An official website of the Pakistan government Here’s how you know
Official websites use .gov
A .gov website belongs to an official government organization in the Pakistan.
Secure .gov websites use HTTPS
A lock () or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

Information Security Consultant Registration Program

To support organizations in the implementation of the Pakistan Information Security Framework (PISF) and achieving compliance with its requirements, the National Cyber Emergency Response Team of Pakistan (PKCERT) is inviting qualified information security professionals to register as consultants for PISF implementation and audit-readiness support.
Selected consultants will assist organizations by:
  1. Conducting comprehensive gap and risk assessments
  2. Providing governance, risk, and technical advisory services
  3. Developing strategic implementation roadmaps
  4. Deploying required security controls
  5. Preparing organizations for formal PISF compliance audits
Consultant Levels & Technical Domains
Consultant Levels
Applicants may apply for registration under one of following three levels:
  1. Expert Consultant
  2. Senior Consultant
  3. Junior Consultant
Technical Domains
Applicants may apply for registration across one or more of the following specialized technical domains:
  1. Information Technology (IT)
  2. Cloud
  3. Operational Technology (OT / ICS)

Basic Eligibility Criteria


Consultant Level Experience Required
(If Highest Qualification is BS)
Experience Required
(If Highest Qualification is MS/PhD)
Engagements Required Certifications Required
(Note: Applicants with PhD degree in a relevant discipline shall be exempt from the certification requirement.)
Expert Total experience ≥ 12 yrs;
Cybersecurity-specific ≥ 8 yrs;
GRC/Audit/Assessment/VAPT ≥ 5 yrs
Total experience ≥ 8 yrs;
Cybersecurity-specific ≥ 5 yrs;
GRC/Audit/Assessment/VAPT ≥ 4 yrs
≥ 10 (Audit/Compliance/Gap & Risk Assessment/ Control Implementation/Strategy or relevant engagements) ≥ 1 Core Certification +
≥ 1 Domain-Specific Certification
Senior Total experience ≥ 8 yrs;
Cybersecurity-specific ≥ 5 yrs;
GRC/Audit/Assessment/VAPT ≥ 4 yrs
Total experience ≥ 6 yrs;
Cybersecurity-specific ≥ 4 yrs;
GRC/Audit/Assessment/VAPT ≥ 3 yrs
≥ 7 (Audit/Compliance/Gap & Risk Assessment/ Control Implementation/Strategy or relevant engagements) ≥ 1 Core Certification +
≥ 1 Domain-Specific Certification
Junior Total experience ≥ 4 yrs;
GRC/Audit/Assessment/VAPT ≥ 3 yrs
Total experience ≥ 3 yrs;
GRC/Audit/Assessment/VAPT ≥ 2 yrs
≥ 5 (Audit/Compliance/Gap & Risk Assessment/ Control Implementation/VAPT or relevant engagements) ≥ 1 Core Certification

Core Certifications Required
Expert & Senior Consultants Junior Consultants
CISSP, CISM, CRISC, CISA, ISO/IEC 27001 LA/LI or equivalent ISO/IEC 27001 LA/LI, CEH, OSCP, Security+ or equivalent

Domain-Specific Certifications Required
Expert & Senior Consultants Junior Consultants
IT: CISSP, CISM, CRISC, CISA, ISO/IEC 27001 LA/LI, ISO/IEC 27701, or equivalent
Cloud: ISO/IEC 27017, CCSP, or equivalent
OT: ISA/IEC 62443 or equivalent
Domain-specific certifications is not a mandatory requirement. However, applicants holding domain-specific certifications will be awarded additional points during the evaluation process.

