Compliance with the standards
that matter to your business
From Quebec’s health-sector TGV and the new CPCSC to ISO 27001, SOC 2 and PCI DSS, OKIOK helps you meet the frameworks your industry and customers require.
Turn demanding requirements into a program you can run
Growing risk and tightening regulation push organizations toward a structured, accountable security program. Compliance is rarely a single standard. It is meeting the specific frameworks your industry and customers demand, without rebuilding from scratch each time.
OKIOK builds that foundation: a governance framework aligned with ISO/IEC 27001 and 27002, a normative framework of policies and procedures, and a key-controls approach to risk that reads your posture quickly and targets the controls with the most impact.
Implementing a secure-once, comply-many strategy, where the required controls and processes are mapped and harmonized with a foundational framework such as ISO/IEC 27001, streamlines the compliance process by minimizing the efforts and costs of achieving and maintaining compliance, as well as certification costs.
I need to comply to…
Trousse Globale de Vérification (TGV), Quebec Ministry of Health and Social Services
TGV certification attests that a specific version of a technology product or service complies with the requirements of Quebec’s health and social services sector. Administered by the Ministry of Health and Social Services’ Certification and Homologation Bureau (BCH), it assesses your solution across four domains: security, personal-information protection, performance and technology. A penetration test has been mandatory since 2022.
It applies to any organization that designs, operates or sells a technology product or service used in a Quebec healthcare context: TGV certification is required to sell, renew or maintain your contracts with the network.
OKIOK can facilitate your TGV certification by:
- Helping you make sense of the requirements matrix, roughly 200 security criteria, 100 personal-information-protection criteria, 30 performance criteria and 20 technology criteria, and harmonize it with your corresponding ISO/IEC 27001 controls
- Assessing your current posture
- Identifying the gaps
- Assisting you in enhancing or implementing the required controls
- Performing the required penetration testing
- Helping you enhance your cybersecurity maturity and resilience with our offensive security and strategic consulting services
- Supporting you through the initial evaluation and subsequent re-certification process
Canadian Program for Cyber Security Certification (CPCSC)
The Canadian Program for Cyber Security Certification makes cyber security certification mandatory for organizations that bid on or perform Government of Canada defence contracts, across three progressively demanding levels, from a 13-control self-assessment to a 200-control Department of National Defence assessment.
CPCSC support is part of OKIOK’s defence and aerospace offer: we prepare you for certification and support you through it. The certification decision rests with the accredited body or DND.
ISO/IEC 27001
ISO/IEC 27001 is the international standard for an information security management system: the policies, controls and governance that keep information secure, with continual improvement built in. It is the foundation for a robust, resilient cybersecurity posture.
OKIOK can facilitate your ISO/IEC 27001 certification by:
- Helping you make sense of the ISO/IEC 27001 and 27002 standards
- Assessing your current posture
- Identifying the gaps
- Providing and tuning sample policies
- Assisting you in enhancing or implementing the required controls and processes
- Testing the effectiveness and resiliency of your cybersecurity controls
- Enhancing the maturity of your cybersecurity program through strategic consulting
- Supporting you through the initial evaluation and subsequent re-certification process
SOC 2
SOC 2 audits your controls against the AICPA Trust Services Criteria: security, availability, processing integrity, confidentiality and privacy. Type I attests the controls are in place at a point in time; Type 2, that they operate effectively over a period.
OKIOK can facilitate your SOC 2 attestation by:
- Helping you make sense of the SOC 2 controls and harmonize them with your corresponding ISO/IEC 27001 controls
- Assessing your current posture
- Identifying the gaps
- Providing and tuning sample policies
- Assisting you in enhancing or implementing the required controls and processes
- Testing the effectiveness and resiliency of your cybersecurity controls
- Enhancing the maturity of your cybersecurity program through strategic consulting
- Supporting you through the audit and subsequent annual re-audits
PCI DSS
PCI DSS is the payment card industry’s data security standard for anyone who stores, processes or transmits cardholder data, a mix of technical controls and mandated periodic testing.
OKIOK can facilitate your PCI DSS compliance by:
- Helping you make sense of the PCI DSS requirements, scope your cardholder data environment and harmonize with your corresponding ISO/IEC 27001 controls
- Assessing your current posture
- Identifying the gaps
- Providing and tuning sample policies
- Assisting you in enhancing or implementing the required controls and processes
- Testing the effectiveness and resiliency of your cybersecurity controls
- Enhancing the maturity of your cybersecurity program through strategic consulting
- Supporting you through the audit and subsequent annual re-audits
Another standard or requirement?
Working toward a framework that isn’t listed here: ITSG-33, NIST SP 800-53, NIST RMF, GDPR, Quebec’s Law 25, an industry mandate, or a customer’s security questionnaire?
OKIOK can facilitate your compliance by:
- Helping you make sense of the standards and frameworks you need to meet, and harmonize them with your corresponding ISO/IEC 27001 or NIST SP 800-53 controls
- Assessing your current posture
- Identifying the gaps
- Providing and tuning sample policies
- Assisting you in enhancing or implementing the required controls and processes
- Testing the effectiveness and resiliency of your cybersecurity controls
- Enhancing the maturity of your cybersecurity program through strategic consulting
- Supporting you through the audit and subsequent annual re-audits
Questions about compliance?
How OKIOK helps you prepare for a certification or an audit.
Not sure where you stand?
Tell us about your compliance requirements, the standards you need to meet and the deadline you are working to.






