Local Public Administration · Municipal companies

A municipal company needs its own governance and evidence.

Its relationship with the municipality does not remove the company's identity, activity, systems, contracts and responsibilities. Cybersecurity should support the services actually delivered and their continuity.

Entity, activity and sector

Activity determines risk more than designation.

A municipal company may operate services with very different impacts and depend on administrative systems, citizen platforms, field equipment or operational technology. The framework should confirm legal personality, sector, size, services and applicable criteria without assuming that the municipal relationship automatically produces a qualification.

  • Legal personality, activity, sector and size assessed together
  • Company governance distinguished from municipal governance
  • Administrative and operational systems included in the same map
  • Evidence produced and retained by the responsible entity

Govern before delegating

Clear responsibility, specialist support and effective reporting.

Governance connects decisions, risk, resources and oversight. It must not exist only in an organization chart or an isolated document.

Own governing bodies and responsibilities

The company's competent bodies should understand risk, approve priorities, ensure resources and oversee measures applicable to the entity and the services it manages.

Coordination without dilution

The municipality may share guidance, technology or capability, but each entity's boundaries, decision-makers, access, responsibilities, contacts and evidence must remain clear.

Effective roles and channels

Where applicable under the confirmed framework, the Cybersecurity Officer (RCS) and Permanent Contact Point (PCP) should have suitable reporting, resources, information and operational coordination.

Services and dependencies

Begin with the services the company delivers and operates.

Transport, waste, environment, facilities, culture, housing and other services create different dependencies and impacts. The security architecture should reflect actual activity.

Management and digital services

  • Identity, email and collaboration
  • Finance, human resources and procurement
  • Portals, citizen services and payments
  • Document management and integrations

Field operations

  • Equipment and mobility
  • Facilities and operational teams
  • Collection, control or supervision systems
  • Communications and remote access

Sectors and impact

  • Transport and mobility
  • Waste, environment and public space
  • Water, sanitation and energy where applicable
  • Housing, culture and other local services

Third parties and service chain

  • Software, cloud and telecommunications
  • Maintenance and specialist support
  • Operational subcontracting
  • Access, responsibilities and contractual continuity

Municipal implementation

From the initial assessment to continuous improvement.

Each stage should produce a decision, verifiable implementation or evidence that allows progress to be monitored.

  1. 01

    Characterise the entity

    Confirm activity, sector, size, services, governance and relationships with the municipality and other entities.

  2. 02

    Map operations

    Connect services, processes, assets, data, facilities, teams, suppliers and the impact of unavailability.

  3. 03

    Treat risk

    Prioritize documentary, identity, infrastructure, endpoint, network, backup, monitoring and third-party measures.

  4. 04

    Prepare response and continuity

    Define decisions, contacts, containment, communication, recovery and alternatives for priority services.

  5. 05

    Demonstrate and improve

    Retain the company's evidence, test controls and update risks, contracts, exceptions and the roadmap.

Usable outcomes

Deliverables that support decision-making and implementation.

A municipal company needs its own instruments, coordinated with the municipality but connected to its governance, systems, contracts, operations and evidence.

  1. 01Framework, activity, sector and assumptions matrix
  2. 02Map of services, processes, assets and dependencies
  3. 03Governance model and coordination with the municipality
  4. 04Company gap assessment and roadmap
  5. 05Supplier and external-access requirements and controls
  6. 06Incident, communication, recovery and continuity plans

Entity evidence

Three perspectives that corroborate one another.

Governance

Resolutions, responsibilities, priorities, resources, risk acceptance and oversight by competent bodies.

Technical and contractual

Inventories, configurations, records, tests, corrections, contracts, requirements and third-party access control.

Operational

Events, incidents, exercises, response times, recovery and continuity of delivered services.

First steps

Begin with enough information to make better decisions.

The initial assessment should separate what is common to the municipal group from what the company decides, implements and demonstrates.

Open the RJCS Checker
  1. 01Confirm legal personality, activity, sector, size and services delivered
  2. 02Separate proprietary, shared and third-party-operated systems
  3. 03Identify services with the greatest impact on users and the territory
  4. 04Review remote access, support contracts, backups and recovery
  5. 05Organize uncertainties and assumptions in the RJCS Checker

Frequently asked questions

Provide guidance without anticipating official decisions.

Does a municipal company automatically have the same framework as the municipality?

This should not be assumed. Legal personality, activity, sector, size, services and applicable criteria should be assessed for the entity itself. Official qualification belongs to the competent authority.

Can it use the municipality's policies and procedures?

A shared basis may be used where appropriate, but documents should reflect the municipal company's actual governing bodies, responsibilities, systems, suppliers, risks and operations.

Are operational systems and field equipment in scope?

They should be considered when they support the entity's services and processes. The assessment should not be limited to administrative systems or Microsoft 365.

Which evidence should belong to the company?

Evidence demonstrating its decisions, measures, configurations, contracts, tests, incidents and continuity. Shared evidence should clearly identify its scope and the entities covered.

Primary sources

Always confirm against the official source.

Information published on . Content and references reviewed on . This information supports initial guidance and should be confirmed against the applicable framework and official instructions for each entity.

Next step

Understand the municipal company as an operational entity.

Confirm the framework, identify services and dependencies, and turn priorities into verifiable work.