World Watch/Pakistan/Cybersecurity

Cybersecurity · Pakistan

Cybersecurity regulation in Pakistan (2026)

Sectoral rulesPatchwork: Prevention of Electronic Crimes Act (PECA) 2016 (as amended 2025) for cybercrime; National Cyber Security Policy 2021 (non-binding) and CERT Rules 2023 administered by the Ministry of IT & Telecommunication (MoITT); plus sector-specific rules (e.g. State Bank of Pakistan ETGRM Framework for financial institutions). No single comprehensive cybersecurity-obligations law; the Personal Data Protection Bill remains a draft.Country index 68 · B

Pakistan shaded by its cybersecurity status

Pakistan regulates cybersecurity through a patchwork rather than a single comprehensive (NIS2-style) statute. PECA 2016 (amended January 2025) is a criminal cybercrime law and established the National Cyber Crime Investigation Agency; the National Cyber Security Policy 2021 sets aspirational goals but is not binding legislation, while binding security and incident-reporting duties exist mainly sectorally (notably the State Bank of Pakistan's framework for banks). A general personal-data-breach notification regime is still only proposed under the draft Personal Data Protection Bill.

Key points

Primary cybercrime law (PECA 2016, amended 2025)

PECA 2016 is Pakistan's principal cyber statute, criminalizing unauthorized access, data interference and electronic fraud. The Prevention of Electronic Crimes (Amendment) Act 2025 (enacted 29 January 2025) replaced the FIA Cyber Crime Wing with the National Cyber Crime Investigation Agency (NCCIA), created a Digital Rights Protection Authority, and criminalized 'fake/false' information — drawing criticism over free-expression impact.

National Cyber Security Policy 2021 (policy, not binding law)

MoITT's National Cyber Security Policy 2021 aims to secure national ICT and Critical Information Infrastructure, mandate security standards, and establish CERTs/SOCs and a Cyber Governance Policy Committee. It is a strategic policy framework rather than directly enforceable legislation.

National CERT and CERT Rules 2023

The Federal Cabinet approved the CERT Rules 2023 (notified 13 October 2023), and MoITT announced the first National Computer Emergency Response Team (PKCERT) on 12 October 2023 to monitor, coordinate and respond to cyber threats across sectors.

Banking-sector cybersecurity & 48-hour incident reporting

The State Bank of Pakistan's Enterprise Technology Governance & Risk Management Framework (BPRD Circular No. 05 of 2017) imposes binding cyber risk-management duties on financial institutions and requires reporting of established information/cyber-security breaches and major incidents to SBP within 48 hours. SBP also issued a Technology Risk Management Framework for payment institutions (2025).

General data-breach notification still only proposed

There is no enacted general personal-data protection law. The draft Personal Data Protection Bill (introduced by MoITT) would require data controllers to notify the proposed National Commission for Personal Data Protection of a breach within 72 hours, but it remains unfinalized pending parliamentary approval and assent.

Move toward a National Cybersecurity Authority

Reporting in 2025 indicates Pakistan is working to establish a dedicated National Cybersecurity Authority to centralize oversight, signaling that comprehensive institutional consolidation is still developing rather than fully in force.

Pakistan - other topics

Last verified 5/25/2026 · Orientation, not legal advice - verify against the primary sources linked above. Explore the full world map →