What changed
The National Computer Emergency Response Team (NCERT) has introduced a structured set of criteria for registering cybersecurity professionals who will provide consultancy and audit-readiness services under the Pakistan Information Security Framework (PISF). The framework is intended to strengthen the cybersecurity posture of organisations across Pakistan by ensuring compliance with security standards and improving their preparedness for audits and assessments.
Under the new framework, registered consultants will operate across three major domains: IT security, operational technology (OT) security and cloud security. Their responsibilities will include conducting gap assessments, preparing implementation roadmaps and assisting organisations during security audits.
How consultants are categorised
Consultants will be placed in four tiers: Expert, Senior, Junior, and domain-specific specialists in IT, OT and cloud security.
Expert consultants are required to have at least 12 years of experience in IT and information security, including a minimum of six years in cybersecurity and at least three years in areas such as risk assessments and compliance audits. They must also hold advanced certifications, including CISSP and CISM, along with domain-specific credentials such as ISO 27001 for IT, ISO/IEC 27017 for cloud security, and ISA/IEC 62443 for OT systems.
Senior consultants must meet similar standards but with comparatively lower experience requirements and fewer audit-related engagements. Junior consultants must have at least three years of cybersecurity experience and hold certifications such as ISO 27001 or CEH. Their role will mainly involve foundational security tasks, including basic assessments and penetration testing under senior supervision.
Which organisations must use experts
Organisations have been classified into different risk categories. High-risk entities, designated CAT-I and CAT-II, will be required to engage Expert Consultants because of the complexity and sensitivity of their systems; those experts will lead security assessments and guide organisations through compliance and audit requirements.
For lower-risk categories, including CAT-III and CAT-IV, the requirements are more flexible. Senior or Expert Consultants may be assigned depending on an organisation’s complexity, while Junior Consultants may assist with tasks such as vulnerability assessments and penetration testing under supervision.
NCERT also plans to introduce a competency-based evaluation test to verify the technical skills of registered consultants, to ensure that professionals meet the minimum standards required under the framework.
Why it matters
The registration criteria create a common benchmark for the consultants that public and private organisations will rely on when preparing for audits under the PISF. By tying high-risk entities to the most experienced consultants and requiring recognised certifications, the framework is meant to make security reviews more consistent and to give organisations a clearer basis for choosing advisers.
Sources & reporting notes
This is a synthesis of published material, not eyewitness reporting. Sources were reviewed on 2026-04-26.
- Primary source — ProPakistani: "Govt Tightens Cybersecurity Rules for IT, Cloud and OT Experts to Work in Pakistan"26 April 2026 · Report on the NCERT registration criteria, the IT, OT and cloud security domains, the four consultant tiers, experience and certification requirements, organisation risk categories, and the planned competency test.


