Pakistan Mandates Cybersecurity Standards by 2028

November 8, 2025Zayn0

National CERT and PSQCA mandate the PSS framework—aligned with FIPS 140 and Common Criteria—across public & private sectors; defense deadline Dec 2025.

What’s Been Announced

Making it mandatory has been made law by the government to the public and the private sector to use cybersecurity standards to secure the critical digital infrastructure. In an updated advisory, the National Computer Emergency Response Team (National CERT) made the instruction, and should vendors, developers, and technology partners start complying. The action will help to ensure communications, protect commerce and government data systems, and mitigate threats of cyber-attacks and unauthorized access.

The PSS Framework and Global Alignment

It is implemented based on the Pakistan Security Standards (PSS) framework that is based on international standards, including the U.S. Federal Information Processing Standards (FIPS 140) and the Common Criteria (ISO 15408). In June 2023, the adoption of PSS was already mandatory formatted by a statutory notification by the Pakistan Standards and Quality Control Authority across cryptographic and ICT security functions. The most recent directive reiterates the idea that systems, devices, and software purportedly cyber secure or encrypted must have PSS certification prior to manufacturing, sale, or installation.

Who Must Comply and by When

Public and private organizations will be fully enforced on June 1, 2028 establishing a national standard of security assurance. Tighter deadlines are used within the context of defense-related organizations: the National Telecom and Information Security Board (NTISB) has mandated that it be implemented by the year 2025. Non-PSS-certified products will be barred to the government procurement to make supply chains more resistant to disruption and mitigate systemic risk.

Certification and Procurement Rules

The vendors and developers have been recommended to commence certification with the help of accredited security testing laboratories. This necessitates the generation of technical documentation (designs, crypto modules, key-management procedures) and test plans as well as evidence that products are adhering to PSS controls as compared to FIPS/Common Criteria. Organizations of the important sector are requested to ensure that the suppliers are alerted and the early adoption strategies are mapped so that the organizations can avoid the disruption of their operations due to the procurement of non-compliant products.

How Organizations Can Prepare Now

Begin with a gap evaluation of PSS controls on cryptography, identity and access management, secure configuration, logging/monitoring, incident response, vulnerability management. Give priority to systems that handle sensitive information or services that are offered to citizens. Create a certification roadmap ordering products in terms of risk, lead-time and allocate budget to laboratory testing and remediation cycles. Modify procurement templates so as to demand PSS certificates, establish formats of supplier attestation, and establish recertification timelines.

Implement crypto hygiene (module validation, entropy, key storage) and DevSecOps, as well as audit-generating evidence. Create a cross-functional steering team that includes security, engineering, legal and procurement to monitor achievements up to December 2025 (defense) and June 2028 (wider sector). Conduct sensitization on the use of non-certified products to make the stakeholders aware of the repercussions of using the non-certified product.

Why Standardization Matters

The government has emphasized that standardized controls are the key to establishing a robust national cyber-defense ecosystem. Mandatory certification enhances interoperability, minimizes ambiguity of vendor assertions, and facilitates the use of the agencies to ensure the level of security before implementation. In the long run, a steady base must reduce the number of incidents and their effects and motivate local developers to develop considering security goals at the earliest stages of the design.

Leave a Reply

Your email address will not be published. Required fields are marked *

Search & have fun

Search anytime for whatever you need, for your business, fun or personal needs. ICCI.PK helps you find it easy and fast.

Search & have fun

Search anytime for whatever you need, for your business, fun or personal needs. ICCI.PK helps you find it easy and fast.

Explore

Users

ICCI.PK

https://www.icci.pk/wp-content/uploads/2020/06/Icci-Logo.jpg

Copyright ©️ 2025 ICCI.PK. All rights reserved.

Back to Bello home

Copyright ©️ 2025 ICCI.PK. All rights reserved. Developed by Target Marketing (Pvt) Limited.