Suitably Qualified and Experienced Person (SQEP)
Independent security architecture endorsement for Singapore Government, CII operators, and regulated enterprise systems. We sit between the System Integrator and the ACISO — endorsing design, supporting sign-off, and providing assurance through every stage of the project lifecycle.
What Is a Suitably Qualified and Experienced Person?
A SQEP is the independent security professional accountable for endorsing a system's security architecture and ensuring it meets the Authority's security requirements throughout its lifecycle — from initial design, through implementation and acceptance testing, into production, and across every annual audit cycle.
For Singapore Government projects, Critical Information Infrastructure (CII) operators, and MAS-regulated systems, engaging a SQEP is mandated to safeguard the integrity, neutrality, and quality of every security decision. The SQEP interprets security requirements, endorses design documents, supports security acceptance testing, justifies waivers when needed, and stands behind every assurance provided.
The SQEP Role: Independent. Embedded. Accountable.
Where the SQEP sits in the project ecosystem.
Our SQEP consultants sit between the System Integrator delivering the solution and the Agency Chief Information Security Officer (ACISO) signing off on residual risk on behalf of the Authority. This separation preserves the neutrality the Authority requires.
System Integrator
Designs and implements the solution to meet business and technical requirements. Responsible for build quality and delivery.
Bravix SQEP
Endorses security architecture, validates compliance, justifies waivers, provides go-live endorsement and annual recertification support. The independent assurance layer.
ACISO
Accepts residual risk on behalf of the Authority. Signs off based on SQEP endorsement. Owns the final risk decision.
Scope of SQEP Services
End-to-end assurance across the project lifecycle.
Security Architecture Endorsement
Design review and endorsement of security architecture documents. Zone and conduit design, control selection, residual risk identification.
IM8 Compliance
Instruction Manual 8 (IM8) for Singapore Government ICT systems. Requirements mapping, gap analysis, and compliance documentation support.
MAS TRM Alignment
MAS Technology Risk Management guidelines for financial institutions. Control mapping, risk assessment, and regulatory examination preparation.
Waiver Justification
Risk-based justification for security exceptions. Documented risk acceptance with compensating controls and mitigation roadmaps.
Security Acceptance Testing
Witness and endorse security acceptance testing performed by the System Integrator. Verify control implementation matches design intent.
Annual Recertification
Ongoing assurance through annual security recertification. Architecture drift detection, control validation, and compliance maintenance.
Our SQEP Credentials
Certifications that meet Singapore's regulatory expectations.
CREST Certified
CREST organisational accreditation with individually certified consultants. The gold standard for offensive security in Singapore.
CISSP-ISSAP
Information Systems Security Architecture Professional certification. Security architecture design and evaluation expertise.
CSRO Licensed
Cyber Security Readiness Officer licensed under Singapore's CSA framework. Local regulatory familiarity built in.
ISO 27001
ISO 27001 certified organisation. Information security management system aligned with international standards.
Our Approach
Structured for every stage of the project lifecycle.
Design Review
Architecture document review, requirements mapping (IM8, MAS TRM, PDPA), threat model validation, risk identification.
Implementation Oversight
Control selection guidance, design refinement, vendor assessment, security testing plan endorsement.
Acceptance and Go-Live
Security acceptance testing witness, waiver justification, go-live endorsement letter to ACISO.
Ongoing Assurance
Annual recertification, architecture drift review, control validation, regulatory update impact assessment.
Engage Our SQEP
Tell us about your project. We'll confirm scope, timeline, and how we can support your Authority sign-off.