Sagentix Cyber & AI
We author the evidence
a governed decision runs on.
For organizations facing a regulated-market gate — a Canadian federal authorization, an ISO certification, a SOC 2 examination, a data-protection regulator — Sagentix authors the evidence the decision runs on.
Sagentix prepares organizations for independent assessment, in Canada, the Caribbean, the United States and Europe. The party who reviews the work is always someone else — a certification body, an examining firm, a regulator, or the department that grants the authority to operate.
That separation is what makes the work survive the review.
How to check that, rather than take our word for it
Independence is a structural question, not a policy question — so it can be verified.
Where our work stops
Sagentix authors
- Control tailoring and requirement traceability
- Evidence production and the assessment package
- Coordination with the assessor and the sponsor
- Readiness against the profile that actually applies
Someone else judges
- The accredited assessor who tests the evidence
- The certification body that issues the certificate
- The departmental official who signs the authorization
Ask three questions
Ask any adviser you are evaluating: does the firm, or any affiliate of it, hold an accreditation as a certification body or a third-party assessment organization? Is it pursuing one? And does it, or an affiliate, audit, attest or certify anything for clients it also advises?
Then check the answers
Accreditations are recorded in a public register maintained by the national accreditation body. It takes a few minutes and it does not require anyone’s permission.
11 service lines across 4 families
Assess & authorize
Getting a system through the authorization that gates the sale
- Security assessment and authorization
- Security assessments and cyber maturity
- Cloud security assessment and authorization
Certify & comply
The certificate or programme a buyer names in the contract
- Market-access compliance programmes
- Standards certification readiness
- Privacy and data-protection readiness
Govern & architect
The instruments that make a decision defensible afterwards
- Enterprise and departmental security governance
- Enterprise architecture assessment
- Embedded senior advisory
AI & cryptography
The two deadlines already inside most replacement cycles
- AI governance programmes
- Post-quantum cryptography migration
What we author
11 service lines across 4 families. Pick a family, or open a line to see what it produces and the record behind it — readiness and authoring, with the judgment always independent of us.
What it produces
- AI governance programme directive
- IT security standard for the secure use and development of AI
- Amendment packages layered onto an existing standards stack
- An AI risk overlay on the existing assessment framework
- Secure-design control baselines organized by deployment pattern
- Reference architectures, agentic-system controls and shadow-AI discovery
Delivered
Built and running at a major Canadian federal financial-sector institution against NIST AI RMF 1.0, NIST AI 600-1, ISO/IEC 42001, the OWASP GenAI LLM Top 10 2026 and MITRE ATLAS.
What it produces
- Cryptographic inventory and crypto-agility assessment
- Quantum-safe cryptography IT security standard
- Amendment packages across the existing standards stack
- Risk-factor integration into the assessment framework
- A phased, milestone-anchored migration roadmap
Delivered
Delivered at a major Canadian federal financial-sector institution against the Cyber Centre ITSM.40.001 migration milestones and the NIST FIPS 203, 204 and 205 standards.
What it produces
- Governance operating model, forums and decision rights
- An intake-first flow separating security recommendation from accountable-owner decision
- Security policy, standard, directive and guideline authoring
- Consolidated risk register and reporting cadence
- Oversight and performance-metrics framework
- Departmental security plan refresh against the Policy on Government Security
Delivered
Built against the instruments an organization is already held to: NIST Cybersecurity Framework 2.0, ISO/IEC 27001 and COBIT; NIST SP 800-53, ITSG-33 and the Protected B profile in Canadian federal work; and, for financial institutions, the OSFI guidelines on technology and cyber risk and on model risk, alongside the Cyber Risk Institute Profile. Delivered as the enterprise policy, standard, directive and guideline stack at a major Canadian federal financial-sector institution, with a standing cross-functional body spanning cyber, privacy, legal, risk, procurement and data.
What it produces
- Domain-by-domain assessment and maturity heat map
- Current-state to target-state roadmap
- Technical-debt and aging-IT concentration analysis
- Architecture review board submission packages
- Investment business case and sequencing
Delivered
Assessed against the Government of Canada Enterprise Architecture Framework and its review-board process, with the control architecture traced to ITSG-33 and NIST SP 800-53 and the target state built to a zero-trust posture. Delivered as a complete current-state to target-state architecture across all six domains for a 43,000-student, 8,000-staff estate, and the same discipline extended to national scale on a cloud-first regional-hub strategy and secure cloud and internet perimeter.
