A software supplier cannot deploy a clinical or clinico-administrative product inside Quebec's health and social services network without certification. The standard tender clause the certification bureau publishes for public health buyers states it directly: "Tout fournisseur d'une application visée par le paragraphe précédent doit obtenir la certification de son application auprès du BCH avant tout déploiement dans le RSSS" ("Any supplier of an application covered by the preceding paragraph must obtain certification for its application from the BCH before any deployment in the RSSS"). That certification is the Trousse globale de vérification, universally shortened to TGV, and since January 2022 it cannot be obtained without an independent penetration test.
This page is the practical English reference for that process. It is built entirely from documents published by the Ministère de la Santé et des Services sociaux (MSSS) and by the Bureau de certification, including the TGV guide, the dedicated penetration testing orientation, the vulnerability remediation orientation, the official application form, the attestation and certificate templates, the annual self declaration form, the supplier agreement, and the verification criteria list itself. French wording is quoted where the exact phrasing matters, with an English translation alongside.
Quick answer. TGV certification is an attestation issued by Quebec's health sector certification bureau confirming that a specific version of a technology product or service meets the health and social services network's requirements for security, protection of personal information, performance, technology and interoperability. Suppliers selling software, SaaS, AI tools or connected devices into the network need it before deployment. The bureau's published criteria list contains 254 criteria across six domains. Criterion S16.02 requires that the application "a fait l'objet d'un test d'intrusion par un prestataire indépendant et reconnu" ("has undergone a penetration test by an independent and recognised provider"). The test must be repeated annually. The verification stage costs C$15,000 excluding taxes in the bureau's agreement template and runs 30 business days, and the certificate is valid for five years subject to annual renewal.
What TGV certification actually is
The MSSS guide Certification: Trousse globale de vérification (TGV) opens with the definition:
"La certification TGV est une attestation de la conformité d'une version d'un produit ou d'un service technologique (ci-après nommé PST ou application) relativement aux exigences du secteur sociosanitaire du Québec en matière de sécurité, de protection des renseignements personnels (PRP), de performance et de technologie."
In English: TGV certification is an attestation that a version of a technology product or service (PST) conforms to the Quebec health and social services sector's requirements for security, protection of personal information, performance and technology. The bureau's tender clause adds interoperability to that list, and the criteria list treats interoperability as its own domain.
Three properties of that definition drive everything else in this guide.
It certifies a version, not a company. The attestation template names the product and a version number in the form x.x.x. The certified-applications page sets out the numbering convention: three natural integers separated by dots, where the first is the major version, the second the minor version, and the third an optional extension. Change the major version and you are back in front of the bureau.
It is a network entry condition, not a badge. The certification bureau's own commitment in the attestation is to assure everyone in the health and social services sector that using a TGV-certified product "confirme le respect des lois, règlements et orientations gouvernementales" ("confirms compliance with government laws, regulations and orientations") on protection of personal health and social services information, security and cybersecurity, performance and technology. Buyers in the network are directed to acquire only certified versions where a certification exists.
Its security bar is set by an external verifier, not by a self assessment. The verification stage is carried out by an external specialised firm, not by the bureau, and that firm sends a verification report to the bureau. The bureau then approves or refuses.
Who needs TGV certification
The bureau's About certification page lists three circumstances in which certification is considered mandatory. A product or service needs it when it:
allows the collection, retention, use, modification, communication or destruction of health or social services information; or
is interfaced, or plans to be interfaced, with a common-interest information asset that collects, retains, uses, modifies or destroys that information; or
is going to be deployed in more than one Quebec health establishment with web access, to deliver health or social services.
The tender clause published for public buyers frames the same scope slightly differently and adds a fourth, discretionary route. Applications covered are those deployed within the integrated multimedia telecommunications network, or exchanging data with the common-interest information assets of the health and social services network (RSSS), or processing confidential and personal data, or judged necessary by an RSSS acquirer for any other reason.
In practice that captures a wide range of suppliers:
Clinical and clinico-administrative SaaS. Electronic medical records, appointment booking, virtual health, patient portals, laboratory systems, pharmacy information systems and billing tools all appear as certified families on the bureau's register.
Connectors and integration middleware. The register has a dedicated family for solutions that facilitate the sharing and follow up of information.
AI products. The December 2025 register carries a family for AI-based voice recognition and transcription. AI tools are not exempt; they are certified through the same TGV.
Connected devices and remote support tools. Decision support, remote control and BIOMED solutions each appear as recognised families.
Two obligations in the attestation matter for anyone building integrations. A certified supplier commits that its product "ne s'arrime qu'avec d'autres PST dûment certifiés par le BC ou ayant reçu l'approbation du BC" ("only interfaces with other products duly certified by the bureau, or that have received the bureau's approval"). And where a product interfaces with provincial assets, the register records those interoperability verifications separately from the TGV verification itself, with columns for the Dossier santé Québec medication, laboratory and imaging domains, PrescripTIon, the appointment booking hub, and the infectious disease information system.
If you are unsure whether your product is in scope, the bureau is explicit that it is the single point of entry for the process and can be reached at certification@sante.quebec.
BCH, BC, MSSS and Santé Québec: why you will see four names
Searching for this topic returns a confusing mix of acronyms. Here is the actual lineage, straight from the documents.
The Bureau de certification et d'homologation (BCH) was created by the health sector's dirigeant réseau de l'information (network information officer) inside the MSSS. Circular 2013-026 and the Règle particulière sur la certification des produits et services technologiques define it as the administrative unit responsible for running the certification process and describe it as the single point of entry.
