Services · Compliance
TGV certification support
Your gateway to Quebec's health and social services network: Sentrix structures your TGV certification journey so your file reaches the BCH solid and ready.
Why this matters
TGV isn't optional if you sell into Quebec's health network. A selected product still can't go live without the attestation, and once you're certified, the clock keeps running on correction deadlines and annual commitments.
Deployment stays blocked
A Quebec health institution can select your product, but cannot deploy it until TGV certification is obtained.
Corrections run on a clock
Non-conformities must be corrected within timeframes set by the BCH, as short as three business days for a critical vulnerability mitigation plan.
Existing compliance isn't enough
Law 25 or GDPR compliance helps, but TGV is a sector-specific framework unique to the health network with its own requirements.
AI adds scrutiny
AI tools (scribes, transcription, generative AI) intended for the health and social services sector face enhanced, evolving requirements.
What sets this apart
We implement the controls, and stay with you through verification. Most support stops at documentation. We go further: we work with your product and IT teams to put the missing technical controls in place, then stay actively involved once the external firm starts its practical verification, translating requests into concrete fixes as they come.
- Security controls: multi-factor authentication, encryption, logging, tested backups.
- Personal information protection practices mapped to MSSS requirements.
- Documentation linked criterion-by-criterion to its supporting evidence.
- Active support during the external firm's practical verification.
Sample gap findings
Illustrative examples; they do not describe a specific client.
- High: multi-factor authentication is not enforced on privileged accounts handling personal health information. Action: implement MFA and role-based access management before the verification firm's technical audit.
- High: data at rest is stored without encryption at the application's database layer. Action: deploy encryption at rest and in transit, and document the configuration for the BCH file.
- Medium: logging is enabled but not centralized, leaving traceability gaps a live audit would surface. Action: centralize logging and retention so every criterion has a clear evidence trail.
- Low: backup jobs run nightly, but restoration has never been tested end to end. Action: schedule and document a full restore test ahead of the practical verification.
What is TGV certification?
TGV certification is an attestation that a specific version of a technology product or service (PST) complies with the requirements of Quebec's health and social services sector. It is administered by the Certification and Homologation Bureau (Bureau de certification et d'homologation, BCH) of the Ministry of Health and Social Services (MSSS), working with partners and subcontractors specialized in cybersecurity and personal information protection.
It evaluates your solution across four domains: security, personal information protection (PIP), performance and technology. Since January 2022, a penetration test has been mandatory, in accordance with the requirements of the Secrétariat du Conseil du trésor.
In practical terms: if your organization designs, operates or sells a technology product or service used in a Quebec healthcare context, TGV certification is required to sell, renew or maintain your contracts with the network.
According to the BCH criteria package, the four domains break down as follows:
- Security: service delivery, data use and access, backup and recovery procedures, logging and traceability (about 200 criteria).
- Personal Information Protection (PIP): legislation and regulation, personal information protection, sharing of health information (about 100 criteria).
- Performance: accounting for remote regions and varied usage contexts (about 30 criteria). The performance controls guide details how to implement and verify each of them.
- Technology: architecture directions, including interoperability with other network systems (about 20 criteria).
A mandatory penetration test is added to this, performed within the three months preceding the start of verifications or before their completion, with requirements that vary depending on the nature of the application. The TGV framework page summarizes the framework.
Who this support is for
Health technology suppliers
You design, operate or sell a technology product or service (PST) intended for the health network. Whether you need a first certification, a renewal, or to expand the scope of an already-certified product, the BCH process requires rigorous preparation and a solid understanding of the criteria being evaluated. We structure your process and clarify what is expected at each step.
Network institutions and organizations
You need to ensure that the technology products and services you use or plan to deploy meet TGV requirements. Your suppliers may need help preparing for it or maintaining their compliance over time. We work with PST suppliers referred by their network clients; feel free to point us to a supplier who needs support.
Is this the right time for you?
If you recognize your situation in any of the following, this support is designed for you.
- A Quebec health institution (CIUSSS, CISSS, family medicine group, Santé Québec) has selected your product, but cannot deploy it until TGV certification is obtained.
