Your resolver is validating DNSSEC correctly. Your ISP seems to make a good job. But what will happen during the KSK rollover?
Your ISP is probably ready to roll KSK seamlessly, but this is hard to verify for you. So please call your ISP and ask, if they are really ready to the KSK Rollover.
Nothing, your resolver is not validating DNSSEC at all. Your ISP seems to ignore DNSSEC. So they are not touched by any changes in DNSSEC setting.
You may call your ISP to ask, if they are plan to roll out DNSSEC and if they are ready for the KSK Rollover.