Loading...
ISO 27001, SOC2, CMMI, PCI-DSS, ISO 22301 & ISO 27701
| Certification | Provider | Cost (PKR) | Validity | Relevance | Reference |
|---|---|---|---|---|---|
| ISO 27001 (InfoSec) | ISO/BSI | 200,000-1,000,000 | 3 years | Government contracts, banking, BPO | |
| ISO 9001 (Quality) | ISO/BSI | 150,000-500,000 | 3 years | Manufacturing, services, export | |
| CMMI Level 2-5 | ISACA/CMMI Institute | 500,000-3,000,000 | 3 years | Software development, government | |
| GDPR Compliance | PSEB Program | Partially subsidized | Ongoing | EU data handling companies | |
| Certify to Export | PSEB | Subsidized | Varies | IT export companies | |
| AWS/Azure/GCP Cert | Cloud providers | 50,000-150,000 | 2-3 years | Cloud engineering | |
| PMP | PMI | 30,000-60,000 | 3 years | Project management | |
| CEH | EC-Council | 40,000-80,000 | 3 years | Cybersecurity | |
| CompTIA Security+ | CompTIA | 30,000-50,000 | 3 years | IT security fundamentals |
| Priority | Certification | Why | Cost | Timeline |
|---|---|---|---|---|
| Critical | ISO 27001 | Govt/banking contracts mandatory; SBP Cyber Shield alignment | PKR 500K-2M (estimated range — verify with provider) | 6-12 months |
| High | SOC 2 Type II | Required by US/EU clients; banking vendor qualification | USD 15K-50K (estimated range — verify with provider) | 12-18 months |
| Medium | PCI-DSS | Mandatory if handling payment card data | USD 5K-20K (estimated range — verify with provider) | 3-6 months |
| Medium | ISO 22301 | BCP certification — some govt/bank contracts require | PKR 300K-1M (estimated range — verify with provider) | 6-12 months |
| Recommended | ISO 27701 | Privacy management — GDPR readiness, competitive edge | PKR 300K-1M (estimated range — verify with provider) | 6-12 months |
| Recommended | CMMI Level 3 | Govt software development contracts preference | PKR 1-3M (estimated range — verify with provider) | 12-24 months |
International standard for Information Security Management Systems (ISMS). The most impactful certification for Pakistani IT companies — increasingly mandatory for banking/fintech vendors per SBP Cyber Shield.
| Company Size | Consultant | Certification Body | Total (PKR) | Annual Surveillance |
|---|---|---|---|---|
| Small (5-20 staff) | 500K-1M | 300K-500K | 800K-1.5M (estimated range — verify with provider) | 150K-250K/yr |
| Medium (20-100 staff) | 1M-3M | 500K-1M | 1.5M-4M (estimated range — verify with provider) | 250K-500K/yr |
| Large (100+ staff) | 3M-8M | 1M-2M | 4M-10M (estimated range — verify with provider) | 500K-1M/yr |
System and Organization Controls — trust service criteria for service organizations. Required by most US/EU clients and increasingly by Pakistani banks under Cyber Shield.
| Criterion | What It Covers | When Required |
|---|---|---|
| Security | System protection against unauthorized access | Always required — baseline for all SOC 2 |
| Availability | System availability for operations | SaaS/IaaS providers |
| Processing Integrity | System processing is complete, valid, accurate | Financial data processing |
| Confidentiality | Data classified as confidential is protected | Handling client IP/trade secrets |
| Privacy | Personal information collection, use, retention, disposal | Handling EU/US personal data |
Mandatory if your IT company stores, processes, or transmits cardholder data. Per PSD C5/2016, SBP requires PCI-DSS for all card-issuing banks and payment processors in Pakistan.
| PCI Level | Criteria | Assessment | Cost |
|---|---|---|---|
| Level 1 | >6M transactions/year | Annual QSA audit + quarterly ASV scan | USD 20K-50K/yr (estimated range — verify with provider) |
| Level 2 | 1M-6M transactions/year | Annual SAQ-D + quarterly ASV scan | USD 5K-15K/yr (estimated range — verify with provider) |
| Level 3 | 20K-1M transactions/year | Annual SAQ-C + quarterly ASV scan | USD 3K-8K/yr (estimated range — verify with provider) |
| Level 4 | <20K transactions/year | Annual SAQ-A/B + quarterly ASV scan | USD 1K-3K/yr (estimated range — verify with provider) |
Process improvement framework — gives competitive advantage for government software development contracts. PPRA evaluation criteria increasingly reference CMMI.
| Level | Meaning | What It Demonstrates |
|---|---|---|
| Level 3 | Defined | Processes are documented and standardized across organization |
| Level 4 | Quantitatively Managed | Process performance is statistically managed |
| Level 5 | Optimizing | Continuous process improvement based on quantitative goals |
Cost: PKR 1-3M for Level 3 (12-24 months). More for Level 4/5. Tip: Level 3 is sufficient for most Pakistan government contracts.
PSEB (PSEB — Pakistan Software Export Board) registration is not a certification per se, but it provides significant tax benefits:
| Benefit | PSEB-Registered | Non-PSEB | Legal Basis |
|---|---|---|---|
| WHT on Export Remittance | 0.25% (Federal/ICT) | 1% | ITO 2001 §154A |
| Corporate Tax Rate | 0.25% (Federal/ICT) (PSEB) / 20% (non-export) | 20% (Federal/ICT) | ITO 2001 |
| SST on IT Services (Sindh) | 3% (Concessional) | 3% (Concessional) | SRO 981(I)/2015 |
| SST on IT Services (Punjab) | 0% | 5-0% (Zero-Rated) | Second Schedule PSTS Act |
| SST on IT Services (KP) | 0% | 2-15% | KP Second Schedule |
| Income Tax Holiday (SEZ) | 10 years if in SEZ | N/A | SEZ Act 2012 |
| Stage | Recommended Certs | Approx. Total Cost | Focus |
|---|---|---|---|
| Startup (0-2 yrs) | PSEB registration + basic security | PKR 5,000 registration (one-time), annual renewal per PSEB schedule | Tax benefits, client trust |
| Growth (2-5 yrs) | PSEB + ISO 27001 | PKR 1-2M (estimated range — verify with provider) | Banking/govt contracts |
| Scale (5+ yrs) | ISO 27001 + SOC 2 + CMMI L3 | USD 30K-80K (estimated range — verify with provider) | International clients, PPRA tenders |
| Fintech vendor | ISO 27001 + PCI-DSS + SOC 2 | USD 25K-70K (estimated range — verify with provider) | SBP Cyber Shield compliance |
| Reference | Description | Source |
|---|---|---|
| CRMD CL01/2026 (Cyber Shield) | ISO 27001 / SOC 2 effectively required for IT vendors to banks | SBP |
| PSD C4/2025 | Tech Risk Framework — third-party risk assessment mandates | SBP |
| ITO 2001 §154A | 0.25% (Federal/ICT) WHT for PSEB-registered IT exporters | FBR |
| PSEB Registration | IT company certification and export facilitation | PSEB |
| PSD C5/2016 | PCI-DSS mandatory for card-issuing banks | SBP |