CTDISR-2025 Section 13 requires vendor security assessment procedures, third-party access controls, supply chain risk management, and contractual security obligations with vendors. For most Pakistani ISPs, this means building a vendor assessment capability rather than just ticking a box: a process that identifies which vendors need assessment, how thoroughly to assess each one, and what to do with the findings.
The practical challenge is proportionality. A systematic assessment of every vendor, from the office cleaning contractor to the core router supplier, is resource consumption without commensurate risk reduction. A risk-tiered approach concentrates assessment effort on vendors whose access or supply matters most.
Building the Vendor Risk Register
The starting point is a register of all third-party relationships with an initial risk classification for each. The classification is based on two dimensions: the access the vendor has to your systems or data, and the criticality of the product or service they provide.
High-risk vendors have both significant access and supply criticality: upstream transit providers (their BGP routing affects all subscriber connectivity), network equipment vendors (their firmware runs on every critical device), managed service providers with access to your infrastructure, and colocation facilities housing your equipment. These vendors warrant the most thorough assessment.
Medium-risk vendors have either significant access or critical supply but not both: a cloud-hosted billing platform that holds subscriber financial data but does not have direct network access, a CCTV and physical security contractor with facility access but no logical network access, and a software vendor whose product is used operationally but who has no direct access to your systems.
Low-risk vendors have neither significant access nor critical supply. Standard commercial relationships with commodity vendors: office supplies, catering, routine professional services. These do not require security assessment beyond ensuring appropriate contractual language.
The Assessment Process by Tier
For high-risk vendors, the assessment includes: a security questionnaire covering their information security programme, incident response capability, staff background check procedures, and specific controls relevant to the access or supply relationship. Review of their available security certifications (ISO 27001, SOC 2 Type II) and their data processing or service agreements. For the most critical vendors (your primary transit provider, your core equipment supplier), an annual review of their publicly available security information and any published security incidents.
The security questionnaire for a high-risk vendor should cover: what security controls do they have in place relevant to the access they have to your systems, how do they manage staff access to your environment, what is their incident notification process if they experience a breach that affects your data or systems, and what certifications or independent assessments support their security claims.
For medium-risk vendors, a shorter questionnaire focused on the specific risk dimensions most relevant to the relationship, plus review of contractual security language, is proportionate.
For low-risk vendors, ensuring standard contractual language around data protection and incident notification is sufficient.
Contractual Security Obligations
Contracts with all medium and high-risk vendors should include: a data processing clause specifying how any subscriber or operational data they access can be used, stored, and protected, an incident notification requirement (they must notify you within a defined period if they experience a breach or security event that may affect your data or systems), and for vendors with direct access to your infrastructure, an access scope limitation and a right to audit.
The incident notification clause is the most operationally important one: if your transit provider experiences a security incident that affects the integrity of the routing they provide you, you need to know promptly to assess your own exposure. A contract that does not include this obligation means you find out from public disclosure rather than direct notification.
Annual Review Cadence
Vendor assessments should be reviewed annually and whenever the vendor relationship changes significantly (new access granted, expanded service scope, ownership change). A vendor register that was built once and never reviewed does not satisfy Section 13's ongoing management requirement.
The annual review does not need to repeat the full assessment for every vendor: a review of any published security incidents involving the vendor, a check that their certifications are still current, and a confirmation that contractual security obligations are still in place is adequate for medium-risk vendors. Full reassessment is appropriate for high-risk vendors and for any vendor where a concern has been identified.
For managing the vendor risk register, assessment records, and contractual evidence alongside all other CTDISR compliance documentation, ComplianceIQ provides the platform structure. For operators who need the vendor assessment programme designed and operated as part of the CISO function, CISO-as-a-Service covers Section 13 as part of the governance programme scope.