Frequently Asked Questions
Everything you need to know about our evidence-based GTM methodology, pricing, and engagement process.
All questions
6–8 weeks for all 10 phases. Each phase produces a branded PDF deliverable, executive brief, and presentation deck.
Four published numerals, each with fixed scope: Phase 1 proof of concept CA$4,500 (Phase 1, delivered in 5–7 business days, money-back guarantee subject to the engagement terms); GTM Foundation CA$13,500 (Phases 1–3, 2–3 weeks); Revenue Architecture CA$27,000 (Phases 1–6, 4–5 weeks); Full engagement CA$45,000 (Phases 1–10, 6–8 weeks). Practice A and Regulated Market Access are scoped and quoted rather than listed.
Management Consulting ($5M–$50M), Cybersecurity SaaS/services, and B2B SaaS (Seed to Series B).
Evidence discipline. Every claim in every deliverable is sourced — APA 7th citations, premium industry research data, page-level provenance.
Every market statistic, competitive assertion, and strategic recommendation includes a traceable citation. Premium industry research data, peer-reviewed research, validated web sources. No unverified claims.
Both. Every deliverable passes an 18-check automated quality gate (evidence density, citation format, Pyramid Principle structure, anti-hallucination checks). Twenty-three checks are implemented; five are phase-specific, so eighteen is the number that applies to every deliverable rather than a headline no single document ever meets. After the gate, Stéphane Raby (CMC) personally reads every deliverable end-to-end and signs it before release. Nothing ships on automation alone — the human-in-the-loop final review is non-negotiable, because as the signing CMC, Stéphane is professionally accountable for every deliverable that leaves the firm.
Minimal. 1–2 hours for onboarding, plus 30-minute review calls after each phase.
Yes. Phase 01 Market Intelligence is the most common standalone — it provides the evidence foundation for all other decisions.
After the initial engagement, CI keeps your strategy current with monthly competitive briefs and quarterly full refreshes. CA$3,000–CA$5,000/month.
All engagements covered by mutual NDA signed before onboarding. Deliverables marked CONFIDENTIAL. Client data, strategies, and business information are never shared across engagements, used in marketing, or retained after engagement close without explicit written permission.
Branded PDF (primary), executive brief (2–4 page summary), and presentation deck (PPTX with speaker notes).
Absolutely. We integrate your internal materials as inputs. Existing research is validated and incorporated.
Stéphane Raby: CMC + CISSP + MBA from Telfer, ranked #1 globally by CEO Magazine in 2023, + P.Eng. 25+ years in tech strategy and cybersecurity.
We offer milestone-based billing and Net 15/30 terms. Annual CI retainers receive a 2-month prepayment discount.
Upon full payment, you own all deliverables. 30-day post-engagement check-in included. CI available for ongoing monitoring.
Book a 30-minute Strategy Diagnostic at sagentix.ca/contact. No commitment required.
Our library holds 134 curated industry profiles. If yours is not among them, we build the profile from primary public datasets — Statistics Canada and ISED's Canadian Industry Statistics for Canada, the U.S. Census Bureau Economic Census and the Bureau of Labor Statistics for the United States — indexed by NAICS code, so a vertical outside the library is a research task rather than a blocker. Coverage is deepest in B2B technology, professional services, manufacturing, and adjacent sectors. Either way, the Phase 1 proof of concept tells us within 5–7 days whether the methodology fits your market — and if it does not, you receive a full refund and keep the deliverable.
Yes. We sign mutual NDAs as a standard part of every Strategy Diagnostic. The NDA covers both your confidential information and our methodology IP. Email stephane@sagentix.ca and the NDA arrives within one business day.
Our four pricing tiers each carry an explicit scope. If your needs expand mid-engagement, we propose a tier upgrade or a follow-on engagement; we do not run silent scope creep. The Phase 1 PoC fee is credited toward any larger package within 30 days.
No. Every Sagentix engagement is delivered under the Sagentix brand by Stéphane Raby (CMC + CISSP + P.Eng. + MBA) directly. We do not sub-contract delivery, and we do not white-label our methodology to other firms.
