Skip to main content

Sagentix Cyber & AI

We author the evidence
a governed decision runs on.

For organizations facing a regulated-market gate — a Canadian federal authorization, an ISO certification, a SOC 2 examination, a data-protection regulator — Sagentix authors the evidence the decision runs on.

Sagentix prepares organizations for independent assessment, in Canada, the Caribbean, the United States and Europe. The party who reviews the work is always someone else — a certification body, an examining firm, a regulator, or the department that grants the authority to operate.

That separation is what makes the work survive the review.

How to check that, rather than take our word for it

Independence is a structural question, not a policy question — so it can be verified.

Where our work stops

Sagentix authors

  • Control tailoring and requirement traceability
  • Evidence production and the assessment package
  • Coordination with the assessor and the sponsor
  • Readiness against the profile that actually applies
Independence line

Someone else judges

  • The accredited assessor who tests the evidence
  • The certification body that issues the certificate
  • The departmental official who signs the authorization
Our entry in the national accreditation register is empty on all three counts — certification body, laboratory, assessor — and stays that way by design. That separation is what makes the work survive the review, and it is the first thing an auditor asks about.

Ask three questions

Ask any adviser you are evaluating: does the firm, or any affiliate of it, hold an accreditation as a certification body or a third-party assessment organization? Is it pursuing one? And does it, or an affiliate, audit, attest or certify anything for clients it also advises?

Then check the answers

Accreditations are recorded in a public register maintained by the national accreditation body. It takes a few minutes and it does not require anyone’s permission.

11 service lines across 4 families

Assess & authorize

Getting a system through the authorization that gates the sale

  • Security assessment and authorization
  • Security assessments and cyber maturity
  • Cloud security assessment and authorization

Certify & comply

The certificate or programme a buyer names in the contract

  • Market-access compliance programmes
  • Standards certification readiness
  • Privacy and data-protection readiness

Govern & architect

The instruments that make a decision defensible afterwards

  • Enterprise and departmental security governance
  • Enterprise architecture assessment
  • Embedded senior advisory

AI & cryptography

The two deadlines already inside most replacement cycles

  • AI governance programmes
  • Post-quantum cryptography migration
Readiness and authoring throughout. In every case the party who judges the result is independent of us.

What we author

11 service lines across 4 families. Pick a family, or open a line to see what it produces and the record behind it — readiness and authoring, with the judgment always independent of us.

What it produces

  • Statement of sensitivity and threat & risk assessment
  • Security requirements traceability matrix
  • Security assessment report
  • Security impact assessments
  • Plan of action and milestones, and the risk-acceptance package
  • Authorization submission support, through to the decision briefing
  • Continuous monitoring, annual refresh, and security impact assessments on change

Delivered

Fifteen authority-to-operate decisions on a single national federal programme — thirteen of them at Protected B / Medium / Medium — carried on one shared traceability matrix and one master plan of action across six release stages, rather than a fresh artifact set per system. The assessment process built for it was subsequently adopted across the department for other systems.

What it produces

  • Cyber maturity assessment across people, process and technology, with peer benchmarking and a 90-day action plan
  • Threat and risk assessments, including the harmonized method used in Canadian federal practice
  • Threat modelling to STRIDE, and secure-design assessment
  • Security impact assessments on changes to an authorized system
  • Third-party and vendor security assessment, with a scoring method and ongoing monitoring protocol
  • Compliance-based architecture assessment against a named control catalogue

Delivered

Frameworks in active use: NIST Cybersecurity Framework 2.0 and NIST SP 800-53; ISO/IEC 27001; COBIT; the Cloud Security Alliance Cloud Controls Matrix, AI Controls Matrix and the CAIQ questionnaire set; and — for financial institutions — the OSFI technology and cyber risk guideline, its model-risk guideline, and the Cyber Risk Institute Profile.