The 2024 MSSS guide still uses BCH throughout. The current attestation, certificate, agreement and annual self declaration templates use Bureau de certification (BC) and are issued under Santé Québec, the agency created by the 2023 health reform legislation. The supplier agreement is signed with Santé Québec at 930 chemin Sainte-Foy in Quebec City, and the contact address on the current forms is certification@sante.quebec.
For a supplier, the practical consequence is simple: BCH and BC refer to the same function, and both names are live in documents you will be asked to read. The older MSSS-branded documents remain published and are still linked from the ministry's own orientations page.
That transition also explains the single most common factual error in third-party write-ups of TGV, which the next sections address: the certificate's validity period and several deadlines were changed, and both the old and the new figures are still in circulation.
The six domains and the 254 published criteria
The bureau publishes a verification criteria list, Critères de vérification de la TGV, as a spreadsheet. Counting its rows by domain gives the structure below.

Domain | Criteria | Categories | What it covers |
|---|---|---|---|
Security (Sécurité) | 104 | 16 | Access control, operations security, asset management, secure development and maintenance, logging and monitoring, supplier relationships, cryptography, incident management, business continuity, compliance management |
Protection of personal information (PRP) | 75 | 11 | Accountability, lawfulness and purpose specification, collection limitation, use and disclosure limitation, security of personal information, openness and transparency, consent and choice, accuracy and quality, retention limitation, data minimisation, individual participation and access |
Interoperability (Interopérabilité) | 56 | 5 | User identification, user place of residence, interoperability mechanics, communication with the user, data from the establishment capturing the user identification |
Technology (Technologie) | 9 | 1 | Technology requirements |
Performance | 7 | 1 | Performance requirements |
General (Général) | 3 | 2 | General requirements and user identification |
Total | 254 | 36 |
Two observations are worth more than the totals.
Security and privacy together account for 179 of the 254 published criteria, roughly seven in ten. The largest single category anywhere in the list is access control, with 24 criteria. If you are budgeting effort, that is where it goes.
The published list is a sample, not the whole exam. The MSSS guide is careful about this. It tells applicants to read the criteria list before applying, then says: "ce document n'est qu'un échantillon représentatif pour vous permettre de vous familiariser avec les types d'exigences du processus" ("this document is only a representative sample to let you become familiar with the types of requirements in the process"). It also warns that for each example that applies to your application you should be ready to provide documentary evidence later: documents, screenshots, copies of contracts and so on. Treat 254 as the shape of the assessment rather than a fixed question count, and treat every criterion as a request for evidence rather than a yes or no question.
The TGV certification process, step by step
The bureau describes the process as three broad stages: preparation with the bureau, verification by an external specialised firm, and post-certification follow up. The published durations are 1 to 6 weeks for preparation, depending on the maturity of the product and of the supplier organisation, and 30 business days for the verification itself. The detailed steps below come from the MSSS guide and the current bureau templates.

1. Assemble the file before you apply
The guide asks applicants to have four things ready before the application form is sent:
a global security architecture document and a high-level global technology architecture showing the links with every other solution the product exchanges information with;
an inventory of the personal information the product handles;
a map of how that information flows;
a form signed by a person registered in Quebec's enterprise register, or holding a properly documented delegation.
2. Submit the signed forms
The forms go to the bureau by email. The guide lists them: the TGV certification application form, a confidentiality undertaking, a Revenu Québec attestation if the supplier has an establishment in Quebec, a declaration of absence of establishment in Quebec if applicable, an attestation of the applicant's probity, and a manufacturer authorisation where relevant.
The application form itself is worth reading before you fill it in, because it asks the penetration testing questions covered in the next major section.
3. Information meeting and official start date
On receipt of the documents the supplier is called to an information meeting with the bureau team, which explains the process, answers questions, and sets the official date on which the file transfers to one of the bureau's verifiers. At that meeting the supplier also completes a form confirming its commitment to meet every requirement of the process.
4. Agreement and fee
The supplier commits to the deadlines that will be set and to paying the process fee, including, where applicable, costs incurred in the event of abandonment. Santé Québec's agreement template states the amount plainly: "Le coût de la certification TGV, assumé par le FOURNISSEUR, est de 15 000 $, excluant les taxes applicables" ("The cost of TGV certification, borne by the SUPPLIER, is $15,000, excluding applicable taxes"), payable by cheque or direct deposit within 30 days of the invoice.
5. Verification by the external firm
This stage is entirely the responsibility of the firm carrying out the verifications, and the guide notes the bureau only intervenes in the event of a major problem. The firm is responsible for supporting the supplier's understanding of the criteria and for sending a verification report to the bureau. The stage runs as a kickoff meeting, a presentation of the solution by the supplier, a presentation of the process by the verifier, then a schedule of deliverables agreed between the verifier and the supplier.
Santé Québec commits in the agreement to provide the services of a professional verifier qualified to carry out the written and practical verifications, to produce a verification report of the verifiers' findings and give it to the supplier, and to produce a document attesting to the conformity or non-conformity of the product.
6. Decision, attestation, certificate
The bureau analyses the results presented by the verifier together with the other available documents, and approves or refuses. If certification is granted, the supplier signs the attestation, the bureau updates its website to reflect the certification, and follow-up obligations begin. The certificate is a separate one-page document carrying an issue date and an expiry date.
If certification is refused, the bureau confirms by email that the product does not meet the requirements. The supplier may reapply at its own cost after a minimum period of three months, provided the expected corrections have been made.
7. Duration and renewal
This is where old and new documents disagree, so both figures are set out here.
Current: the About certification page states that "la durée de validité de toutes les certifications délivrées par le Bureau de certification est de cinq ans" ("the validity period of all certifications issued by the certification bureau is five years"), renewable annually after evaluation of the self declaration form. The current attestation template says the same, with a tacit one-year renewal on the bureau's acceptance of the self declaration. The register of certified products carries an explicit note: the TGV certificate is valid for five years "suite au rehaussement du processus de suivi après certification" ("following the enhancement of the post-certification follow-up process").
Superseded: the 2024 MSSS guide still describes a three-year contract, renewable annually, with a three-year validity period. If you are reading that guide, this is the paragraph that has moved on.
8. Annual maintenance
Certification is conditional, every year, on a defined set of commitments. The current attestation lists nine. In summary, the supplier must:
log every change made after the certification was issued, in a register the bureau can request at any time;
submit every major change to the bureau for evaluation and approval before it goes to production;
run at least one penetration test a year with an independent firm, following the bureau's orientations, and transmit the result and the proof of any mitigation measures;
remediate vulnerabilities found in penetration tests, and notify the bureau of any critical vulnerability as soon as it is known, with a mitigation plan within three business days;
notify the bureau of any major problem found in the product as soon as it is observed, with a correction plan within three business days;
run a disaster recovery exercise in a separate centre every two years, taking account of the complexity of its IT infrastructure, and provide the plan and a report to the bureau;
update the product at the bureau's request so it continues to meet the requirements;
only interface with other certified or bureau-approved products;
complete and submit the annual self declaration form ahead of the certification anniversary.
Failure to respect these obligations can lead to publication of the non-conformity on the bureau's website, a targeted verification at the supplier, a review of the certification, or its withdrawal.
On the deadlines, the documents vary and you should confirm yours with the bureau. The certified-applications page says major changes must reach the bureau at least 20 days before the planned production date, and lists nine categories of major change: a new feature, a change in access management, an interface with a new application, a change of development, deployment or remote-control approach, a change that alters how the product met a criterion, replacing the solution with another, a change of operating system, a configuration change, and a new version bundling a batch of updates. The current attestation and self declaration forms use 15 days for the same obligation, and the 2024 guide used 20 business days. The self declaration is due at least 15 days before the certification anniversary in the current forms, and was 20 business days in the 2024 guide.
The penetration testing requirement, in depth
This is the part of TGV that most suppliers underestimate, and it is unusually well documented. Three sources define it: criterion S16.02 in the verification criteria list, the bureau's dedicated Orientation concernant les tests d'intrusion, and the annual commitments in the attestation.
The criterion
Criterion S16.02, in the security domain under the compliance management category, reads:
"Votre application a fait l'objet d'un test d'intrusion par un prestataire indépendant et reconnu par le MSSS."
"Your application has undergone a penetration test by a provider that is independent and recognised by the MSSS."
The MSSS guide explains why it is there: "depuis janvier 2022, un test d'intrusion est obligatoire conformément aux exigences du Secrétariat du Conseil du Trésor" ("since January 2022, a penetration test is mandatory in accordance with the requirements of the Secrétariat du Conseil du trésor"). The penetration testing orientation ties it to the Treasury Board directive on vulnerability detection plans (NVD19) and states that penetration tests "sont maintenant un prérequis à l'obtention de la certification Trousse globale de vérification (TGV) pour tous les produits ou services technologiques utilisant des données personnelles, de santé et de services sociaux" ("are now a prerequisite for obtaining TGV certification for all technology products or services using personal, health and social services data").
What "independent and recognised" means
The orientation sets out six requirements. The bureau will accept results only from a provider that:
has legally authorised representatives in Canada;
is at minimum specialised in cybersecurity and in the protection of personal information, with staff holding recognised certifications in penetration and vulnerability testing;
is able to provide criminal background evidence for the personnel performing the tests, because they are called on to access extremely sensitive information;
is responsible and accountable for the results, whether or not it uses subcontractors;
is able, with its client's agreement, to provide the test report in French to the bureau at no cost;
is able to run tests in a production environment or an equivalent one, taking account of the client's business risks.
Two of those are procurement filters that catch suppliers late. A firm with no legally authorised Canadian presence does not qualify, and a firm that cannot produce a French-language report for the bureau at no charge does not qualify.
How a supplier confirms a firm's status. There is no public list of recognised firms. Independence and recognition are assessed against the criteria above, so the reliable route is to send the bureau the firm's details, its testers' certifications, its background-check capability and its French-reporting capability, and confirm acceptance in writing before the engagement starts. The bureau is the single point of entry for the process and answers this question at certification@sante.quebec. Do it before you buy the test, not after.
Scope: what the test has to cover
The orientation is prescriptive, and the box-colour rules alone rule out a large share of ordinary commercial penetration tests.
Methodology. Tests must draw on recognised standards, proven best practices and techniques that guarantee realistic and relevant testing. The orientation names the National Vulnerability Database (NVD), the Open Web Application Security Project (OWASP), the Open Source Security Testing Methodology Manual (OSSTMM) and the National Institute of Standards and Technology (NIST).
Environment. Tests must be carried out "dans un environnement de production ou un environnement équivalent à l'environnement de production" ("in a production environment or an environment equivalent to the production environment"). A hardened staging environment that differs materially from production is a finding waiting to happen.
Roles. Every role, meaning every actor in the system, must be identified and tested in its intended context of use, whether or not it is reachable from the web. That single sentence is what turns a TGV test into an authorisation-heavy engagement: it means testing each role against each other role, which is exactly where broken object level authorisation and privilege escalation live.
Box colour. The orientation is unambiguous, and this is the rule most often missed:
Test type | Bureau position |
|---|---|
White box (boîte blanche) | Accepted in all cases |
Grey box (boîte grise) | Accepted only for certain non-sensitive products for which no province-wide deployment is planned |
Black box (boîte noire) | Not accepted by the bureau, and to be avoided if you want TGV certification |
The orientation defines the three in ascending order: black box tests the attack surface available to any external attacker; grey box adds the perspective of clients, partners and employees; white box adds continuous and consistent confirmation, analysing the security level with the same access as a system administrator.
Patching and deployment model. The test must identify and test flaws linked to software updates that were not applied, and vulnerabilities linked to the product's deployment mode, whether it is installed in the client's environment (an application test), hosted by the supplier (a test on its network), or hosted in a cloud environment.
Attack vectors. The test must identify possible attack vectors, meaning entry points, according to the criticality of the product, explicitly including web platforms, mobile applications, infrastructure and networks, and build test scenarios against them. A final catch-all covers any other verification judged relevant to discovering vulnerabilities in the use of the product.
For a modern health SaaS product, translating those rules into a scope statement usually means: the web application with every role tested against every other role, the REST or GraphQL APIs behind it including any integration endpoints, the mobile applications if they exist, the cloud configuration and identity model of the hosting account, and, where the product embeds an AI component, the model-facing surfaces that accept untrusted input and the authorisation boundary around whatever that component can reach. AI features are not carved out anywhere in the orientation; the criticality-based attack-vector rule pulls them in.
Freshness: how recent the test has to be
The official TGV application form asks: "Est-ce que le PST a fait l'objet d'un test d'intrusion récent (moins de six mois)?" ("Has the product or service undergone a recent penetration test, less than six months old?"). If the answer is yes, the form then asks for the date the test was carried out, the name of the firm that performed it, the scope of the test, whether any anomalies detected were corrected, whether any remain uncorrected, and whether the supplier agrees to provide a copy of the report.
Six months is therefore the practical freshness window at application time. After certification, the obligation becomes annual: at least one penetration test a year with an independent firm.
The form's remaining questions are a useful reality check. A test whose report you are unwilling to share, or that closed with unremediated findings and no plan, weakens the file rather than strengthening it.
Remediation deadlines
Three separate deadlines apply, and they are not the same thing.
The contractual window. The attestation and self declaration forms require that vulnerabilities detected in penetration tests be corrected, or mitigation measures put in place, within 15 days of receiving the test report. The 2024 guide phrased this as 15 business days. The most recent attestation template replaces the fixed window with "suivant une échéance convenue avec le BC" ("according to a deadline agreed with the bureau"), which is a reason to agree yours explicitly.
The critical-finding clock. For any critical vulnerability, the supplier must inform the bureau as soon as it is informed of it, and present a plan for putting mitigation measures in place within three business days.
The government remediation matrix. The bureau publishes a separate orientation carrying the remediation timelines set by the ministère de la Cybersécurité et du Numérique under the information resources legislation. It is shared for information, and the bureau states that "Il demeure essentiel de discuter et de convenir des échéances précises avec le BC" ("it remains essential to discuss and agree precise deadlines with the bureau"). The timelines are driven by impact level and probability of materialisation:
Asset exposure | Fix available | Fastest deadline | Slowest deadline |
|---|---|---|---|
Internet exposed | Patch or workaround available | 2 days (very high impact, very high probability) | 60 days (low impact) |
Internet exposed | No patch or workaround, development may be needed | 8 days (very high impact, very high probability) | 90 days (low impact) |
Not internet exposed | Either | 8 days (very high impact, very high probability) | 90 days (low impact) |
The orientation ends with an instruction in bold: the resolution deadlines are expressed in calendar days, not business days.
A two-calendar-day fix window for a critical, internet-exposed finding is the number to design your release process around. It is the reason the sequencing advice later in this guide matters: test early enough that the fixes land before the verification window, not during it.
What the bureau expects in the report
The orientation lists eight minimum elements a penetration test report must contain for the bureau to be able to base its decision on it:
context, meaning the objectives and scope of the penetration test;
the methodology for assessing risk and identifying vulnerabilities;
a description of each test performed, conclusive or not, and the results obtained;
detailed documentation of each vulnerability identified and the associated risks;
identification and documentation of the strengths and weaknesses of the security measures examined;
documentation of potentially present vulnerabilities that could not be exploited;
specific recommendations for major or critical vulnerabilities, plus general recommendations;
a management-summary synthesis, complete and easy to interpret, either inside the report or as a separate document.
Items 3 and 6 are the ones that separate a certification-grade report from a scanner export. The bureau wants to see the tests that did not succeed and the vulnerabilities that were suspected but not exploitable, because that is how it distinguishes coverage from luck. If you want to see what a report structured this way looks like before commissioning one, our sample penetration testing report walks through the same sections.
Add the operational requirements from the firm criteria and the report has to be deliverable in French to the bureau at no cost, and the testers behind it have to be background checked.
Scoping one test so it also serves Law 25 and other evidence needs
TGV overlaps heavily with obligations Quebec healthtech companies already carry, so the sensible move is to scope one engagement that produces evidence for several files at once.
Quebec Law 25 (the Act to modernize legislative provisions as regards the protection of personal information, which amended the Act respecting the protection of personal information in the private sector, P-39.1) requires under section 10 that a person carrying on an enterprise "must take the security measures necessary to ensure the protection of the personal information collected, used, communicated, kept or destroyed and that are reasonable given the sensitivity of the information, the purposes for which it is to be used, the quantity and distribution of the information and the medium on which it is stored." Section 3.3 requires a privacy impact assessment for any project to acquire, develop or overhaul an information system involving personal information. Sections 3.5 to 3.8 govern confidentiality incidents, notification of the Commission d'accès à l'information where there is a risk of serious injury, and the incident register. A penetration test that documents authorisation boundaries between roles and the exposure of personal information feeds directly into both the section 10 security-measures record and the section 3.3 assessment. The TGV privacy domain, with its 75 criteria across accountability, purpose specification, collection limitation, retention limitation and data minimisation, is built on the same principles.
Other frameworks. Health suppliers that also sell into the United States can usually reuse the same evidence for a HIPAA-aligned testing programme, and the report structure the bureau requires satisfies the evidence expectations of SOC 2 and ISO 27001 audits without a separate engagement.
Practical scoping rules that make one test serve all of them:
Enumerate roles first, then scope. TGV requires every role tested in its intended context. Write the role matrix before you request quotes; it is the single biggest driver of both cost and coverage.
Ask for white box from the start. It is accepted by the bureau in all cases, it is the only option for a product with province-wide deployment ambitions, and the source access it implies also produces the code-level evidence other audits ask for.
Include the cloud identity model. The deployment-mode rule explicitly covers cloud hosting, and cloud role assumption chains are where authorisation findings hide.
Require the French deliverable in the statement of work. Retrofitting a translation after the report is written is slower and more expensive than commissioning it.
Set the retest terms up front. With a 15-day remediation expectation and a 3-business-day plan requirement for critical findings, retesting has to be part of the engagement, not a change order.
How TGV compares with Law 25, SOC 2, ISO 27001 and HIPAA
TGV | Quebec Law 25 | SOC 2 | ISO 27001 | HIPAA | |
|---|---|---|---|---|---|
Type | Sector certification of a product version | Statute | Attestation report on controls | Management system certification | Statute and rules |
Who issues it | Quebec health sector certification bureau | Not issued; enforced by the Commission d'accès à l'information | Independent audit firm | Accredited certification body | Not issued; enforced by regulators |
Scope | One version of one product or service | The enterprise's handling of personal information | Chosen trust services criteria | The information security management system | Protected health information |
Penetration test required | Yes, explicitly, criterion S16.02 | Not named in the statute; security measures obligation implies testing | Not named; commonly expected evidence | Not named; commonly expected evidence | Not named; evaluation obligation commonly met with testing |
Test cadence | At least annually | Risk based | Typically annually | Typically annually | Risk based |
Test type constrained | Yes: white box preferred, grey box limited, black box refused | No | No | No | No |
Remediation deadline set | Yes, about 15 days, 3 business days for a critical plan | No fixed deadline | No | No | No |
Report language | Must be available in French to the bureau at no cost | Not specified | Not specified | Not specified | Not specified |
Validity | 5 years, annual renewal | Ongoing | 12 months typical | 3 years with surveillance audits | Ongoing |
The row that surprises people is "test type constrained". TGV is one of very few frameworks anywhere that tells you what kind of penetration test it will accept. Most compliance programmes accept whatever the organisation commissioned. The Quebec health bureau does not.
Realistic cost and time expectations
The certification fee. Santé Québec's agreement template sets the amount at C$15,000 excluding applicable taxes, described as the costs borne by Santé Québec during the verification stage of the certification process, payable within 30 days of invoice. The About certification page adds the qualifications that costs are borne by suppliers, are not refundable, and vary with the complexity of the product and the interoperability objectives pursued. It also warns that beyond the direct certification costs, suppliers must budget for the work needed to bring the product up to the network's requirements. Confirm your own figure in the agreement you are asked to sign; the template value is the published reference point, not a quote.
The penetration test. This is a separate cost, paid to the testing firm, and it recurs annually. The variables that move it are the number of roles, the number of applications and APIs in scope, whether mobile clients are included, whether the cloud environment is in scope, and whether the report has to be produced in French. Our penetration testing cost guide breaks the drivers down, and the penetration test cost calculator will give you a scoped range in a couple of minutes.
Internal effort. The published durations are 1 to 6 weeks of preparation and 30 business days of verification. Neither number includes the engineering work that the criteria list usually triggers. With 104 security criteria and 75 privacy criteria, each expecting documentary evidence, most first-time applicants find the evidence assembly and the remediation of gaps take longer than the formal stages.
Elapsed time to a certificate. Adding the published stages together, a well-prepared applicant is looking at roughly three to four months from application to decision, assuming the penetration test is already done and remediated. A first-time applicant that discovers gaps during verification should plan for longer, and a refused applicant faces a minimum three-month wait before reapplying.
Renewal cost. The recurring annual cost is dominated by the penetration test, the self declaration, and, every second year, the disaster recovery exercise.
Common reasons applicants stall
These are the failure patterns the published documents point to most directly.
Commissioning a black box test. The single most expensive mistake available. The bureau does not accept black box results, so the money is spent and the criterion is still open. Commission white box.
Using a firm that does not meet the six criteria. No legally authorised Canadian representation, no background checks for testers, or no ability to produce the report in French means the results are not accepted, regardless of the quality of the testing.
Testing too late. A test finished the week verification starts leaves no room for the roughly 15-day remediation expectation, and none at all for the two-calendar-day expectation on a critical, internet-exposed finding.
Testing a subset of roles. The orientation requires every role tested in its intended context, including roles not reachable from the web. Partial role coverage is a coverage gap the verifier will find.
Testing a staging environment that is not equivalent to production. The environment rule is explicit and is one of the easiest things for a verifier to check.
Arriving without the architecture and data-flow artefacts. The guide asks for a global security architecture, a global technology architecture showing links to other solutions, an inventory of personal information and a flow map, before the application is sent.
Answering criteria without evidence. The guide tells applicants to be ready to provide documentary proof for each answer: documents, screenshots, copies of contracts. Assertions without artefacts stall the verification.
