State Bank of Pakistan: test your mobile banking app before every launch.
SBP asks banks and microfinance banks to run a security review of every new or changed digital product, and to fix all critical, high and medium vulnerabilities before launch. Its technology risk framework adds vulnerability assessments and penetration tests, and its 2023 digital banking measures set device binding, authentication and encryption controls, with compensation duties for victims of fraud if the controls are missing. Ostorlab tests the controls in your app and the APIs behind it, on every release.
- Static and dynamic testing of the build you ship, with no source code needed
- Tests login, one-time codes, step-up checks and session handling with your test accounts
- Follows the app into its APIs, even with TLS pinning
- Risk ratings, tickets and retests, so every fix is validated before launch
- Who it applies to
- Banks, DFIs and microfinance banks in Pakistan, and other SBP regulated entities for some texts
- Key date
- Digital banking security measures due by 31 December 2023 (BPRD Circular No. 04 of 2023)
- Focus
- Security reviews before launch, penetration testing, authentication and device binding
- Main references
- BPRD Circular No. 05 of 2017 and BPRD Circular No. 04 of 2023
How the SBP rules for digital channels took shape
SBP has built its rules for technology and digital channels through circulars. The dates below are for the texts cited on this page.
- 22 June 2016
Prevention against cyber attacks
BPRD Circular No. 07 of 2016 asks banks, DFIs and microfinance banks for periodic independent assessments of their cyber security controls, including vulnerability assessments and penetration testing.
- 30 May 2017
Technology governance framework
BPRD Circular No. 05 of 2017 issues the Enterprise Technology Governance & Risk Management Framework, with compliance required by 30 June 2018.
- 28 November 2018
Security of digital payments
PSD Circular No. 09 of 2018 requires vulnerability assessment and penetration testing of alternate delivery channels, including internet and mobile banking, and an independent third-party review.
- 14 April 2023
Digital banking security measures
BPRD Circular No. 04 of 2023 sets control measures for digital banking products and services, with a plan due to SBP within 30 days and monthly progress reports.
- 31 December 2023
Deadline for the measures
Banks and microfinance banks that miss it are liable to compensate victim customers within three working days of the reporting of fraud.
- 16 February 2026
Cyber Shield strategy
SBP's Cyber Resilience Strategy for regulated entities, with milestones to be implemented in a phased manner by 2030.
The SBP rules, applied to your mobile app
For each rule: what the text says, what it means for a mobile banking app, how Ostorlab helps, and what stays with your team.
- BPRD Circular No. 04 of 2023, Annexure A, 2(vii) and 2(viii)
Review every new or changed digital product before launch
What the text says
Conduct comprehensive information security reviews of new digital products and services, and of any modification to existing ones, covering people, process and technology. Weaknesses and all critical, high and medium vulnerabilities found in those reviews must be rectified and controlled through validation before deployment to production and launch.
Source:BPRD Circular No. 04 of 2023, Annexure A, 2(vii) and 2(viii)
What it means for your mobile app
Each release of the mobile app changes a digital product. It needs a security review, and every medium, high or critical finding has to be fixed and retested before the store update goes live.
How Ostorlab helps
Run automated scans from your CI/CD pipeline on every build. Mobile SAST analyses the APK, AAB or IPA directly, with no source code needed, and Mobile DAST runs the app. Findings are rated critical, high, medium or low, tracked as tickets in the platform or in Jira and ServiceNow, and retested once the fix ships.
What stays with you
The review baseline, the people and process parts of the review, and the go-live decision.
- BPRD Circular No. 04 of 2023, Annexure B (FAQs), Management Control 2(vii)
Run periodic application security reviews
What the text says
SBP's FAQs on the 2023 measures say regulated entities must conduct periodic application security reviews, including vulnerability assessments, penetration testing and source code reviews, and address and rectify all identified vulnerabilities in a timely manner. Each entity develops its own review baseline, based on best practices and its own risk assessment.
Source:BPRD Circular No. 04 of 2023, Annexure B (FAQs), Management Control 2(vii)
What it means for your mobile app
Release checks are not enough on their own. The app and its APIs also need a recurring cycle of vulnerability assessment, penetration testing and code review, with a record that the findings were fixed.
How Ostorlab helps
Fast scans usually finish in 1 to 5 minutes and full scans in 15 to 45 minutes, so they fit every release. An AI-agent pentest goes deeper, typically in a few hours, with a working exploit you can replay for each AI-agent finding, for critical changes and your periodic deep tests.
What stays with you
Source code reviews of your backend, the review schedule and the baseline itself.
