Pakistan - National Cyber Security Policy (2021)

National Cyber Security Policy 2021

Pakistan

RAI-PK-NA-NCS2XXX-2021
Effective: July 27, 2021
In Force(In Force)
PolicyGovernance and OversightCybersecurity and Model SecurityConformity Assessment and Registration
Export PDF

The National Cyber Security Policy 2021 (NCSP 2021), issued by the Ministry of Information Technology & Telecommunication (MoITT), establishes a national framework to strengthen Pakistan’s cyber resilience, protect critical information infrastructure, and coordinate public-private cybersecurity governance. The policy sets out governance structures, risk-based approaches, standards, capacity-building, incident response arrangements and international cooperation measures to manage cyber threats across government, critical sectors and private industry.

Summary

The National Cyber Security Policy 2021 (NCSP 2021), prepared by the Ministry of Information Technology & Telecommunication (MoITT) and approved by the Federal Cabinet in July 2021, is Pakistan’s first comprehensive national-level policy designed to consolidate and coordinate the country’s cyber security posture. The policy recognises cyberspace as a strategic domain for national development and security and frames information assets and ICT infrastructure as national assets that require governance, standardisation and protection. NCSP 2021 sets a vision of a secure, robust and continually improving nationwide digital ecosystem ensuring confidentiality, integrity and availability of digital assets to support socio-economic development and national security.

NCSP 2021 identifies gaps in the existing landscape — including fragmented institutional arrangements, limited incident response coordination, reliance on imported hardware and software, lack of uniform standards and testing frameworks, and shortages in skilled workforce. To address these gaps the policy establishes a governance and institutional framework including a Cyber Governance Policy Committee (CGPC) for oversight and assigns responsibilities for implementation across ministries, sectoral regulators and national CERTs. Key deliverables include establishing active defence capabilities, protection of internet-based services, strengthening resilience of National Critical Information Infrastructure (CII), mandated security standards for government and regulated sectors, an information security assurance framework (audits, accreditation and testing), and public-private partnerships for threat intelligence sharing.

The policy emphasises a risk-based approach to cyber security and prescribes measures across technical, organisational and legal fronts — promoting adoption of national security standards, conformity assessment and screening of ICT products, establishing accreditation and forensic testing capabilities, and building national CERT capacity. It sets out objectives for workforce development, R&D, awareness-raising and incentivising local industry to produce secure ICT solutions. NCSP 2021 also underscores the need to protect citizens’ online privacy and to align Pakistan’s cyber actions with international cooperation frameworks and law.

NCSP 2021 integrates incident response and cybercrime response mechanisms and urges stronger coordination among existing laws such as the Prevention of Electronic Crimes Act (PECA) 2016, and sectoral standards (e.g., SBP guidance for finance). It calls for interim measures, periodic policy review, and implementation milestones. While the document is policy-level (not an act), it envisages regulatory and legislative follow-ups to operationalise many provisions and to empower designated agencies with enforcement and compliance authority.

Overall, NCSP 2021 is a foundational policy designed to centralise governance, build capabilities, introduce standards and mechanisms for assurance and testing, and to foster international collaboration — intending to raise Pakistan’s cyber resilience and to protect both public sector and private-sector digital assets.

Full article

Read full text ↗

Overview

The National Cyber Security Policy 2021 (NCSP 2021), published by the Ministry of Information Technology & Telecommunication (MoITT) in July 2021, provides a strategic, cross-sectoral framework to secure Pakistan’s cyberspace and digital economy. It defines the national vision to create a secure, robust and continually improving digital ecosystem and sets objectives for governance, risk management, standards, capacity building and international cooperation. The policy addresses protection of National Critical Information Infrastructure (CII), enhancement of incident response capabilities through national and sectoral CERTs, information assurance and conformity assessment, and measures to promote indigenous cyber security solutions. The official policy document is available in full as a government-circulated PDF (see Sources). The NCSP positions cyber incidents that affect institutions of the state as matters of national security and seeks to harmonise actions across ministries, regulators and the private sector to improve detection, response and resilience.

Definitions

NCSP 2021 sets out a glossary of terms used throughout the policy including definitions for terms such as "Critical Information Infrastructure" (CII), "cyberspace", "incident response", "active defence", "assurance", "conformity assessment", "CERT/CSIRT" and "information assurance framework". The policy clarifies that CII comprises systems supporting essential services and national functions whose disruption or compromise would have a significant impact on national security, public health, safety or economic stability. It distinguishes between policy-level obligations and operational roles assigned to implementing bodies such as national CERTs, sectoral regulators, and accredited testing laboratories.

Governance and Institutional Framework

NCSP 2021 establishes a central governance structure headed by a Cyber Governance Policy Committee (CGPC) to provide policy oversight and inter-ministerial coordination. It designates the Ministry of IT & Telecommunication as the focal ministry for policy stewardship and calls for creation or strengthening of national and sectoral CERTs, accreditation bodies, and an information assurance framework for audits, testing, and certification. The policy assigns responsibilities for regulation, standards, incident response coordination, public-private engagement and capacity building among federal ministries, provincial authorities, sector regulators (such as the Pakistan Telecommunication Authority), the national CERT (now operating under the MoITT as PKCERT / nCERT), the National Centre for Cyber Security (NCCS) and the State Bank of Pakistan for the finance sector. The governance model envisaged by the NCSP aims to reduce fragmentation, enable timely strategic decision-making and ensure ownership at the highest administrative levels.

