Local Public Administration · Portugal

Protecting public services requires governance, technology and continuity to work together.

Municipalities, parishes, municipal companies and municipal services share dependencies, but they do not have the same regulatory framework. We begin with the entity's actual circumstances and turn requirements into executable work and verifiable evidence.

Begin with the entity

Four contexts that require their own interpretation.

Territorial coordination matters, but it does not remove the need to identify each entity's responsibilities, assets, services and evidence.

01Cross-functional decision-making and coordination

Municipalities

Governance, citizen services, critical systems, suppliers, incident response and municipal continuity.

02Proportionality and dependencies

Parishes and parish unions

Proportionate measures, shared systems, email and access, backups, capability building and continuity of public service.

03Autonomy and services provided

Municipal companies

Activity and sector, independent governance, operational systems, third parties and evidence produced by the entity.

04Continuity and operational environments

Municipal services and water

Essential services, IT and OT, SCADA, remote access, maintenance suppliers, configurations and recovery.

Rigour before the answer

Neither assumptions nor paper-only compliance.

No presumed qualification

Sector or public status alone does not replace confirmation of scope, special criteria and the applicable procedure.

Proportionality with context

Size, services, criticality, dependencies and operational capability shape priorities and resources.

Evidence connected to implementation

A document alone does not prove that a measure has been implemented, tested, maintained and reviewed.

Qualification and applicable framework

Essential, important and relevant public entities do not mean the same thing.

The applicable category depends on the framework established by the RJCS, the entity's specific information and the official procedure. Public status or institutional designation alone cannot determine the outcome in advance.

Article 6 of the RJCS

Essential entity

A category assigned under Article 6, taking account of the qualification criteria and mechanisms applicable to the entity, its activity and the services it provides.

ApplicationIt is subject to the framework for essential entities, including the applicable management responsibilities and cybersecurity risk-management measures.
Article 6 of the RJCS

Important entity

A category also determined under Article 6 and the applicable procedure, rather than arising solely from the organization's size, sector or public designation.

ApplicationIt is subject to the framework for important entities, with its own obligations and a supervisory model distinct from that applying to essential entities.
Article 7 of the RJCS

Relevant public entity

This covers public entities that are not qualified as essential or important under Article 6 and are subsequently placed in one of the groups established in Article 7.

ApplicationIt implements the cybersecurity measures determined by the CNCS for the corresponding group, proportionately and under Article 33.

This explanation helps distinguish the different frameworks; it does not replace self-identification, official qualification or confirmation of the criteria applicable to the specific entity.

Management responsibility

Specialist support does not transfer the entity's responsibility.

For essential and important entities, Article 25 assigns specific duties to management, executive and administrative bodies. These rules must be applied according to the entity's category and actual structure, without automatically extending them to relevant public entities.

Duties requiring decisions and oversight

  1. 01Approve cybersecurity risk-management measures.
  2. 02Oversee the implementation of approved measures.
  3. 03Ensure compliance with obligations concerning supervision and implementation.
  4. 04Undertake regular training to understand and oversee risks and the measures adopted.

Management bodies

Decide, approve, oversee and ensure the resources and integration needed to embed cybersecurity in the entity's governance.

Cybersecurity Officer (RCS)

Supports governance and coordinates risk management and the performance of legally defined functions, without replacing the responsibility of the competent bodies.

Permanent Contact Point (PCP)

Ensures permanent availability and operational coordination under the applicable rules, coordinating with the RCS where the roles are not held by the same person.

Relevant public entities implement the measures determined by the CNCS for their respective group. Full application of the governance framework for essential and important entities must not be presumed without confirmation.

Integrated pathway

Comply, demonstrate and remain operational.

The work does not end with an assessment. Each movement prepares the next and leaves decisions and evidence that can be reviewed.

  1. 01

    Establish the framework

    Gather information on the entity, services, sector, size, dependencies and representation.

  2. 02

    Govern

    Define decision-makers, the Cybersecurity Officer (RCS), Permanent Contact Point (PCP), teams and suppliers.

  3. 03

    Implement

    Turn gaps into documentary and technical measures, owners, deadlines and acceptance criteria.

  4. 04

    Operate

    Integrate monitoring, support, incident management, communications and continuity.

  5. 05

    Demonstrate and improve

    Maintain evidence, test controls, measure outcomes and update risk and the roadmap.

From decision to implementation

Documentary, technical and operational capability.

Implementation must reflect the entity's actual architecture and services, not a universal catalog of measures.

