The National Assembly has passed the Cybercrime Amendment Bill 2026, introducing stricter regulations for technology companies operating in Pakistan. The bill mandates data localization for financial and healthcare platforms, with a 12-month compliance deadline.
Key provisions include mandatory incident reporting within 6 hours of breach detection, appointment of Chief Information Security Officers for companies with over 50 employees, and annual security audits by certified firms.
The bill also introduces a tiered penalty structure: fines ranging from PKR 5 million for minor violations to PKR 500 million for critical infrastructure breaches. Repeat offenders face potential license suspension.
Tech industry leaders have expressed mixed reactions. While acknowledging the need for stronger cybercrime laws, NASSCOM Pakistan chapter raised concerns about the compliance burden on startups. “The 12-month timeline is aggressive for early-stage companies,” noted the chapter president.
The Pakistan Software Export Board (PSEB) will provide free compliance training and certification programs to help companies meet the new requirements.