Skip to main content

Sagentix Cyber & AI

One control baseline.
Several audits.

Most organizations build a separate programme for every certificate a customer asks for. They do not have to. The frameworks overlap heavily by design, and the expensive part — the evidence — can be collected once.

We author the management system and the evidence behind an ISO/IEC 27001 certification, its 27017 and 27018 extensions, and a SOC 2 examination. We do not audit them, and that separation is the point.

Whichever gate you are facing, someone else judges it

That is true in every jurisdiction we work in, and it does not change with the framework. We prepare; an independent party decides.

The gateWho judges itWhat we do
CCCS Cloud Medium at Protected BThe Cyber Centre, and the department that grants the authority to operateReadiness and authoring
ISO/IEC 27001, 27017 and 27018An accredited certification bodyReadiness and authoring
SOC 2, Type I or Type IIA licensed CPA firm — no one else may perform the examinationReadiness and authoring
GDPR, US state law, a Caribbean data-protection ActThe supervisory authority or regulatorReadiness and authoring

What each one actually is

Three of these are certifications against a management system. The fourth is an examination report, and confusing the two is the most common mistake in a first conversation.

ISO/IEC 27001:2022

The management system

Certification is granted against the management system, not against a control list. Scope definition, risk assessment and treatment, the statement of applicability, internal audit and management review are what an auditor actually tests — and they are where unprepared organizations fail.

The 2022 revision carries 93 Annex A controls across four themes: organizational, people, physical and technological.

ISO/IEC 27017

The cloud extension

Cloud-specific guidance layered on the same management system — the shared-responsibility split, virtual environment separation, administrative access, and what a customer can and cannot inherit from a provider.

Extends the baseline rather than replacing it; assessed alongside 27001.

ISO/IEC 27018

The personal-data extension

Controls for a provider processing personal information in a public cloud on behalf of a customer — consent and choice, purpose limitation, disclosure to third parties, and returning or deleting data at the end of a contract.

This is the standard that connects the security programme to the privacy obligations on the companion page.

SOC 2

The attestation

Not a certification but an examination report, written against the Trust Services Criteria: Security as the common criteria, plus Availability, Processing Integrity, Confidentiality and Privacy where they are in scope. Type I reports design at a point in time; Type II tests operating effectiveness over a period.

Only a licensed CPA firm may perform it — which is precisely why an advisor who prepares you for it cannot also be the one who signs it.

Why the second certificate costs far less than the first

These frameworks were not built in isolation from each other, and the assessment regimes that consume them know it.

The Canadian Centre for Cyber Security’s own cloud assessment process says so directly: rather than re-testing everything, it reuses the internationally recognized attestations a provider already holds — naming SOC 2 Type II and the ISO/IEC standards among them. A Protected B submission expects a SOC 2 Type II report, ISO/IEC 27001 and ISO/IEC 27017, with 27018 expected for the privacy dimension.

The practical consequence is the whole argument of this page. A Caribbean bank building an information security management system, a United States software vendor preparing a SOC 2, and a cloud provider heading for a Canadian Protected B authorization are building substantially the same evidence base. Treated as one programme, each additional gate is a delta. Treated as separate projects, each one is paid for again.

What gets built once

  • A single risk assessment and control baseline, scoped once
  • One statement of applicability that maps to several frameworks
  • Evidence collected once and presented in the form each audit expects
  • A control-delta map showing exactly what each additional gate adds
  • An internal audit and management review cycle that satisfies the management system and feeds the examination

What it does not remove: each body still audits independently, and each gate keeps its own scope, its own criteria and its own decision.

What the engagement covers

Readiness and authoring, through to the door of the audit — and not one step past it.

Scoping and gap assessment

Which standards actually apply to what you sell and to whom, where the boundary of the system sits, and an honest read of the distance between where you are and what an auditor will ask for.

The harmonized control baseline

One control set designed to serve every gate you face rather than a separate programme per certificate — the single largest cost reduction available in this work.

Authoring the management system

Policies, procedures, the risk methodology, the statement of applicability, the asset and supplier registers, and the records an auditor samples — written to be used, not to be shelved.

Internal audit and management review

Standing up the cycle the standard requires, and running it once with you so the first external audit is not the first time anyone has done it.

Audit preparation and liaison

Readiness review against the criteria, evidence packs organized the way an assessor works, interview preparation for the people who will be asked, and coordination with the body or firm you appoint.

Carrying it across borders

Where the same baseline also has to satisfy a Canadian Protected B assessment or a Caribbean data-protection regulator, mapping that once rather than rebuilding it per jurisdiction.

Where you will want someone else

  • Perform the certification audit
  • Issue a certificate or an attestation report
  • Act as an accredited certification body
  • Act as the CPA firm that examines your controls
  • Provide legal or audit and attest opinions

We hold no certification-body accreditation and no assessor accreditation, and none is in progress. An adviser who prepares you for an audit cannot also be the party that signs it off — that is not a limitation, it is what makes the preparation worth paying for.

Which certificate is your customer asking for?

Thirty minutes. We establish which standards actually apply to what you sell, what your existing evidence is worth against them, and whether one baseline can carry all of it — including any Canadian or data-protection gate sitting behind the same customer.

Sources

  • Canadian Centre for Cyber Security — Cloud service provider information technology security assessment process (ITSM.50.100). cyber.gc.ca. Source of the attestation-reuse position and the reports named.
  • International Organization for Standardization — ISO/IEC 27001:2022, ISO/IEC 27017 and ISO/IEC 27018. iso.org.
  • American Institute of Certified Public Accountants — Trust Services Criteria (TSP Section 100). aicpa-cima.com.

Standards are revised. Confirm the current edition and the criteria in force with your certification body or examining firm before relying on any summary, including this one.