What it produces

  • Assessment path options and critical-path plan, per regime
  • Control-delta map across CCCS Cloud Medium, FedRAMP, ISO/IEC 27017 and 27018, SOC 2 and the CSA Cloud Controls Matrix
  • CAIQ and customer security-questionnaire responses
  • Cloud security architecture review — AWS, Azure and hybrid: landing zones, identity and access, data protection, network security and zero-trust posture
  • Well-Architected review against the AWS pillars — security, reliability, performance efficiency, operational excellence and cost optimization
  • Data residency, sovereignty and key-management positions
  • Third-party assessor coordination — scoped so the assessor tests the Canadian delta rather than re-testing what your existing certifications already cover
  • Continuous compliance after the authorization: annual reassessment, and adding new products to an authorization you already hold

Delivered

Delivered live for a global infrastructure and security provider as the single point of contact across the client, the Cyber Centre, the federal shared-services organization and the third-party assessor; as a gap analysis mapping an existing FedRAMP High and ISO 27001 posture onto the Canadian profile for a global cybersecurity vendor; and, earlier, as the authored partner-validation submission that won a consulting firm its ATO on AWS designation, alongside landing-zone and SaaS platform assessments on AWS and Microsoft cloud estates.

The Protected B cloud path

What it produces

  • AI governance programme directive
  • IT security standard for the secure use and development of AI
  • Amendment packages layered onto an existing standards stack
  • An AI risk overlay on the existing assessment framework
  • Secure-design control baselines organized by deployment pattern
  • Reference architectures, agentic-system controls and shadow-AI discovery

Delivered

Built and running at a major Canadian federal financial-sector institution against NIST AI RMF 1.0, NIST AI 600-1, ISO/IEC 42001, the OWASP GenAI LLM Top 10 2026 and MITRE ATLAS.

How an AI governance programme is built

What it produces

  • Cryptographic inventory and crypto-agility assessment
  • Quantum-safe cryptography IT security standard
  • Amendment packages across the existing standards stack
  • Risk-factor integration into the assessment framework
  • A phased, milestone-anchored migration roadmap

Delivered

Delivered at a major Canadian federal financial-sector institution against the Cyber Centre ITSM.40.001 migration milestones and the NIST FIPS 203, 204 and 205 standards.

The migration roadmap

What it produces

  • Governance operating model, forums and decision rights
  • An intake-first flow separating security recommendation from accountable-owner decision
  • Security policy, standard, directive and guideline authoring
  • Consolidated risk register and reporting cadence
  • Oversight and performance-metrics framework
  • Departmental security plan refresh against the Policy on Government Security

Delivered

Built against the instruments an organization is already held to: NIST Cybersecurity Framework 2.0, ISO/IEC 27001 and COBIT; NIST SP 800-53, ITSG-33 and the Protected B profile in Canadian federal work; and, for financial institutions, the OSFI guidelines on technology and cyber risk and on model risk, alongside the Cyber Risk Institute Profile. Delivered as the enterprise policy, standard, directive and guideline stack at a major Canadian federal financial-sector institution, with a standing cross-functional body spanning cyber, privacy, legal, risk, procurement and data.

What it produces

  • Domain-by-domain assessment and maturity heat map
  • Current-state to target-state roadmap
  • Technical-debt and aging-IT concentration analysis
  • Architecture review board submission packages
  • Investment business case and sequencing

Delivered

Assessed against the Government of Canada Enterprise Architecture Framework and its review-board process, with the control architecture traced to ITSG-33 and NIST SP 800-53 and the target state built to a zero-trust posture. Delivered as a complete current-state to target-state architecture across all six domains for a 43,000-student, 8,000-staff estate, and the same discipline extended to national scale on a cloud-first regional-hub strategy and secure cloud and internet perimeter.

What it produces

  • Which programme the buyer actually means, and whether it reaches your product on the facts
  • Canada — Controlled Goods Program registration readiness, and CPCSC Level 1 against its thirteen controls
  • United States — CMMC posture, whether a valid certification can be offered in place of a Canadian self-assessment, and ITAR or EAR classification of the product itself
  • European Union — obligations arriving under the Cyber Resilience Act, and the Radio Equipment Directive where the product carries a radio
  • Procurement conditions that are not regulations at all — Common Criteria evaluation and FIPS 140 cryptographic validation, which buyers write into contracts
  • Supplier-questionnaire and bid-response positions, and the ones worth holding back

Delivered

Produced for a global infrastructure and security provider on a live federal file — including the data-handling analysis that resolves whether a service which never stores data at rest is in scope at all — and, in the defence sector, export-control classification and procurement-condition analysis for products sold into Canadian, United States and European or NATO channels.

