Sagentix Cyber & AI
FedRAMP does not
carry into Canada.
The control design does. The authorization does not. Establishing exactly where that line falls, for your service, is the difference between a credible timeline and a slipped one.
We prepare cloud and SaaS providers for the Canadian Centre for Cyber Security assessment at Protected B — and we are not the assessor, which is what makes the preparation worth anything.
What you are actually walking into
Five parties, four of whom are not you, and a clock most of them do not control.
What the assessment is
The Canadian Centre for Cyber Security assesses a cloud service provider so a federal department can host data at Protected B on that service. It is built on ITSG-33 and the Canadian adaptation of NIST SP 800-53, and the result is a reusable risk authorization a department draws on rather than repeating.
Who does what
You design and operate the controls. An accredited third-party assessor tests them. The Cyber Centre assesses the result, alongside the federal shared-services organization where a contract runs through it. The department signs the authority to operate. We advise — and we are none of the other four.
What actually sets the timeline
Not the control work. The elapsed time is set by assessor scheduling, the sponsor relationship, contract security screening and the parts of the queue nobody in the room controls. A plan that only sequences the controls is a plan that will slip.
If you already hold FedRAMP or SOC 2
Partly transferable, and the partly is the whole engagement. Both profiles descend from NIST SP 800-53, so the control design travels. The Canadian overlay is tested freshly.
What carries over
- The control design itself — both profiles descend from NIST SP 800-53
- Existing test evidence, where the assessment boundary genuinely overlaps
- The engineering maturity that produced the evidence in the first place
- The habit of operating under continuous monitoring
What does not
- The authorization itself — a US federal authorization is not a Canadian one
- Data residency, where Canadian expectations are their own question
- Key management and who can hold cleartext
- Personnel screening, and the clearance level the contract actually requires
- The supply chain, followed through subcontractors rather than stopping at your own staff
The practical consequence: the net-new effort concentrates in a thin Canadian slice, not across the whole control set. Sizing that slice honestly — before a date is promised to a sponsor — is the first deliverable, and it is the one that decides whether everything after it is realistic.
What the engagement covers
Readiness and authoring. The testing stays with an accredited assessor and the assessment stays with the Cyber Centre.
Path selection and critical path
Which assessment route applies to your service, what each one costs you in elapsed time, and where the true critical path runs — usually somewhere other than the controls.
The control-delta map
Your existing certifications mapped against the Canadian profile, control family by control family, so the net-new work is a known quantity before anyone commits to a date.
Residency and boundary analysis
Where the data physically sits, what counts as processing, and whether a service that never stores data at rest is in scope at all — a question that is decided on the facts of your architecture, not on a marketing position.
Key management and access positions
Who holds the keys, who can see cleartext, and the defensible written answer to the privileged-user question — which is usually the single input that sets your screening population.
Assessor and authority coordination
Acting as the single point of contact across your team, the assessor, the Cyber Centre and the shared-services organization, so four parties are working from one version of the plan.
Sponsor and departmental positioning
The assessment needs a federal sponsor with a real requirement. Establishing who that is, and what makes your service worth their sponsorship, is part of the work rather than a precondition for it.
Delivered
Run live for a global infrastructure and security provider as the single point of contact across the client, the Cyber Centre, the federal shared-services organization and the third-party assessor — and separately as a gap analysis mapping an existing FedRAMP High and ISO 27001 posture onto the Canadian profile for a global cybersecurity vendor. No client is named; engagements are described at method level, with named references available on request subject to client consent.
Find out how thin the Canadian slice is.
Thirty minutes. We establish which assessment path applies, what your existing evidence is worth against the Canadian profile, and what the elapsed time realistically looks like — including the parts nobody controls.