Acquiring an existing ISP in Pakistan is faster than building one from scratch: you inherit subscribers, infrastructure, operational know-how, and a licensed entity. You also inherit everything the previous operator did not disclose: compliance gaps, aging infrastructure, subscriber contracts with unfavourable terms, and potential PTA regulatory exposure. The due diligence process is what separates a sound acquisition from an expensive surprise.
Regulatory and Licensing Due Diligence
Start here because everything else depends on the license being valid and transferable. Verify: the current license type, scope, and expiry date, whether the license is in good standing with PTA (no outstanding enforcement actions, no default on license fees), the compliance history for CTDISR audits (request copies of any audit reports and findings from the past two cycles), whether there are any open enforcement matters or show-cause notices, and the status of the nTSOC integration (Section 6 integration quality is assessed continuously, and a degraded integration is a compliance liability you are acquiring).
License transfer or change of ownership typically requires notification to PTA and in some cases PTA approval, depending on the nature of the ownership change. Confirm the process for the specific transaction structure before signing any definitive agreement.
CTDISR Compliance Liability
A CTDISR audit finding becomes the new owner's remediation obligation after an acquisition. Request the most recent CTDISR audit report. If the target has not been audited, that is itself a risk indicator: either they are not yet in the audit cycle (acceptable for a newly licensed operator) or they have been avoiding scrutiny (a red flag).
Review the audit findings against each of the 19 CTDISR sections and estimate the remediation cost. Critical findings requiring immediate remediation, such as absent nTSOC integration or no incident response plan, can be quantified. Hidden compliance gaps that would only surface in the next audit cycle are harder to assess from documents alone: an ISP Audit assessment of the target's infrastructure provides a scored gap analysis against all 104 controls that reveals the actual compliance posture rather than what the target's management believes it to be.
Network Infrastructure Assessment
The infrastructure assessment determines whether the network you are buying is what it appears to be on paper. Conduct a physical audit of the primary sites: inspect the actual equipment installed, its age and condition, the physical state of the NOC and PoP facilities, the quality of cable management and physical organisation (a well-maintained network is easier to operate than a messy one), and whether the equipment inventory matches the asset register the target has provided.
For a WISP, specifically assess the condition of tower sites and the age of access-layer radios: wireless equipment has a shorter effective life than fiber infrastructure, and radios that are three to four years old in Pakistani outdoor conditions may be approaching the end of their reliable service life.
For a fiber operator, assess the quality of the fiber plant: the number of splices, the loss budget on each PON port relative to the split ratio being operated, and any known fiber cuts that have been repaired rather than replaced. A fiber plant with many field splices or high loss on repaired sections has a higher maintenance burden than one with a clean plant.
Subscriber Base Quality
Not all subscribers are equal in value. Assess: the mix between CIR corporate clients and residential subscribers (CIR subscribers are more stable revenue, residential subscribers are higher churn), the average revenue per subscriber compared to the market rate (below-market pricing inflates subscriber count at the cost of revenue), the subscriber churn rate over the past 12 months (high churn indicates service quality problems or aggressive competitive pressure), and the quality of subscriber contracts for corporate CIR clients (a CIR client with an informal agreement and no SLA is less secure revenue than one with a multi-year contract).
Financial Liabilities
Beyond the headline purchase price, understand: outstanding payables to upstream providers (a target that has not paid its PTCL or TWA invoice in 90 days is about to lose connectivity), any equipment financing or leases that transfer with the business, PTA fee arrears if any, and any subscriber deposits or advance payments that become your obligation to service after the acquisition.
For the full due diligence assessment including regulatory, technical, and financial review as a structured engagement, ISP Consulting & Advisory covers ISP acquisition due diligence with Pakistan-specific regulatory and technical expertise. For the technical network assessment component, Network Design & Optimization covers infrastructure quality review. For the CTDISR compliance gap assessment of the target, CTDISR Audit Readiness covers the compliance posture review as a standalone engagement.