Evaluation Process

The Information Security Consultant Registration program follows a structured four-stage registration process:
Step 1: Application Submission
  1. Applications for consultant registration may be submitted at any time throughout the year.
  2. Evaluations are conducted on a quarterly basis according to the following schedule:
Application Intake Period Evaluation Month
Q1: January – March April
Q2: April – June July
Q3: July – September October
Q4: October – December January
Step 2: Preliminary Eligibility Review
  1. All submitted applications undergo an initial screening to ensure candidates meet the basic eligibility criteria, including academic qualifications, practical experience, and required certifications, before advancing to interview and technical assessment.
Step 3: Interview & Technical Assessment
  1. Shortlisted candidates who pass the basic eligibility criteria will undergo direct evaluation to verify domain expertise, practical competencies, and alignment with PISF advisory requirements:
    1. Interview: An interview (in-person or virtual) conducted by the evaluation panel to assess key capabilities and practical experience.
    2. Test based Assessment: A written or practical examination may be conducted, if deemed necessary by PKCERT, to evaluate specialized technical skills and capabilities.
Step 4: Comprehensive Profile Scoring & Final Empanelment
  1. Following the interview and technical assessment, candidates will be evaluated through PKCERT’s internal scoring system. This final score combines interview/technical assessment results with additional achievements and professional contributions, some of which may include but are not limited to:
    1. Thought Leadership & Knowledge Sharing: Keynote addresses, expert panel contributions, peer-reviewed publications, research papers, or published security articles.
    2. Cybersecurity Standards & Governance Working Groups: Active involvement in national or international standards bodies, regulatory advisory committees, or industry working groups.
    3. Professional Recognition & Industry Accolades: National cybersecurity awards, peer-recognized honors, institutional commendations, or industry excellence awards.
    4. Strategic Leadership & Governance: Proven experience leading cybersecurity initiatives, managing technical teams, directing GRC programs within critical infrastructure or enterprise environments.
    5. Advanced Capacity Building & Continuous Education: Specialized certifications, advanced trainings, specialized capacity-building workshops.
  2. Candidates who meet the minimum qualifying score will be formally notified and invited to register as PISF Consultants.

Terms & Conditions

  1. Registration under this program constitutes recognition of a consultant’s qualifications, experience and expertise only. Registration does not constitute an employment contract, service agreement, or commercial partnership between PKCERT and the consultant.
  2. PKCERT acts solely as an evaluation, registration, and governance body to facilitate organizations in obtaining services from qualified PISF consultants. PKCERT assumes no liability for the quality, accuracy, timeliness, omissions, or outcomes of consultancy services delivered by a registered consultant to an organization.
  3. Registration under this program does not guarantee any minimum number of project assignments, client referrals, or business opportunities from PKCERT.
  4. PKCERT will not enter into commercial contracts, financial arrangements, or Service Level Agreements (SLAs) on behalf of registered consultants. All such arrangements shall be executed directly between the hiring organization and the consultant.
  5. Hiring organizations retain full responsibility for evaluating, selecting, contracting, and managing consultants. Organizations are strongly advised to execute binding commercial contracts, Non-Disclosure Agreements (NDAs), Service Level Agreements (SLAs), etc. directly with the consultant prior to initiating any engagement.
  6. Successful candidates offered registration as PISF Consultants shall be required to pay the prescribed registration fee prior to activation of their registration status. Registration shall remain valid subject to payment of the applicable annual renewal fee and continued compliance with the program requirements.
  7. To maintain active registration in the program, consultants must comply with the following ongoing requirements:
    1. Complete a minimum of one (1) PISF consultancy engagement during each calendar year.
    2. Register PISF consultancy engagements at PKCERT’s designated consultant portal in accordance with the applicable program procedures.
    3. Submit an annual summary of completed PISF consultancy engagements to PKCERT.
    4. Comply with the quality assurance and engagement monitoring procedures established by PKCERT for registered consultants. Details shall be communicated separately to consultants invited for registration.
  8. A consultant may request voluntary removal from the PKCERT’s registered consultant roster at any time by providing a written notice.
  9. PKCERT reserves the right to modify registration criteria, evaluation scoring mechanisms, governance procedures, fee structure, renewal requirements, or technical details from time to time. Registered consultants shall be provided reasonable notice and an appropriate transition period, where applicable, to comply with revised program requirements.

Organization and Consultant Mapping

The following framework outlines the recommended mapping of registered consultants with four different categories of organizations:
Category Target Organizations Operational Scope & Complexity Recommended Minimum Lead Consultant Requirement
CAT-I Critical Sectors
(e.g., Energy, Power, Banking, Finance, Telecommunications, Defense, Federal Entities)
Multi-site infrastructure, hybrid environments, IT/OT/Cloud integration, complex supply chain, >150 nodes or national impact. Expert Consultant (Lead)
+ Senior/Junior team members
CAT-II Critical Sectors (e.g., Regional Utilities, Local Government) Single/Focused site, specialized IT/OT or Cloud deployments, ≤150 nodes with localized operational impact. Expert OR Senior Consultant (Lead)
+ Junior team members
CAT-III Non-Critical Enterprise / Large Public & Private Entities
(e.g., Large Commercial Services, Universities)
Enterprise IT & Cloud environments, >150 nodes, complex data handling, non-critical sector. Senior Consultant (Lead)
+ Junior team members
CAT-IV Non-Critical Medium/Small Entities
(e.g., SMEs, Regional Commercial Entities)
Baseline IT services, local network, ≤150 nodes. Senior OR Junior Consultant (Lead)
Subscribe To Alerts