20K transactions/yearAnnual SAQ-A/B + quarterly ASV scanUSD 1K-3K/yr (estimated range — verify with provider)

4. CMMI — Capability Maturity Model IntegrationSOURCE VERIFIED

Process improvement framework — gives competitive advantage for government software development contracts. PPRA evaluation criteria increasingly reference CMMI.

LevelMeaningWhat It Demonstrates
Level 3DefinedProcesses are documented and standardized across organization
Level 4Quantitatively ManagedProcess performance is statistically managed
Level 5OptimizingContinuous process improvement based on quantitative goals

Cost: PKR 1-3M for Level 3 (12-24 months). More for Level 4/5. Tip: Level 3 is sufficient for most Pakistan government contracts.

5. PSEB Registration & CertificationSOURCE VERIFIED

PSEB (PSEB — Pakistan Software Export Board) registration is not a certification per se, but it provides significant tax benefits:

BenefitPSEB-RegisteredNon-PSEBLegal Basis
WHT on Export Remittance0.25% (Federal/ICT)1%ITO 2001 §154A
Corporate Tax Rate0.25% (Federal/ICT) (PSEB) / 20% (non-export)20% (Federal/ICT)ITO 2001
SST on IT Services (Sindh)3% (Concessional)3% (Concessional)SRO 981(I)/2015
SST on IT Services (Punjab)0%5-0% (Zero-Rated)Second Schedule PSTS Act
SST on IT Services (KP)0%2-15%KP Second Schedule
Income Tax Holiday (SEZ)10 years if in SEZN/ASEZ Act 2012
PSEB Registration Process
  1. Apply online at pseb.org.pk — Registration
  2. Submit: SECP certificate, NTN, business plan, list of IT services
  3. PSEB verification and inspection
  4. Registration issued within 30-60 days
  5. Annual renewal required — failure = deregistration + loss of 0.25% WHT rate

Certification Roadmap by Company StageSOURCE VERIFIED

StageRecommended CertsApprox. Total CostFocus
Startup (0-2 yrs)PSEB registration + basic securityPKR 5,000 registration (one-time), annual renewal per PSEB scheduleTax benefits, client trust
Growth (2-5 yrs)PSEB + ISO 27001PKR 1-2M (estimated range — verify with provider)Banking/govt contracts
Scale (5+ yrs)ISO 27001 + SOC 2 + CMMI L3USD 30K-80K (estimated range — verify with provider)International clients, PPRA tenders
Fintech vendorISO 27001 + PCI-DSS + SOC 2USD 25K-70K (estimated range — verify with provider)SBP Cyber Shield compliance

Key Legal ReferencesSOURCE VERIFIED

ReferenceDescriptionSource
CRMD CL01/2026 (Cyber Shield)ISO 27001 / SOC 2 effectively required for IT vendors to banksSBP
PSD C4/2025Tech Risk Framework — third-party risk assessment mandatesSBP
ITO 2001 §154A0.25% (Federal/ICT) WHT for PSEB-registered IT exportersFBR
PSEB RegistrationIT company certification and export facilitationPSEB
PSD C5/2016PCI-DSS mandatory for card-issuing banksSBP

Related PoliciesSOURCE VERIFIED

IT Certification Compliance Checklist
ISO/IEC 27001:2013 International Standard
Share:
ISO 9001:2015 International Standard
Share:
AICPA SOC 2 Type II Framework
Share:
PSEB Certification Guidelines 2020
Share:
NAVTTC National Skills Framework
Share:
CMMI Institute Maturity Framework
Share:
PCI-DSS v4.0 Payment Card Industry Standard
Share:
EU GDPR Regulation 2016/679
Share:
Checkboxes are saved in your browser
Source Citations (155)
IGNITE — National Tech R&D Fund
https://ignite.org.pk/
restricted website
Related Topics
Share:
Share:
Share: