Home/ TGV Certification
Services · Compliance

TGV certification support (Trousse globale de vérification)

Your gateway to Quebec’s health and social services network. Sentrix structures your certification journey and takes on the coordination, documentation rigour, and security expertise so your file reaches the Certification Bureau solid and ready — without unnecessary detours.

What is TGV certification?

TGV certification is an attestation that a specific version of a technology product or service (PST) complies with the requirements of Quebec’s health and social services sector. It is administered by the Certification and Homologation Bureau (Bureau de certification et d’homologation, BCH) of the Ministry of Health and Social Services (MSSS), working with partners and subcontractors specialized in cybersecurity and personal information protection.

It evaluates your solution across four domains: security, personal information protection (PIP), performance, and technology. Since January 2022, a penetration test has been mandatory, in accordance with the requirements of the Secrétariat du Conseil du trésor.

In practical terms: if your organization designs, operates, or sells a technology product or service used in a Quebec healthcare context, TGV certification is required to sell, renew, or maintain your contracts with the network.

Security

Service delivery, data use and access, backup and recovery procedures, logging and traceability. (≈ 200 criteria)

Personal Information Protection (PIP)

Legislation and regulation, personal information protection, sharing of health information. (≈ 100 criteria)

Performance

Accounting for remote regions and varied usage contexts. (≈ 30 criteria)

Technology

Architecture directions, including interoperability with other network systems. (≈ 20 criteria)

A mandatory penetration test is added to this, performed within the three months preceding the start of verifications or before their completion, with requirements that vary depending on the nature of the application.

Who this support is for

Health technology suppliers

You design, operate, or sell a technology product or service (PST) intended for the health network. Whether you need a first certification, a renewal, or to expand the scope of an already-certified product, the BCH process requires rigorous preparation and a solid understanding of the criteria being evaluated. We structure your process and clarify what is expected at each step.

Network institutions and organizations

You need to ensure that the technology products and services you use or plan to deploy meet TGV requirements. Your suppliers may need help preparing for it or maintaining their compliance over time. We work with PST suppliers referred by their network clients — feel free to point us to a supplier who needs support.

Is this the right time for you?

If you recognize your situation in any of the following, this support is designed for you.

  • A Quebec health institution (CIUSSS, CISSS, family medicine group, Santé Québec) has selected your product, but cannot deploy it until TGV certification is obtained.
  • You have reviewed the criteria package and realize the gap between your current practices and MSSS requirements calls for a structured approach, not just a line-by-line read.
  • You are already compliant with Law 25 or GDPR, and want to know exactly what TGV adds (the answer: a lot, since it is a sector-specific framework unique to the health network).
  • Your product received non-conformities in a verification report and you need to correct them within the allotted timeframe without jeopardizing the contract.
  • You are an international or out-of-province supplier, your product is already used elsewhere, and you are discovering that Quebec’s health market requires a specific certification that is not recognized as equivalent.
  • You publish an AI tool (AI scribe, transcription, generative AI) intended for the health and social services sector, where TGV has become a prerequisite.
  • You need a penetration test compliant with MSSS guidance, coordinated with the right providers and delivered with the evidence required by the Certification Bureau.
  • You are already certified and preparing your annual self-declaration renewal, wanting to make sure nothing has drifted.

What you get

Full gap analysis

A mapping of your current product against TGV criteria, prioritized by domain (security, PIP, performance, technology) and by level of effort required.

Realistic estimate before commitment

An assessment of the timeline, total cost (our fees + the verification firm’s fees + any technical investments) and the load on your internal teams — before you commit.

Documentation and supporting evidence

The policies, procedures, and documentary evidence expected, written or adapted to your reality and to the level of detail required by the BCH — not a stack of generic templates.

Penetration test coordination

Scoping, provider selection if needed, then delivery of results and mitigation measures to the Certification Bureau within the required timeframe.

Implementation of missing controls

Working with your product and IT teams to put in place required technical controls: multi-factor authentication, encryption, logging, access management, tested backups, incident management, and more.

Filing-ready file + support during verification

A file structured to BCH expectations, with a clear link between each criterion and its evidence, then active support during verification by the external firm: responding to requests, managing non-conformities, preparing your teams.

The TGV journey, step by step

Certification follows a process structured by the Certification Bureau. We support you at every one of these steps.

