Pakistan - Cloud Solutions Adoption (2022)
Pakistan Cloud First Policy
Pakistan
RAI-PK-NA-PAKCLFI-2022The Pakistan Cloud First Policy requires federal public sector entities to prioritize cloud deployment for new ICT investments, issued by the Ministry of Information Technology and Telecommunication in 2022. In force since 2022-02-25, it is monitored by a Cloud Office within the ministry and sets accreditation criteria for cloud service providers.
Summary
The Pakistan Cloud First Policy (PCFP), finalised and published in February 2022, establishes a government-wide directive to treat cloud solutions as the preferred option for new information and communications technology (ICT) investments by federal Public Sector Entities (PSEs). The policy’s principal objectives are to reduce time-to-deploy and procurement cycles, lower capital expenditure on isolated departmental data centres, achieve economies of scale through aggregated cloud adoption, improve interoperability and service delivery across government agencies, strengthen information security by applying classification-based security baselines, and enable environmental benefits through optimized resource use.
Scope and mandatory approach: The policy applies to federal ministries, their attached departments and other PSEs. Under PCFP, PSEs must consider cloud-based deployment for new ICT procurements; if a PSE seeks to implement a non-cloud solution (including a private data centre), it must obtain formal approval and satisfy stringent justification requirements. The PCFP also instructs the Planning Commission and relevant budget authorities to avoid allocating development funds for new departmental data centres, redirecting funding to cloud-based solutions and consolidated infrastructure.
Governance and institutional arrangements: The PCFP mandates establishment of a Cloud Office within the Ministry of Information Technology and Telecommunication (MoITT) to serve as the operational hub for implementation. A Cloud Board, chaired by the Secretary MoITT and including provincial representatives and industry experts, is tasked with oversight. The Cloud Office is responsible for creating classification and accreditation frameworks for CSPs, maintaining a pre-accredited list of CSPs for PSE procurement, developing security baselines aligned to international standards, and providing No Objection Certificates (NOCs) for justified exceptions.
Accreditation, registration and standards: The policy requires CSPs seeking to service government workloads to obtain accreditation and registration consistent with the Cloud Office’s criteria. Accreditation criteria focus on security, reliability, interoperability, availability and cost-effectiveness, and are benchmarked against international standards. The Cloud Office retains authority to audit CSPs and revoke accreditation in cases of material non-compliance.
Data classification and security: The PCFP introduces a five-tier data classification (Open, Public, Restricted, Sensitive/Confidential, Secret) and assigns minimum security and deployment baselines for each class. The policy requires PSEs and accredited CSPs to implement controls appropriate to the declared classification, and mandates security assessments and ICT audits as part of procurement and accreditation.
Procurement and contractual safeguards: The policy recommends use of pre-accredited CSP lists in procurement to speed deployment, includes standard contract provisions and annexes (minimum suggested contractual requirements), and expects PSEs to perform due diligence (security, privacy, business continuity) before onboarding cloud services. It also provides for time-bound NOCs where deviations are justified.
Capacity, workforce and change management: PCFP directs development of a cloud-enabled workforce through training and upskilling programs for public servants, creation of operational playbooks and migration guidance, and phased migration plans to support risk-managed cloud adoption.
Sectoral coordination and interaction with regulators: While the policy is federal, it provides guidance for sectoral regulators (e.g., State Bank of Pakistan, SECP) to align sector-specific cloud outsourcing or prudential rules with the PCFP’s framework. The PCFP is positioned as complementary to Pakistan’s National Cyber Security Policy (2021) and the then-drafting Personal Data Protection Bill, and envisages international benchmarking to attract investment while meeting domestic security needs.
Implementation status and subsequent measures: Following cabinet approval in February 2022, MoITT established an interim Cloud Office to begin operational tasks including drafting accreditation criteria and procurement templates. In 2024 MoITT published accreditation criteria and standard bidding documents consistent with PCFP, and has undertaken consultations with provinces to harmonise adoption across federating units.
Impacts and considerations: PCFP promises reduced ICT costs, faster digital service delivery and improved inter-agency interoperability, but raises policy trade-offs including data residency considerations, market effects on global hyperscalers and local CSPs, and the need for robust governance and capacity to manage cloud security risks. The policy establishes a governance architecture and foundational requirements, leaving operational details (detailed technical standards, sector-specific variants and enforcement modalities) to subsequent instruments and Cloud Office rulemaking.
Full article
Read full text ↗Overview
The Pakistan Cloud First Policy (PCFP) is a federal policy instrument adopted in February 2022 that instructs Public Sector Entities (PSEs) to prioritise cloud solutions for new ICT investments and establishes a central Cloud Office and governance board to manage cloud adoption across government. The PCFP aims to accelerate digital transformation, reduce capital expenditure on individual departmental data centres, and improve information security and service delivery by introducing standardized data classification, security baselines and a CSP accreditation/registration regime. The policy text and implementation materials are published by the Ministry of Information Technology & Telecommunication; the published final policy is available from the ministry’s repository (see Pakistan Cloud First Policy (Final, 25-Feb-2022)) and MoITT program pages (Ministry of IT & Telecom).