Which one is the buyer asking about?

What it produces

  • Scoping and gap assessment against each standard in play
  • A harmonized control baseline and statement of applicability
  • Policies, procedures, registers and the records an auditor samples
  • The internal audit and management review cycle the standard requires
  • Evidence packs organized the way an assessor works
  • Coordination with the certification body or examining firm you appoint

Delivered

The same evidence base a Canadian Protected B assessment consumes — the Cyber Centre’s own assessment process reuses SOC 2 Type II and the ISO/IEC standards rather than re-testing them, which is why the second certificate costs a fraction of the first.

One baseline, several audits

What it produces

  • Jurisdictional applicability on the facts, not on the map
  • One harmonized baseline with the deltas documented
  • Processing register, notices, impact-assessment methodology
  • Data-subject-rights procedures and retention schedules
  • Breach-response runbook calibrated to the shortest clock that applies
  • Vendor and processor clauses, and supervisory readiness

Delivered

Built on our own cross-mapping of the Jamaican, Barbadian and Cayman Acts onto ISO/IEC 27001, NIST CSF 2.0 and the SOC 2 Trust Services Criteria. Advisory and authoring only — Sagentix is not a law firm and gives no legal opinions.

Six regimes, one baseline

What it produces

  • Standing independent oversight and forum chairing
  • Risk register and reporting maintenance
  • Assurance over modernization and authorization decisions
  • Audit-ready evidence discipline
  • Capability-transfer log with advisor effort phasing down

No client is named on this page. Engagements are described at method level, with the delivery record stated in figures that can be discussed under a non-disclosure agreement and named references available on request, subject to client consent.

The instruments we work in

The work is conducted in the language and structure your organization already operates within. No proprietary framework is imposed on top of the one that binds you.

One baseline, four packages

One control baseline

authored once

  • CCCS Protected B+ deltaITSG-33 · ITSP.10.033
  • ISO/IEC 27001+ 27017 / 27018
  • SOC 2Type I / Type II
  • CSA CAIQcustomer questionnaire

+ delta marks the work the shared baseline does not cover. The Canadian overlay — residency, key management, personnel screening and supply chain — is genuinely net-new and is tested freshly, which is why establishing where that delta sits comes before anyone commits to a timeline.

Most of the evidence is common; the packaging and the assurance path are not. Which regime a buyer means is the first thing the engagement settles.

Canadian federal security

  • ITSG-33 — IT security risk management lifecycle
  • ITSP.10.033 — security and privacy controls catalogue
  • The Protected B / Medium / Medium control profile
  • CCCS cloud guidance and the GC cloud control profiles
  • Cloud guardrails and the shared-services broker model
  • GC Cyber Security Event Management Plan

Policy and architecture

  • Policy on Government Security and the Directive on Security Management
  • Policy and Directive on Service and Digital
  • GC Enterprise Architecture Framework and the review-board flow
  • Departmental security plan expectations

International and sector

  • NIST SP 800-53 and the risk management framework
  • ISO/IEC 27001, 27017 and 42001
  • SOC 2 and FedRAMP as comparison regimes
  • NIST AI RMF 1.0 and NIST AI 600-1
  • OWASP GenAI LLM Top 10 2026 and MITRE ATLAS
  • MITRE ATT&CK v19 — adversary tactics and techniques
  • CSA Cloud Controls Matrix v4 — the CAIQ is built into it
  • CIS Benchmarks — hardening baselines, per platform
  • NIST FIPS 203, 204 and 205; CCCS ITSM.40.001

Certification, attestation and privacy

  • ISO/IEC 27001 management system certification
  • ISO/IEC 27017 cloud and 27018 personal-data extensions
  • SOC 2 Trust Services Criteria, Type I and Type II
  • NIST Cybersecurity Framework 2.0
  • EU General Data Protection Regulation
  • United States state privacy law and sectoral regimes
  • Caribbean data-protection Acts; Canadian federal and Quebec law

Financial-sector cyber

  • CPMI-IOSCO — cyber resilience for financial market infrastructures (2016)
  • G7 Cyber Expert Group — post-quantum roadmap; AI and cyber security
  • BIS Papers No 145 — generative AI and cyber security in central banking
  • FS-ISAC — sector threat intelligence and information sharing
  • TIBER-EU — threat-intelligence-based red teaming
  • CFDIR — the digital-infrastructure resilience forum ISED convenes

