Framework guide • Pakistan

CTDISR: Critical Telecom Data and Infrastructure Security Regulations 2025

CTDISR 2025 (the Critical Telecom Data and Infrastructure Security Regulations) is the Pakistan Telecommunication Authority's mandatory security regulation for telecom licensees operating critical information infrastructure. It was gazetted on 31 December 2025 as S.R.O. 2504(I)/2025 and repeals CTDISR 2020. It contains 84 regulations across 14 chapters.

Last updated · By the Faseel compliance team · Not legal advice

CTDISR at a glance

Issued by
Pakistan Telecommunication Authority (PTA)
Reference
S.R.O. 2504(I)/2025, gazetted 31 December 2025 (repeals CTDISR 2020)
Applies to
PTA licensees, for the security of telecom Critical Information Infrastructure
Size
84 regulations across 14 chapters
Pakistan-specific obligations
SIEM integration with the National Telecom SOC (nTSOC), 24-hour breach reporting, data localization, IPv6 targets
Audit
Annual PTA-certified third-party audit, due by 28 February

Who must comply with CTDISR

Telecom licensees

Mobile, fixed-line, broadband and other PTA-licensed operators.

CII operators

Operators of telecom infrastructure designated as critical.

Vendors & service providers

Suppliers whose systems or services support licensees' critical data and infrastructure are pulled in through supply-chain requirements.

What CTDISR requires

  • Governance: security leadership, policy and oversight structures.
  • Asset, risk, incident, access and operations management across the telecom estate.
  • Integrate SIEM with the National Telecom SOC (nTSOC).
  • Report security breaches to PTA within 24 hours.
  • Keep critical data in Pakistan as the data-localization rules require.
  • Commission an annual PTA-certified third-party audit, due by 28 February.
  • Business continuity & DR, physical security, cloud security and HR security controls.

CTDISR domains and control counts

84 controls across 13 areas, as mapped in Komply.

CTDISR domains with number of controls
DomainControls
Governance7
Asset Management6
Risk Management5
Incident Management4
Access Control6
Operations & Communications13
Business Continuity & DR5
Systems Acquisition & Development8
Environmental & Physical Security6
Cloud Security2
Human Resource Security3
Assurance, Compliance & Audit7
Regulatory Oversight12
Total84

How CTDISR maps to ISO 27001

81 of the 84 regulations map to ISO/IEC 27001:2022 Annex A. The regulations aim to align with ISO 27001, so a licensee with an ISMS already has most of the groundwork. The Pakistan-specific duties (nTSOC, 24-hour reporting, localization, the PTA audit) need their own evidence.

Komply tracks all 84 CTDISR regulations next to ISO 27001, keeps the evidence your PTA-certified auditor will request, and flags the Pakistan-only obligations so nothing is missed before the 28 February audit. See how Komply works.

CTDISR FAQ

What is CTDISR 2025?

CTDISR 2025 is the Critical Telecom Data and Infrastructure Security Regulations issued by the Pakistan Telecommunication Authority. It was gazetted on 31 December 2025 as S.R.O. 2504(I)/2025, replaces CTDISR 2020, and is mandatory for PTA licensees operating critical telecom infrastructure.

How many regulations are in CTDISR 2025?

84 regulations across 14 chapters. They cover governance, asset and risk management, incident management, access control, operations, business continuity, systems development, physical, cloud and HR security, assurance and audit, and regulatory oversight.

What are the Pakistan-specific requirements in CTDISR?

SIEM integration with the National Telecom SOC (nTSOC), reporting breaches to PTA within 24 hours, data-localization requirements for critical data, IPv6 targets, and an annual PTA-certified third-party audit due by 28 February.

Does ISO 27001 cover CTDISR?

Mostly. 81 of the 84 regulations map to an ISO 27001:2022 Annex A control, so an ISMS covers most of the ground. The Pakistan-specific obligations still need dedicated controls and evidence.

How does Komply help with CTDISR?

Komply ships all 84 regulations cross-mapped to ISO 27001. It drafts policies, tracks owners and evidence, and exports an auditor-ready package for the annual PTA-certified audit.

Do ISO 27001 once. Prove CTDISR too.

Komply maps 14 frameworks and 1,100+ controls into one control set. Start with a free gap assessment.