Sagentix Cyber & AI
FedRAMP does not
carry into Canada.
The control design does. The authorization does not. Establishing exactly where that line falls, for your service, is the difference between a credible timeline and a slipped one.
We prepare cloud and SaaS providers for the Canadian Centre for Cyber Security assessment at Protected B — and we are not the assessor, which is what makes the preparation worth anything.
What you are actually walking into
Five parties, four of whom are not you, and a clock most of them do not control.
What the assessment is
The Canadian Centre for Cyber Security assesses a cloud service provider so a federal department can host data at Protected B on that service. It is built on ITSG-33 and the Canadian adaptation of NIST SP 800-53, and the result is a reusable risk authorization a department draws on rather than repeating.
Who does what
You design and operate the controls. An accredited third-party assessor tests them. The Cyber Centre assesses the result, alongside the federal shared-services organization where a contract runs through it. The department signs the authority to operate. We advise — and we are none of the other four.
What actually sets the timeline
Not the control work. The elapsed time is set by assessor scheduling, the sponsor relationship, contract security screening and the parts of the queue nobody in the room controls. A plan that only sequences the controls is a plan that will slip.
If you already hold FedRAMP or SOC 2
Partly transferable, and the partly is the whole engagement. Both profiles descend from NIST SP 800-53, so the control design travels. The Canadian overlay is tested freshly.
What an existing posture buys you
What carries over
- The control design itself — both profiles descend from NIST SP 800-53
- Existing test evidence, where the assessment boundary genuinely overlaps
- The engineering maturity that produced the evidence in the first place
- The habit of operating under continuous monitoring
What does not
- The authorization itself — a US federal authorization is not a Canadian one
- Data residency, where Canadian expectations are their own question
- Key management and who can hold cleartext
- Personnel screening, and the clearance level the contract actually requires
- The supply chain, followed through subcontractors rather than stopping at your own staff
Sizing that slice honestly — before a date is promised to a sponsor — is the first deliverable, and it is the one that decides whether everything after it is realistic.
What the engagement covers
Readiness and authoring. The testing stays with an accredited assessor and the assessment stays with the Cyber Centre.
Path selection and critical path
Which assessment route applies to your service, what each one costs you in elapsed time, and where the true critical path runs — usually somewhere other than the controls.
The control-delta map
Your existing certifications mapped against the Canadian profile, control family by control family, so the net-new work is a known quantity before anyone commits to a date.
Residency and boundary analysis
Where the data physically sits, what counts as processing, and whether a service that never stores data at rest is in scope at all — a question that is decided on the facts of your architecture, not on a marketing position.
Key management and access positions
Who holds the keys, who can see cleartext, and the defensible written answer to the privileged-user question — which is usually the single input that sets your screening population.
Assessor and authority coordination
Acting as the single point of contact across your team, the assessor, the Cyber Centre and the shared-services organization, so four parties are working from one version of the plan.
Sponsor and departmental positioning
The assessment needs a federal sponsor with a real requirement. Establishing who that is, and what makes your service worth their sponsorship, is part of the work rather than a precondition for it.
Delivered
Run live for a global infrastructure and security provider as the single point of contact across the client, the Cyber Centre, the federal shared-services organization and the third-party assessor — and separately as a gap analysis mapping an existing FedRAMP High and ISO 27001 posture onto the Canadian profile for a global cybersecurity vendor. No client is named; engagements are described at method level, with named references available on request subject to client consent.
For federal buyers
There is a contracting vehicle for this
A department does not have to build a bespoke procurement to get this work. The security assessment and authorization capability is available through a federal supply arrangement via a prime, for software-as-a-service workloads up to Protected B.
Three ways to call it up
- A sole-source justification naming the specialized capability
- A simplified bid solicitation against holders of the arrangement
- Bundled alongside a software purchase made through the same vehicle
Work packages
- Assessment plan and categorization
- Control tailoring and traceability matrix
- Evidence collection and validation
- Security assessment report
- Plan of action and risk acceptance
- Authorization submission support
- Continuous monitoring and annual refresh
Scope and screening
- Up to Protected B, on the Medium control profile
- Cloud High (Protected B / High / High) available on request
- Protected C and classified are out of scope
- Personnel screened at Reliability or higher
- Data resident in Canada; no offshore processing
Sizing runs the same way it does on any engagement here: a short, fixed-price pre-qualification assessment settles the categorization, the control profile and the complexity before anyone commits to a scope. Ask and we will tell you which vehicle applies and who holds it.
Find out how thin the Canadian slice is.
Thirty minutes. We establish which assessment path applies, what your existing evidence is worth against the Canadian profile, and what the elapsed time realistically looks like — including the parts nobody controls.