- You have reviewed the criteria package and realize the gap between your current practices and MSSS requirements calls for a structured approach, not just a line-by-line read.
- You are already compliant with Law 25 or GDPR, and want to know exactly what TGV adds (the answer: a lot, since it is a sector-specific framework unique to the health network).
- Your product received non-conformities in a verification report and you need to correct them within the allotted timeframe without jeopardizing the contract.
- You are an international or out-of-province supplier, your product is already used elsewhere, and you are discovering that Quebec's health market requires a specific certification that is not recognized as equivalent.
- You publish an AI tool (AI scribe, transcription, generative AI) intended for the health and social services sector, where TGV has become a prerequisite.
- You need a penetration test compliant with MSSS guidance, coordinated with the right providers and delivered with the evidence required by the Certification Bureau.
- You are already certified and preparing your annual self-declaration renewal, wanting to make sure nothing has drifted.
What you get
Full gap analysis
A mapping of your current product against TGV criteria, prioritized by domain (security, PIP, performance, technology) and by level of effort required.
Realistic estimate before commitment
An assessment of the timeline, total cost (our fees, the verification firm's fees and any technical investments) and the load on your internal teams, before you commit. Sentrix provides this estimate after the gap analysis.
Documentation and supporting evidence
The policies, procedures and documentary evidence expected, written or adapted to your reality and to the level of detail required by the BCH, not a stack of generic templates.
Penetration test coordination
Scoping, provider selection if needed, then delivery of results and mitigation measures to the Certification Bureau within the required timeframe.
Implementation of missing controls
Working with your product and IT teams to put in place required technical controls: multi-factor authentication, encryption, logging, access management, tested backups, incident management.
Filing-ready file and support during verification
A file structured to BCH expectations, with a clear link between each criterion and its evidence, then active support during verification by the external firm: responding to requests, managing non-conformities, preparing your teams.
The TGV journey, step by step
Certification follows a process structured by the Certification Bureau. We support you at every one of these steps.
- Scoping and application preparation. We validate together the scope of the targeted product, its version, the target institutions and its exchanges with network systems. We help you prepare the certification application form, gather security and technology architecture documents, as well as the inventory of personal information processed and the mapping of its flows.
- Gap analysis and implementation. We map your product against TGV criteria, identify what is already in place, what needs adjusting and what requires real work. We write the expected documentation and implement missing technical controls with your teams.
- Filing the application with the BCH. We support you in signing and sending the required forms (certification application, confidentiality agreement, applicable attestations) and prepare you for the information meeting with the BCH team.
- Penetration test. We coordinate the penetration test in accordance with MSSS guidance: scoping, provider selection if needed, and delivery of results and mitigation measures to the Certification Bureau.
- Verification by the external firm. Verification includes a theoretical (documentary) evaluation followed by a practical verification (live audit of the solution). We stay involved throughout: translating the firm's requests into concrete actions, preparing for exchanges, quickly managing requested adjustments to keep the file moving. According to the BCH process, this phase takes about 30 business days; the preparation beforehand is the most variable part.
- Decision and ongoing maintenance. The BCH renders its decision and, if certified, a contract is signed. We remain available to support you in meeting follow-up commitments: change log, major change declarations, annual penetration test, self-declaration and IT recovery exercise.
Certification doesn't stop at the attestation
TGV certification is valid for three years, but is renewable annually and conditional on meeting ongoing commitments. Failing to meet these obligations can lead to a specific verification, a review, or even withdrawal of certification. According to the follow-up commitments set out in the BCH process, the certified supplier must:
- maintain a log of any change occurring after the certification is issued;
- submit to the BCH, at least twenty business days in advance, any major change requiring or not a new version;
- carry out at least one penetration test annually with a firm recognized by the BCH and complete the self-declaration;
- correct detected vulnerabilities within prescribed timeframes (mitigation measures within a maximum of fifteen business days; mitigation plan for a critical vulnerability within three business days);
- inform the BCH of any major issue as soon as it is identified and present a correction plan within three business days;
- carry out an IT recovery exercise every two years;
- submit the self-declaration at least twenty business days before the attestation's anniversary date.