The Phase 1 PoC carries a 14-day money-back guarantee. If the Phase 1 Market Intelligence reveals nothing you did not already know, you receive a full refund within 14 days and you keep the deliverable. This guarantee is unique among the boutique consulting firms we benchmark against.
Eight service lines: security assessment and authorization to an authority-to-operate decision at Protected B; right-sizing an overloaded SA&A process; CCCS Cloud Medium readiness for cloud and SaaS providers; AI governance programmes; post-quantum cryptography migration; enterprise and departmental security governance; enterprise architecture assessment across the six GC EA domains; and Canadian compliance programme mapping. Plus embedded senior advisory placed inside a federal programme through a prime.
No. We author the evidence and the recommendation package; the authorization is signed by the accountable departmental official, and any certification decision belongs to an independent assessor. Sagentix holds no certification-body accreditation and no assessor accreditation, and none is in progress. That separation is the reason the work carries weight.
Not by itself. A United States authorization does not extend to Canadian data or Canadian data centres — CCCS Cloud Medium is a separate, Canadian-run programme. What does transfer is the control design, because both profiles descend from NIST SP 800-53, and often the existing test evidence. What is tested freshly is the Canadian overlay: data residency, key management, personnel screening and supply chain. Sizing that delta is the first piece of work.
The CCCS roadmap (ITSM.40.001) sets departmental migration plans from April 2026, high-priority systems migrated by the end of 2031, and remaining systems by the end of 2035. The "2030" figure often quoted is NIST IR 8547 — NIST's own algorithm-deprecation timeline, a separate instrument. Confusing the two understates your runway by a year.
No. The practice is governance, architecture and oversight advisory: the advisor directs and assures, while your staff or specialist suppliers execute. For testing, security operations, hands-on remediation, accredited assessment, or legal and export-controls opinions, we will point you to a firm that does it well.
Yes. Stéphane Raby is natively bilingual and delivered the Canadian Centre for Cyber Security curriculum in both official languages across thirty-two months. Deliverables are produced in either language, or in your department's own templates.
Three structural reasons rather than a claim about quality. A Government of Canada Secret clearance is already held, so no screening cycle consumes the front of the mandate. The federal authorization machinery is being worked on live files this quarter rather than recalled. And the CMC designation binds the practitioner to an ethics board and an enforceable code on objectivity, confidentiality and conflict of interest — with no certification arm anywhere in the firm that could end up assuring its own advice.
No. The Canadian federal work is where the deepest proof sits, but the method is not Canada-specific: an ISO/IEC 27001 certification, a SOC 2 examination, a GDPR programme and a Caribbean data-protection Act are all gates where someone independent judges evidence we author. We work across Canada, the Caribbean, the United States and Europe, in English and French.
They consume substantially the same evidence. The Canadian Centre for Cyber Security assessment process reuses internationally recognized attestations rather than re-testing everything, and a Protected B submission expects a SOC 2 Type II report, ISO/IEC 27001 and ISO/IEC 27017, with 27018 for the privacy dimension. Practically: one harmonized control baseline can serve several gates, and each additional certificate becomes a delta rather than a new programme.
No. An ISO certification is granted by an accredited certification body, and a SOC 2 examination may only be performed by a licensed CPA firm. We are neither, hold no accreditation, and have none in progress. We author the management system and the evidence, then you appoint the body or firm that judges it.
No. Sagentix is not a law firm, holds no legal practising certificate, and gives no legal advice or opinions. The division is straightforward: a CISSP builds the control baseline, data inventory, breach-response methodology and the evidence a regulator would be shown; a lawyer decides whether a statute applies to you, the lawful basis, the contracts, and any opinion on liability. We work alongside your counsel and say so when a question crosses that line.
No, and treating it as one is the most expensive mistake available in that market. Jamaica's Act has been in force since December 2023 with a Commissioner and 72-hour breach reporting; Barbados since January 2022; the Cayman Islands under its 2021 Revision. The Bahamas has an in-force Act with very little enforcement, and Trinidad and Tobago's 2011 Act — one of the earliest and still listed everywhere — is not fully in force and has no regulator. Sequencing follows the operative regime, not the statute's existence.
