Waqar Uddin

PISF Closes the Hosting Layer in Pakistan's Sovereignty Stack

July 14, 2026 (4w ago)29 views

nCERT's Pakistan Information Security Framework is the most detailed cybersecurity instrument Pakistan has issued: 13 control documents, 238 individually numbered controls, turning the National Cyber Security Policy 2021's intent and the CERT Rules 2023's legal authority into requirements an auditor can score. It applies to federal and provincial ministries, autonomous bodies, corporations, CERTs, and designated Critical Information Infrastructure (CII).

Disclosure: I work at Jazz as Principal Evangelist Cloud & AI. This article is written as personal industry analysis. Views are my own.

13
Control documents
Governance through CII protection
238
Individually numbered controls
PISFID-001 to PISFID-238
72 hrs
CII breach reporting window
To sectoral CERT, post-verification
4
Sovereignty stack layers
Data, compute, network, hosting

What the 13 documents cover

DocumentControlsSets the baseline for
Governance19Independent security function, steering committee, budget
Asset & Risk Management22Asset register, classification, risk treatment
Security Training9Mandatory awareness, role-based certification
System & Communication Protection25Network security, endpoints, logging, backups
Identity & Access Management9Authentication, privileged access, lifecycle
Data Protection & Privacy19Lawful basis, retention, privacy impact assessment
Incident Response14Detection, reporting timelines, BCP/DRP
Physical Security9Facility access, surveillance, fire safety
Supply Chain Management19Vendor due diligence, concentration risk
Audit11Independent review, control self-assessment
Data Center & Web Hosting35DC compliance bar, hosting repatriation
SSDLC10Secure coding, CI/CD security gates
CII Protection37Classification, resilience, sector coordination

The hosting layer joins the sovereignty stack

I have spent the last several months tracking Pakistan's regulatory direction on cloud, data, and AI: a data layer from SBP, a compute layer from the Cloud First Policy and local IaaS, an application layer from the National AI Policy. PISF adds a fourth, and it is explicit about it. PISF's Data Center and Web Hosting Services document supplies the hosting layer, in a single unambiguous clause:

Organizations hosting their websites and applications outside Pakistan shall plan migration to data centers within Pakistan's geographical boundaries.

A second, separate clause backs it with an enforcement mechanism: any organization using a data center that cannot pass the framework's audit and compliance bar "shall ensure migration of services to a secure and compliant data center." One clause pulls hosting back across the border. The other pushes workloads out of any facility, foreign or domestic, that fails the audit. Together they connect directly to my earlier reads on SBP's Cloud Regulatory Framework, Pakistan's 5G sovereign cloud moment, and PTA's domestic routing mandate.

The bar a data center has to clear

I verified the email-hardening line item against five prominent federal domains, including nCERT's own. All five already had SPF configured, and all five already had DMARC in enforcement mode. The easy, externally checkable control is already met at the top of the pyramid. The harder controls, independent security functions and dedicated budgets, cannot be checked from outside.

Critical infrastructure gets its own tier

CII Protection is the largest document by control count and the most structurally rigorous. It classifies assets into four tiers, mapped against confidentiality, integrity, and availability impact:

LevelImpact of compromise
Most CriticalCatastrophic: extreme safety threats, extreme financial damage, or complete business shutdown
Highly CriticalSevere disruption of essential services, high financial damage, safety threats
CriticalNoticeable but manageable operational issues, medium financial damage, limited safety threats
Non-CriticalMinimal operational effect, tolerable financial impact

A CII owner has 30 days to notify its sector regulator of any material change to a critical system. Recovery is measured against RTO, RPO, MTTD, and MTTR together, not uptime alone. Breaches on designated CII go to the sectoral CERT within 72 hours, the same cadence GDPR uses for personal data breaches in the EU. Non-critical infrastructure gets 120 hours.

Governance is the real test

The technical controls are specific and checkable. The governance document asks for something harder: an information security function organizationally independent from IT, led by someone reporting directly to the head of the organization, sitting on a formally notified steering committee, with a documented RACI matrix and a dedicated budget line. Organizations without headcount are told to convert redundant positions rather than leave the role unfilled.

For a federal ministry with an existing IT wing, that is demanding but achievable. For a provincial department running IT and security out of the same two people, it is a reorganization, and it has to happen before the other twelve documents mean much in practice.

What to watch

Where this fits

Part of an ongoing series on Pakistan's cloud, AI, and digital infrastructure from a practitioner's perspective. Previous posts: Pakistan's Domestic Routing Mandate Closes the Network Layer, Pakistan's 5G Moment Is Also a Sovereign Cloud Moment, SBP's Cloud Regulatory Framework, and The 2026 Pakistani Cloud Map.