- Enterprise Technology Governance & Risk Management Framework, 2.7
Keep a testing program with vulnerability assessments and penetration tests
What the text says
Establish a comprehensive testing program to validate the effectiveness of the information security environment on a regular basis. Depending on the complexity of operations, use vulnerability assessments followed by a validation test that the gaps were filled, scenario-based testing, periodic penetration tests, with tests of internal systems at the time of major updates and deployments, and an independent quality assurance function that tests in-house developments for vulnerabilities. The policy sets how often each test runs.
Source:Enterprise Technology Governance & Risk Management Framework, 2.7
What it means for your mobile app
Your policy defines how often the app is tested. A major release of the app or its backend is a natural trigger for a penetration test, and each assessment needs a follow-up test that proves the gaps are closed.
How Ostorlab helps
Your security or second-line team runs the tests and owns the results. Each finding comes with a risk rating, reproduction steps, request and response logs and screenshots, and retesting confirms whether the underlying issue is resolved.
What stays with you
Scenario-based and recovery testing, the testing policy and its periodicity.
- BPRD Circular No. 07 of 2016; PSD Circular No. 09 of 2018
Have your cyber controls assessed independently
What the text says
Banks, DFIs and microfinance banks must ensure periodic independent assessments of the adequacy and effectiveness of their cyber security controls. These may include vulnerability assessments and penetration testing by officials independent of the area under review, or by external parties with sufficient IT security experience where internal teams lack the expertise. In 2018, SBP also required internal vulnerability assessment and penetration testing, and an independent third-party review, of alternate delivery channels, including internet and mobile banking.
Source:BPRD Circular No. 07 of 2016; PSD Circular No. 09 of 2018
What it means for your mobile app
The people who test the app should be independent of the team that builds it. For mobile banking, SBP has already asked for both internal testing and a third-party review.
How Ostorlab helps
Ostorlab tests the build your customers download and the APIs it calls. Your security or second-line team runs the tests and owns the results, separately from the developers.
What stays with you
Deciding whether a test meets the independence expectation, and engaging external assessors.
- Regulations for the Security of Internet Banking, 1 and 2.2.1; BPRD Circular No. 04 of 2023, Annexure A, 3-I(iv)
Authenticate with at least two factors, and control sessions
What the text says
Banks must authenticate internet banking customers with at least two-factor authentication, such as a password and a one-time token, and add layered security for high-value transactions. Authentication controls take into account failed log-in attempts, password change frequency, session time-outs and re-authentication based on predefined criteria. The regulations apply whatever access device the customer uses, and SBP's 2023 measures add that one-time passwords must be of reasonable length with appropriate validity.
What it means for your mobile app
Lockout after failed attempts, session expiry, re-authentication for high-value transfers and one-time password lifetime are all testable settings in the app and its backend.
How Ostorlab helps
Ostorlab logs in with your test accounts, completes SMS, email or TOTP one-time codes, and tests login and logout, token refresh, timeouts, session invalidation and MFA enforcement, including step-up flows.
What stays with you
Choosing the factors and the policy values, such as lockout thresholds and one-time password validity.
- BPRD Circular No. 04 of 2023, Annexure A, 3-A(iii), (v), (vi), (viii) and (ix)
Bind devices and protect credential resets
What the text says
Register customer devices through device fingerprinting or device binding, and notify the customer immediately of any new device. Credential resets may only be performed from the registered device, with one-time password auto-fetch or auto-fill and sender binding that restricts manual entry. A 2-hour cooling-off period applies before the mobile app is activated for newly registered customers, and before key account changes such as device, mobile number, email, transaction limits and password reset. Sign-up must not confirm that an account exists before the process is complete.
Source:BPRD Circular No. 04 of 2023, Annexure A, 3-A(iii), (v), (vi), (viii) and (ix)
What it means for your mobile app
These controls have to hold in the backend, not only in the app screens. A request sent straight to the API should hit the same device check, the same cooling-off period and the same silent sign-up.
How Ostorlab helps
Ostorlab completes SMS, email or TOTP one-time codes with your test accounts and tests MFA enforcement and step-up flows, including how attackers try to manipulate them, together with the API calls behind account changes. API tests cover abuse such as enumeration, replay and automation.
What stays with you
Device binding design, NADRA biometric verification, call-back confirmation and customer notifications.
- BPRD Circular No. 04 of 2023, Annexure A, 3-B(v) and 3-E
Encrypt and mask customer data
What the text says
Encrypt data in transit and at rest at all stages of a transaction, based on its classification and sensitivity, including personally identifiable information and payment card data. Customer information is stored or transmitted in hashed or encrypted form with non-obsolete algorithms such as AES 256 and SHA256, biometric information is never stored or transmitted unencrypted, and critical information such as card numbers is masked.