Missing the change-control obligations after certification. Shipping a major change without bureau approval, or letting the self declaration deadline pass, puts the certification itself at risk, up to withdrawal.
Planning an integration with an uncertified product. A certified product may only interface with products certified or approved by the bureau.
Assuming the certificate covers the next major version. It certifies a version. Plan the reverification into your roadmap.
TGV readiness checklist
Before you apply:
[ ] Confirm with the bureau that your product is in scope and which family it belongs to.
[ ] Produce a global security architecture and a global technology architecture showing every integration.
[ ] Build an inventory of the personal information the product handles and map the flows.
[ ] Read the published criteria list and record, for each applicable criterion, the evidence you would hand over.
[ ] Write the role matrix: every actor, every intended context of use, web reachable or not.
[ ] Confirm the penetration testing firm meets all six bureau criteria, in writing, before engaging it.
[ ] Commission a white box test against production or a production-equivalent environment, covering web, APIs, mobile, cloud configuration and any AI components.
[ ] Require a report containing all eight elements, including unsuccessful tests and unexploitable vulnerabilities, plus a management summary, deliverable in French to the bureau at no cost.
[ ] Remediate, retest, and keep the proof of mitigation.
[ ] Confirm the test is less than six months old at the moment you submit the application form.
[ ] Have the form signed by a person registered in the Quebec enterprise register or holding a documented delegation.
[ ] Budget the C$15,000 verification fee plus taxes, plus the test, plus the remediation engineering.
After you are certified:
[ ] Keep a change register from day one.
[ ] Submit major changes for approval ahead of the production date, and confirm your applicable notice period with the bureau.
[ ] Book next year's penetration test at least three months before the certification anniversary.
[ ] File the annual self declaration ahead of the anniversary, with the test report and the mitigation evidence attached.
[ ] Run the disaster recovery exercise in a separate centre every two years, and keep the plan and the report.
[ ] Check that any product you plan to integrate with is itself certified or bureau approved.
How Stingrai supports a TGV penetration test
Stingrai is a Toronto-headquartered, CREST-accredited penetration testing service provider, founded in 2021, serving clients across Canada, the United States and Europe. Stingrai does Offensive Security only, and its penetration testing supports clients' TGV, Quebec Law 25, SOC 2, ISO 27001, HIPAA and PCI DSS programmes with the test evidence those programmes ask for.
Stingrai performed the TGV-scoped penetration test for Bia Education, a Quebec healthtech platform, as part of its certification.
Stingrai's engagements are scoped to the bureau's independence and evidence requirements: Canadian-based delivery, certified testers, background-checked personnel, testing in production or a production-equivalent environment, full role-matrix coverage, and a report structured around the eight elements the bureau lists. Firm recognition itself is confirmed by the supplier with the bureau before the engagement begins, and we will provide whatever the bureau asks for to support that confirmation.
Which engagement fits. For TGV, the Hybrid engagement or a custom-scoped engagement is the right shape, because the bureau expects manual testing by an independent firm and a signed report. On every engagement, Snipe, Stingrai's autonomous AI agent for web application penetration testing, works concurrently with certified penetration testers who direct its focus, extend its attack paths, and pursue what it surfaces. Snipe is purpose-built to hunt the complex classes that matter most under TGV's role-coverage rule: broken object level authorisation, business logic flaws and access-control failures. It performs both dynamic testing against the running application and white-box review of the source code, which is the combination the bureau's orientation asks for, generates AutoFix pull requests, and can run as a pull-request gating check, which is useful when you are working against a 15-day remediation expectation. Stingrai delivers both one-time annual penetration tests and continuous testing programmes, so the annual TGV test and year-round assurance can come from the same team.
Published Stingrai pricing is US$3,000 one time or US$450 a month on a 12-month engagement for the Autonomous package, and US$6,800 one time or US$1,275 a month for Hybrid, each covering exactly one web application and its APIs. "No High or Critical Finding = Don't Pay" applies to the Autonomous tier only. TGV scopes that include mobile clients, cloud environments, multiple applications or a French-language deliverable go through Get a Quote. Full details are on the pricing page.
What the data says about the report you will be filing. Across Stingrai's 2026 penetration testing research, 1,206 verified findings came out of 55 tests, 92.7% of tests surfaced at least one High or Critical issue, the false positive rate was 0.74%, and the median time to fix a Critical was 10.5 days. Two of those numbers matter for TGV planning. A test that surfaces a High or Critical is the norm rather than the exception, so build remediation time into the schedule rather than hoping for a clean report. And a 10.5-day median Critical fix sits uncomfortably close to the bureau's roughly 15-day expectation, and well outside the two-calendar-day matrix figure for a critical internet-exposed asset, which is exactly why the test needs to happen months before verification and not weeks.
Frequently asked questions
What is TGV certification in Quebec? (Qu'est-ce que la certification TGV?)
TGV certification, from Trousse globale de vérification, is an attestation issued by Quebec's health sector certification bureau confirming that a specific version of a technology product or service meets the health and social services network's requirements for security, protection of personal information, performance, technology and interoperability. The MSSS defines it as "une attestation de la conformité d'une version d'un produit ou d'un service technologique". A supplier needs it before deploying a covered product into the network.
Is a penetration test required for TGV certification? (Le test d'intrusion est-il obligatoire pour la TGV?)
Yes. Criterion S16.02 requires that the application "a fait l'objet d'un test d'intrusion par un prestataire indépendant et reconnu" ("has undergone a penetration test by an independent and recognised provider"). The MSSS guide states that a penetration test has been mandatory since January 2022, in line with Secrétariat du Conseil du trésor requirements, and the bureau publishes a dedicated orientation on how those tests must be run. The obligation repeats every year for as long as the certification is held.
How much does TGV certification cost? (Combien coûte la certification TGV?)
Santé Québec's TGV agreement template sets the certification cost, borne by the supplier, at C$15,000 excluding applicable taxes, payable within 30 days of invoice, covering the verification stage. The bureau's About certification page adds that costs are not refundable and vary with the complexity of the product and the interoperability objectives pursued, and that suppliers must separately budget for the work needed to bring the product up to the network's requirements. The annual penetration test is a further, recurring cost paid to the testing firm.
How long does TGV certification take? (Combien de temps prend la certification TGV?)
The bureau publishes two durations: 1 to 6 weeks for the preparation stage, depending on the maturity of the product and the supplier organisation, and 30 business days for the verification carried out by the external specialised firm. Adding the application, information meeting, decision and attestation steps, a well-prepared applicant should plan for roughly three to four months from application to decision, assuming the penetration test is already complete and its findings remediated.
How long is a TGV certificate valid? (Quelle est la durée de validité de la certification TGV?)
Five years, with annual renewal. The bureau states that the validity period of all certifications it issues is five years, renewable annually after evaluation of the self declaration form, and the register of certified products notes the five-year validity followed the enhancement of the post-certification follow-up process. Note that the 2024 MSSS guide still describes a three-year period; that figure has been superseded.
What kind of penetration test does the bureau accept? (Quel type de test d'intrusion est accepté?)
White box testing is accepted in all cases. Grey box is accepted only for certain non-sensitive products for which no province-wide deployment is planned. Black box is not accepted by the bureau and the orientation says it should be avoided if you want TGV certification. Tests must also be run in a production environment or an equivalent one, must cover every role in its intended context of use whether or not it is reachable from the web, and must draw on recognised methodologies such as NVD, OWASP, OSSTMM and NIST.
How recent does the penetration test have to be? (Le test doit-il être récent?)
The official TGV application form asks whether the product has undergone a recent penetration test, defined on the form as "moins de six mois" ("less than six months"). If yes, the form asks for the test date, the firm's name, the scope, whether detected anomalies were corrected, whether any remain, and whether the supplier will provide a copy of the report. After certification, the requirement becomes at least one test per year.
What makes a testing firm "independent and recognised"? (Qu'est-ce qu'une firme indépendante et reconnue?)
The bureau's orientation lists six minimum requirements: legally authorised representatives in Canada; specialisation in cybersecurity and protection of personal information with staff holding recognised penetration and vulnerability testing certifications; the ability to provide criminal background evidence for the testing personnel; accountability for the results whether or not subcontractors are used; the ability, with the client's agreement, to provide the report in French to the bureau at no cost; and the ability to test in a production or equivalent environment. There is no public list, so confirm a firm's acceptability with the bureau in writing before engaging it.
How fast must vulnerabilities be fixed after a TGV penetration test? (Quel est le délai de correction des vulnérabilités?)
The attestation and self declaration forms expect vulnerabilities detected in penetration tests to be corrected, or mitigation measures put in place, within 15 days of receiving the report, and require the bureau to be informed of any critical vulnerability as soon as the supplier knows of it, with a mitigation plan within three business days. The bureau separately publishes the government remediation matrix, which sets deadlines by impact and probability, from 2 calendar days for a very high impact internet-exposed asset with a fix available, up to 90 calendar days at the low end of the scale. Those matrix deadlines are shared for information and are expressed in calendar days, not business days.
What must the penetration test report contain? (Que doit contenir le rapport de test d'intrusion?)
Eight elements: the context including objectives and scope; the methodology for risk assessment and vulnerability identification; a description of each test performed, conclusive or not, and the results; detailed documentation of each vulnerability and its associated risk; the strengths and weaknesses of the security measures examined; documentation of potentially present vulnerabilities that could not be exploited; specific recommendations for major or critical vulnerabilities plus general recommendations; and a complete, easy-to-interpret management summary, in the report or as a separate document.
Who runs TGV certification, the BCH or Santé Québec? (Qui délivre la certification TGV?)
Both names refer to the same function. The Bureau de certification et d'homologation (BCH) was created inside the MSSS by the health sector's network information officer and is described in the governing rule as the single point of entry for the certification process. Current attestation, certificate, agreement and self declaration templates are issued by the Bureau de certification of Santé Québec, and the contact address on those forms is certification@sante.quebec. Older MSSS-branded documents using BCH remain published and in force.
Do AI tools need TGV certification? (Les outils d'IA doivent-ils être certifiés TGV?)
Yes, where they meet the scope conditions. Nothing in the published documents exempts AI products, and the bureau's register of certified products includes a family for AI-based voice recognition and transcription solutions. An AI product that handles health or social services information, interfaces with a common-interest information asset, or is deployed across more than one establishment with web access falls under the same three scope conditions as any other technology product, and its model-facing surfaces are pulled into the penetration test by the orientation's criticality-based attack-vector rule.
Related reading
Sample penetration testing report (2026), to see the structure the bureau's eight required elements map onto.
Penetration testing cost in 2026 and the penetration test cost calculator, for scoping the annual TGV test.
HIPAA penetration testing requirements (2026), for suppliers selling into both Quebec and the United States.
The State of Penetration Testing 2026, for remediation timelines and finding rates.
Top penetration testing companies in Canada (2026), for the wider Canadian market context.
Web application penetration testing and Snipe, for how Stingrai runs the engagement.
Book your TGV penetration test
The penetration test is the one TGV requirement a Quebec healthtech founder or CTO cannot solve internally, and the one with the least slack in the schedule. It has to be white box, run against production or a production-equivalent environment, cover every role, come from a firm with Canadian representation and background-checked testers, produce a report with eight specific sections available in French to the bureau at no cost, and leave enough time to remediate before verification starts.
