ISLAMABAD: The Federal Cabinet has directed the Ministry of Information Technology and Telecommunication that Pakistan Information Security Framework (PISF) 2026 must specify clear implementation timelines and include a provision for an independent third- party audit, well informed sources told Business Recorder. These directions were issued during discussion on the PISF 2026 submitted by the Ministry of Information Technology and Telecommunication on increasing digitalisation of government functions, expansion of e- governance initiatives and growing interconnectivity of public sector systems that had significantly increased exposure to cyber risks and Government entities now relied extensively on information systems for service delivery, financial operations, citizen data management and inter-organisational coordination/communication. READ ALSO: Pakistan’s growing banking and cyber fraud crisis The Ministry of Information Technology and Telecommunication further apprised the Cabinet that variations in institutional capacity and the absence of a unified reference framework had resulted in inconsistent security practices across the public sector, leading to vulnerabilities/exposures. The National Cyber Security Policy-2021, the CERT Rules-2023 and CERT Council, emphasised strengthening of governance, coordinated response mechanisms, and standardised implementation of information security controls, therefore, a nationally approved framework was required to translate policy direction into a uniform operational structure, enable regulatory oversight, and ensure accountability. The Ministry of Information Technology and Telecommunication apprised the Cabinet that in accordance with Rule 13(1)(a)(i) of the CERT Rules-2023, the PISF 2026 had been formulated by National CERT in consultation with the subject matter experts in the relevant domain. The salient features of the framework were given as under: (i) PISF establishes a national baseline of essential information security controls applicable to Federal and Provincial Ministries, Divisions, Departments, autonomous bodies, public sector corporations, CERTs, and designated Critical Information Infrastructures (CIIs); (ii) the framework aims to standardise and strengthen protection of government information assets, digital services, and critical systems across the public sector; (iii) The framework provides a unified, scalable, and risk-based approach to information security, taking into account the varying size, operational complexity, and risk exposure of public sector organisations, while ensuring consistency with national Cyber Security objectives and regulatory direction; and (iv) PISF comprises thirteen core control domains covering: governance, asset and risk management, security awareness and training, system and communication protection, identity and access management, data protection and privacy, incident response, physical security, data centre and hosting security, secure software development life cycle, supply chain security, audit controls, and protection of Critical Information Infrastructure. It was noted that while formulating PISE, a comprehensive review and consultation process was adopted as described under: (i) circulation of 1 percent Draft Framework in November 2025 among members of the CERT Council, Provincial/Sectoral CERTs and relevant Federal Ministries, Divisions, and Departments to ensure inter-ministerial alignment and to obtain feedback from academia, industry, and information security practitioners; (ii) based on feedback, the revised version (2nd Draft) was again shared with key stakeholders followed by a briefing at NCERT on 22nd January 2026 to apprise objectives, structure, and implementation approach; and (iii) the 3rd version of the draft framework was again circulated on 26th February 2026 and has now been finalised for approval/implementation. The Ministry of Information Technology and Telecommunication apprised the Cabinet that approval and implementation of PISE would enable achievement of the following objectives, in line with National Cyber Security Policy 2021: (i) establishing a standardised national information security baseline across all public and private sector entities and designated critical sectors; (ii) strengthening protection of government information assets, digital platforms, and citizen data, while enhancing institutional capacity to prevent, detect, and respond to cyber incidents; (iii) the maturity-based compliance mechanism will provide government-wide visibility of information/ Cyber Security posture and risk exposure; (iv) supporting evidence-based decision-making, targeted investment in information/Cyber Security capabilities, secure digital transformation initiatives, and continuity of essential government services; and (v) enhancing public trust in government digital services and strengthening national resilience in the digital domain. The Ministry of Information Technology and Telecommunication further apprised the Cabinet that under Section 48(1) of PECA-2016 and as further prescribed in Rule 13(1)(a)(i) of CERT Rules-2023, the PISF 2026 may kindly be notified as the national baseline information security standard for all public and private sector entities (federal or provincial), including autonomous/semi-autonomous, corporations, CERTs, and designated Critical Information Infrastructures (CIIs), in order to establish standardised information security governance and strengthen the national Cyber Security posture. In view of the foregoing, the Ministry of Information Technology and Telecommunication submitted the Pakistan Information Security Framework (PISF- 2026) for approval of the Cabinet. During the ensuing discussion, the Cabinet members appreciated the Ministry of Information Technology and Telecommuni-cation for the timely formulation of the PISF 2026, which was urgently required in view of the growing Cyber Security threats. The Cabinet members, however, observed that the proposed Framework should specify clear implementation timelines and should also include provision for an independent third party audit. On a query, it was informed that the Prime Minister had already issued strict directions that the policy framework issued by the Ministry of Information Technology and Telecommuni-cation for establishment and use of data centres shall be strictly adhered to and enforced; it shall be ensured that the already established data centres by the Ministry of Information Technology and Telecommuni-cation are used by every Ministry for any of their initiatives; and Ministry of Planning, Development & Special Initiatives shall ensure that no proposal of any Ministry regarding independent/new data centre is approved /included in the PC-Is. After detailed discussion, the federal cabinet approved the PISF 2026 with directions that the PISF must specify clear implementation timelines and include a provision for an independent third party audit. Copyright Business Recorder, 2026
PISF 2026: IT ministry directed to specify implementation timelines
RELATED ARTICLES