Source:BPRD Circular No. 04 of 2023, Annexure A, 3-B(v) and 3-E
What it means for your mobile app
The app is one stage of the transaction. What it writes to the device, puts in logs or sends over the network is in scope.
How Ostorlab helps
Ostorlab looks for session tokens and personal data in local storage, caches, logs and screenshots, checks for misconfigurations that weaken transport and session protections, and tests the APIs behind transactions.
What stays with you
Key management, data classification and encryption on your servers.
- BPRD Circular No. 04 of 2023, cover letter and Annexure A, 4(iii)(f) and 4(v)
Be able to show your controls were in place
What the text says
Banks and microfinance banks that fail to implement the controls within the timeline are liable to compensate victim customers within three working days of the reporting of fraud, apart from enforcement action. Under the liability framework, FIs compensate customers where they cannot establish that transactions were executed through the customer’s registered device, and originating FIs compensate customers where any stipulated control is not implemented or has failed.
Source:BPRD Circular No. 04 of 2023, cover letter and Annexure A, 4(iii)(f) and 4(v)
What it means for your mobile app
When a fraud claim comes in, the question is whether your controls existed and worked. Test results for each release help you answer it.
How Ostorlab helps
Scan results, findings with reproduction steps and retest results give you a dated record of how the app’s controls were tested and fixed, release after release.
What stays with you
Fraud monitoring, dispute handling in FTDH and the compensation decision.
- Framework on Outsourcing to Cloud Service Providers, Section T
Test cloud-hosted systems at least once a year
What the text says
Conduct vulnerability assessment, penetration testing and scenario-based security testing of systems hosted with cloud service providers, at least once annually, taking into account threats unique to cloud services such as weak application programming interfaces. Vulnerabilities in cloud workloads are categorized by risk, tracked and rectified, including post validation.
Source:Framework on Outsourcing to Cloud Service Providers, Section T
What it means for your mobile app
If the backend or APIs behind your app run in the cloud, they need at least a yearly assessment and penetration test, and API weaknesses are named as a scenario to cover.
How Ostorlab helps
Ostorlab intercepts the app's traffic, even with TLS pinning, and tests the APIs for broken authorization (BOLA, BFLA, IDOR), misuse of tokens and sessions, and abuse such as enumeration, replay and automation, with request and response evidence for each finding.
What stays with you
Testing of the cloud infrastructure, the provider's own assessments and data centre reviews.
Summary of public SBP texts, checked on 27 September 2026. Some texts apply only to banks and microfinance banks, as noted. This page is not legal advice.
SBP rules, control by control
The controls the SBP texts point to, how Ostorlab tests them in your app and its APIs, and the evidence you can keep.
| Control | How Ostorlab helps | Evidence you keep |
|---|---|---|
| Security review of each new or changed digital productBPRD 04/2023, Annex A 2(vii) | Mobile SAST and DAST in the release pipeline, before the app reaches the store. Details | Scan results for each build |
| Critical, high and medium findings fixed and validated before launchBPRD 04/2023, Annex A 2(viii) | Groups findings into tickets in the platform or in Jira and ServiceNow, and retests after the fix. Details | Ticket history and retest result for each finding |
| Periodic vulnerability assessments and penetration testsETGRMF 2.7; BPRD 04/2023, Annex B | AI-agent pentest of the app and its APIs, behind login, on the build you ship. Details | A working exploit you can replay for each AI-agent finding, and a coverage heatmap |
| Two-factor authentication, failed log-ins and session time-outsInternet banking regulations, 2.2.1 | Logged-in testing with one-time codes, and checks of sessions, tokens, timeouts and MFA enforcement. Details | Findings on login, session and step-up flows with reproduction steps |
| Device checks and cooling-off on key account changesBPRD 04/2023, Annex A 3-A | Logs in with one-time codes and tests MFA enforcement and step-up flows, and the API calls behind them. Details | Findings on login and step-up flows, with reproduction steps |
| Sign-up that does not reveal whether an account existsBPRD 04/2023, Annex A 3-A(ix) | Intercepts traffic even with TLS pinning and tests authorization, token misuse and abuse such as enumeration and replay. Details | Request and response evidence for each API finding |
| Encryption and masking of customer dataBPRD 04/2023, Annex A 3-B(v), 3-E | Looks for tokens and personal data in storage, caches, logs and screenshots, and checks transport protections. Details | File system evidence showing what was written, where and when |
| Security and vulnerability assessment of software modulesETGRMF 4.2.1(d) | Fingerprints statically compiled libraries and maps them to known vulnerabilities, release to release. Details | Mapped vulnerabilities with upgrade or replace recommendations, and closure tracked across releases |
| Yearly testing of cloud-hosted APIsCloud framework, Section T | Logged-in testing that follows the app into its APIs to test authorization, sessions and MFA enforcement. Details | Request and response logs and reproduction steps for each finding |
| A record of tested controls for fraud claimsBPRD 04/2023, Annex A 4 | Keeps scan results, tickets and retests for each release. | Dated scan history, tickets and retest results |
Ostorlab tests controls in the app and its APIs. Fraud monitoring, FTDH disputes, NADRA biometric verification, call center controls, PCI DSS and PCI SSF accreditation, business continuity and reporting to SBP stay with your teams.