Microsoft 365 and identity

  • Accounts and privileges
  • MFA and conditional access
  • Configuration and monitoring
  • User lifecycle

Infrastructure and networks

  • Inventory and architecture
  • Segmentation and remote access
  • Servers, endpoints and updates
  • Backups and recovery

Operations and incidents

  • Low-noise monitoring
  • Triage and escalation
  • Notification and coordination
  • Exercises and improvement

Services and third parties

  • Critical dependencies
  • ICT procurement requirements
  • Supplier access
  • Continuity of public services

Obligation, implementation and proof

Four connections that prevent paper-only compliance.

Each obligation should produce decisions, working instruments, implemented measures and proportionate evidence. The specific list depends on qualification, service, risk and the instructions applying to the entity.

Governance and roles

Obligation
Approve and oversee measures; define applicable responsibilities and roles.
Documents
Resolutions, policy, appointment instruments, responsibility matrix and mandate.
Measures
Reporting to governing bodies, allocated resources, decision channels and RCS/PCP coordination.
Evidence
Signed minutes and instruments, communications, review records, contact tests and training.

Risk and measures

Obligation
Manage risks affecting assets, services, dependencies and residual risk.
Documents
Inventory, methodology, risk matrix, treatment plan and roadmap.
Measures
Technical, operational and organizational controls with an owner, deadline and acceptance criterion.
Evidence
Configurations, records, test results, corrections, approvals and accepted residual risk.

Incidents and continuity

Obligation
Prevent, detect, handle, communicate and recover from incidents while maintaining service continuity.
Documents
Incident response, continuity and recovery plans, contacts, on-call arrangements and notification procedures.
Measures
Monitoring, triage, backups, recovery, alternative communications and exercises.
Evidence
Handled alerts, timelines, notifications, restoration tests, exercises and improvement actions.

Suppliers and ICT contracts

Obligation
Manage supply-chain risks and relationships with direct service providers.
Documents
Supplier assessment, security requirements, contract, SLA, exit plan and subcontracting provisions.
Measures
Least-privilege access, MFA, updates, logs, incident cooperation, audit and reversibility.
Evidence
Assessments, service reports, access records, corrections, tests, revocations and final handover.

Verifiable evidence

Demonstration requires more than storing files.

Useful evidence shows what was implemented, by whom, when, for which asset or service, and with what validation.

  1. 01Identified source, date, context and owner
  2. 02Connection between requirement, risk, measure and implementation
  3. 03Validation and integrity appropriate to the type of proof
  4. 04Defined updating and retention
  5. 05Documented gaps, exceptions and residual risk

Ten priority answers

Better decisions begin by removing false assumptions.

The following answers organize interpretation of the RJCS in local public administration. They provide information based on official sources and do not replace qualification by the competent authority, decisions by the entity's bodies or legal advice for a specific case.

01Is a municipality automatically an essential entity?

No. Municipal status places the entity within Public Administration, but does not in itself determine qualification as an essential entity.

Qualification follows Articles 6 to 8 of the RJCS. A municipality may be qualified as essential, important or a relevant public entity, depending on its responsibilities, digital integration, services, size, criticality and the competent authority's decision.

CautionDo not rely solely on the designation 'municipality' or population size to anticipate the outcome.

02Are parish councils covered by the RJCS?

Parishes form part of autonomous administration, which falls within the personal scope of the RJCS, but the specific framework should not be presumed without self-identification and qualification.

Size, services, shared dependencies and the criteria in Articles 6 and 7 shape the category and applicable measures. Small parishes should not be treated as though they automatically have the same framework as a municipality or an essential entity.

CautionPersonal scope, qualification and the level of measures are separate questions.

03Does a municipal company complete its own self-identification?

As a rule, yes, where it is an autonomous legal person, acts in its own name and has its own tax identity and representation.

The Regulation creates one provisional registration per entity, regardless of the number of sectors or subsectors. A municipality and municipal company should not be combined merely because of ownership, oversight or institutional dependence.

CautionAlways confirm legal personality, tax number, legal representation and which entity actually provides each service.

04Who can be the Cybersecurity Officer in a municipality?

Where the municipality is qualified as an essential or important entity, it must appoint a person who belongs to its management, executive or administrative bodies, or who reports organically and directly to them.

The appointed person must be able to propose measures, inform and support the competent bodies, ensure risk management and the annual report, and coordinate the Permanent Contact Point (PCP) where that role is held by someone else.

CautionAuthority to make the appointment and the reporting model must be confirmed against the local authority's organization and specific rules.

05Can the CISO or vCISO be external?

An external CISO or vCISO may support governance, risk and implementation, but should not be presented as automatically eligible to fulfill the statutory Cybersecurity Officer (RCS) role.

