If you hold a PTA telecom license in Pakistan, CTDISR-2025 is the regulatory framework that governs your cybersecurity obligations. It is not voluntary, it is not advisory, and it is not something you can address when you get around to it. Compliance is mandatory for every category of PTA licensee, audits are conducted annually by registered third-party firms, and PTA conducts its own validation audits on a significant proportion of those it has already audited. The consequences of non-compliance are formal findings, imposed remediation deadlines, and escalating regulatory exposure for operators who miss them.
This article is a plain-English breakdown of what CTDISR-2025 actually requires, structured for operators who need to understand the full scope before deciding how to approach it, rather than discovering requirements one at a time through the audit process.
What CTDISR-2025 Is and Who It Applies To
CTDISR stands for Cyber and Telecom Digital Infrastructure Security Regulations. The 2025 version replaced and substantially expanded the previous DIRBS-era security guidelines and brought Pakistani telecom security regulation into alignment with contemporary frameworks including ISO 27001, NIST CSF, and MANRS.
Every category of PTA licensee is in scope: Internet Service Providers, Wireless ISPs, Mobile Network Operators, Long Distance and International operators, telecom infrastructure providers, and Value-Added Service licensees. There is no size threshold. A district-level CVAS licensee with fifty subscribers is subject to the same framework as a national ISP with a million.
The framework covers 104 controls across 19 sections. Not all controls apply equally to every licensee category, but the default assumption for audit purposes is full applicability unless a specific exemption is documented and justified.
The 19 Sections: What Each One Requires
Section 1, Governance and Organisational Roles, establishes the structural foundations everything else depends on. A Chief Information Security Officer must be formally appointed, not just informally designated. An Information Security Steering Committee must be established, chaired by the CEO, with documented meeting cadence and board-level reporting. Without this structure in place, controls in subsequent sections have no accountable owner, which is itself an audit finding.
Section 2, Access Control and Authentication, mandates role-based access control across all systems, multi-factor authentication on every privileged account without exception, and privileged access management controls. Zero Trust architecture implementation status is assessed here, meaning it isn't yet a hard requirement to have it fully deployed, but PTA expects a documented position and roadmap.
Section 3, Asset Management, requires a complete and current inventory of every IT and network asset, classified by criticality, with lifecycle management procedures documented. For ISPs with large access-layer deployments across dozens of sites, this is one of the more operationally demanding sections.
Section 4, Risk Management, requires an annual formal risk assessment, a maintained risk register, documented risk treatment plans, and board-level risk reporting. The assessment must be conducted by a qualified party and documented in a way that satisfies an auditor, not just produced internally and filed.
Section 5, Incident Response, requires a documented IR plan covering detection, containment, eradication, recovery, and post-incident review. Critically, it mandates 24-hour reporting to PTA for qualifying incidents, and coordination with nTCERT. The 24-hour clock runs from detection, not from resolution.
Section 6, nTSOC Integration, is one of the most operationally specific requirements. Every licensee must integrate with PTA's National Telecom Security Operations Center, forwarding real-time alerts and log data in the required format, and consuming inbound threat intelligence feeds. Integration quality is assessed continuously, not just at audit time. As of the 2024-25 audit cycle, 36 licensees had completed integration from a much larger licensed population.
Section 7, Data Privacy, covers data localisation compliance, PII handling procedures, data retention and disposal policies, and privacy impact assessments for new systems. Operators handling subscriber data at scale need documented procedures that can be produced to an auditor on request.
Section 8, Cloud Security, applies to any operator using cloud-hosted infrastructure for any part of their service. Cloud provider risk assessments, data sovereignty documentation, and cloud access governance are all required.
Section 9, Network Security, covers infrastructure hardening standards, network segmentation, firewall policy documentation and review cycles, IDS/IPS deployment, and DDoS mitigation controls. This section is where many ISPs have the largest gap between what they've built and what they can document.
Section 10, Routing Security, mandates RPKI implementation and MANRS compliance as the primary baseline. Anti-spoofing controls and BGP security practices are assessed here. For operators not yet RPKI-configured, this is a hard remediation item before an audit.
Section 11, DDoS Mitigation, goes further than Section 9's general controls, specifically requiring AI-driven DDoS mitigation capability, traffic scrubbing, and documented upstream coordination procedures for volumetric attacks.
Section 12, Endpoint and Device Security, covers endpoint protection on all organisational devices, mobile device management, patch management procedures, and device hardening standards.
Section 13, Third-Party and Supply Chain Risk, requires documented vendor security assessment procedures, third-party access controls, and contractual security obligations with suppliers.
Section 14, HR Controls, mandates background checks for all staff with system access, documented security awareness training with attendance records, insider threat detection mechanisms, and formal joiner/mover/leaver access procedures.
Section 15, Physical Security, covers data centre and facility physical access controls, visitor management, CCTV requirements, and environmental controls documentation.
Section 16, Business Continuity Planning, requires a documented BCP that has actually been tested. Paper plans that have never been exercised do not satisfy this requirement. Tabletop exercises with documented results are the minimum. RTO and RPO targets must be defined and documented, and the BCP must be reviewed annually.
Section 17, Audit and Compliance Monitoring, requires an internal audit function for cybersecurity, continuous compliance monitoring, and structured reporting to the ISSC.
Section 18, Security Awareness and Training, mandates annual security awareness training for all staff with records maintained for audit evidence, role-specific training for technical and privileged users, and phishing simulation exercises.
Section 19, Vulnerability Management, requires a regular vulnerability assessment cadence, periodic penetration testing, CVSS-based patch prioritisation, and documented remediation tracking.
The Audit Reality
PTA conducted 50 formal audits in the 2024-25 cycle through registered third-party audit firms, then conducted its own validation audit on 35 of those 50. That ratio is not a sampling strategy, it's a signal that PTA is actively verifying third-party findings rather than relying on them. Findings result in formal documentation and imposed remediation deadlines. Repeat or critical findings carry increasing regulatory exposure.
The majority of Pakistan's licensed telecom operators had not been formally audited as of the 2024-25 cycle. That gap is closing. PTA's own published roadmap includes development of an in-house audit automation application, which signals both that the manual audit process is being systematised and that the audit cadence will likely increase as the tooling catches up.
Where to Start
For operators approaching CTDISR-2025 for the first time, the practical starting point is a gap assessment across all 19 sections before any remediation work begins, so effort goes to actual gaps rather than controls you've already satisfied without documenting them properly. ISP Audit runs a scored self-assessment across all 104 controls and produces a gap report showing where you stand. For ongoing compliance tracking and evidence management, ComplianceIQ manages the full control library with audit-ready reporting.
For operators who need hands-on preparation before an audit cycle, CTDISR Audit Readiness covers gap closure, evidence packaging, and mock review across all 19 sections. The governance layer, CISO appointment, ISSC establishment, board reporting, is covered under CISO-as-a-Service for operators who need that function without a full-time hire.