What CSF 2.0 changed, and why a board reads it first

GOVERN (GV)

strategy · expectations · policy

  • IDENTIFY (ID)current risks are understood
  • PROTECT (PR)safeguards are used
  • DETECT (DE)attacks are found and analyzed
  • RESPOND (RS)actions are taken
  • RECOVER (RC)assets and operations are restored
The five on the right are operational. GOVERN is the one an examiner can hold a named person to, which is why it is the half a board reads first — NIST puts it at the centre of the wheel because it informs how an organization will implement the other five Functions. Function outcomes quoted from NIST, The NIST Cybersecurity Framework (CSF) 2.0, NIST CSWP 29.

For federally regulated financial institutions

A bank does not ask whether a control is sensible. It asks which guideline puts it there, which line of defence owns it, and what the examiner will read.

OSFI and the Financial Consumer Agency of Canada reported that AI use among federally regulated financial institutions rose from roughly 30% in 2019 to roughly 50% in 2023, and projected 70% by 2026; three-quarters of responding institutions said they intended to invest in AI over the following three years (Office of the Superintendent of Financial Institutions & Financial Consumer Agency of Canada, 2024). The governance instrument that will judge those models does not take effect until 1 May 2027, which is the gap this work sits in.

The instruments, by the date they bind

  1. 31 Jul 2022

    B-13

    Technology and Cyber Risk Management — governance, technology operations and resilience, cyber security

  2. 30 Apr 2023

    B-10

    Third-Party Risk Management — the institution keeps accountability for what it outsources

  3. 22 Aug 2024

    E-21

    Operational Risk Management and Resilience — critical operations, mapped end to end, with tolerances for disruption

  4. 1 May 2027

    E-23

    Model Risk Management — covers AI and machine-learning models explicitly. Not yet in force.

Three in force, one coming. E-23 is the one most often quoted as though it already applied — it does not, and the difference is the whole planning window. Sources: Office of the Superintendent of Financial Institutions, Guidelines B-13, B-10, E-21 and E-23, retrieved 1 September 2026.

Which line owns the control is the question the examiner asks first

An AI control that nobody owns is a finding. Most of the difficulty in an AI or model-risk programme is not writing the control — it is placing it, so that the people who build, the people who challenge and the people who audit are not the same people.

Three lines of defence, applied to model and AI risk

  1. 01

    First line

    The business and technology teams that build and run the model

    • Identify and own the risk in what they deploy
    • Model documentation, data lineage, testing evidence
    • Controls operated day to day

    B-13 · technology operations and resilience

  2. 02

    Second line

    Risk management and compliance — independent challenge

    • Model validation, independent of the builder
    • The model inventory and its risk rating
    • Policy, standards and the approval gate

    E-23 · from 1 May 2027

  3. 03

    Third line

    Internal audit

    • Assurance that the first two lines work
    • Reports to the audit committee, not to management
    • Tests the framework, not just the model

    E-21 · operational risk framework

Widths are a reading aid, not a measure of headcount. Sagentix works in the first and second lines — writing the instruments, the control baselines and the evidence. The third line, and any independent validation the second line commissions, stays with someone else, for the same reason it does everywhere else on this page.

One control baseline, four regimes reading it

A Canadian bank standing up AI governance is usually answering to a domestic supervisor, an international standard its board already recognises, and a control catalogue its security function already runs. These are not four programmes.

What the AI governance baseline has to satisfy

One AI control baseline

authored once

  • OSFI E-23+ deltamodel risk · 2027
  • NIST AI RMF 1.0govern · map · measure · manage
  • ISO/IEC 42001AI management system
  • NIST SP 800-53the control catalogue underneath

+ delta marks the work the shared baseline does not cover. E-23 asks a supervisory question the international standards do not — who validated this model, independently of who built it, and can the institution show the examiner that record. That is a governance obligation, not a control, and it is the part a framework crosswalk alone will not produce.

The instruments overlap heavily on what a good control looks like and barely at all on who has to sign for it. Establishing which regime the buyer actually means is the first deliverable.