1. Scoping and application preparation
We validate together the scope of the targeted product, its version, the target institutions, and its exchanges with network systems. We help you prepare the certification application form, gather security and technology architecture documents, as well as the inventory of personal information processed and the mapping of its flows. Duration: variable.
2. Gap analysis and implementation
We map your product against TGV criteria, identify what is already in place, what needs adjusting, and what requires real work. We write the expected documentation and implement missing technical controls with your teams.
3. Filing the application with the BCH
We support you in signing and sending the required forms (certification application, confidentiality agreement, applicable attestations) and prepare you for the information meeting with the BCH team.
4. Penetration test
We coordinate the penetration test in accordance with MSSS guidance: scoping, provider selection if needed, and delivery of results and mitigation measures to the Certification Bureau.
5. Verification by the external firm
Verification includes a theoretical (documentary) evaluation followed by a practical verification (live audit of the solution). We stay involved throughout: translating the firm’s requests into concrete actions, preparing for exchanges, quickly managing requested adjustments to keep the file moving. Duration: about 30 business days.
6. Decision and ongoing maintenance
The BCH renders its decision and, if certified, a contract is signed. We remain available to support you in meeting follow-up commitments: change log, major change declarations, annual penetration test, self-declaration, and IT recovery exercise.

Certification doesn’t stop at the attestation

TGV certification is valid for three years, but is renewable annually and conditional on meeting ongoing commitments. Failing to meet these obligations can lead to a specific verification, a review, or even withdrawal of certification. We help you stay compliant over time.

  • Maintain a log of any change occurring after the certification is issued.
  • Submit to the BCH, at least twenty business days in advance, any major change requiring or not a new version.
  • Carry out at least one penetration test annually with a firm recognized by the BCH and complete the self-declaration.
  • Correct detected vulnerabilities within prescribed timeframes (mitigation measures within a maximum of 15 business days; mitigation plan for a critical vulnerability within 3 business days).
  • Inform the BCH of any major issue as soon as it is identified and present a correction plan within 3 business days.
  • Carry out an IT recovery exercise every two years.
  • Submit the self-declaration at least twenty business days before the attestation’s anniversary date.

Why trust Sentrix with your TGV journey

Security and personal information protection expertise

A team specialized in cybersecurity and PIP, up to date on the requirements specific to Quebec’s health and social services sector.

A scalable approach

An approach adjusted to the nature of your PST, your current maturity level, and your operational constraints.

Skills transfer

Hands-on, educational support: your team builds capability during the project, which serves you well beyond certification.

Current with the Certification Bureau

Ongoing monitoring of MSSS guidance and requirements so your file reflects the current state of expectations.

We prepare — we do not certify. Certification is issued exclusively by the Certification and Homologation Bureau (BCH) of the MSSS / Santé Québec, following independent verification.

Frequently asked questions

Is this mandatory to sell to Quebec’s health network?
In practice, yes: a network institution generally cannot deploy a technology product or service until TGV certification is obtained. If your product does not exchange any data with network systems, TGV may not apply — we check this together from the first call.
We are already compliant with Law 25 / GDPR / ISO 27001. Is that enough?
No. TGV is a sector-specific framework unique to the health network, with specific requirements that these frameworks do not cover. Your existing compliance is an asset and reduces certain gaps, but it does not replace certification.
How long is the certification valid?
Certification is valid for three years, renewable annually, provided follow-up commitments are met (self-declaration, annual penetration test, major change declarations, etc.).
How long does the process take?
This depends heavily on your starting maturity and the scale of the gaps to correct. Verification by the external firm takes about 30 business days; the preparation beforehand is the most variable part. We give you a realistic estimate after the gap analysis.
What happens if our product receives non-conformities?
We help you correct the gaps within the allotted timeframe. If certification is not granted, a new application is possible after a minimum three-month delay, once corrections have been made.
Our product includes artificial intelligence. Are there specific considerations?
Yes. Solutions incorporating AI (scribes, transcription, generative AI) are subject to enhanced and evolving requirements. We adapt the approach accordingly.
Is this confidential?
Yes. The process is governed by a confidentiality agreement, which is itself required by the BCH process.
Are we locked into a mandatory recurring engagement?
No. Once certification is obtained, you take back the reins. We remain available for one-off needs (interpretation, major change, renewal), without locking you into a recurring contract.

Let’s talk about your TGV journey.

Whether you’re weighing your options, already underway, or just want to check your readiness — a first conversation costs nothing and helps scope what applies to your solution.