What NADRA Must Publish Before Declaring Victory
NADRA should release a non-sensitive technical white paper identifying the QR data fields, signature algorithm, trust-chain model, key-rotation process, verifier authorization tiers, offline behaviour, revocation logic, scan logging, retention limits and response to damaged or copied codes. Publishing this information would not hand criminals a master key; serious cryptography is expected to remain secure even when its architecture is understood.
It should also prohibit routine retention of complete QR payloads where a simple “verified” response is sufficient, provide citizens with a history of institutional verification events, introduce penalties for unauthorized scanning or storage, and finally begin dismantling Pakistan’s photocopy culture.
For banks, hospitals, telecom operators and KYC vendors, the message is equally direct: do not treat a successful QR scan as permission to warehouse every returned field. Organizations preparing integrations should commission an independent privacy-by-design and identity-workflow review before deployment. Enterprises needing that assessment can initiate a technology and operational-risk inquiry through Zorays Khalid.
Frequently Asked Questions
Is NADRA’s QR CNIC an upgrade or a downgrade?
It is an operational and manufacturing upgrade because it replaces an underused imported chip with locally produced, smartphone-accessible verification. Its privacy and high-assurance security remain unproven until NADRA publishes the QR and verifier specifications.
Can somebody forge the new CNIC by copying its QR code?
Copying an authentic QR is not the same as altering it. A properly verified digital signature should expose modified data, but a copied code could replay genuine information. Verifiers must therefore compare the encoded photograph with the presenter, use biometric or liveness checks where appropriate, and check the card’s current status.
Is the QR code encrypted?
NADRA has not publicly disclosed enough technical detail to answer that conclusively. Digital signatures can prove authenticity without encryption, but they do not conceal encoded information.









