Delivered

An AI governance programme and a post-quantum migration programme, both delivered at a major Canadian federal financial-sector institution and running in parallel — a governance directive, an IT security standard for the secure use and development of AI, amendment packages across the existing standards stack, and control baselines by deployment pattern.

No client is named. Engagements are described at method level, with named references available on request, subject to client consent.

How the work runs

A delivery model built so the advice survives an internal audit — and so your team can carry it once we leave.

Principal-led, and signed

Stéphane Raby is principal, lead and signatory on every deliverable. Where depth or parallelism is needed, a vetted bench works under that direction — but the signature does not move.

Phase-gated, at a cadence you set

Engagements run at a part-time cadence scaled by phase — heavier through assessment and framework build, lighter through sustainment — with weekly working contact, a monthly steering review, and sign-off at the close of each phase.

Capability transfer is the exit condition

The objective is a capability your team sustains, not a permanent dependency. Advisor effort phases down as internal maturity rises, tracked against a capability-transfer log rather than asserted at the end.

Evidence discipline throughout

Every claim is sourced and every deliverable passes an 18-check automated quality gate before the principal reads it end-to-end and signs it. Deliverables are produced in your own templates where your department requires them.

Why the method holds

Individually these are common. Together, in one advisor, cleared and available today, they are not.

Taught the Government of Canada’s own method

Instructor at the Canadian Centre for Cyber Security for thirty-two months, through November 2025, across four courses delivered in both official languages — the ITSG-33 security risk management boot camp, the foundations of cloud security in the Government of Canada, the cloud security assessment and authorization process, and the cloud service provider assessment course that certifies the people who perform these assessments.

Holds the cloud service provider assessment certification

The Canadian Centre for Cyber Security certification for conducting cloud service provider IT security assessments at Protected B — held, and applied from the readiness side of the table rather than the assessment side.

Four credentials at the security, engineering and governance intersection

CISSP, from (ISC)². Professional Engineer, Ordre des ingénieurs du Québec. Certified Management Consultant, CMC-Canada and CMC-Global — the designation that binds the practitioner to an ethics board and an enforceable code covering objectivity, confidentiality and conflict of interest. Executive MBA, Telfer School of Management, University of Ottawa.

Cleared, bilingual, and currently engaged

A Government of Canada Secret clearance is held, so there is no screening cycle to plan around. French is native and English fluent. The federal authorization machinery is being worked inside this quarter, on live files — current, rather than recalled from a past posting.

Who this is for

Six situations, one common shape: a decision that has to hold up in front of someone who did not make it.

Federal departments and agencies

An authorization backlog, a departmental security plan that has gone stale, cyber risk tracked in silos, or an enterprise architecture nobody has baselined.

Crown corporations and federal financial-sector institutions

An enterprise instrument stack to author or refresh, an AI governance programme to stand up, or a post-quantum migration with a fixed deadline and no inventory.

Technology vendors selling into regulated buyers

A certification or procurement gate standing between a working product and revenue — a Canadian authorization at Protected B, an ISO certificate or a SOC 2 report a customer will not proceed without, and the compliance-programme question behind it.

Caribbean banks and financial institutions

Boards accountable for AI oversight they have not been equipped for, correspondent-banking pressure, and data-protection regimes that differ sharply from one jurisdiction to the next even where the statutes look alike.

Organizations operating across several jurisdictions

The same control environment answering to a European regulator, a United States customer’s security questionnaire, a Caribbean data-protection Act and a Canadian authorization — built once rather than four times.

Suppliers to the defence and security supply chain

A supplier questionnaire, a cyber-certification tier, or a controlled-goods question that has to be answered in writing and correctly the first time.

Where you will want someone else — and we will tell you who

  • Perform independent assessments
  • Issue or audit certifications as an accredited assessor
  • Operate a security operations centre
  • Run penetration tests or red-team exercises
  • Perform hands-on engineering, configuration or remediation
  • Provide legal, export-controls or audit and attest opinions

For any of these, we will point you to a firm that does them well. The advisor directs and assures; your staff and specialist suppliers execute. That boundary is not a limitation — it is what stops us from ever assuring our own work, which is the first question an auditor asks.

How this practice is priced

Two steps, and the first one is deliberately small.

