Resources
Guides and articles to prepare your certifications
Three in-depth articles and three working guides: ISO 27001:2022 clauses, TGV controls, CPCSC levels. Written for security and compliance leads who decide.
Guides and articles to prepare your certifications.
Practical guides and articles written for security and compliance leads who need to make decisions: what each framework requires, what the auditor will ask for, and where to start.
Articles
ISO 27001:2022 clauses: the requirements that lead to certification
Published July 15, 2026. It is clauses 4 through 10, not Annex A, that determine whether you get certified. Each of the seven certifiable clauses in plain language, with the mandatory documents the auditor will ask for.
CPCSC explained for Canadian defence suppliers
Published July 15, 2026. Level 1 of the Canadian Program for Cyber Security Certification has been available since April 1, 2026. What Levels 1, 2 and 3 require, who is in scope, and how to prepare.
Law 25: the five gaps that persist
Published March 24, 2026. A register that stops being maintained, PIAs triggered too late, notification playbooks never rehearsed, consent without a purpose, a PIPEDA crosswalk that lives in one person's head: a starting checklist for reviewing your program.
Guides
ISO 27001:2022 clause guide
The 41 clauses and sub-clauses of the standard, from clause 4 (context of the organization) to clause 10 (improvement), each with what it requires, the evidence the auditor will ask for and the common pitfalls.
TGV control guide
The controls of the Trousse globale de vérification for Quebec's health and social services network, each with how to implement it and how to verify it. The Performance group (PF01 to PF07) is published.
CPCSC guide
The self-assessment, the 13 Level 1 controls, the 98 Level 2 controls and the comparison between CPCSC and the US CMMC for suppliers active in both markets.
Take action
Each framework described here matches a support service: ISO 27001 compliance, TGV compliance, CPCSC certification and managed governance for personal information protection programs.
Resources · Article
ISO 27001:2022 clauses that lead to certification
It is clauses 4 through 10, not Annex A, that determine whether you get ISO 27001 certified. The seven certifiable clauses in plain language, for the audit.
Learn more →
Resources · Article
CPCSC explained for Canadian defence suppliers
Level 1 of the Canadian Program for Cyber Security Certification has been available since April 1, 2026. What Levels 1, 2 and 3 require, and where to start.
Learn more →
Resources · Article
Law 25: the five gaps that persist
Most Law 25 obligations have been in force since September 2023. Five gaps still come up in personal information protection programs; here is how to close them.
Learn more →
Frequently asked questions
- What do these resources contain?
- Three in-depth articles on the clauses of ISO 27001:2022, the Canadian Program for Cyber Security Certification (CPCSC) and the gaps that persist in Law 25 programs, plus three working guides: the 41 clauses of ISO 27001 one by one, the performance controls of the Trousse globale de vérification (TGV), and the CPCSC self-assessment, Level 1, Level 2 and CPCSC-versus-CMMC pages.
- What is the difference between an article and a guide?
- An article is dated, signed and cites its sources; it explains a framework or a practice at a given point in time. A guide is a standing reference, organized by clause or by control, with the evidence the auditor will ask for and the common pitfalls; it is updated as the framework evolves, without a publication date.
- Are these contents tied to Sentrix services?
- Each article and guide links to the matching service when one exists: ISO 27001 support, TGV compliance, CPCSC certification, managed governance. The contents stand on their own and do not assume use of the platform; they describe what the framework requires, not what a tool does.
Let's talk about your compliance program.
Last updated: 2026-09-17