What it produces
- Which programme the buyer actually means, and whether it reaches your product on the facts
- Canada — Controlled Goods Program registration readiness, and CPCSC Level 1 against its thirteen controls
- United States — CMMC posture, whether a valid certification can be offered in place of a Canadian self-assessment, and ITAR or EAR classification of the product itself
- European Union — obligations arriving under the Cyber Resilience Act, and the Radio Equipment Directive where the product carries a radio
- Procurement conditions that are not regulations at all — Common Criteria evaluation and FIPS 140 cryptographic validation, which buyers write into contracts
- Supplier-questionnaire and bid-response positions, and the ones worth holding back
Delivered
Produced for a global infrastructure and security provider on a live federal file — including the data-handling analysis that resolves whether a service which never stores data at rest is in scope at all — and, in the defence sector, export-control classification and procurement-condition analysis for products sold into Canadian, United States and European or NATO channels.
What it produces
- Scoping and gap assessment against each standard in play
- A harmonized control baseline and statement of applicability
- Policies, procedures, registers and the records an auditor samples
- The internal audit and management review cycle the standard requires
- Evidence packs organized the way an assessor works
- Coordination with the certification body or examining firm you appoint
Delivered
The same evidence base a Canadian Protected B assessment consumes — the Cyber Centre’s own assessment process reuses SOC 2 Type II and the ISO/IEC standards rather than re-testing them, which is why the second certificate costs a fraction of the first.
What it produces
- Jurisdictional applicability on the facts, not on the map
- One harmonized baseline with the deltas documented
- Processing register, notices, impact-assessment methodology
- Data-subject-rights procedures and retention schedules
- Breach-response runbook calibrated to the shortest clock that applies
- Vendor and processor clauses, and supervisory readiness
Delivered
Built on our own cross-mapping of the Jamaican, Barbadian and Cayman Acts onto ISO/IEC 27001, NIST CSF 2.0 and the SOC 2 Trust Services Criteria. Advisory and authoring only — Sagentix is not a law firm and gives no legal opinions.
What it produces
- Standing independent oversight and forum chairing
- Risk register and reporting maintenance
- Assurance over modernization and authorization decisions
- Audit-ready evidence discipline
- Capability-transfer log with advisor effort phasing down
No client is named on this page. Engagements are described at method level, with the delivery record stated in figures that can be discussed under a non-disclosure agreement and named references available on request, subject to client consent.
The instruments we work in
The work is conducted in the language and structure your organization already operates within. No proprietary framework is imposed on top of the one that binds you.
One baseline, four packages
One control baseline
authored once
- CCCS Protected B+ deltaITSG-33 · ITSP.10.033
- ISO/IEC 27001+ 27017 / 27018
- SOC 2Type I / Type II
- CSA CAIQcustomer questionnaire
+ delta marks the work the shared baseline does not cover. The Canadian overlay — residency, key management, personnel screening and supply chain — is genuinely net-new and is tested freshly, which is why establishing where that delta sits comes before anyone commits to a timeline.
