Every Virtual Asset Service Provider (VASP) sits on top of systems that, if breached, can move customer funds irreversibly in seconds. The Virtual Assets Act, 2026 responds to that reality with a standing duty rather than a one-off checklist: licensees must maintain cybersecurity and operational resilience at all times, not merely at the point of licensing. This article sets out what section 34 actually requires, what is left to future Regulations, and where related duties sit elsewhere in the Act.
What does section 34 of the Act require?
Section 34 requires every Licensee to comply with cybersecurity and operational-resilience requirements prescribed by the Pakistan Virtual Assets Regulatory Authority (PVARA, “the Authority”) or under any other applicable law, covering technical standards, security controls, and reporting mechanisms, among other matters.
Section 34 states:
Licensees shall comply with cybersecurity and operational-resilience requirements prescribed by the Authority or under any other applicable laws, including, but not limited to, technical standards, security controls, and reporting mechanisms.
Two things follow. First, the duty is not confined to Regulations the Authority itself issues — “any other applicable laws” pulls in obligations that may sit in other statutes, such as data protection or critical-infrastructure legislation administered by other bodies. Second, the list of “technical standards, security controls, and reporting mechanisms” is expressly non-exhaustive (“including, but not limited to”), so a licensee cannot treat compliance as complete once it satisfies only those three named categories. At the time of writing, PVARA had not published the detailed technical standards section 34 anticipates.
Where does the Authority’s power to set these standards come from?
Section 34 is the specific duty on licensees. The Authority’s power to actually write the standards behind it sits in section 9(2)(b), which allows the Authority to “set prudential, conduct, operational resilience, risk-management, cybersecurity, data protection & technical standards.”
A second, related power sits in section 9(2)(g): the Authority may “ensure compliance of data-protection, data-governance and cyber security obligations by Virtual Asset Service Providers subject to supervisory follow-up.” In our reading, section 9(2)(b) is the rule-making power and section 9(2)(g) is the supervisory power to check that licensees actually meet those rules once written — the Act gives the Authority both the pen and the inspection mandate.
Is cybersecurity a one-off licensing requirement or a continuing obligation?
It is continuing. Section 22, which lists the ongoing obligations of every Licensee, requires under section 22(e) that a Licensee “maintain risk-management, compliance and cybersecurity systems in accordance with applicable legal and regulatory requirements including adherence to data privacy standards” — stated as a duty that applies “at all times,” per the opening words of section 22.
This matters in practice: a VASP that builds a strong security posture for its licence application and then lets it lapse is not meeting the Act’s standard. The obligation under section 22(e) runs alongside the general duty under section 34 for the life of the licence, not just at the point of approval.
| Provision | What it covers |
|---|---|
| Section 34 | Direct cybersecurity and operational-resilience duty on Licensees |
| Section 9(2)(b) | Authority’s power to set the underlying technical standards |
| Section 9(2)(g) | Authority’s power to supervise ongoing compliance |
| Section 22(e) | Cybersecurity as a continuing obligation of every Licensee |
| Section 26(1)(b) | Operational-resilience duty specific to custody licensees |
Do custody providers face an additional operational-resilience duty?
Yes. Section 26, which governs custody standards and key-management controls, imposes a duty specific to any Licensee providing custody services for Virtual Assets. Section 26(1) requires such a Licensee to:
(a) ensure the secure custody and protection of Virtual Assets against unauthorized access, loss, or misuse; and (b) maintain operational resilience, including robust disaster-recovery and business-continuity arrangements.
Section 26(1)(b) is narrower than section 34 in one respect and more specific in another. It applies only to Licensees providing custody services, not to every VASP — but for those Licensees, it names two concrete components of operational resilience that section 34 leaves general: disaster-recovery arrangements and business-continuity arrangements. Section 26(2) then gives the Authority power to prescribe the detailed technical standards, operational requirements and audit procedures behind this duty, including standards for key management, custody mechanisms, and verification or assurance processes — again, not yet published at the time of writing.
Who inside a VASP is accountable for cybersecurity?
The Act names a specific role. Section 3(1)(xv) defines “Key Individual” to include, at sub-paragraph (i), the “head of information-security and cyber-security.” Key Individuals are subject to the fit-and-proper regime under section 20, meaning the person holding this role at a Licensee is individually assessed by the Authority, not simply nominated internally.
