Skip to content

Compliance with the standards
that matter to your business

From Quebec’s health-sector TGV and the new CPCSC to ISO 27001, SOC 2 and PCI DSS, OKIOK helps you meet the frameworks your industry and customers require.

ISO 9001:2015 certified by IntertekISO/IEC 27001:2022 certified by Insight AssuranceBureau de la sécurité privée (BSP) licence

Turn demanding requirements into a program you can run

Growing risk and tightening regulation push organizations toward a structured, accountable security program. Compliance is rarely a single standard. It is meeting the specific frameworks your industry and customers demand, without rebuilding from scratch each time.

OKIOK builds that foundation: a governance framework aligned with ISO/IEC 27001 and 27002, a normative framework of policies and procedures, and a key-controls approach to risk that reads your posture quickly and targets the controls with the most impact.

Implementing a secure-once, comply-many strategy, where the required controls and processes are mapped and harmonized with a foundational framework such as ISO/IEC 27001, streamlines the compliance process by minimizing the efforts and costs of achieving and maintaining compliance, as well as certification costs.

I need to comply to…

Trousse Globale de Vérification (TGV), Quebec Ministry of Health and Social Services

TGV certification attests that a specific version of a technology product or service complies with the requirements of Quebec’s health and social services sector. Administered by the Ministry of Health and Social Services’ Certification and Homologation Bureau (BCH), it assesses your solution across four domains: security, personal-information protection, performance and technology. A penetration test has been mandatory since 2022.

It applies to any organization that designs, operates or sells a technology product or service used in a Quebec healthcare context: TGV certification is required to sell, renew or maintain your contracts with the network.

OKIOK can facilitate your TGV certification by:

  • Helping you make sense of the requirements matrix, roughly 200 security criteria, 100 personal-information-protection criteria, 30 performance criteria and 20 technology criteria, and harmonize it with your corresponding ISO/IEC 27001 controls
  • Assessing your current posture
  • Identifying the gaps
  • Assisting you in enhancing or implementing the required controls
  • Performing the required penetration testing
  • Helping you enhance your cybersecurity maturity and resilience with our offensive security and strategic consulting services
  • Supporting you through the initial evaluation and subsequent re-certification process

Questions about compliance?

How OKIOK helps you prepare for a certification or an audit.

Not sure where you stand?

Tell us about your compliance requirements, the standards you need to meet and the deadline you are working to.

Send us a message

Only your email is required. Pick a subject, add a note, and send.

Incident in progress? Call the 24/7 line instead of waiting for a reply: +1 450 681-1681, extension 277