Most ISPs preparing for their first CTDISR-2025 audit make the same mistake: they focus on whether controls exist rather than whether those controls are auditable. A firewall policy that's never been reviewed and documented fails the same way as one that doesn't exist. An incident response plan that lives in someone's head fails the same way as one that was never written. The audit isn't a technical assessment of whether your network is secure. It's an evidence-based assessment of whether you can demonstrate, through documented proof, that you've implemented and are actively maintaining the required controls.

Understanding that distinction before you start preparing changes how you spend your time.

How the Audit Process Actually Works

PTA conducts CTDISR audits through registered third-party audit firms, not through its own staff directly. These firms are approved by PTA, work to PTA's defined audit methodology, and submit findings to PTA on a standardised format. PTA then conducts its own validation audit on a subset of completed audits, in the 2024-25 cycle that was 35 out of 50 formal audits, which means you should treat the third-party audit and the PTA validation as one continuous process, not two separate events.

The audit itself typically runs across multiple sessions: a documentation review first, then technical verification of selected controls, then an evidence review of anything flagged during the documentation phase. The timeline from opening meeting to final report varies by operator size and complexity, but two to four weeks is typical for a mid-sized ISP with reasonable documentation in place. For operators with documentation gaps, the timeline extends because the auditor is waiting on evidence the operator needs to produce mid-audit, which is a poor position to be in.

Findings are categorised by severity. Critical findings are controls that are entirely absent where they're mandatory. Major findings are controls that are partially implemented or implemented without adequate documentation. Minor findings are controls where implementation is adequate but documentation or review cycles are incomplete. The remediation deadlines PTA imposes correspond to finding severity, with critical findings carrying the shortest timelines.

What Auditors Examine Section by Section

The documentation review covers governance structure first because everything else flows from it. Auditors look for: the formal appointment letter or board resolution naming the CISO, the ISSC charter or terms of reference, documented meeting minutes showing the ISSC has actually convened, and board-level cybersecurity reporting records. Missing minutes for a committee that was supposed to meet quarterly is a finding even if the committee exists on paper.

For access control, auditors typically request a sample of user access records, MFA configuration evidence from your authentication platform, and your privileged access management policy. They will request access logs for specific accounts and verify that MFA is actually enforced, not just configured on paper. Accounts that bypass MFA through a policy exception that was never reviewed are a common finding.

The asset inventory check is more thorough than most operators expect. Auditors compare your documented asset list against discovered devices on the network, often running their own discovery scan or requesting output from your NMS. Devices that appear on the network but not in the inventory, which is virtually every network with organic growth over several years, generate findings. The severity depends on whether the undocumented devices have privileged access or hold sensitive data.

Incident response gets tested against a specific scenario in many audits: auditors present a hypothetical incident and ask the team to walk through their response procedure, then compare what the team describes against what the documented IR plan actually says. Gaps between the written procedure and what the team would actually do are findings, because an IR plan that the team doesn't follow is not a functioning control.

For nTSOC integration, auditors verify active connectivity and data flow, not just that integration was set up at some point. Log forwarding gaps, missed alert categories, or inactive feeds are common findings for operators who completed integration but haven't maintained it since. Quality of integration is assessed on an ongoing basis between audit cycles as well.

Network security documentation tends to generate the most findings for ISPs that have grown organically: firewall policies that haven't been formally reviewed in over a year, segmentation that exists in practice but isn't documented in a network diagram that matches the current topology, and hardening standards that were applied during initial setup but have no documented review cycle.

The Evidence That Actually Passes

The auditor's question for each control is: can you show me that this control is implemented, that it's working, and that someone is responsible for maintaining it. That three-part test means evidence needs to demonstrate implementation, current status, and ownership.

A firewall ruleset screenshot shows implementation but not current status or ownership. Adding a change log showing the ruleset was reviewed last month and a policy document naming the responsible owner converts the same evidence into something that passes all three parts of the test.

For training records, a spreadsheet listing staff who completed awareness training with dates and signatures passes. An email thread where someone said training happened does not. Auditors look for records that were designed to be records, not correspondence that incidentally mentions that something occurred.

For BCP, a document that describes recovery procedures passes the documentation test. A document plus a tabletop exercise report with date, participants, scenarios tested, and gaps identified passes the testing evidence test. Many operators have the plan but not the exercise record, which means Section 16 generates a finding even though the plan itself is solid.

The Three Things That Kill Preparation Timelines

The first is not knowing your current state before you start. Starting preparation by working through documentation from scratch, without a gap assessment showing which controls are already satisfied and which aren't, means spending equal time on things that are fine and things that aren't. A structured gap assessment at the start of preparation, which is what ISP Audit produces, focuses effort where it's actually needed.

The second is treating evidence collection as a final step. Evidence collection should run in parallel with remediation, not after it. Operators who remediate first and then try to produce evidence of controls that were implemented weeks ago often find they can't reconstruct the documentation trail an auditor needs. Fix and document simultaneously.

The third is underestimating the governance section. Many ISPs focus preparation effort on technical controls and assume the governance section is easy because it's mostly paperwork. In practice, Section 1 findings are among the most common because ISSC minutes, board reporting records, and formal CISO appointment documentation require executive involvement that takes time to arrange, and executives are often the bottleneck.

How ISP World Approaches Audit Readiness

Our CTDISR Audit Readiness engagement runs in eight stages: qualification, scope definition, document intake, gap assessment across all 104 controls, remediation support, evidence packaging, mock review, and audit day support. The gap assessment phase uses the same three-part test (implementation, current status, ownership) that auditors apply, so findings in our assessment are findings in the real audit, not just advisory observations.

For the governance layer, CISO-as-a-Service handles ISSC setup, board reporting cadence, and the ongoing governance documentation that Section 1 requires. For operators who want to track compliance between audit cycles rather than scrambling before each one, ComplianceIQ manages the full control library with evidence management and audit-ready reporting.