- the head of information-security and cyber-security is a named Key Individual role under section 3(1)(xv)(i)
- Key Individuals are assessed against fit-and-proper criteria under section 20, which the Authority may apply on a continuing basis under section 20(4)
- a Licensee must notify the Authority of matters affecting a Key Individual’s fitness and propriety, under section 20(4)
- this places accountability for cybersecurity failures with a named, regulator-vetted individual rather than diffusing it across a technical team
What happens if a cybersecurity breach occurs at a licensed VASP?
The Act gives the Authority an emergency power for exactly this scenario. Section 60 allows the Authority, “in the event of a systemic threat, market manipulation, fraud, or cybersecurity breach, or other serious risk to customers or market integrity,” to issue an order temporarily suspending specified Virtual Asset Services or freezing related assets for a period not exceeding thirty days.
In practice, this means a cybersecurity breach is not treated by the Act purely as an internal incident for the Licensee to manage and self-report after the fact. It sits alongside market manipulation and fraud as a trigger for the Authority’s strongest short-term intervention power — a thirty-day suspension or asset freeze — which can take effect before any finding of fault against the Licensee has been made, because the power is framed around risk containment rather than punishment.
How does the cybersecurity duty interact with Pakistan’s other data protection laws?
Section 5(2) of the Act addresses this directly. Where any other law prescribes measures relating to data protection, data governance, or cybersecurity, financial secrecy, or cross-border transfer of personal data, “such provisions shall prevail and be complied with by the Authority and Licensees.” This is an exception to the Act’s general rule in section 5(1), under which the Act otherwise prevails over inconsistent laws.
Our reading is that a Licensee cannot treat compliance with PVARA’s future cybersecurity Regulations as a substitute for compliance with any separate data protection or cybersecurity statute that already applies to it — the two sets of obligations run in parallel, and where they conflict, the other law wins, not the Act. Where a licensee is uncertain which specific data protection statute applies to a given system or dataset, that is a matter to raise directly with legal counsel or the Authority, since the Act does not itself name the other laws in question.
What should a VASP applicant do before PVARA’s technical standards are published?
- appoint and properly document a head of information-security and cyber-security as a named Key Individual, in anticipation of the section 20 fit-and-proper assessment
- build disaster-recovery and business-continuity arrangements now if custody services are planned, since section 26(1)(b) already states the duty even though section 26(2) standards are pending
- map which other Pakistani laws on data protection or cybersecurity already apply to the business, given that section 5(2) preserves those obligations regardless of what PVARA later prescribes
- treat reporting mechanisms as a distinct workstream from technical controls, since section 34 lists them as a separate, non-exhaustive category
- avoid waiting for the published technical standards before building a security programme — section 34 and section 22(e) already impose the underlying duty, and a licensee assessed against undefined but foreseeable standards is in a stronger position than one starting from nothing
A VASP that treats cybersecurity as a licensing-day formality misreads the structure of the Act. The duty in section 34 is framed as continuous, is reinforced by section 22(e) as an ongoing obligation, is tied to a named accountable individual under section 3(1)(xv)(i), and carries one of the Authority’s sharpest emergency powers under section 60 if it fails. Building genuine regulatory licensing readiness around this duty, rather than around the narrower question of what the eventual technical standards will say, is the more defensible position for an applicant preparing its Virtual Assets Act submission.
Related reading
- PVARA Exchange License: Capital, Rules & Obligations 2026
- PVARA Transfer & Settlement License: Crypto Payments 2026
About this analysis
This analysis was prepared by the CoinConnect research desk from the Virtual Assets Act, 2026, read as published. Where practice is not yet settled or guidance has not been issued, that is stated in the text above.
Regulatory positions change and specific requirements should be verified against the current position published by the relevant authority before you act on them. This is information and analysis, not legal advice, and it does not create an advisory relationship. Take professional advice on your own circumstances.
Entering Pakistan's crypto market?
CoinConnect handles market entry, partnerships, PR and launch for exchanges and Web3 companies moving into Pakistan and South Asia.
Visit CoinConnect