PISF: Pakistan Information Security Framework
The Pakistan Information Security Framework (PISF) is the national baseline of mandatory information-security controls for Pakistan's public sector and critical information infrastructure. It is issued under the National Cyber Security Policy 2021 and CERT Rules 2023, with the national CERT (PKCERT / nCERT) and NTISB as the issuing bodies. PISF 2026 was approved by the Federal Cabinet on 11 August 2026. Komply maps its 238 essential controls across 13 domains.
Last updated · By the Faseel compliance team · Not legal advice
PISF at a glance
- Issued by
- NTISB & nCERT (PKCERT), under the National Cyber Security Policy 2021 and CERT Rules 2023
- Latest version
- PISF 2026, approved by the Federal Cabinet on 11 August 2026
- Applies to
- Federal & provincial ministries, divisions, departments, autonomous bodies, government corporations, CERTs and designated CII
- Size
- 238 essential controls across 13 domains (as mapped in Komply)
- Incident reporting
- CII incidents: detailed report within 72 hours; non-CII: within 120 hours
- ISO 27001 overlap
- 201 of 238 controls map to an ISO/IEC 27001:2022 Annex A control
Who must comply with PISF
Government ministries & departments
Federal and provincial ministries, divisions, attached departments, autonomous bodies and government-owned corporations.
Critical Information Infrastructure
Designated CII operators, which also carry a dedicated set of CII-protection (CIIP) controls.
Their technology suppliers
Data centres, web-hosting providers, software developers, email services and other third parties serving in-scope entities.
What PISF requires
- Establish a governance structure with a RACI matrix and an independent information-security function reporting to top management.
- Maintain asset inventories and a documented risk-management process.
- Report incidents to the sectoral CERT and the national CERT within the prescribed windows (72 hours for CII, 120 hours for others).
- Apply data-protection, identity-and-access, system-protection and physical-security controls.
- Manage supply-chain risk and run periodic information-security audits.
- Meet the dedicated controls for data centres, web hosting and secure software development, including planning migration of government websites hosted abroad to domestic data centres.
PISF domains and control counts
238 controls across 13 areas, as mapped in Komply.
| Domain | Controls |
|---|---|
| Governance | 19 |
| Assets & Risk Management | 22 |
| Security Training | 9 |
| System & Communication Protection | 25 |
| Identity & Access Management | 9 |
| Data Protection & Privacy | 19 |
| Incident Response | 14 |
| Physical Security | 9 |
| Supply Chain | 19 |
| Audit | 11 |
| Data Center & Web Hosting Services | 35 |
| Secure Software Development Lifecycle | 10 |
| Critical Information Infrastructure Protection (CIIP) | 37 |
| Total | 238 |
How PISF maps to ISO 27001
201 of PISF's 238 controls have an equivalent ISO/IEC 27001:2022 Annex A control, so ISO evidence can be reused. CII-protection and government-specific controls stand on their own.
Komply is built to operationalize PISF: every one of the 238 controls is tracked with an owner, evidence and status. Readiness rolls up per department, and the same work is reused for ISO 27001. See how Komply works.
PISF FAQ
What is PISF?
PISF (Pakistan Information Security Framework) is Pakistan's national baseline of mandatory information-security controls for the public sector and critical information infrastructure. It is issued under the National Cyber Security Policy 2021 and CERT Rules 2023, and the 2026 version was approved by the Federal Cabinet on 11 August 2026.
Who must comply with PISF?
Federal and provincial ministries, divisions and departments, autonomous bodies, government corporations, CERTs and designated Critical Information Infrastructure (CII) operators. Suppliers serving those entities, such as data centres, hosting providers, software developers and email services, are also covered by specific controls.
How many controls does PISF have?
As mapped in Komply, PISF contains 238 essential controls across 13 domains. Examples include Governance, Assets & Risk Management, Incident Response, Supply Chain, Data Center & Web Hosting Services, and Critical Information Infrastructure Protection. Always confirm scope against the current official PKCERT publication.
What are the PISF incident-reporting timelines?
Incidents affecting critical infrastructure must be reported to the sectoral regulator or CERT and the national CERT, with a detailed report within 72 hours. Incidents in non-critical infrastructure must be reported within 120 hours.
Is PISF the same as ISO 27001?
No. PISF is a national regulatory baseline, while ISO 27001 is a voluntary international certification. They overlap heavily, though: 201 of PISF's 238 controls map to an ISO 27001:2022 Annex A control. Doing both in one control set avoids duplicate work.
How does Komply help with PISF?
Komply ships the full PISF control set with ISO 27001 mappings, policy drafting, evidence tracking, readiness scoring and an auditor-ready export. Departments implement a control once and prove it for both PISF and ISO 27001.
Do ISO 27001 once. Prove PISF too.
Komply maps 14 frameworks and 1,100+ controls into one control set. Start with a free gap assessment.