Book a free scoping call and we will map your role matrix and your integration surface to the bureau's requirements, or get a quote for a TGV-scoped engagement. Package details and what is included are on the pricing page.
References
Ministère de la Santé et des Services sociaux. _Certification: Trousse globale de vérification (TGV)._ Publication 24-715-38W, 2024. https://publications.msss.gouv.qc.ca/msss/document-003757/. The six-page official guide to the certification: definition, the steps before and after application, the verification stage, and the list of commitments a certified supplier takes on.
Bureau de certification. _Orientation concernant les tests d'intrusion._ https://www.msss.gouv.qc.ca/professionnels/documents/technologies-information/certification-produits-services/orientation-tests-intrusion.pdf. The dedicated penetration testing orientation: scope rules, box-colour rules, the six firm eligibility criteria, and the eight required report elements.
Bureau de certification. _Orientation sur le délai de remédiation des vulnérabilités._ https://www.msss.gouv.qc.ca/professionnels/documents/technologies-information/certification-produits-services/orientation-delai-remediation-vulnerabilites.pdf. The government remediation matrix by impact level and probability, in calendar days.
Bureau de certification de Santé Québec. _Attestation, certification TGV_ (BC-D0001-01). https://www.msss.gouv.qc.ca/professionnels/documents/technologies-information/certification-produits-services/BC_TGV_ATTESTATION.pdf. The signed attestation template, including the five-year validity and the nine annual commitments.
Bureau de certification de Santé Québec. _Certificat, certification du produit ou service technologique_ (BC_TGV_CERTIFICAT). https://www.msss.gouv.qc.ca/professionnels/documents/technologies-information/certification-produits-services/BC_TGV_CERTIFICAT.pdf. The one-page certificate template with issue and expiry dates.
Bureau de certification. _Formulaire d'attestation_ (gabarit, 24-715-27W). https://www.msss.gouv.qc.ca/professionnels/documents/technologies-information/certification-produits-services/gabarit-formulaire-attestation.pdf. The earlier MSSS-branded attestation template, useful for tracing which deadlines changed.
Santé Québec. _Entente, certification TGV_ (BC-D0002-01). https://www.msss.gouv.qc.ca/professionnels/documents/technologies-information/certification-produits-services/BC_TGV_ENTENTE_SQ_Fournisseur.pdf. The supplier agreement, including the C$15,000 fee excluding taxes and each party's undertakings.
Bureau de certification. _Autodéclaration, suivi et évaluation annuelle des engagements_ (BC-F0003-01). https://www.msss.gouv.qc.ca/professionnels/documents/technologies-information/certification-produits-services/gabarit-formulaire-autodeclaration-annuelle.pdf. The twelve-point annual self declaration, including the penetration test and remediation attestations.
Bureau de certification. _Formulaire pour une demande de certification TGV._ https://www.msss.gouv.qc.ca/professionnels/documents/technologies-information/certification-produits-services/Formulaire-demande-certification-tgv.xlsm. The official application workbook, source of the six-month penetration test recency question.
Ministère de la Santé et des Services sociaux. _Critères de vérification de la TGV._ https://www.msss.gouv.qc.ca/professionnels/technologies-information/certification-produits-et-services-technologiques/orientations-procedures-documents-utiles-certification/. The published verification criteria list, source of the 254 criteria across six domains and of criterion S16.02.
Bureau de certification et d'homologation. _Clause pour appel d'offres visant l'acquisition de produits et services technologiques dans le RSSS._ https://www.msss.gouv.qc.ca/professionnels/documents/technologies-information/certification-produits-services/clause-type-appels-offres-acquisition-technologiques.pdf. The standard tender clause, which states the pre-deployment certification obligation and names the five verified areas.
Ministère de la Santé et des Services sociaux. _À propos de la certification._ https://www.msss.gouv.qc.ca/professionnels/technologies-information/certification-produits-et-services-technologiques/a-propos-certification/. The bureau's mandate, the three mandatory-certification conditions, the five-year validity, the cost policy and the three-stage process with published durations.
Ministère de la Santé et des Services sociaux. _Applications certifiées._ https://www.msss.gouv.qc.ca/professionnels/technologies-information/certification-produits-et-services-technologiques/applications-certifiees/. The recognised product families, the definition of a major change, the notice period, and the version-numbering convention.
Bureau de certification de Santé Québec. _Tableau des produits et services technologiques certifiés par familles_, December 2025. https://www.msss.gouv.qc.ca/professionnels/documents/technologies-information/certification-produits-services/ListeDesPSTCertifiesActifs.pdf. The public register of certified products, with certification dates and provincial interoperability verifications.
Ministère de la Santé et des Services sociaux. _Règle particulière sur la certification des produits et services technologiques_ and _Circulaire 2013-026, cadre de gestion de la certification et de l'homologation._ https://www.msss.gouv.qc.ca/professionnels/documents/technologies-information/certification-produits-services/regle-particuliere-certification.pdf. The legal basis for certification and the definition of the certification bureau's role.
LégisQuébec. _Act respecting the protection of personal information in the private sector_, chapter P-39.1, as amended by Law 25. https://www.legisquebec.gouv.qc.ca/en/document/cs/p-39.1. Sections 3.1 to 3.8 on responsibilities, privacy impact assessments and confidentiality incidents, and section 10 on security measures.
Stingrai. _The State of Penetration Testing 2026._ https://www.stingrai.io/blog/state-of-penetration-testing-2026. 1,206 verified findings across 55 penetration tests, with severity distribution, false positive rate and remediation timelines.