Definitions
Key definitions used by PCFP include: "Public Sector Entities (PSEs)" (federal ministries, departments and attached bodies); "Cloud Service Provider (CSP)" (entities offering IaaS/PaaS/SaaS services); "Cloud Office" (the MoITT operational unit responsible for implementation); "Cloud Board" (policy oversight body led by Secretary MoITT and provincial/industry representatives); and the five data classes—Open, Public, Restricted, Sensitive/Confidential and Secret—each triggering distinct security and deployment baselines in procurement and accreditation.
Governance and Institutional Framework
The PCFP creates a two-tier governance structure: a Cloud Board for policy oversight and the Cloud Office within MoITT for execution. The Cloud Board, chaired by the Secretary MoITT, includes provincial chief secretary representatives (conditional on provincial adoption) and industry experts to ensure stakeholder engagement and sector coordination. The Cloud Office’s responsibilities are broad and operational: establish accreditation/registration criteria for CSPs; maintain a pre-accredited list of CSPs to streamline procurement; define security baselines and data-class specific deployment requirements; perform compliance verification, ICT audits and technical assessments; issue time-bound NOCs for justified departures from cloud-first requirements; and support provinces in adoption. The MoITT has issued public calls for nominations to the Cloud Board and set up interim Cloud Office arrangements to begin these activities (Cloud Board nominations, MoITT Policies & Plan listing).
Key Focus Areas
The policy emphasises several core pillars: (1) Procurement and Accreditation — creation of an accredited CSP list and pre-approved procurement channels to reduce time-to-deploy and encourage competitive supply; (2) Data Classification and Security — a five-tier data classification regime with associated security baselines and minimum contractual protections; (3) Cost Optimisation & Aggregation — move from departmental CAPEX to OPEX pay-as-you-go models and aggregation of demand to leverage economies of scale; (4) Interoperability & Standardisation — standard contract clauses and minimum technical standards to promote portability and interoperability; (5) Local Capacity & Market Development — encourage investment by local and international CSPs, provide incentives for local presence and capacity building; (6) Risk Management & Compliance — mandatory security assessments, audits and accreditation enforcement; and (7) Workforce Transformation — training and change management to create a cloud-enabled public sector workforce. These focus areas are implemented through accreditation criteria, standard bidding documents, and sector-level guidance published by MoITT and coordinated with regulators (MoITT policy list).
Implementation Framework
PCFP sets a staged implementation approach: immediate creation of an interim Cloud Office to define baselines and prepare accreditation criteria; establishment of a permanent Cloud Office; preparation of pre-accredited CSP lists and standard procurement documents; mandatory adoption checkpoints for PSEs when planning new ICT investments; issuance of guidance on migration planning, risk assessment and contractual safeguards; and coordination with budget authorities to prevent new allocations for standalone departmental data centres. The policy delegates technical specification and enforcement detail to the Cloud Office and subsequent MoITT instruments, including the Standard Bidding Documents and the Accreditation Criteria published in 2024.
Monitoring and Evaluation
Monitoring is achieved through: (1) maintenance of an accredited CSP register and periodic compliance audits of accredited CSPs; (2) ICT audits of PSE cloud procurements and migration projects; (3) Cloud Office reporting to the Cloud Board and MoITT on adoption metrics (number of workloads migrated, cost-savings, service availability, security incidents); and (4) periodic review and revision of baselines and procurement templates. The Cloud Office is mandated to publish guidance and to support provinces and PSEs in measurement and reporting. Where necessary, the Office may recommend policy changes based on operational findings.
Penalties, Liability, and Appeals
The PCFP and its implementing instruments provide for administrative and contractual remedies rather than criminal sanctions. Key enforcement levers include: removal or suspension from the pre-accredited CSP register; termination or non-renewal of government contracts; withholding of procurement approvals; and requirements to remediate security or compliance failures within specified timelines. PSEs that contravene mandatory adoption rules may be denied funding for non-compliant CAPEX. The policy also contemplates appeal and review mechanisms within the Cloud Office/Cloud Board structure for contested accreditation or NOC decisions.
Relationship to Other Instruments
PCFP is explicitly linked to Pakistan’s broader digital strategy instruments such as the Digital Pakistan Policy and the National Cyber Security Policy (2021). It was approved contemporaneously with work on the Personal Data Protection Bill and functions as an implementation-level instrument that interacts with sectoral guidance (e.g., central bank cloud outsourcing frameworks) and procurement rules. The policy expects sectoral regulators to align their cloud outsourcing and prudential requirements with the PCFP’s baseline while preserving sector-specific risk controls.
International Alignment
The PCFP benchmarks its accreditation and security criteria against international standards to ensure interoperability and to attract investment from global and regional CSPs. PCFP emphasises alignment with widely accepted cloud security frameworks and international best practices in service availability, resilience and data protection. At the same time, policy design balances international engagement with domestic security and data classification needs to manage national security and citizen privacy concerns.