Canadian federal security
- ITSG-33 — IT security risk management lifecycle
- ITSP.10.033 — security and privacy controls catalogue
- The Protected B / Medium / Medium control profile
- CCCS cloud guidance and the GC cloud control profiles
- Cloud guardrails and the shared-services broker model
- GC Cyber Security Event Management Plan
Policy and architecture
- Policy on Government Security and the Directive on Security Management
- Policy and Directive on Service and Digital
- GC Enterprise Architecture Framework and the review-board flow
- Departmental security plan expectations
International and sector
- NIST SP 800-53 and the risk management framework
- ISO/IEC 27001, 27017 and 42001
- SOC 2 and FedRAMP as comparison regimes
- NIST AI RMF 1.0 and NIST AI 600-1
- OWASP GenAI LLM Top 10 2026 and MITRE ATLAS
- MITRE ATT&CK v19 — adversary tactics and techniques
- CSA Cloud Controls Matrix v4 — the CAIQ is built into it
- CIS Benchmarks — hardening baselines, per platform
- NIST FIPS 203, 204 and 205; CCCS ITSM.40.001
Certification, attestation and privacy
- ISO/IEC 27001 management system certification
- ISO/IEC 27017 cloud and 27018 personal-data extensions
- SOC 2 Trust Services Criteria, Type I and Type II
- NIST Cybersecurity Framework 2.0
- EU General Data Protection Regulation
- United States state privacy law and sectoral regimes
- Caribbean data-protection Acts; Canadian federal and Quebec law
Financial-sector cyber
- CPMI-IOSCO — cyber resilience for financial market infrastructures (2016)
- G7 Cyber Expert Group — post-quantum roadmap; AI and cyber security
- BIS Papers No 145 — generative AI and cyber security in central banking
- FS-ISAC — sector threat intelligence and information sharing
- TIBER-EU — threat-intelligence-based red teaming
- CFDIR — the digital-infrastructure resilience forum ISED convenes
What CSF 2.0 changed, and why a board reads it first
GOVERN (GV)
strategy · expectations · policy
- IDENTIFY (ID)current risks are understood
- PROTECT (PR)safeguards are used
- DETECT (DE)attacks are found and analyzed
- RESPOND (RS)actions are taken
- RECOVER (RC)assets and operations are restored
For federally regulated financial institutions
A bank does not ask whether a control is sensible. It asks which guideline puts it there, which line of defence owns it, and what the examiner will read.
OSFI and the Financial Consumer Agency of Canada reported that AI use among federally regulated financial institutions rose from roughly 30% in 2019 to roughly 50% in 2023, and projected 70% by 2026; three-quarters of responding institutions said they intended to invest in AI over the following three years (Office of the Superintendent of Financial Institutions & Financial Consumer Agency of Canada, 2024). The governance instrument that will judge those models does not take effect until 1 May 2027, which is the gap this work sits in.
The instruments, by the date they bind
31 Jul 2022
B-13
Technology and Cyber Risk Management — governance, technology operations and resilience, cyber security
30 Apr 2023
B-10
Third-Party Risk Management — the institution keeps accountability for what it outsources
22 Aug 2024
E-21
Operational Risk Management and Resilience — critical operations, mapped end to end, with tolerances for disruption
1 May 2027
E-23
Model Risk Management — covers AI and machine-learning models explicitly. Not yet in force.
Which line owns the control is the question the examiner asks first
An AI control that nobody owns is a finding. Most of the difficulty in an AI or model-risk programme is not writing the control — it is placing it, so that the people who build, the people who challenge and the people who audit are not the same people.
Three lines of defence, applied to model and AI risk
- 01
First line
The business and technology teams that build and run the model
- Identify and own the risk in what they deploy
- Model documentation, data lineage, testing evidence
- Controls operated day to day
B-13 · technology operations and resilience
- 02
Second line
Risk management and compliance — independent challenge
- Model validation, independent of the builder
- The model inventory and its risk rating
- Policy, standards and the approval gate
E-23 · from 1 May 2027
- 03
Third line
Internal audit
- Assurance that the first two lines work
- Reports to the audit committee, not to management
- Tests the framework, not just the model
E-21 · operational risk framework
One control baseline, four regimes reading it
A Canadian bank standing up AI governance is usually answering to a domestic supervisor, an international standard its board already recognises, and a control catalogue its security function already runs. These are not four programmes.
What the AI governance baseline has to satisfy
One AI control baseline
authored once
- OSFI E-23+ deltamodel risk · 2027
- NIST AI RMF 1.0govern · map · measure · manage
- ISO/IEC 42001AI management system
- NIST SP 800-53the control catalogue underneath
+ delta marks the work the shared baseline does not cover. E-23 asks a supervisory question the international standards do not — who validated this model, independently of who built it, and can the institution show the examiner that record. That is a governance obligation, not a control, and it is the part a framework crosswalk alone will not produce.
