Loading...
Cybersecurity Standards, IT Security Certification & Risk Assessment
| Framework | Issuing Authority | Scope | Year | Reference |
|---|---|---|---|---|
| National Cyber Security Policy 2021 | Ministry of IT & Telecom | All sectors, national-level strategy | 2021 | |
| PTA Cyber Security Strategy 2023-2028 | Pakistan Telecommunication Authority | Telecom sector | 2023 | |
| PTA National CS Framework for Telecom | Pakistan Telecommunication Authority | Telecom operators and ISPs | 2022 | |
| PTA Critical Telecom Data Regulation | Pakistan Telecommunication Authority | Critical telecom data handling | 2023 | |
| PTA 5G Security Guidelines 2026 | Pakistan Telecommunication Authority | 5G network deployments | 2026 | |
| PECA 2016 | Government of Pakistan | Electronic crimes and cyber offenses | 2016 |
| Year | Development | Reference |
|---|---|---|
| 2016 | PECA (Prevention of Electronic Crimes Act) enacted | |
| 2021 | National Cyber Security Policy adopted | |
| 2022 | PTA National Cyber Security Framework for Telecom issued | |
| 2023 | PTA Cyber Security Strategy 2023-2028 launched | |
| 2023 | Critical Telecom Data Regulations issued by PTA | |
| 2026 | PTA 5G Security Guidelines released |
Cybersecurity compliance for IT companies in Pakistan involves multiple overlapping frameworks:
Adopted by MoITT, sets strategic direction for all sectors including IT. Establishes governance structures, threat response mechanisms, and sector-specific requirements.
Five-year strategy targeting telecom sector: network security, data protection, incident response, and 5G security.
The primary criminal legislation for cyber offenses. IT companies must ensure operations do not violate PECA provisions. Legal Reference: PECA 2016 PDF
| Offense | Section | Max Imprisonment | Max Fine | Jurisdiction |
|---|---|---|---|---|
| Unauthorized access to information system | §3 | 3 months | PKR 50,000 | Federal/ICT |
| Unauthorized copying of data | §4 | 6 months | PKR 50,000 | Federal/ICT |
| Interference with information system | §5 | 2 years | PKR 500,000 | Federal/ICT |
| Unauthorized access to critical infrastructure | §7 | 5 years | PKR 10 million | Federal/ICT |
| Electronic fraud | §8 | 7 years | PKR 10M or 3x fraud | Federal/ICT |
| Cyber terrorism | §10A | 14 years | PKR 50 million | Federal/ICT |
| Online defamation (2025 amendment) | §21 | 5 years | PKR 5 million | Federal/ICT |
| Cyber stalking | §21 | 3 years | PKR 1 million | Federal/ICT |
| Spamming | §10 | 1 month | PKR 50,000 | Federal/ICT |
| Body | Role | Key Framework | Website/Contact |
|---|---|---|---|
| NCERT | National incident response | PECA 2016; National CS Policy 2021 | pkpkcert.gov.pk |
| PTA | Telecom cybersecurity; 5G Security Guidelines | CS Strategy 2023-2028 | pta.gov.pk | 0800-55055 |
| NCCIA | Cybercrime investigation (separate from FIA since Sep 2025) | PECA 2016 | — |
| FIA Cybercrime Wing | Enforcement; DG: Ahmad Ishaque Jahangir | PECA 2016; FIA Act | Helpline 1991 | cybercrime.gov.pk |
| SBP Cyber Shield | Banking system protection (Mar 19, 2026) | SBP banking cybersecurity | sbp.org.pk |
| NFA | Digital forensics; H-11/4 Islamabad | NFA Act | — |
| PakCERT | National CERT coordination | Operated by NTC | pakcert.org |
| Date | Development | Impact |
|---|---|---|
| 2016 | PECA enacted | Primary cybercrime law |
| 2021 | National Cyber Security Policy adopted | Strategic direction for all sectors |
| 2022 | PTA National CS Framework for Telecom | Standards for telecom operators |
| 2023 | PTA CS Strategy 2023-2028 + Critical Data Regs | 5-year strategy and data rules |
| Sep 2025 | NCCIA confirmed independent from FIA | Separate cybercrime investigation body |
| Feb 2026 | PTA 5G Security Guidelines + Digital Assistant | Security for 5G deployments |
| Mar 19, 2026 | SBP Cyber Shield launched | Banking sector cybersecurity |
| Mar 19, 2026 | PTA 5G licenses granted | 5G operational security requirements |
| Apr 2, 2026 | NCERT SideWinder APT advisory | High-priority threat: fake govt domains |
| Future | Digital Nation Pakistan Bill 2025 | Pakistan Digital Authority may restructure CS governance |
On April 2, 2026, NCERT issued a high-priority advisory regarding the SideWinder (Rattlesnake) APT targeting Pakistani government systems.
| Directive | Issued | Scope | Compliance Deadline |
|---|---|---|---|
| Cyber Security Framework for Government Entities | 2024 | All federal ministries, divisions, attached departments | Immediate |
| Mandatory Email Security Policy | 2024 | Government email systems (.gov.pk) | Within 90 days of issuance |
| Cloud Security Guidelines | 2024 | Entities using NTC/GovCloud | Within 6 months |
| Software Asset Management Policy | 2023 | All govt entities — licensed software only | Immediate |
| Incident Reporting Standard Operating Procedure | 2023 | All govt entities + their IT vendors | Within 30 days |
| VPN Usage Policy | 2023 | Government network access | NTC-managed VPN only |
| Item | Rate | Jurisdiction | Legal Basis |
|---|---|---|---|
| IT Export WHT | 0.25% (PSEB) / 1% (non-PSEB) | Federal/ICT | ITO 2001 §154A |
| Corporate Tax (IT) | 20% | Federal/ICT | ITO 2001 §35 |
| Startup Tax Credit | 100% for 3 years | Federal | ITO 2001 §65F(b) |
| PECA Penalties (Data Breach) | 3 months–14 years + PKR 50K–10M | Federal | PECA 2016 |
| EOBI | 5% employer + 1% employee (PKR 37,000/mo ceiling — EOBI Act & Rules) | Federal | EOBI Act 1976 |