An official website of the Pakistan government Here’s how you know
Official websites use .gov
A .gov website belongs to an official government organization in the Pakistan.
Secure .gov websites use HTTPS
A lock () or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.
Registered Audit Firms
The implementation of information and cybersecurity controls across Information Technology (IT), Operational Technology (OT), and Cloud environments by Federal Ministries, Divisions, and Departments, in compliance with the frameworks, guidelines, and policies issued by NCERT/NTISB, has been initiated by NCERT. This process requires engagement with firms that follow recognized cybersecurity standards, methodologies, and industry best practices.
Based on the assessment of documents submitted under the Cybersecurity Auditing Firm Registration criteria published on the NCERT website, appropriate categories have been assigned to the firms listed below. These firms are available to support Federal Ministries, Divisions, and Departments in compliance audits. To maintain auditor independence and avoid conflicts of interest, a firm engaged for consultancy and/or internal compliance audits shall not be engaged for any subsequent external audit, if required by NCERT or any relevant regulator.

This list will be constantly updated, as new firms are approved, or categories of existing firms are elevated/de-elevated. To verify an audit firm’s certificate click here

Cloud Security Registered Firms

CATEGORY FIRM CONTACT INFORMATION
CAT-I RISK ASSOCIATES (PVT) LTD. Name: Kashif Hassan
Email: kashif.hassan@riskassociates.com
CATALYIC SECURITY Name: Muhammad Bilal Islam
Email: bilal@catalyic.com

IT Security Registered Firms

CATEGORY FIRM CONTACT INFORMATION
CAT-I RISK ASSOCIATES (PVT) LTD. Name: Kashif Hassan
Email: kashif.hassan@riskassociates.com
CATALYIC SECURITY Name: Muhammad Bilal Islam
Email: bilal@catalyic.com
YOTTAA BYTE (PVT) LTD. Name: Maryam Shakir
Email: maryam.shakir@yottabyte.ae
TRILLIUM INFORMATION SECURITY SYSTEMS (PVT) LTD. Name: Aniqa Fareed
Email: aniqa.fareed@trilliuminfosec.com
EBRYX (PVT) LTD. Name: Talal Hassan Bukhari
Email: syed.talal@ebryx.com
NATIONAL ELECTRONICS COMPLEX OF PAKISTAN (NECOP)
Approved Mode: Direct Contracting in Government-to-Government (G2G)
Name: Zia-Ur-Rehman
Email: info.cs@necop.gov.pk
COMMON CRITERIA PAKISTAN LAB Name: M Saim Malik
Email: saim@commoncriteria.gov.pk,
director@commoncriteria.gov.pk
REDSECLABS (PVT) LTD. Name: Hashim Mufti
Email: hashim.mufti@redseclabs.com,
rafay@redseclabs.com
360 TECHNOLOGIES (PVT) LTD. Name: Bilal Asif
Email: bilal@360technologies.net
CAT-III REWTERZ (PVT) LTD. Name: Amir Kazmi
Email: amir.kazmi@rewterz.com
GROWTHARBOR (PVT) LTD. Name: Kumail Morawala
Email: info@growtharbor.com

OT Security Registered Firms

CATEGORY FIRM CONTACT INFORMATION
The registration and evaluation of OT Security firms is currently in progress. The list of approved firms will be announced soon.
Subscribe To Alerts