We help you stay compliant over time; Security Governance and Reporting can carry this cadence after certification.
Why trust Sentrix with your TGV journey
Security and personal information protection expertise
A team specialized in cybersecurity and PIP, up to date on the requirements specific to Quebec's health and social services sector.
A scalable approach
An approach adjusted to the nature of your PST, your current maturity level and your operational constraints.
Skills transfer
Hands-on, educational support: your team builds capability during the project, which serves you well beyond certification.
Current with the Certification Bureau
Ongoing monitoring of MSSS guidance and requirements so your file reflects the current state of expectations.
We prepare; we do not certify. Certification is issued exclusively by the Certification and Homologation Bureau (BCH), following independent verification by an external firm.
Where TGV fits
TGV, ISO 27001 and Law 25: what are the differences? Existing compliance is an asset, not a shortcut: TGV covers health-network specific requirements that these frameworks don't.
| Aspect | TGV | ISO 27001 | Law 25 |
|---|---|---|---|
| Scope | Quebec health network | Any organization, any sector | Organizations handling personal information in Quebec |
| Authority | Certification and Homologation Bureau (BCH), MSSS | Accredited certification body | Commission d'accès à l'information (CAI) |
| Main role | Mandatory certification to sell to the health network | Information security management system | Protection of personal information |
| Validity | 3 years, renewable annually | 3 years, annual surveillance audits | Ongoing, no formal certification |
The ISO 27001 service and data protection cover the technical controls TGV shares with these frameworks.
Let's talk about your TGV journey.
Whether you're weighing your options, already underway, or just want to check your readiness, a first conversation costs nothing and helps scope what applies to your solution.
Frequently asked questions
- Is this mandatory to sell to Quebec's health network?
- In practice, yes: a network institution generally cannot deploy a technology product or service until TGV certification is obtained, even after selecting your product. If your solution does not exchange any data with network systems, TGV may not apply; we check this together from the first call.
- We are already compliant with Law 25, GDPR or ISO 27001. Is that enough?
- No. TGV is a sector-specific framework unique to the health network, with specific requirements (security, personal information protection, performance, technology) that these frameworks do not cover. Your existing compliance is an asset and reduces certain gaps, but it does not replace certification, and it is not recognized as equivalent.
- How long is the certification valid?
- Certification is valid for three years, renewable annually, provided the follow-up commitments set out in the BCH process are met: annual self-declaration, annual penetration test, change log, major change declarations and an IT recovery exercise. Failing to meet these obligations can lead to a specific verification, a review, or even withdrawal of the certification.
- What documents should we prepare for TGV certification?
- Depending on scope: the application form and confidentiality agreement, the security and technology architecture documents, the inventory of personal information processed and the mapping of its flows, the security and personal information protection policies, technical evidence, the change log, then the penetration test results and mitigation plans.
- What happens if our product receives non-conformities?
- We help you correct the gaps within the allotted timeframe, translating the verification firm's requests into concrete actions for your product and IT teams. If certification is not granted, a new application is possible after a minimum delay set by the BCH, once the corrections have been made.
Related pages
Services · Compliance
ISO/IEC 27001 certification support
From gap analysis to the certification body's audits, Sentrix structures your ISO 27001 journey and keeps the verification independent of the preparation.
Services · Compliance
CAN/DGSI 104 certification support (CyberSecure Canada)
The Canadian standard built for SMEs (CyberSecure Canada): choosing Level 1 or 2, closing the gaps and preparing for the audit. We prepare; we do not certify.
Services · Compliance
CPCSC certification support (Levels 1, 2 and 3)
CPCSC is becoming a contractual requirement for defence suppliers. Sentrix structures your process at Levels 1, 2 and 3, from gap analysis to evidence.
Services · Implementation
Data protection: we test the restore, not the backup job
Classification, DLP, encryption and backups deployed, then validated end to end: a restore test actually performed and timed instead of a green checkmark.
Services · Managed services
Security governance and reporting
Prove improvement over time: KPIs and KRIs reported on a fixed cadence, a current risk register and audit evidence always ready, not assembled the week before.
Let's talk about your compliance program.
Last updated: 2026-09-17