Step one

A paid pre-qualification, before anyone quotes a programme

Every engagement starts with a scope-fixing first unit at its own fixed price. It produces a scoping memo: a security categorization, the control profile that actually applies, a complexity classification, and the scope the work genuinely needs rather than the one that fits a template.

The fee is credited against the engagement if you proceed within ninety days — the same structure as the Phase 1 entry engagement in the go-to-market practice.

Step two

Then a firm fixed price, or a monthly engagement

Catalogue work sold through a prime is firm-fixed-price in defined blocks. Continuing readiness work is sold as a monthly engagement at one of two levels, scoped by capability rather than by hours:

  • ReadinessOne authorization path — control tailoring and requirement traceability, evidence production, and the package itself.
  • ProgrammeA continuing programme — several systems or frameworks at once, with continuous monitoring, annual refresh and regulatory liaison.

Both practices, side by side

The pricing page sets this practice beside the go-to-market ladder — one published in full, one scoped and quoted — and says plainly why only one of them can carry a number.

See full pricing

Why there is no number on this page

We publish a price where we can guarantee the scope. Our go-to-market methodology produces a fixed set of deliverables to a fixed standard, so we can tell you the price before we know anything about you. Compliance readiness does not work that way — the effort depends on your control environment, your cloud footprint and how much evidence already exists. Anyone who publishes a fixed number for that is either quoting a gap analysis or planning to re-scope you later. We start with a paid pre-qualification, and then you get a firm fixed price for the actual work.

Questions we are asked first

Usually in the first ten minutes of the diagnosis call.

Do you issue the authority to operate?

No. We author the evidence and the recommendation package; the authorization decision is signed by the accountable departmental official — typically the designated official for cyber security, the chief information officer and the business owner. That separation is what makes the work survive review.

Are you a third-party assessment organization?

We hold the authoring role, and deliberately that role alone: our entry in the accreditation register stays empty as certification body and as assessor. We prepare organizations for independent assessment; the party who judges the work is always someone else. Sagentix does hold the Canadian Centre for Cyber Security cloud service provider assessment certification, so the method is known from the assessor side — and it goes into preparing your package rather than into judging it.

What is CCCS Cloud Medium, and how does it relate to Protected B?

CCCS Cloud Medium is the Canadian Centre for Cyber Security assessment a cloud service provider goes through so its service can hold Government of Canada data at the Protected B sensitivity level. It is built on ITSG-33 and the Canadian adaptation of NIST SP 800-53, and it is a separate, Canadian-run programme — a United States FedRAMP authorization does not extend to Canadian data or Canadian data centres.

We already hold FedRAMP or SOC 2. Does that carry over?

Partly, and the partly is the whole engagement. Both the Canadian and United States profiles descend from NIST SP 800-53, so a mature control design transfers and existing assessment evidence can often be reused. What does not transfer is the Canadian control overlay — residency, key management, personnel screening and supply chain — which is tested freshly. The work is establishing exactly where the delta sits before anyone commits to a timeline.

A federal buyer asked whether we are compliant. Compliant with what?

That question usually points at one of several different Government of Canada programmes, each run by a different authority and answering a different question — cloud authorization at Protected B, a cyber-certification tier, controlled-goods registration, or contract security screening. They are complementary, not interchangeable. Establishing which one the buyer means, before anyone puts an answer in writing, is the first piece of work.

Do you run penetration tests or operate a security operations centre?

No. We provide governance, architecture and oversight advisory; the advisor directs and assures, and your staff or specialist suppliers execute. For testing, security operations, hands-on remediation or accredited assessment, we will point you to a firm that does it well.

Do you deliver in French?

Yes. The principal is natively bilingual and delivered the Canadian Centre for Cyber Security curriculum in both official languages. Deliverables are produced in either language, or in your department’s own templates.

Is the principal security cleared?

Yes — a Government of Canada Secret clearance is held. On a mandate with a fixed ceiling, a multi-month screening cycle is not an administrative detail, so this is stated up front rather than discovered at onboarding.

Depth you can test. A method you can follow.

Start with the gate, not the proposal.

Thirty minutes. We establish which Canadian gate actually applies to you, what the evidence you already hold is worth against it, and what the elapsed time realistically looks like — including the parts nobody controls.