Pakistan - Cloud Solutions Adoption (2022)

Pakistan Cloud First Policy

Pakistan

RAI-PK-NA-PAKCLFI-2022
Effective: February 25, 2022
In Force(In Force)
PolicyGovernance and OversightConformity Assessment and RegistrationRisk Management
Export PDF

The Pakistan Cloud First Policy requires federal public sector entities to prioritize cloud deployment for new ICT investments, issued by the Ministry of Information Technology and Telecommunication in 2022. In force since 2022-02-25, it is monitored by a Cloud Office within the ministry and sets accreditation criteria for cloud service providers.

Summary

The Pakistan Cloud First Policy (PCFP), finalised and published in February 2022, establishes a government-wide directive to treat cloud solutions as the preferred option for new information and communications technology (ICT) investments by federal Public Sector Entities (PSEs). The policy’s principal objectives are to reduce time-to-deploy and procurement cycles, lower capital expenditure on isolated departmental data centres, achieve economies of scale through aggregated cloud adoption, improve interoperability and service delivery across government agencies, strengthen information security by applying classification-based security baselines, and enable environmental benefits through optimized resource use.

Scope and mandatory approach: The policy applies to federal ministries, their attached departments and other PSEs. Under PCFP, PSEs must consider cloud-based deployment for new ICT procurements; if a PSE seeks to implement a non-cloud solution (including a private data centre), it must obtain formal approval and satisfy stringent justification requirements. The PCFP also instructs the Planning Commission and relevant budget authorities to avoid allocating development funds for new departmental data centres, redirecting funding to cloud-based solutions and consolidated infrastructure.

Governance and institutional arrangements: The PCFP mandates establishment of a Cloud Office within the Ministry of Information Technology and Telecommunication (MoITT) to serve as the operational hub for implementation. A Cloud Board, chaired by the Secretary MoITT and including provincial representatives and industry experts, is tasked with oversight. The Cloud Office is responsible for creating classification and accreditation frameworks for CSPs, maintaining a pre-accredited list of CSPs for PSE procurement, developing security baselines aligned to international standards, and providing No Objection Certificates (NOCs) for justified exceptions.

Accreditation, registration and standards: The policy requires CSPs seeking to service government workloads to obtain accreditation and registration consistent with the Cloud Office’s criteria. Accreditation criteria focus on security, reliability, interoperability, availability and cost-effectiveness, and are benchmarked against international standards. The Cloud Office retains authority to audit CSPs and revoke accreditation in cases of material non-compliance.

Data classification and security: The PCFP introduces a five-tier data classification (Open, Public, Restricted, Sensitive/Confidential, Secret) and assigns minimum security and deployment baselines for each class. The policy requires PSEs and accredited CSPs to implement controls appropriate to the declared classification, and mandates security assessments and ICT audits as part of procurement and accreditation.

Procurement and contractual safeguards: The policy recommends use of pre-accredited CSP lists in procurement to speed deployment, includes standard contract provisions and annexes (minimum suggested contractual requirements), and expects PSEs to perform due diligence (security, privacy, business continuity) before onboarding cloud services. It also provides for time-bound NOCs where deviations are justified.

Capacity, workforce and change management: PCFP directs development of a cloud-enabled workforce through training and upskilling programs for public servants, creation of operational playbooks and migration guidance, and phased migration plans to support risk-managed cloud adoption.

Sectoral coordination and interaction with regulators: While the policy is federal, it provides guidance for sectoral regulators (e.g., State Bank of Pakistan, SECP) to align sector-specific cloud outsourcing or prudential rules with the PCFP’s framework. The PCFP is positioned as complementary to Pakistan’s National Cyber Security Policy (2021) and the then-drafting Personal Data Protection Bill, and envisages international benchmarking to attract investment while meeting domestic security needs.

Implementation status and subsequent measures: Following cabinet approval in February 2022, MoITT established an interim Cloud Office to begin operational tasks including drafting accreditation criteria and procurement templates. In 2024 MoITT published accreditation criteria and standard bidding documents consistent with PCFP, and has undertaken consultations with provinces to harmonise adoption across federating units.

Impacts and considerations: PCFP promises reduced ICT costs, faster digital service delivery and improved inter-agency interoperability, but raises policy trade-offs including data residency considerations, market effects on global hyperscalers and local CSPs, and the need for robust governance and capacity to manage cloud security risks. The policy establishes a governance architecture and foundational requirements, leaving operational details (detailed technical standards, sector-specific variants and enforcement modalities) to subsequent instruments and Cloud Office rulemaking.

Full article

Read full text ↗

Overview

The Pakistan Cloud First Policy (PCFP) is a federal policy instrument adopted in February 2022 that instructs Public Sector Entities (PSEs) to prioritise cloud solutions for new ICT investments and establishes a central Cloud Office and governance board to manage cloud adoption across government. The PCFP aims to accelerate digital transformation, reduce capital expenditure on individual departmental data centres, and improve information security and service delivery by introducing standardized data classification, security baselines and a CSP accreditation/registration regime. The policy text and implementation materials are published by the Ministry of Information Technology & Telecommunication; the published final policy is available from the ministry’s repository (see Pakistan Cloud First Policy (Final, 25-Feb-2022)) and MoITT program pages (Ministry of IT & Telecom).

