Compliance/NBFC / SECP
Financial
Testing named in the standard

NBFC / SECP penetration testing

NBFC cybersecurity testing (SECP, Pakistan)

Vulnerability assessment and penetration testing for SECP regulated entities, including digital lending app audits.

Sample report

Engagement at a glance

Drives testing

SECP cybersecurity advisories and digital lending circulars: Security testing for regulated entities

Cadence

At least annually, before a digital lending app launch, and after significant change

Typical duration

2 to 4 weeks of testing, plus retest

Region

Pakistan

Issued by

Regulated by the Securities and Exchange Commission of Pakistan

SECP

Regulator

Circular 15

Digital lending requirement

PK

Team based in Pakistan

Annual

Testing cadence

The requirement

What NBFC / SECP asks for

SECP cybersecurity advisories and digital lending circulars · Security testing for regulated entities

SECP expects regulated entities to maintain and test cybersecurity controls, reinforced through advisories including Cyber Security Advisory Circular 10 of 2025. Digital lending apps require a cybersecurity compliance certificate from a PTA approved Cyber Security Audit Firm before SECP whitelisting under Circular 15.

Non-bank finance companies in Pakistan, including lending, leasing, investment and asset management firms, are regulated by the SECP. Alongside conduct and licensing rules, the regulator expects regulated entities to protect customer and financial data and to test that those protections work.

Digital lending is where this bites hardest. Under Circular 15, a digital lending app needs a cybersecurity compliance certificate from a PTA approved Cyber Security Audit Firm before SECP will add it to the approved whitelist. The regulator is specific about protecting borrower data, including phone contacts and photo galleries that predatory apps have historically abused.

XHack is based in Pakistan and tests against these expectations directly. We assess your customer-facing platforms, core systems and lending apps, report findings the regulator will understand, support remediation, retest to closure and sign an attestation letter. Licensing, conduct and regulatory filings remain your responsibility.

What your auditor checks

The report has to clear every one of these

These are the questions a NBFC / SECP auditor asks of a penetration test before accepting it as evidence. Every engagement we run is built to answer all of them.

Independent testing by a qualified firm

Scope covering customer-facing and core financial systems

Mobile application testing where a lending app is in scope

Recognised methodology documented in the report

Findings rated consistently with CVSS v4.0

Explicit coverage of borrower data and device permissions

Evidence of remediation with dates

Independent retest confirming closure

Report suitable for regulatory submission and inspection

Signed attestation letter from the testing firm

What we test

Where the testing effort concentrates

The surfaces this engagement covers, weighted by how much of the work they typically represent. Scope is confirmed with you before anything starts.

Customer-facing platforms and portals

Web and mobile applications

95%

Digital lending application

Android and iOS, static and dynamic

90%

Borrower data and device permissions

Contacts, gallery, location, storage

90%

Core APIs and backend systems

Authorization and financial transaction flows

85%

Infrastructure and perimeter

Internet-facing services and hosts

70%

Weights are indicative of typical effort. Your exact scope is agreed and signed before testing begins.

How the engagement runs

Scope, test, close, attest

Typically 2 to 4 weeks of testing, plus retest. The retest is included, because a report full of open findings is not evidence of anything.

01

Scope against regulatory expectations

Week 1

We map which systems matter to the regulator, including any digital lending app and the borrower data it touches, and agree the rules of engagement.

02

Test platforms, APIs and apps

Weeks 1 to 3

Web, API, infrastructure and mobile testing, with static and dynamic analysis of Android and iOS builds where a lending app is in scope.

03

Report for the regulator

Week 3

Findings written so a regulator or inspector can follow them, with explicit treatment of borrower data handling and device permissions.

04

Remediation support

Weeks 3 to 6

Your team fixes. Anything exposing customer or financial data is escalated the day we find it rather than held for the report.

05

Retest and attestation

Week 6 onward

Every finding retested and closed, with a signed attestation letter suitable for regulatory submission.

Where the effort goes

Share of a typical engagement, by phase

100%EFFORT

Scoping & rules of engagement

15%

Testing & exploitation

45%

Reporting & mapping

20%

Retest & attestation

20%

What we bring

Built for the NBFC / SECP auditor specifically

The parts of this engagement that are shaped by the framework rather than copied from a generic testing template.

Local, and in the room

We are based in Pakistan and work with SECP expectations directly, including how findings are best presented for inspection.

Mobile testing included

Static and dynamic testing of Android and iOS lending apps, covering hardcoded secrets, insecure storage and runtime weaknesses.

Borrower data scrutinised

Explicit testing of device permissions and data handling, the area the regulator has been most vocal about.

Written for submission

A report and attestation letter formatted so it can go to the regulator without rewriting.

The deliverable

What lands on your auditor's desk

A report structured so the evidence sits where the auditor is already looking, with every finding mapped to the control it touches.

In the report

  • Signed letter of attestation with testing dates

  • Scope covering platforms, APIs, infrastructure and mobile apps

  • Methodology, qualifications and independence statement

  • Findings with CVSS v4.0, evidence and reproduction steps

  • Borrower data handling and device permission analysis

  • Remediation implemented and independent retest result

  • Summary formatted for regulatory submission

Control mapping

How the report evidences each control

SECP cybersecurity advisories

Independent testing evidence of the controls the advisories expect.

Circular 15 digital lending

Security assessment of the lending app ahead of the required audit certificate.

Borrower data protection

Explicit testing of device permissions and personal data handling.

Financial transaction integrity

Authorization and transaction flow testing across core APIs.

Incident readiness

Evidence of whether monitoring detected the test activity.

Where our work stops, and who takes it from there

XHack provides the penetration testing evidence for SECP cybersecurity advisories and digital lending circulars. We do not issue certificates, attestation opinions or regulatory approvals, and we do not run your wider compliance programme. For NBFC / SECP, that sits with: Regulated by the Securities and Exchange Commission of Pakistan. Staying independent of them is exactly what makes our evidence worth something when they review it.

Questions

NBFC / SECP testing, answered

The cybersecurity compliance certificate for SECP whitelisting comes from a PTA approved Cyber Security Audit Firm. What we do is test the app and its backend the way that audit will, and report the findings, so nothing in the certificate review is a surprise to you.

Borrower data. SECP has been explicit about apps that harvest phone contacts and photo galleries. We test device permissions, what the app actually collects, how it stores and transmits it, and whether the backend leaks it.

No. Licensing, conduct requirements and regulatory filings are your responsibility, usually with legal and compliance advisers. We provide the security testing evidence that supports them.

Under signed rules of engagement and a Data Processing Agreement. No live customer or financial data is exfiltrated, and anything captured to prove a finding is redacted in the report.

Get the NBFC / SECP evidence sorted

Tell us who is auditing you and when your review period closes. We will scope the test, tell you what it costs, and make sure there is room to remediate and retest before the deadline.

All frameworks