SBP controls to test in your mobile app
A practical list for security, technology risk and fraud teams, based on the SBP texts on this page.
Review each release
Scan every build before it reaches the store, and hold the release while critical, high or medium findings are open.
Validate the fixes
Retest each fix before launch and keep the result, so the validation step is on record.
Periodic deep tests
Plan periodic penetration tests and code reviews of the app and its APIs, and a test after each major update.
Login and one-time passwords
Check two-factor login, lockout after failed attempts, session time-outs, re-authentication for high-value transfers and one-time password validity.
Device binding and cooling-off
Try credential resets and key account changes from an unregistered device and directly through the APIs, and check that the 2-hour cooling-off holds.
Silent sign-up
Check that registration never confirms whether an account exists before the process is complete, including through repeated API calls.
Data on the device and in transit
Look for tokens, personal data and card numbers in storage, caches, logs and screenshots, and check that traffic is encrypted.
Evidence for fraud claims
Keep dated results and retests for each release, to show which controls were in place and tested.
A suggested list, not an SBP template. This is not legal advice.
The capabilities behind this page
Each one has its own page with the details.
- Mobile Agentic Deep ScanAI agents pentest the store build on every release, with a working exploit you can replay for each AI-agent finding.Learn more
- Authenticated testingTest login, one-time codes and step-up flows with your test accounts.Learn more
- API and backend testingIntercept app traffic even with TLS pinning, then test the APIs and backends behind accounts and payments.Learn more
- Mobile SASTBinary-based static analysis of APK, AAB and IPA files, with taint analysis across the app and its embedded SDKs.Learn more
- SCA and SBOMFind vulnerable dependencies, including statically compiled native libraries, and track their closure release after release.Learn more
- Mobile Shielding ScanTest root and jailbreak detection, anti-tampering and pinning at runtime, and see which protections held and which were bypassed.Learn more
- Bring your own AI keyRun AI-agent scans on your own AI provider key with a spend cap per scan, so usage follows your internal policies.Learn more
- On-premises scanningScan staging apps, APIs and repositories behind your firewall or VPN, on infrastructure you control.Learn more
Trusted by banks and fintechs, including
Sources
The official texts this page is based on, checked on 27 September 2026.
- Enterprise Technology Governance & Risk Management Framework for Financial InstitutionsSBP, BPRD Circular No. 05 of 2017, 30 May 2017. Applies to banks, DFIs and microfinance banks, compliance by 30 June 2018. Section 2.7 covers security testing and 4.2 system development and testing
- Measures to Enhance Security of Digital Banking Products and ServicesSBP, BPRD Circular No. 04 of 2023, 14 April 2023, with Annexure A. Applies to banks and microfinance banks: security reviews, device binding, authentication, encryption and the liability framework
- Frequently Asked Questions on Measures to Enhance Security of Digital Banking Products and ServicesSBP, Annexure B to BPRD Circular No. 04 of 2023. Includes the requirement for periodic application security reviews
- Regulations for the Security of Internet BankingSBP Payment Systems Department, PSD Circular No. 03 of 2015, 21 October 2015, effective 1 April 2016. Two-factor authentication, session controls and security testing
- Security of Digital PaymentsSBP, PSD Circular No. 09 of 2018, 28 November 2018. Vulnerability assessment, penetration testing and third-party review of alternate delivery channels
- Prevention against Cyber AttacksSBP, BPRD Circular No. 07 of 2016, 22 June 2016. Periodic independent assessments of cyber security controls
- Framework on Outsourcing to Cloud Service ProvidersSBP, BPRD Circular No. 01 of 2023, 16 January 2023. Section T sets yearly security testing of systems hosted with cloud service providers
- Launch of Cyber Shield Cyber Resilience Strategy for SBP Regulated Entities (2025-2030)SBP, CRMD Circular Letter No. 01 of 2026, 16 February 2026. Milestones to be implemented in a phased manner by 2030
Frequently asked questions
Straight answers on coverage, setup, and how results reach your team.
Can't find your answer? Book a demo or contact us.
Test your mobile banking app against the SBP controls
Start with a free scan of your app from the store, or book a demo to run logged-in and API tests with our team.