Implementation Timeline
| Milestone | Date |
|---|---|
| Federal cabinet approval | 2022-02-16 – 2022-02-18 (cabinet meeting period) |
| Published final policy (MoITT repository) | 2022-02-25 |
| Interim Cloud Office established | Mar–Apr 2022 (interim arrangements announced) |
| Accreditation criteria & Standard Bidding Documents published | 2024-06 – 2024-07 |
| Ongoing Cloud Board nominations and provincial consultations | 2024–2025 (consultations and calls for nominations) |
Sources and References
| Source | Type |
|---|---|
| Pakistan Cloud First Policy (Final, 25-Feb-2022) | Primary Source |
| MoITT Policies & Plan listing (PCFP) | Primary Source |
| IT ministry completes groundwork for govt move to cloud — Dawn (Feb 2022) | Secondary Source |
| Govt formulates accreditation criteria for cloud service providers — Business Recorder (Jul 2024) | Secondary Source |
Requirements for a company
What an organisation has to do under Pakistan - Cloud Solutions Adoption (2022), at a glance. Not legal advice — the table below gives the provision and deadline for each item.
Must do
11- Prioritize cloud-based solutions for all new Information and Communication Technology investments.Public Sector Entities (PSEs)
- Document cloud-first justification or obtain a No-Objection Certificate for any exceptions.Public Sector Entities (PSEs)
- Procure cloud services only from the Cloud Office's pre-accredited list of Cloud Service Providers.Public Sector Entities (PSEs)
- Classify all datasets according to the five-tier regime and follow the associated minimum security baselines.Public Sector Entities (PSEs)
- Include PCFP minimum contract clauses for business continuity, service level agreements, and audit rights.Public Sector Entities (PSEs)
- Complete pre-onboarding security assessments and periodic audits for all cloud services.Public Sector Entities (PSEs)
- +5 more in the table below
Must not do
0Nothing in this category.
Should do
0Nothing in this category.
Should not do
0Nothing in this category.
Who must do what
The obligations under Pakistan - Cloud Solutions Adoption (2022), most serious first. Not legal advice — verify against the official text before relying on it.
| # | Who | Requirement | By when | Where | Severity |
|---|---|---|---|---|---|
| 1 | Public Sector Entities (PSEs) | Prioritize cloud-based solutions for all new Information and Communication Technology investments. “Public Sector Entities (PSEs) to prioritise cloud solutions for new ICT investments” | When planning new ICT investments | Overview | Critical |
| 2 | Public Sector Entities (PSEs) | Document cloud-first justification or obtain a No-Objection Certificate for any exceptions. “issue time-bound NOCs for justified departures from cloud-first requirements” | Before new ICT investment approval | Implementation Framework | Critical |
| 3 | Public Sector Entities (PSEs) | Procure cloud services only from the Cloud Office's pre-accredited list of Cloud Service Providers. “maintain a pre-accredited list of CSPs to streamline procurement” | Before procuring cloud services | Key Focus Areas | Critical |
| 4 | Public Sector Entities (PSEs) | Classify all datasets according to the five-tier regime and follow the associated minimum security baselines. “five data classes—Open, Public, Restricted, Sensitive/Confidential and Secret—each triggering distinct security and deployment baselines” | — | Definitions | Critical |
| 5 | Public Sector Entities (PSEs) | Include PCFP minimum contract clauses for business continuity, service level agreements, and audit rights. “minimum contractual protections” | Before signing cloud service contracts | Key Focus Areas | Critical |
| 6 | Public Sector Entities (PSEs) | Complete pre-onboarding security assessments and periodic audits for all cloud services. “mandatory security assessments, audits and accreditation enforcement” | Before onboarding cloud services | Key Focus Areas | Critical |
| 7 | Public Sector Entities (PSEs) | Coordinate with budget authorities to prevent new funding allocations for standalone departmental data centers. “prevent new allocations for standalone departmental data centres” | — | Implementation Framework | Critical |
| 8 | Cloud Service Providers (CSPs) seeking to serve PSEs | Obtain and maintain accreditation or registration from the Cloud Office to serve Public Sector Entities. “establish accreditation/registration criteria for CSPs” | Before offering services to PSEs | Governance and Institutional Framework | Critical |
| 9 | Accredited Cloud Service Providers (CSPs) | Comply with security baselines and data-class specific deployment requirements defined by the Cloud Office. “define security baselines and data-class specific deployment requirements” | — | Governance and Institutional Framework | Critical |
| 10 | Accredited Cloud Service Providers (CSPs) | Undergo periodic compliance audits by the Cloud Office. “periodic compliance audits of accredited CSPs” | — | Monitoring and Evaluation | Critical |
| 11 | Public Sector Entities (PSEs) | Undertake required training and maintain migration playbooks to ensure a cloud-enabled public sector workforce. “Workforce Transformation — training and change management to create a cloud-enabled public sector workforce.” | — | Key Focus Areas | Important |
Related Regulations
© Regulations.AI · updated on 13-Jun-2026 · reviewed against official sources on 07-Sep-2026 using Gemini 3.6 Flash