Delivered
An AI governance programme and a post-quantum migration programme, both delivered at a major Canadian federal financial-sector institution and running in parallel — a governance directive, an IT security standard for the secure use and development of AI, amendment packages across the existing standards stack, and control baselines by deployment pattern.
No client is named. Engagements are described at method level, with named references available on request, subject to client consent.
How the work runs
A delivery model built so the advice survives an internal audit — and so your team can carry it once we leave.
Principal-led, and signed
Stéphane Raby is principal, lead and signatory on every deliverable. Where depth or parallelism is needed, a vetted bench works under that direction — but the signature does not move.
Phase-gated, at a cadence you set
Engagements run at a part-time cadence scaled by phase — heavier through assessment and framework build, lighter through sustainment — with weekly working contact, a monthly steering review, and sign-off at the close of each phase.
Capability transfer is the exit condition
The objective is a capability your team sustains, not a permanent dependency. Advisor effort phases down as internal maturity rises, tracked against a capability-transfer log rather than asserted at the end.
Evidence discipline throughout
Every claim is sourced and every deliverable passes an 18-check automated quality gate before the principal reads it end-to-end and signs it. Deliverables are produced in your own templates where your department requires them.
Why the method holds
Individually these are common. Together, in one advisor, cleared and available today, they are not.
Taught the Government of Canada’s own method
Instructor at the Canadian Centre for Cyber Security for thirty-two months, through November 2025, across four courses delivered in both official languages — the ITSG-33 security risk management boot camp, the foundations of cloud security in the Government of Canada, the cloud security assessment and authorization process, and the cloud service provider assessment course that certifies the people who perform these assessments.
Holds the cloud service provider assessment certification
The Canadian Centre for Cyber Security certification for conducting cloud service provider IT security assessments at Protected B — held, and applied from the readiness side of the table rather than the assessment side.
Four credentials at the security, engineering and governance intersection
CISSP, from (ISC)². Professional Engineer, Ordre des ingénieurs du Québec. Certified Management Consultant, CMC-Canada and CMC-Global — the designation that binds the practitioner to an ethics board and an enforceable code covering objectivity, confidentiality and conflict of interest. Executive MBA, Telfer School of Management, University of Ottawa.
Cleared, bilingual, and currently engaged
A Government of Canada Secret clearance is held, so there is no screening cycle to plan around. French is native and English fluent. The federal authorization machinery is being worked inside this quarter, on live files — current, rather than recalled from a past posting.
Who this is for
Six situations, one common shape: a decision that has to hold up in front of someone who did not make it.
Federal departments and agencies
An authorization backlog, a departmental security plan that has gone stale, cyber risk tracked in silos, or an enterprise architecture nobody has baselined.
Crown corporations and federal financial-sector institutions
An enterprise instrument stack to author or refresh, an AI governance programme to stand up, or a post-quantum migration with a fixed deadline and no inventory.
Technology vendors selling into regulated buyers
A certification or procurement gate standing between a working product and revenue — a Canadian authorization at Protected B, an ISO certificate or a SOC 2 report a customer will not proceed without, and the compliance-programme question behind it.
Caribbean banks and financial institutions
Boards accountable for AI oversight they have not been equipped for, correspondent-banking pressure, and data-protection regimes that differ sharply from one jurisdiction to the next even where the statutes look alike.
Organizations operating across several jurisdictions
The same control environment answering to a European regulator, a United States customer’s security questionnaire, a Caribbean data-protection Act and a Canadian authorization — built once rather than four times.
Suppliers to the defence and security supply chain
A supplier questionnaire, a cyber-certification tier, or a controlled-goods question that has to be answered in writing and correctly the first time.
Where you will want someone else — and we will tell you who
- Perform independent assessments
- Issue or audit certifications as an accredited assessor
- Operate a security operations centre
- Run penetration tests or red-team exercises
- Perform hands-on engineering, configuration or remediation
- Provide legal, export-controls or audit and attest opinions
For any of these, we will point you to a firm that does them well. The advisor directs and assures; your staff and specialist suppliers execute. That boundary is not a limitation — it is what stops us from ever assuring our own work, which is the first question an auditor asks.
How this practice is priced
Two steps, and the first one is deliberately small.
