Skip to main content

Sagentix Cyber & AI

FedRAMP does not
carry into Canada.

The control design does. The authorization does not. Establishing exactly where that line falls, for your service, is the difference between a credible timeline and a slipped one.

We prepare cloud and SaaS providers for the Canadian Centre for Cyber Security assessment at Protected B — and we are not the assessor, which is what makes the preparation worth anything.

What you are actually walking into

Five parties, four of whom are not you, and a clock most of them do not control.

What the assessment is

The Canadian Centre for Cyber Security assesses a cloud service provider so a federal department can host data at Protected B on that service. It is built on ITSG-33 and the Canadian adaptation of NIST SP 800-53, and the result is a reusable risk authorization a department draws on rather than repeating.

Who does what

You design and operate the controls. An accredited third-party assessor tests them. The Cyber Centre assesses the result, alongside the federal shared-services organization where a contract runs through it. The department signs the authority to operate. We advise — and we are none of the other four.

What actually sets the timeline

Not the control work. The elapsed time is set by assessor scheduling, the sponsor relationship, contract security screening and the parts of the queue nobody in the room controls. A plan that only sequences the controls is a plan that will slip.

If you already hold FedRAMP or SOC 2

Partly transferable, and the partly is the whole engagement. Both profiles descend from NIST SP 800-53, so the control design travels. The Canadian overlay is tested freshly.

What an existing posture buys you

What carries over

  • The control design itself — both profiles descend from NIST SP 800-53
  • Existing test evidence, where the assessment boundary genuinely overlaps
  • The engineering maturity that produced the evidence in the first place
  • The habit of operating under continuous monitoring
Net-new work

What does not

  • The authorization itself — a US federal authorization is not a Canadian one
  • Data residency, where Canadian expectations are their own question
  • Key management and who can hold cleartext
  • Personnel screening, and the clearance level the contract actually requires
  • The supply chain, followed through subcontractors rather than stopping at your own staff
Partly transferable, and the partly is the whole engagement. A United States authorization is not recognised in Canada — the programmes are separate, and the Canadian overlay is assessed from scratch however mature the rest of the posture is.

Sizing that slice honestly — before a date is promised to a sponsor — is the first deliverable, and it is the one that decides whether everything after it is realistic.

What the engagement covers

Readiness and authoring. The testing stays with an accredited assessor and the assessment stays with the Cyber Centre.

Path selection and critical path

Which assessment route applies to your service, what each one costs you in elapsed time, and where the true critical path runs — usually somewhere other than the controls.

The control-delta map

Your existing certifications mapped against the Canadian profile, control family by control family, so the net-new work is a known quantity before anyone commits to a date.

Residency and boundary analysis

Where the data physically sits, what counts as processing, and whether a service that never stores data at rest is in scope at all — a question that is decided on the facts of your architecture, not on a marketing position.

Key management and access positions

Who holds the keys, who can see cleartext, and the defensible written answer to the privileged-user question — which is usually the single input that sets your screening population.

Assessor and authority coordination

Acting as the single point of contact across your team, the assessor, the Cyber Centre and the shared-services organization, so four parties are working from one version of the plan.

Sponsor and departmental positioning

The assessment needs a federal sponsor with a real requirement. Establishing who that is, and what makes your service worth their sponsorship, is part of the work rather than a precondition for it.

Delivered

Run live for a global infrastructure and security provider as the single point of contact across the client, the Cyber Centre, the federal shared-services organization and the third-party assessor — and separately as a gap analysis mapping an existing FedRAMP High and ISO 27001 posture onto the Canadian profile for a global cybersecurity vendor. No client is named; engagements are described at method level, with named references available on request subject to client consent.

For federal buyers

There is a contracting vehicle for this

A department does not have to build a bespoke procurement to get this work. The security assessment and authorization capability is available through a federal supply arrangement via a prime, for software-as-a-service workloads up to Protected B.

Three ways to call it up

  • A sole-source justification naming the specialized capability
  • A simplified bid solicitation against holders of the arrangement
  • Bundled alongside a software purchase made through the same vehicle

Work packages

  • Assessment plan and categorization
  • Control tailoring and traceability matrix
  • Evidence collection and validation
  • Security assessment report
  • Plan of action and risk acceptance
  • Authorization submission support
  • Continuous monitoring and annual refresh

Scope and screening

  • Up to Protected B, on the Medium control profile
  • Cloud High (Protected B / High / High) available on request
  • Protected C and classified are out of scope
  • Personnel screened at Reliability or higher
  • Data resident in Canada; no offshore processing

Sizing runs the same way it does on any engagement here: a short, fixed-price pre-qualification assessment settles the categorization, the control profile and the complexity before anyone commits to a scope. Ask and we will tell you which vehicle applies and who holds it.

Find out how thin the Canadian slice is.

Thirty minutes. We establish which assessment path applies, what your existing evidence is worth against the Canadian profile, and what the elapsed time realistically looks like — including the parts nobody controls.

See the full practice