Solutions · Public sector
Law 25. CPCSC. TGV. And every standard they map to.
Law 25, CPCSC and TGV supported natively, with compliance data hosted in Canada, bilingual documentation, and crosswalks that understand provincial legislation.
Canadian framework coverage
Law 25. CPCSC. TGV. And every standard they map to.
Sentrix ships pre-built crosswalks between Canadian frameworks and the international standards public sector organizations typically run in parallel. Meet your provincial privacy obligations, federal cyber requirements, and ISO 27001 certification from a single evidence set.
- Law 25 (Québec): all obligations including PIA, breach notification, and data minimization
- CPCSC: the Canadian Program for Cyber Security Certification for defence contractors and federal suppliers
- TGV (Québec): the certification framework of the health and social services network, administered by the MSSS's Bureau de certification et d'homologation
- PIPEDA and the federal privacy reform: federal private sector privacy requirements
- NIST CSF and SP 800-53: federal security frameworks cross-mapped to Canadian standards
- ISO 27001: international certification crosswalked to Law 25 and TGV
Law 25, CPCSC and TGV are built in, not bolted on, with pre-built crosswalks to NIST, ISO 27001 and SOC 2. The platform is fully bilingual: policies, evidence and audit packages are available in French and English.
Built for the compliance realities of Canadian public organizations.
Law 25 compliance program
Complete Law 25 compliance program including PIA templates, consent management tracking, breach notification workflows, and data minimization documentation aligned to CAI guidance.
CPCSC certification path
Step-by-step CPCSC Level 1 and Level 2 readiness programs for defence and federal supply chain organizations. Pre-built controls, evidence collection, and audit-ready documentation.
TGV alignment
TGV requirements pre-mapped to your technical controls. Automated evidence collection from your cloud providers and on-premise systems.
Data residency
Compliance data is hosted in Canada. Data sovereignty documentation for provincial and federal procurement requirements.
Bilingual documentation
All policies, evidence narratives, audit packages, and risk reports available in French and English. Required for Québec public sector organizations and federal bilingual requirements.
Procurement-ready security posture
Security attestation packages formatted for federal and provincial procurement processes. SOC 2, ISO 27001, and CPCSC evidence bundled for RFP security questionnaire responses.
See how Sentrix handles your Canadian compliance requirements.
We prep a session tailored to your specific provincial and federal framework obligations.
Frequently asked questions
- Which Canadian frameworks does Sentrix support for public sector organizations?
- Law 25 (Québec), with all obligations including privacy impact assessments, breach notification and data minimization; CPCSC, the Canadian Program for Cyber Security Certification for defence contractors and federal suppliers; TGV, the certification framework of Québec's health and social services network; PIPEDA; and the CAN/DGSI 104 baseline used by smaller public-sector suppliers. NIST CSF, NIST SP 800-53 and ISO 27001 are cross-mapped to them.
- What does the Law 25 compliance program include?
- A complete Law 25 program: privacy impact assessment templates, consent management tracking, breach notification workflows, and data minimization documentation aligned to the guidance of the Commission d'accès à l'information. Each obligation is mapped to the technical controls that satisfy it, so evidence collected for ISO 27001 or SOC 2 also documents your Law 25 posture.
- How does Sentrix support a CPCSC certification path?
- Step-by-step CPCSC Level 1 and Level 2 readiness programs for defence and federal supply chain organizations, with pre-built controls, evidence collection and audit-ready documentation. The CPCSC controls are crosswalked to NIST SP 800-53, NIST CSF and ISO 27001, so suppliers already certified against an international standard see which requirements they already meet.
- Is the platform bilingual?
- Yes. All policies, evidence narratives, audit packages and risk reports are available in French and English, which Québec public sector organizations and federal bilingual requirements demand. Security attestation packages bundle SOC 2, ISO 27001 and CPCSC evidence for federal and provincial procurement processes and RFP security questionnaire responses.
Related pages
Solutions · Healthcare
HIPAA continuous. SOC 2 always ready. PHI protected.
Continuous HIPAA monitoring, automatic evidence collection for BAA requirements and SOC 2 readiness for health-adjacent companies, without a separate tool.
Solutions · Financial services
Your regulators just multiplied. Your GRC stack should not.
DORA, NIS2, OSFI, PCI DSS, SOC 2 and ISO 27001 each run on their own calendar. Sentrix maps every control once and satisfies all of them from one evidence set.
Let's talk about your compliance program.
Last updated: 2026-09-17