Definitions

Key definitions used by PCFP include: "Public Sector Entities (PSEs)" (federal ministries, departments and attached bodies); "Cloud Service Provider (CSP)" (entities offering IaaS/PaaS/SaaS services); "Cloud Office" (the MoITT operational unit responsible for implementation); "Cloud Board" (policy oversight body led by Secretary MoITT and provincial/industry representatives); and the five data classes—Open, Public, Restricted, Sensitive/Confidential and Secret—each triggering distinct security and deployment baselines in procurement and accreditation.

Governance and Institutional Framework

The PCFP creates a two-tier governance structure: a Cloud Board for policy oversight and the Cloud Office within MoITT for execution. The Cloud Board, chaired by the Secretary MoITT, includes provincial chief secretary representatives (conditional on provincial adoption) and industry experts to ensure stakeholder engagement and sector coordination. The Cloud Office’s responsibilities are broad and operational: establish accreditation/registration criteria for CSPs; maintain a pre-accredited list of CSPs to streamline procurement; define security baselines and data-class specific deployment requirements; perform compliance verification, ICT audits and technical assessments; issue time-bound NOCs for justified departures from cloud-first requirements; and support provinces in adoption. The MoITT has issued public calls for nominations to the Cloud Board and set up interim Cloud Office arrangements to begin these activities (Cloud Board nominations, MoITT Policies & Plan listing).

Key Focus Areas

The policy emphasises several core pillars: (1) Procurement and Accreditation — creation of an accredited CSP list and pre-approved procurement channels to reduce time-to-deploy and encourage competitive supply; (2) Data Classification and Security — a five-tier data classification regime with associated security baselines and minimum contractual protections; (3) Cost Optimisation & Aggregation — move from departmental CAPEX to OPEX pay-as-you-go models and aggregation of demand to leverage economies of scale; (4) Interoperability & Standardisation — standard contract clauses and minimum technical standards to promote portability and interoperability; (5) Local Capacity & Market Development — encourage investment by local and international CSPs, provide incentives for local presence and capacity building; (6) Risk Management & Compliance — mandatory security assessments, audits and accreditation enforcement; and (7) Workforce Transformation — training and change management to create a cloud-enabled public sector workforce. These focus areas are implemented through accreditation criteria, standard bidding documents, and sector-level guidance published by MoITT and coordinated with regulators (MoITT policy list).

Implementation Framework

PCFP sets a staged implementation approach: immediate creation of an interim Cloud Office to define baselines and prepare accreditation criteria; establishment of a permanent Cloud Office; preparation of pre-accredited CSP lists and standard procurement documents; mandatory adoption checkpoints for PSEs when planning new ICT investments; issuance of guidance on migration planning, risk assessment and contractual safeguards; and coordination with budget authorities to prevent new allocations for standalone departmental data centres. The policy delegates technical specification and enforcement detail to the Cloud Office and subsequent MoITT instruments, including the Standard Bidding Documents and the Accreditation Criteria published in 2024.

Monitoring and Evaluation

Monitoring is achieved through: (1) maintenance of an accredited CSP register and periodic compliance audits of accredited CSPs; (2) ICT audits of PSE cloud procurements and migration projects; (3) Cloud Office reporting to the Cloud Board and MoITT on adoption metrics (number of workloads migrated, cost-savings, service availability, security incidents); and (4) periodic review and revision of baselines and procurement templates. The Cloud Office is mandated to publish guidance and to support provinces and PSEs in measurement and reporting. Where necessary, the Office may recommend policy changes based on operational findings.

Penalties, Liability, and Appeals

The PCFP and its implementing instruments provide for administrative and contractual remedies rather than criminal sanctions. Key enforcement levers include: removal or suspension from the pre-accredited CSP register; termination or non-renewal of government contracts; withholding of procurement approvals; and requirements to remediate security or compliance failures within specified timelines. PSEs that contravene mandatory adoption rules may be denied funding for non-compliant CAPEX. The policy also contemplates appeal and review mechanisms within the Cloud Office/Cloud Board structure for contested accreditation or NOC decisions.

Relationship to Other Instruments

PCFP is explicitly linked to Pakistan’s broader digital strategy instruments such as the Digital Pakistan Policy and the National Cyber Security Policy (2021). It was approved contemporaneously with work on the Personal Data Protection Bill and functions as an implementation-level instrument that interacts with sectoral guidance (e.g., central bank cloud outsourcing frameworks) and procurement rules. The policy expects sectoral regulators to align their cloud outsourcing and prudential requirements with the PCFP’s baseline while preserving sector-specific risk controls.

