SQEP Services
07 — SQEP SERVICES

Suitably Qualified and Experienced Person (SQEP)

Independent security architecture endorsement for Singapore Government, CII operators, and regulated enterprise systems. We sit between the System Integrator and the ACISO — endorsing design, supporting sign-off, and providing assurance through every stage of the project lifecycle.

What Is a Suitably Qualified and Experienced Person?

A SQEP is the independent security professional accountable for endorsing a system's security architecture and ensuring it meets the Authority's security requirements throughout its lifecycle — from initial design, through implementation and acceptance testing, into production, and across every annual audit cycle.

For Singapore Government projects, Critical Information Infrastructure (CII) operators, and MAS-regulated systems, engaging a SQEP is mandated to safeguard the integrity, neutrality, and quality of every security decision. The SQEP interprets security requirements, endorses design documents, supports security acceptance testing, justifies waivers when needed, and stands behind every assurance provided.

The SQEP Role: Independent. Embedded. Accountable.

Where the SQEP sits in the project ecosystem.

Our SQEP consultants sit between the System Integrator delivering the solution and the Agency Chief Information Security Officer (ACISO) signing off on residual risk on behalf of the Authority. This separation preserves the neutrality the Authority requires.

System Integrator

Designs and implements the solution to meet business and technical requirements. Responsible for build quality and delivery.

Bravix SQEP

Endorses security architecture, validates compliance, justifies waivers, provides go-live endorsement and annual recertification support. The independent assurance layer.

ACISO

Accepts residual risk on behalf of the Authority. Signs off based on SQEP endorsement. Owns the final risk decision.

Scope of SQEP Services

End-to-end assurance across the project lifecycle.

Security Architecture Endorsement

Design review and endorsement of security architecture documents. Zone and conduit design, control selection, residual risk identification.

IM8 Compliance

Instruction Manual 8 (IM8) for Singapore Government ICT systems. Requirements mapping, gap analysis, and compliance documentation support.

MAS TRM Alignment

MAS Technology Risk Management guidelines for financial institutions. Control mapping, risk assessment, and regulatory examination preparation.

Waiver Justification

Risk-based justification for security exceptions. Documented risk acceptance with compensating controls and mitigation roadmaps.

Security Acceptance Testing

Witness and endorse security acceptance testing performed by the System Integrator. Verify control implementation matches design intent.

Annual Recertification

Ongoing assurance through annual security recertification. Architecture drift detection, control validation, and compliance maintenance.

Our SQEP Credentials

Certifications that meet Singapore's regulatory expectations.

CREST Certified

CREST organisational accreditation with individually certified consultants. The gold standard for offensive security in Singapore.

CISSP-ISSAP

Information Systems Security Architecture Professional certification. Security architecture design and evaluation expertise.

CSRO Licensed

Cyber Security Readiness Officer licensed under Singapore's CSA framework. Local regulatory familiarity built in.

ISO 27001

ISO 27001 certified organisation. Information security management system aligned with international standards.

Our Approach

Structured for every stage of the project lifecycle.

01

Design Review

Architecture document review, requirements mapping (IM8, MAS TRM, PDPA), threat model validation, risk identification.

02

Implementation Oversight

Control selection guidance, design refinement, vendor assessment, security testing plan endorsement.

03

Acceptance and Go-Live

Security acceptance testing witness, waiver justification, go-live endorsement letter to ACISO.

04

Ongoing Assurance

Annual recertification, architecture drift review, control validation, regulatory update impact assessment.

Engage Our SQEP

Tell us about your project. We'll confirm scope, timeline, and how we can support your Authority sign-off.

Get in Touch