Pakistan has approved a 90-day Cybersecurity Strategic Action Plan to strengthen the country’s cyber-defence capabilities amid growing cyber warfare and digital security threats.
The federal government has also directed provincial authorities to accelerate the establishment of Computer Emergency Response Teams (CERTs) and ensure the implementation of the Pakistan Information Security Framework 2026 (PISF) at both federal and provincial levels.
The decisions were taken during the second meeting of the National Committee for Information and Communications, chaired by the Secretary of the Ministry of Information Technology and Telecommunications and Chairman of the committee at the Cabinet Division, according to sources cited by Jang.
The meeting emphasized the need for immediate and coordinated measures to improve Pakistan’s overall cyber resilience. Officials were informed that PISF 2026 has already been approved and its implementation should be carried out across federal and provincial institutions.
The National Computer Emergency Response Team (NCERT), which leads the Cybersecurity Working Committee, presented the 90-day action plan during the meeting. The roadmap focuses on cybersecurity governance, regulatory compliance, resource coordination, cyber incident response, crisis management, security assessments and supply-chain security.
The plan comes as Pakistan faces an increasingly complex cyber threat environment. The National CERT is responsible for protecting the country’s digital assets, sensitive information and critical infrastructure against cyberattacks, cyber terrorism and cyber espionage.
During 2026, the National CERT has also issued several security advisories concerning vulnerabilities affecting widely used technologies and systems, including products from Fortinet, Palo Alto Networks, Microsoft, Ivanti and Cisco.
The government has additionally prepared a National Cybersecurity Handbook for public-sector organisations. The handbook provides baseline guidance on cybersecurity governance, data protection, network and access security, vulnerability management, incident response, business continuity and disaster recovery.
Officials also highlighted the importance of establishing sectoral and provincial CERTs to improve the country’s ability to detect, contain and respond to cyber incidents.
Under Pakistan’s CERT Rules, the National CERT is expected to serve as a coordinating body for cyber incident reporting and response across government institutions, critical infrastructure, telecommunications, banking, finance, academia and other sectors.
The Pakistan Telecommunication Authority (PTA) chairman also stressed that activating the federal CERT requires careful and comprehensive planning, particularly as sector-specific and provincial CERT structures are still being developed.