International Alignment

The PCFP benchmarks its accreditation and security criteria against international standards to ensure interoperability and to attract investment from global and regional CSPs. PCFP emphasises alignment with widely accepted cloud security frameworks and international best practices in service availability, resilience and data protection. At the same time, policy design balances international engagement with domestic security and data classification needs to manage national security and citizen privacy concerns.

Implementation Timeline

MilestoneDate
Federal cabinet approval2022-02-16 – 2022-02-18 (cabinet meeting period)
Published final policy (MoITT repository)2022-02-25
Interim Cloud Office establishedMar–Apr 2022 (interim arrangements announced)
Accreditation criteria & Standard Bidding Documents published2024-06 – 2024-07
Ongoing Cloud Board nominations and provincial consultations2024–2025 (consultations and calls for nominations)

Sources and References

SourceType
Pakistan Cloud First Policy (Final, 25-Feb-2022)Primary Source
MoITT Policies & Plan listing (PCFP)Primary Source
IT ministry completes groundwork for govt move to cloud — Dawn (Feb 2022)Secondary Source
Govt formulates accreditation criteria for cloud service providers — Business Recorder (Jul 2024)Secondary Source

Requirements for a company

What an organisation has to do under Pakistan - Cloud Solutions Adoption (2022), at a glance. Not legal advice — the table below gives the provision and deadline for each item.

Must do

11
  • Prioritize cloud-based solutions for all new Information and Communication Technology investments.Public Sector Entities (PSEs)
  • Document cloud-first justification or obtain a No-Objection Certificate for any exceptions.Public Sector Entities (PSEs)
  • Procure cloud services only from the Cloud Office's pre-accredited list of Cloud Service Providers.Public Sector Entities (PSEs)
  • Classify all datasets according to the five-tier regime and follow the associated minimum security baselines.Public Sector Entities (PSEs)
  • Include PCFP minimum contract clauses for business continuity, service level agreements, and audit rights.Public Sector Entities (PSEs)
  • Complete pre-onboarding security assessments and periodic audits for all cloud services.Public Sector Entities (PSEs)
  • +5 more in the table below

Must not do

0

Nothing in this category.

Should do

0

Nothing in this category.

Should not do

0

Nothing in this category.

Who must do what

The obligations under Pakistan - Cloud Solutions Adoption (2022), most serious first. Not legal advice — verify against the official text before relying on it.

#WhoRequirementBy whenWhereSeverity
1Public Sector Entities (PSEs)Prioritize cloud-based solutions for all new Information and Communication Technology investments.
Public Sector Entities (PSEs) to prioritise cloud solutions for new ICT investments
When planning new ICT investmentsOverviewCritical
2Public Sector Entities (PSEs)Document cloud-first justification or obtain a No-Objection Certificate for any exceptions.
issue time-bound NOCs for justified departures from cloud-first requirements
Before new ICT investment approvalImplementation FrameworkCritical
3Public Sector Entities (PSEs)Procure cloud services only from the Cloud Office's pre-accredited list of Cloud Service Providers.
maintain a pre-accredited list of CSPs to streamline procurement
Before procuring cloud servicesKey Focus AreasCritical
4Public Sector Entities (PSEs)Classify all datasets according to the five-tier regime and follow the associated minimum security baselines.
five data classes—Open, Public, Restricted, Sensitive/Confidential and Secret—each triggering distinct security and deployment baselines
DefinitionsCritical
5Public Sector Entities (PSEs)Include PCFP minimum contract clauses for business continuity, service level agreements, and audit rights.
minimum contractual protections
Before signing cloud service contractsKey Focus AreasCritical
6Public Sector Entities (PSEs)Complete pre-onboarding security assessments and periodic audits for all cloud services.
mandatory security assessments, audits and accreditation enforcement
Before onboarding cloud servicesKey Focus AreasCritical
7Public Sector Entities (PSEs)Coordinate with budget authorities to prevent new funding allocations for standalone departmental data centers.
prevent new allocations for standalone departmental data centres
Implementation FrameworkCritical
8Cloud Service Providers (CSPs) seeking to serve PSEsObtain and maintain accreditation or registration from the Cloud Office to serve Public Sector Entities.
establish accreditation/registration criteria for CSPs
Before offering services to PSEsGovernance and Institutional FrameworkCritical
9Accredited Cloud Service Providers (CSPs)Comply with security baselines and data-class specific deployment requirements defined by the Cloud Office.
define security baselines and data-class specific deployment requirements
Governance and Institutional FrameworkCritical
10Accredited Cloud Service Providers (CSPs)Undergo periodic compliance audits by the Cloud Office.
periodic compliance audits of accredited CSPs
Monitoring and EvaluationCritical
11Public Sector Entities (PSEs)Undertake required training and maintain migration playbooks to ensure a cloud-enabled public sector workforce.
Workforce Transformation — training and change management to create a cloud-enabled public sector workforce.
Key Focus AreasImportant

© Regulations.AI · updated on 13-Jun-2026 · reviewed against official sources on 07-Sep-2026 using Gemini 3.6 Flash