Key Focus Areas

The policy identifies a set of interlinked focus areas: (1) governance and oversight to coordinate national cybersecurity actions; (2) active defence and incident response capabilities including a national framework for CERT operations and threat intelligence sharing; (3) protection of National CII and government information systems by mandating security standards and lifecycle controls for ICT assets; (4) information security assurance through accreditation, conformity assessment and independent testing for high-risk ICT products and services; (5) public-private partnerships for threat sharing, joint exercises and resilience-building; (6) capacity building and human capital development by scaling education and training pipelines; (7) research, development and promotion of indigenous cybersecurity technologies; (8) fostering a national culture of cyber awareness through mass communication programs; (9) data protection and citizens’ privacy measures; and (10) global cooperation and legal/regulatory alignment for cross-border incident handling. The policy stresses a risk-based approach to prioritise resources and apply controls proportionate to potential impact.

Implementation Framework

NCSP 2021 lays out an implementation approach that blends policy directives with mandated regulatory follow-ups. The implementation framework includes formation of the Cyber Governance Policy Committee for oversight, assignment of lead agencies for each policy deliverable, development of technical standards (Pakistan Security Standards - PSS), establishment of conformity assessment labs and accreditation processes, roll-out of national and sectoral CERTs for operational incident management, and development of an assurance and audit regime for both government and critical private sector entities. The policy foresees legislative and regulatory instruments to operationalise provisions — for instance, to mandate compliance for public sector entities and for designated CIIs — and anticipates creating incentives and procurement rules to prioritise secure, accredited products. The framework emphasises staged rollouts with interim measures to strengthen immediate gaps while building medium-term institutional capacity.

Monitoring and Evaluation

Monitoring under NCSP 2021 is to be managed by the CGPC together with designated implementation leads. The policy requires periodic reporting on key performance indicators (KPIs) such as time-to-detect and time-to-respond for incidents, number of accredited testing and conformity-assessment bodies established, percentage of critical services covered by incident response plans, workforce training outputs, and public awareness metrics. It recommends independent audits and reviews to measure compliance with the information assurance framework and to inform continual improvement. A scheduled policy review and update mechanism is specified to adjust the policy in response to evolving threats, technological changes and implementation experience.

Penalties, Liability, and Appeals

NCSP 2021 is a policy instrument (not standalone primary legislation) that sets out obligations and envisages regulatory and legislative measures to provide enforcement teeth. The policy calls for the development of regulatory instruments that will define compliance obligations, penalties and liability rules for failing entities — particularly for operators of designated CII and government systems. It also anticipates establishing processes for administrative appeals, remediation timelines, and mechanisms for redress. In practice, enforcement and penalties are expected to be implemented through sector regulators (e.g., PTA, SBP) and through updates to existing laws such as PECA 2016 and related regulatory frameworks.

Relationship to Other Instruments

NCSP 2021 sits alongside and seeks to harmonise with existing Pakistani laws and policies such as the Prevention of Electronic Crimes Act (PECA) 2016, the Electronic Transaction Ordinance 2002, sectoral guidance from the State Bank of Pakistan, and telecom regulations by the PTA. The policy instructs a review of legal gaps and recommends legislative and regulatory changes where existing laws do not adequately cover national cyber security responsibilities. It also complements national strategies such as "Digital Pakistan" and is intended to feed into sectoral security programs and procurement policies to ensure consistent security baselines across government and regulated industries.

International Alignment

While tailored to Pakistan’s priorities, NCSP 2021 emphasises international cooperation as a core pillar: cross-border incident coordination, participation in international forums for norms and capacity building, mutual legal assistance for cybercrime, and alignment with international standards and good practices for assurance, testing and incident handling. The policy encourages engagement with bilateral and multilateral partners for threat intelligence exchange, capacity-building support, and coordinated responses to sophisticated transnational threats. International alignment also includes the adoption/adaptation of international security standards and certification regimes to facilitate trade while protecting national security.

Implementation Timeline

MilestoneTarget DateLead
Cabinet approval and policy publication2021-07-27MoITT
Form Cyber Governance Policy Committee (CGPC)Within 3 months of publicationMoITT / Federal Cabinet
Establish national CERT and define sectoral CERT roles6-12 monthsMoITT / PKCERT
Develop Pakistan Security Standards (PSS) and assurance framework6-18 monthsMoITT / Standards Bodies
Set up accredited testing & conformity assessment labs12-24 monthsMoITT / Accreditation Bodies
Implement regulatory instruments for designated CII12-24 monthsSector Regulators
Periodic review and first major policy evaluation24 monthsCGPC

Compliance Checklist

RequirementApplies ToVerification
Adopt national security standards (PSS) for systemsGovernment, CII, regulated sectorsEvidence of standard adoption & configuration baselines
Register and coordinate with national/sectoral CERTsAll critical providers and government agenciesCERT registration record and incident reporting logs
Implement incident response & business continuity plansCII & government systemsPlan documents and exercise reports
Submit to information assurance auditsDesignated entitiesAudit reports and corrective action records
Use accredited testing/accreditation for high-risk ICT importsProcurement authorities and vendorsConformity certificates and test reports

Sources and References

SourceType
National Cyber Security Policy 2021 - Ministry of IT & Telecom (official PDF)Primary Source
Ministry of Information Technology & Telecommunication (MoITT) - PakistanPrimary Source
PKCERT - Policies and LegislationPrimary Source
Dawn - "Cabinet gives the green light to cyber security policy" (news, 28 July 2021)Secondary Source

© Regulations.AI · updated on 13-Jun-2026