Managing CTDISR-2025 compliance, PTA licensing obligations, and operational governance alongside running an ISP requires that recurring obligations are tracked proactively rather than discovered when they are overdue. A compliance calendar converts the full set of obligations into a schedule that can be managed and delegated.
This article structures the annual compliance obligations for a typical Pakistani ISP licensee. Dates for PTA-specific obligations (annual fee payment, specific reporting deadlines) are tied to your individual license issuance date and the current PTA schedule: confirm precise dates for your entity rather than treating this calendar as definitive for your specific circumstances.
Annual Obligations by Category
Regulatory and licensing obligations: annual license fee payment (due on the anniversary of license issuance, confirm date and current fee quantum with PTA before payment), any PTA-mandated subscriber count or network performance reports (confirm current requirements with PTA as reporting obligations evolve with regulatory updates), and renewal application preparation (for licenses approaching their term end, begin preparation 6-12 months before expiry).
CTDISR-2025 governance: the annual risk assessment (Section 4) must be conducted each year and documented, typically aligned with the ISSC calendar. The board-level risk report that follows the risk assessment must be presented to the ISSC and board. Annual security awareness training for all staff (Section 18) must be completed and records maintained. Annual BCP review (Section 16) must be documented.
CTDISR-2025 assurance: annual vulnerability assessment of internet-facing infrastructure (Section 19) and annual penetration test (Section 19, or biennial for organisations with lower risk profiles). Annual access review confirming all user accounts are appropriate for current roles (Section 2). Annual review of the vendor risk register and significant vendor assessments (Section 13).
CTDISR-2025 monitoring: nTSOC integration quality monitoring is continuous, not annual, but an annual formal review of integration completeness and quality as an evidence item is appropriate. ISSC meetings quarterly (Section 1). Phishing simulation exercises quarterly (Section 18).
The 12-Month Calendar Template
Months 1-3 (Q1): conduct annual risk assessment and update risk register, schedule the year's ISSC meetings, commence annual security awareness training programme, schedule penetration test for Q2 or Q3.
Month 2-3 specifically: if your CTDISR audit is expected in the second half of the year, begin pre-audit gap assessment now. Six months of preparation time is significantly better than six weeks.
Months 4-6 (Q2): annual vulnerability assessment of internet-facing infrastructure, penetration test if scheduled for Q2, annual access review and remediation of any inappropriate access identified, Q2 ISSC meeting with risk register update.
Months 7-9 (Q3): phishing simulation exercise, BCP tabletop exercise and documentation, Q3 ISSC meeting, begin preparing compliance evidence package if external audit is expected in Q4.
Months 10-12 (Q4): annual review of vendor risk register, Q4 ISSC meeting, annual security programme review for CISO, confirm annual license fee payment date and prepare payment, begin next year's compliance calendar.
Obligations That Are Continuous, Not Annual
Some CTDISR obligations have no annual cadence but require continuous management: 24-hour incident reporting to PTA (whenever a qualifying incident occurs), nTSOC integration monitoring, change management records maintenance, and log retention management. These are operational rather than calendar obligations and should be covered by operational procedures rather than calendar reminders.
For managing the full compliance calendar alongside the evidence records it generates, ComplianceIQ provides automated reminders for recurring obligations, due date tracking for evidence reviews, and a dashboard showing what is current and what is approaching. For operators who need the CISO function to own and manage the compliance calendar, CISO-as-a-Service covers the full programme management function.