Article 31 requires the appointed person to be a member of a management, executive or administrative body, or to report organically and directly to it. The law does not expressly resolve every external-delivery model, so the contract, named appointment, reporting, autonomy, resources and conflicts of interest require specific validation.

CautionUntil there is unequivocal official guidance for the specific model, distinguish CISOaaS/vCISO services from statutory appointment as RCS.

06Do a municipality and its municipal services make a single submission?

It depends on whether there is one legal entity or separate entities. The operational rule is one registration per entity, not one registration per service or sector.

Municipal services without autonomous legal personality may be included in the municipality's self-identification, identifying the relevant sectors and services. A municipal company or other autonomous legal person should generally have its own registration.

CautionMap legal personality, tax number, representation, assets, workers and responsibility for service delivery before submitting.

07How should evidence be prepared for MyCiber?

Organize proof through the connection between requirement, risk, measure, implementation and validation, rather than accumulating files without context.

For each item of evidence, identify the entity, asset or service, owner, source, date, period, approval, integrity and review status. Combine documents with operational records, configurations, test results, minutes, reports, tickets and proof of correction appropriate to the control.

CautionDo not submit sensitive information indiscriminately: confirm the request, classification, channel, necessity and minimization before communicating it.

08Which decisions require approval by the competent bodies?

In essential and important entities, management, executive and administrative bodies approve risk-management measures and oversee their implementation.

Decisions on policies, responsibilities, accepted risk, priorities, resources, measures, exceptions, continuity, incident response, critical procurement and oversight should be formalised under the applicable internal powers. Role appointments and powers of representation must also have a valid basis.

CautionArticle 25 does not allow the bodies' responsibility to be transferred to a consultant; authority for each decision must be confirmed within the entity's organizational framework.

09How should the RJCS, GDPR and RGPC be coordinated?

Treat the three frameworks as coordinated layers of governance while preserving their own purposes, owners, decisions and evidence.

The RJCS addresses risks to networks and systems and service continuity; the GDPR protects personal data and data-subject rights; the RGPC organizes corruption prevention, integrity, training, risk and whistleblowing. An incident, supplier or process may activate all three without one assessment or notification replacing the others.

CautionUse a common matrix of processes, assets, data, risks, controls, owners and obligations while keeping legal bases, deadlines and competent authorities separate.

10Which cybersecurity requirements should be included in ICT contracts?

Requirements should reflect the risk, service and access granted to the supplier, with verifiable obligations throughout the contract lifecycle and at exit.

As appropriate, include scope and assets, responsibilities, access control and MFA, data location and protection, logs, vulnerabilities and updates, subcontracting, incident notification and cooperation, continuity and recovery, service levels, testing, audit, evidence, return or deletion of information, and transition at contract end.

CautionAvoid generic clauses: define acceptance criteria, deadlines, evidence, oversight and consequences, aligned with the procurement procedure and validated by legal, technical, data-protection and compliance functions.

The answers reflect the official sources available. Qualification and instructions applying to the specific entity remain the responsibility of the competent cybersecurity authority.

Frequently asked questions

Answers without shortcuts.

Are all local authorities automatically covered by the RJCS?

An outcome should not be presumed solely from the entity's designation. Its type, services, applicable criteria and the self-identification and qualification procedure must be confirmed.

Can a municipality, municipal company and municipal service use the same analysis?

They may share context and dependencies, but legal personality, activity, governance, assets and evidence must be assessed for each entity and service.

Is documentation sufficient to demonstrate compliance?

No. Documentation must correspond to implemented and maintained measures, supported by records, configurations, tests, decisions and other appropriate evidence.

What is the difference between an essential, important and relevant public entity?

Essential and important entities are qualified under Article 6 of the RJCS. A relevant public entity is a public entity not qualified as essential or important and placed in one of the groups established in Article 7, with measures determined by the CNCS under Article 33.

Are management responsibilities the same across all three categories?

They should not be generalized. Article 25 establishes specific duties for management, executive and administrative bodies of essential and important entities. Relevant public entities implement measures determined by the CNCS for their group, and the specific framework must be confirmed.

Does Cyberprotech replace the competent authority's decision?

No. Cyberprotech organizes information, identifies uncertainty and supports preparation and implementation. Official qualification belongs to the competent authority.

Primary sources

Always confirm against the official source.

Information published on . Content and references reviewed on . This information supports initial guidance and should be confirmed against the applicable framework and official instructions for each entity.

Next step

Begin with your entity's actual context.

Use the RJCS Checker to organize what you already know, or first review how the supported process works.