Sagentix Advisors Inc. was accepted as a Service Member by the Board of the Caribbean Association of Banks in 2026. That is a standing, not an endorsement — service membership carries no vote, and nothing about it represents a CAB view of our services.
CPCSC is the Canadian Program for Cyber Security Certification — PSPC-led, with National Defence, the Cyber Centre and the Standards Council of Canada. Its control standard is ITSP.10.171, the Canadian adaptation of the NIST SP 800-171 family; ITSP.10.171 is the standard, CPCSC is the programme that certifies against it. Level 1 is a self-assessment of thirteen controls, attested annually in your CanadaBuys supplier profile and required at contract award rather than at bid. Whether you need it is conditional and risk-assessed per contract — it is not a blanket requirement for doing defence business with Canada, and anyone telling you otherwise is overselling.
There is no published date, and we will not give you one. PSPC states that Levels 2 and 3 are currently under development. The "spring 2027" figure in circulation traces to vendor commentary rather than to any Government of Canada page, and planning spend against it would be planning against something nobody has committed to. Treat Level 2 as a capability to build toward, not a deadline.
Partly. The third-party assessment gate — Level 2 via an accredited assessor, and Level 3 — has been suspended since July 2026 pending a reform review, so only self-assessment tiers may be required at present. What did not pause is the obligation: the DFARS clause and all 110 NIST SP 800-171 requirements still apply, self-attested, with False Claims Act exposure behind that attestation. Two details matter commercially: it is Revision 2 that is in force, not Revision 3, whose rule is unpublished; and a score posted in SPRS is a Basic Assessment score, not a certification. Describing it as a certification is where the real risk sits.
For Level 1, potentially — PSPC recognises a valid CMMC certification in place of the Level 1 self-assessment, case by case, because both countries build on the same technical controls. Two cautions. A self-assessment with an SPRS score is not a certification. And with the US third-party path suspended, a firm that does not already hold a certification cannot currently obtain one, so for most Canadian suppliers the Canadian self-assessment is the only open route.
Not on storage alone, under current guidance. The rule moved: providers that typically do not examine, possess or control customer content are treated differently from those whose services require them to examine or possess controlled data — and it is examination that triggers registration. The older bright-line language about storage is still widely quoted but describes a revised rule. Residency also matters: controlled goods data should sit on servers in Canada, and Global Affairs Canada must be consulted where it does not. Before any written compliance representation here, confirm the actual data flow and have Canadian export-controls counsel sign it off.
No, and they are run by different parts of government answering different questions — one is about who may access defence-controlled goods and their technical data, the other about how cyber-mature your own systems are. But they can reach the same information: the Specified Information that CPCSC protects may expressly include controlled goods information. Sequenced as one decision, much of the underlying work is shared. Run as two separate projects, it is paid for twice.
Yes — in English or French, for professional associations, accelerators and incubators, and universities. Training is a delivery format for the same two practices rather than a separate business: cybersecurity and AI governance, go-to-market, and the federal market-entry work between them. Association sessions run two to two-and-a-half hours; accelerator sessions are ninety-minute working sessions where founders use their own company as the case.
No. That role ran from April 2023 to November 2025 and has ended. Sagentix is an independent firm with no affiliation to the Canadian Centre for Cyber Security or the Communications Security Establishment, delivers none of their courses, and speaks for neither. It is listed as a teaching record — roughly 2,000 federal public-service learners across four bilingual courses — not as a current role or an endorsement.
Method, never the client. Sessions are built from the shape of live work — how a governance stack is layered, how a control baseline is tailored, how an engagement is scoped — with the client, their data and their findings left out. The same boundary covers any prior employer: no course material, no assessment content, no third party’s intellectual property.
Through a federal supply arrangement via a prime, for software-as-a-service workloads up to Protected B — called up by a sole-source justification, a simplified bid solicitation against holders of the arrangement, or bundled alongside a software purchase made through the same vehicle. Sizing starts with a short fixed-price pre-qualification that settles categorization, control profile and complexity. Ask and we will tell you which vehicle applies and who holds it.
Still have questions?
Book a free 30-minute Strategy Diagnostic. No commitment required.