Step one
A paid pre-qualification, before anyone quotes a programme
Every engagement starts with a scope-fixing first unit at its own fixed price. It produces a scoping memo: a security categorization, the control profile that actually applies, a complexity classification, and the scope the work genuinely needs rather than the one that fits a template.
The fee is credited against the engagement if you proceed within ninety days — the same structure as the Phase 1 entry engagement in the go-to-market practice.
Step two
Then a firm fixed price, or a monthly engagement
Catalogue work sold through a prime is firm-fixed-price in defined blocks. Continuing readiness work is sold as a monthly engagement at one of two levels, scoped by capability rather than by hours:
- ReadinessOne authorization path — control tailoring and requirement traceability, evidence production, and the package itself.
- ProgrammeA continuing programme — several systems or frameworks at once, with continuous monitoring, annual refresh and regulatory liaison.
Both practices, side by side
The pricing page sets this practice beside the go-to-market ladder — one published in full, one scoped and quoted — and says plainly why only one of them can carry a number.
Why there is no number on this page
We publish a price where we can guarantee the scope. Our go-to-market methodology produces a fixed set of deliverables to a fixed standard, so we can tell you the price before we know anything about you. Compliance readiness does not work that way — the effort depends on your control environment, your cloud footprint and how much evidence already exists. Anyone who publishes a fixed number for that is either quoting a gap analysis or planning to re-scope you later. We start with a paid pre-qualification, and then you get a firm fixed price for the actual work.
Questions we are asked first
Usually in the first ten minutes of the diagnosis call.
Do you issue the authority to operate?
No. We author the evidence and the recommendation package; the authorization decision is signed by the accountable departmental official — typically the designated official for cyber security, the chief information officer and the business owner. That separation is what makes the work survive review.
Are you a third-party assessment organization?
We hold the authoring role, and deliberately that role alone: our entry in the accreditation register stays empty as certification body and as assessor. We prepare organizations for independent assessment; the party who judges the work is always someone else. Sagentix does hold the Canadian Centre for Cyber Security cloud service provider assessment certification, so the method is known from the assessor side — and it goes into preparing your package rather than into judging it.
What is CCCS Cloud Medium, and how does it relate to Protected B?
CCCS Cloud Medium is the Canadian Centre for Cyber Security assessment a cloud service provider goes through so its service can hold Government of Canada data at the Protected B sensitivity level. It is built on ITSG-33 and the Canadian adaptation of NIST SP 800-53, and it is a separate, Canadian-run programme — a United States FedRAMP authorization does not extend to Canadian data or Canadian data centres.
We already hold FedRAMP or SOC 2. Does that carry over?
Partly, and the partly is the whole engagement. Both the Canadian and United States profiles descend from NIST SP 800-53, so a mature control design transfers and existing assessment evidence can often be reused. What does not transfer is the Canadian control overlay — residency, key management, personnel screening and supply chain — which is tested freshly. The work is establishing exactly where the delta sits before anyone commits to a timeline.
A federal buyer asked whether we are compliant. Compliant with what?
That question usually points at one of several different Government of Canada programmes, each run by a different authority and answering a different question — cloud authorization at Protected B, a cyber-certification tier, controlled-goods registration, or contract security screening. They are complementary, not interchangeable. Establishing which one the buyer means, before anyone puts an answer in writing, is the first piece of work.
Do you run penetration tests or operate a security operations centre?
No. We provide governance, architecture and oversight advisory; the advisor directs and assures, and your staff or specialist suppliers execute. For testing, security operations, hands-on remediation or accredited assessment, we will point you to a firm that does it well.
Do you deliver in French?
Yes. The principal is natively bilingual and delivered the Canadian Centre for Cyber Security curriculum in both official languages. Deliverables are produced in either language, or in your department’s own templates.
Is the principal security cleared?
Yes — a Government of Canada Secret clearance is held. On a mandate with a fixed ceiling, a multi-month screening cycle is not an administrative detail, so this is stated up front rather than discovered at onboarding.
Depth you can test. A method you can follow.
Start with the gate, not the proposal.
Thirty minutes. We establish which Canadian gate actually applies to you, what the evidence you already hold is worth against it, and what the elapsed time realistically looks like — including the parts nobody controls.