Get Demo
↑

PCI DSS Compliance in Pakistan: SBP Expectations, QSAs, and Cost Drivers

PCI DSS in Pakistan - State Bank digital-payment security expectations, acquirer validation.

Published: September 2026 Compliance · PCI DSS 8-12 min read

Card acceptance in Pakistan still sits under brand and acquirer PCI programs (SAQ or ROC + AOC, plus ASV where required). Separately, the State Bank of Pakistan (SBP) has issued digital-payment security instructions that push banks and microfinance banks (MFBs) toward PCI DSS assessment and adoption. Treat SBP circulars as regulatory pressure and prudential expectation - not a substitute for brand SAQ/ROC rules, and not a Council-issued “PCI certificate.”

Related: Certification myth · Cost · UAE and Saudi Arabia · SAQ types · PISF hub.

Gotcha: Saying “SBP certified us for PCI” is wrong. Validation remains SAQ/ROC/AOC (and ASV where required). SBP may examine digital-payment security separately. When SBP text says “certified as applicable,” that still does not mean a PCI SSC vanity certificate - see the certification myth page.

SBP PSD Circular No. 09 of 2018 (Security of Digital Payments)

Instrument: PSD Circular No. 09 of 2018, dated 28 November 2018 (“Security of Digital Payments”). Official index: sbp.org.pk/psd/2018/C9.htm. SBP later cross-referenced this circular in PSD Circular Letter No. 01 of 2022.

Banks/MFBs were directed to start assessing the feasibility of implementing PCI DSS and PA-DSS for their digital payment systems and adoption of the same standards by their third-party technology service providers, and to submit assessment reports to PSD (deadline cited in the circular: 31 January 2019). That is a feasibility assessment and reporting instruction - not a statement that every Pakistani merchant must hold a current ROC/AOC by law.

Acquiring banks/MFBs were also directed to discourage card swiping at merchants’ non-POS terminals especially when the merchant is not PCI DSS compliant.

BPRD Circular No. 04 of 2023 — Annexure A ¶ix

Instrument: Annexure A – Measures to Enhance Security of Digital Banking Products and Services, parent BPRD Circular No. 04 dated 14 April 2023 (FIs include banks and MFBs per the annex footnotes).

Paragraph ix directs FIs to ensure that the applications, payment cards, and channels used for such services are PCI DSS and PCI SSF certified as applicable (footnotes identify Payment Card Industry Data Security Standard and Payment Card Industry Software Security Framework).

How to read “certified as applicable”: Quote SBP carefully. PCI SSC still does not issue entity compliance certificates. Practical validation remains official SAQ/ROC/AOC (and ASV) artefacts, plus PCI SSF paths where software security frameworks apply. Cross-link: Is there a PCI DSS certification?

Practical Path for Pakistani Entities

  1. Confirm acquirer level and SAQ eligibility (or ROC) under brand programs
  2. Scope the CDE - fully outsourced gateways often lean SAQ A / A-EP candidates when eligibility is met
  3. Engage a PCI SSC-listed QSA and ASV (regional delivery is common)
  4. Align with existing PISF / ISO programs without double-counting evidence carelessly
  5. Budget using cost and timeline drivers - local PKR quotes vary; avoid fake fixed-price tables

See PCI cost drivers and timeline.

How CyberSilo Helps

Map PCI DSS v4.0.1 Controls to Continuous Evidence

CyberSilo CSA and ThreatHawk SIEM help merchants and service providers collect QSA-ready evidence across scoping, cloud, and SAQ/ROC validation paths.

Frequently Asked Questions

Do all Pakistani SMEs need a ROC?

No. Path depends on acquirer level and brand rules. Many smaller merchants remain SAQ-eligible when criteria are met.

Are local QSAs required?

Use a PCI SSC-listed QSA. Many companies operate regionally into Pakistan.

What about EMIs and fintech?

Often a service-provider path, or a dual merchant/SP role - confirm with counsel, the regulator, and your acquirer.

Certification myth · Cost · UAE and Saudi Arabia · SAQ types · PISF hub · SAQ selector

📰 More from CyberSilo

Latest Articles

Stay ahead of evolving cyber threats with our expert insights

✅ Link copied!