Framework · TGV
TGV: four domains, one BCH certification dossier
The BCH/MSSS Trousse globale de vérification for technological products and services in Québec's health and social services network: four evaluation domains.
The Trousse globale de vérification (TGV) is the certification framework administered by the Bureau de certification et d'homologation (BCH) of Québec's Ministère de la Santé et des Services sociaux (MSSS). It attests the conformity of technological products and services (PST) used in the province's health and social services network across four domains: security, personal information protection (PRP), performance, and technology.
Key facts
- BCH: the Bureau de certification et d'homologation administers TGV on behalf of the MSSS.
- 4 domains: security, personal information protection, performance, and technology, assessed for every PST.
- PST: technological products and services deployed in the health and social services network.
- Attestation: BCH-issued conformity attestation for procurement and contract compliance, to be maintained between cycles.
What TGV covers
TGV certifies that a technological product or service deployed in Québec's health and social services network meets the province's requirements across four evaluation domains.
- Security: cybersecurity, access management, incidents and continuity
- Personal information protection (PRP): collection, retention, disclosure and confidentiality incident notification
- Performance: availability, response time and service level conformity
- Technology: architecture standards, interoperability and lifecycle management
- Certification attestation: BCH-issued conformity attestation for procurement and contract compliance
- Renewal: continuous posture tracking to prevent lapses between certification cycles
What Sentrix provides for TGV
Pre-built TGV controls
All four TGV evaluation domains are pre-built into Sentrix. BCH framework updates are reflected automatically.
BCH certification dossier
Sentrix generates the evidence packages and attestation documentation required by the BCH for TGV certification submissions and renewal cycles.
Bilingual documentation
All TGV policies, evidence reports and certification packages are available in French and English.
Renewal tracking
Sentrix collects evidence continuously, so your BCH certification dossier is always current and renewal does not start from scratch.
Crosswalks
- Law 25: TGV's PRP domain and Law 25 share the same personal information protection requirements; evidence is mapped once.
- ISO 27001: TGV's security domain overlaps significantly with ISO 27001; organizations already pursuing ISO certification reduce TGV-specific remediation.
- CPCSC: for suppliers who also supply the defence sector.
Further reading
The Sentrix TGV guide describes the performance criteria PF01 to PF07 (minimum specifications, latency tolerance, bandwidth, link traffic share, expected response times, packet handling, retention and recovery delays), each with how to implement and verify it; the TGV support service covers dossier preparation. Public institution or para-public body: public sector solution; healthcare solution supplier: healthcare solution.
Get your TGV certification dossier ready.
Frequently asked questions
- What is TGV and who administers it?
- The Trousse globale de vérification (TGV) is the certification framework administered by the Bureau de certification et d'homologation (BCH) of Québec's Ministère de la Santé et des Services sociaux (MSSS). It attests the conformity of technological products and services (PST) used in Québec's health and social services network across four evaluation domains: security, personal information protection, performance, and technology.
- Who does TGV apply to?
- Suppliers whose technological product or service is deployed in Québec's health and social services network. The conformity attestation issued by the BCH serves procurement and contract compliance, and it must be maintained from one certification cycle to the next, which requires continuous posture tracking rather than a dossier rebuilt at every renewal.
- How does TGV relate to Law 25?
- TGV's personal information protection (PRP) domain and Law 25 share the same requirements: collection, retention, disclosure and notification of confidentiality incidents. Sentrix maps evidence once and satisfies both frameworks simultaneously; TGV's security domain, for its part, overlaps significantly with ISO 27001.
Related pages
Framework · Law 25
Law 25: PIAs, incidents, access and portability, documented
Québec's private-sector privacy law, in full force since September 2023: privacy impact assessments, confidentiality incidents, access rights and portability.
Framework · ISO 27001:2022
ISO 27001:2022: from ISMS to certification in one program
The international standard for information security management systems: clauses 4 to 10, 93 Annex A controls, and a two-stage certification audit.
Framework · CPCSC
CPCSC: self-assessment, third party, National Defence
Canadian Program for Cyber Security Certification for defence suppliers: Levels 1, 2 and 3, ITSP.10.171 controls, accredited assessment and a crosswalk to CMMC.
Let's talk about your compliance program.
Last updated: 2026-09-17
