Pakistan Security Standard Documents

The Pakistan Security Standards (PSS) document repository is structured into three domains — Public, Restricted, and Private. Each domain defines the accessibility and sensitivity level of documents, ensuring transparency, security, and compliance with national cybersecurity standards.

Category Sub-Category Details
Public Domain Documents NSS Guide Book
Public Domain Documents ITSec Guide Book
Restricted Release Documents Security Standard Overview Document, LAB Accreditation Guide (PNAC)
Restricted Release Documents Cryptographic Primitives 1x GR, 1x DTR
Restricted Release Documents Cryptographic Equipment 1x GR, 1x DTR
Restricted Release Documents Secure Design Implementation 1x GR, 1x DTR
Restricted Release Documents Key Management System 1x GR, 1x DTR
Private Domain Lab Documents (Lab Specific) Cryptographic Primitives 6x GR, 6x DTR
Private Domain Lab Documents (Lab Specific) Cryptographic Equipment 5x GR, 5x DTR
Private Domain Lab Documents (Lab Specific) Key Management System 1x GR, 1x DTR
Private Domain Lab Documents (NSSIS GB) Evaluation Guide Book
Private Domain Lab Documents (NSSIS GB) NTISB Guidebook

PSS Documents Lists

Ser Category Document Name
1 Green (Public Domain) Public - PSS Crypto Guide Book
2 Public - PSS IT Sec Guide Book
1 Black (Restricted Domain) Restricted - Overview Document
2Restricted - GR for CP
3Restricted - DTR CP
4Restricted - GR for CE
5Restricted - DTR for CE
6Restricted - GR for KMS
7Restricted - DTR for KMS
8Restricted - DTR for SDI
9Restricted - GR for SDI
10Restricted - PSSIS-NASCEL
1 Red (Private Domain) Private - DTR of General Technical Requirements for HF Radio Encryptor
2Private - General Technical Requirements for HF Radio Encryptor
3Private - General Technical Requirements for VUHF Radio Encryptor
4Private - DTR of General Technical Requirements for VUHF Radio Encryptor
5Private - General Technical Requirements for Link Encryptor
6Private - Derived Test Requirements for General Technical Requirements for Link Encryptor
7Private - General Technical Requirements for Wireline Encryptor
8Private - DTR of General Technical Requirements for Wireline Encryptor
9Private - General Technical Requirements for IP Encryptor
10Private - Derived Test Requirements of General Technical Requirements for IP Encryptor
11Private - General Requirements for Block Ciphers
12Private - Derived Test Requirements of General Requirements for Block Ciphers
13Private - General Requirements for Stream Ciphers
14Private - Derived Test Requirements of General Requirements for Stream Ciphers
15Private - General Requirements for Public Key Cryptography
16Private - Derived Test Requirements of General Requirements for Public Key Cryptography
17Private - General Requirements for Digital Signature Scheme
18Private - Derived Test Requirements for Digital Signature Scheme
19Private - General Requirements for Hash
20Private - Derived Test Requirements of General Requirements for Hash
21Private - General Requirements for RNG
22Private - Derived Test Requirements of General Requirements for RNG
23Private - Derived Test Requirements for Secure Software Application
24Private - Detailed Test Requirements for ICT Audit
25Private - PSSIS - Evaluation Lab
26Private - PSSIS - Implementation Scheme
27Private - Overview Document

IT Sector Evaluations Documents List

Surface Evaluation Screening Detailed Evaluation
  1. Administrative / Installation Manual (Installation, Configuration, Operations)
  2. User / End-User Manual
  3. Developer / API / SDK Guide (if applicable)
  4. Upgrade, Patch & Lifecycle Management Guide
  5. End-of-Sale (EOS) / End-of-Life (EOL) Information
  6. Product Release Date & Version History
  7. Supported Operating Systems / Platforms / Firmware Versions
  8. Product Model, Type & Category
  9. Available Features & Functional Specifications
  10. Performance Benchmarks (with and without advanced features enabled)
  11. Supported Security Protocols & Standards
  12. Publicly Known Vulnerabilities (CVE/Advisory) — Exploit Reports (if any)
  13. Security Certifications (e.g., CC, NIST, FIPS, ISO, etc.)
  14. Industry Rankings / References (e.g., Gartner, Forrester, NSS Labs, etc.)
  15. Vendor Legitimacy Status (if applicable)
  16. Cryptographic Specifications (Encryption, VPN, SSL/TLS etc.)
  17. Proposed Deployment Scenario
  18. Any other product/solution-specific documentation as applicable
  1. Administrative / Installation Manual (Installation, Configuration, Operations)
  2. User / End-User Manual
  3. Security Hardening & Compliance documentation
  4. Operating Systems / Platforms / Firmware Versions
  5. Product Datasheet (Model, Firmware Type, Category)
  6. Product Datasheet
  7. Chipset / Processor details with manufacturer info
  8. Mil-Std (If Claimed)
  9. Chipset / Architecture Details
  10. Bill of Materials (BOM) — major ICs, controllers, memory modules
  11. End-of-Sale (EOS) & End-of-Life (EOL) dates
  12. Certificates:
    1. FCC ID / Certification
    2. CE Marking compliance
    3. RoHS (Restriction of Hazardous Substances) Certificate/report
    4. EnergyStar / Green IT Certification
  13. Country-specific safety & EMI/EMC compliance reports

All documents required in Surface Evaluation, plus the additional documents below:

  1. High-Level Design (HLD)
  2. Low-Level Design (LLD)
  3. Deployment Architecture Diagram
  4. Data Flow Diagram
  5. Process Flow Diagrams
  6. Network & Security Architecture Documents
  7. System Integration Documentation
  8. Test Cases & Test Reports
  9. Technical Compliance Matrix
  10. Audit & Penetration Testing Reports (if available)
  11. Security Hardening & Compliance Guide
  12. Interactive sessions and support deemed necessary during evaluation