CTDISR: Critical Telecom Data and Infrastructure Security Regulations 2025
CTDISR 2025 (the Critical Telecom Data and Infrastructure Security Regulations) is the Pakistan Telecommunication Authority's mandatory security regulation for telecom licensees operating critical information infrastructure. It was gazetted on 31 December 2025 as S.R.O. 2504(I)/2025 and repeals CTDISR 2020. It contains 84 regulations across 14 chapters.
Last updated · By the Faseel compliance team · Not legal advice
CTDISR at a glance
- Issued by
- Pakistan Telecommunication Authority (PTA)
- Reference
- S.R.O. 2504(I)/2025, gazetted 31 December 2025 (repeals CTDISR 2020)
- Applies to
- PTA licensees, for the security of telecom Critical Information Infrastructure
- Size
- 84 regulations across 14 chapters
- Pakistan-specific obligations
- SIEM integration with the National Telecom SOC (nTSOC), 24-hour breach reporting, data localization, IPv6 targets
- Audit
- Annual PTA-certified third-party audit, due by 28 February
Who must comply with CTDISR
Telecom licensees
Mobile, fixed-line, broadband and other PTA-licensed operators.
CII operators
Operators of telecom infrastructure designated as critical.
Vendors & service providers
Suppliers whose systems or services support licensees' critical data and infrastructure are pulled in through supply-chain requirements.
What CTDISR requires
- Governance: security leadership, policy and oversight structures.
- Asset, risk, incident, access and operations management across the telecom estate.
- Integrate SIEM with the National Telecom SOC (nTSOC).
- Report security breaches to PTA within 24 hours.
- Keep critical data in Pakistan as the data-localization rules require.
- Commission an annual PTA-certified third-party audit, due by 28 February.
- Business continuity & DR, physical security, cloud security and HR security controls.
CTDISR domains and control counts
84 controls across 13 areas, as mapped in Komply.
| Domain | Controls |
|---|---|
| Governance | 7 |
| Asset Management | 6 |
| Risk Management | 5 |
| Incident Management | 4 |
| Access Control | 6 |
| Operations & Communications | 13 |
| Business Continuity & DR | 5 |
| Systems Acquisition & Development | 8 |
| Environmental & Physical Security | 6 |
| Cloud Security | 2 |
| Human Resource Security | 3 |
| Assurance, Compliance & Audit | 7 |
| Regulatory Oversight | 12 |
| Total | 84 |
How CTDISR maps to ISO 27001
81 of the 84 regulations map to ISO/IEC 27001:2022 Annex A. The regulations aim to align with ISO 27001, so a licensee with an ISMS already has most of the groundwork. The Pakistan-specific duties (nTSOC, 24-hour reporting, localization, the PTA audit) need their own evidence.
Komply tracks all 84 CTDISR regulations next to ISO 27001, keeps the evidence your PTA-certified auditor will request, and flags the Pakistan-only obligations so nothing is missed before the 28 February audit. See how Komply works.
CTDISR FAQ
What is CTDISR 2025?
CTDISR 2025 is the Critical Telecom Data and Infrastructure Security Regulations issued by the Pakistan Telecommunication Authority. It was gazetted on 31 December 2025 as S.R.O. 2504(I)/2025, replaces CTDISR 2020, and is mandatory for PTA licensees operating critical telecom infrastructure.
How many regulations are in CTDISR 2025?
84 regulations across 14 chapters. They cover governance, asset and risk management, incident management, access control, operations, business continuity, systems development, physical, cloud and HR security, assurance and audit, and regulatory oversight.
What are the Pakistan-specific requirements in CTDISR?
SIEM integration with the National Telecom SOC (nTSOC), reporting breaches to PTA within 24 hours, data-localization requirements for critical data, IPv6 targets, and an annual PTA-certified third-party audit due by 28 February.
Does ISO 27001 cover CTDISR?
Mostly. 81 of the 84 regulations map to an ISO 27001:2022 Annex A control, so an ISMS covers most of the ground. The Pakistan-specific obligations still need dedicated controls and evidence.
How does Komply help with CTDISR?
Komply ships all 84 regulations cross-mapped to ISO 27001. It drafts policies, tracks owners and evidence, and exports an auditor-ready package for the annual PTA-certified audit.
Official sources
Do ISO 27001 once. Prove CTDISR too.
Komply maps 14 frameworks and 1,100+ controls into one control set. Start with a free gap assessment.