Local Public Administration · Portugal
Protecting public services requires governance, technology and continuity to work together.
Municipalities, parishes, municipal companies and municipal services share dependencies, but they do not have the same regulatory framework. We begin with the entity's actual circumstances and turn requirements into executable work and verifiable evidence.
Begin with the entity
Four contexts that require their own interpretation.
Territorial coordination matters, but it does not remove the need to identify each entity's responsibilities, assets, services and evidence.
Municipalities
Governance, citizen services, critical systems, suppliers, incident response and municipal continuity.
Parishes and parish unions
Proportionate measures, shared systems, email and access, backups, capability building and continuity of public service.
Municipal companies
Activity and sector, independent governance, operational systems, third parties and evidence produced by the entity.
Municipal services and water
Essential services, IT and OT, SCADA, remote access, maintenance suppliers, configurations and recovery.
Cross-cutting questions
Four guides for preparing roles, data and response.
These subjects cut across different local public-sector entities. Each guide addresses a specific need without replacing confirmation of the applicable framework.
MyCiber for local authorities
Organize the entity, representation, services, data, roles and evidence before submission.
Prepare the process →GovernanceMunicipal CISOaaS
Structure oversight, risk, roadmap and reporting without diluting the entity's responsibilities.
Explore the model →RoleCybersecurity Officer
Understand the role's mandate, reporting, resources, coordination and evidence within local authorities.
Explore the role →OperationsPCP and incident response
Connect availability, triage, escalation, notification, recovery and improvement.
Prepare the response →Rigour before the answer
Neither assumptions nor paper-only compliance.
No presumed qualification
Sector or public status alone does not replace confirmation of scope, special criteria and the applicable procedure.
Proportionality with context
Size, services, criticality, dependencies and operational capability shape priorities and resources.
Evidence connected to implementation
A document alone does not prove that a measure has been implemented, tested, maintained and reviewed.
Qualification and applicable framework
Essential, important and relevant public entities do not mean the same thing.
The applicable category depends on the framework established by the RJCS, the entity's specific information and the official procedure. Public status or institutional designation alone cannot determine the outcome in advance.
Essential entity
A category assigned under Article 6, taking account of the qualification criteria and mechanisms applicable to the entity, its activity and the services it provides.
Important entity
A category also determined under Article 6 and the applicable procedure, rather than arising solely from the organization's size, sector or public designation.
Relevant public entity
This covers public entities that are not qualified as essential or important under Article 6 and are subsequently placed in one of the groups established in Article 7.
This explanation helps distinguish the different frameworks; it does not replace self-identification, official qualification or confirmation of the criteria applicable to the specific entity.
Management responsibility
Specialist support does not transfer the entity's responsibility.
For essential and important entities, Article 25 assigns specific duties to management, executive and administrative bodies. These rules must be applied according to the entity's category and actual structure, without automatically extending them to relevant public entities.
Duties requiring decisions and oversight
- 01Approve cybersecurity risk-management measures.
- 02Oversee the implementation of approved measures.
- 03Ensure compliance with obligations concerning supervision and implementation.
- 04Undertake regular training to understand and oversee risks and the measures adopted.
Management bodies
Decide, approve, oversee and ensure the resources and integration needed to embed cybersecurity in the entity's governance.
Cybersecurity Officer (RCS)
Supports governance and coordinates risk management and the performance of legally defined functions, without replacing the responsibility of the competent bodies.
Permanent Contact Point (PCP)
Ensures permanent availability and operational coordination under the applicable rules, coordinating with the RCS where the roles are not held by the same person.
Relevant public entities implement the measures determined by the CNCS for their respective group. Full application of the governance framework for essential and important entities must not be presumed without confirmation.
Integrated pathway
Comply, demonstrate and remain operational.
The work does not end with an assessment. Each movement prepares the next and leaves decisions and evidence that can be reviewed.
- 01
Establish the framework
Gather information on the entity, services, sector, size, dependencies and representation.
- 02
Govern
Define decision-makers, the Cybersecurity Officer (RCS), Permanent Contact Point (PCP), teams and suppliers.
- 03
Implement
Turn gaps into documentary and technical measures, owners, deadlines and acceptance criteria.
- 04
Operate
Integrate monitoring, support, incident management, communications and continuity.
- 05
Demonstrate and improve
Maintain evidence, test controls, measure outcomes and update risk and the roadmap.
From decision to implementation
Documentary, technical and operational capability.
Implementation must reflect the entity's actual architecture and services, not a universal catalog of measures.
Microsoft 365 and identity
- Accounts and privileges
- MFA and conditional access
- Configuration and monitoring
- User lifecycle
Infrastructure and networks
- Inventory and architecture
- Segmentation and remote access
- Servers, endpoints and updates
- Backups and recovery
Operations and incidents
- Low-noise monitoring
- Triage and escalation
- Notification and coordination
- Exercises and improvement
Services and third parties
- Critical dependencies
- ICT procurement requirements
- Supplier access
- Continuity of public services
Obligation, implementation and proof
Four connections that prevent paper-only compliance.
Each obligation should produce decisions, working instruments, implemented measures and proportionate evidence. The specific list depends on qualification, service, risk and the instructions applying to the entity.
Governance and roles
- Obligation
- Approve and oversee measures; define applicable responsibilities and roles.
- Documents
- Resolutions, policy, appointment instruments, responsibility matrix and mandate.
- Measures
- Reporting to governing bodies, allocated resources, decision channels and RCS/PCP coordination.
- Evidence
- Signed minutes and instruments, communications, review records, contact tests and training.
Risk and measures
- Obligation
- Manage risks affecting assets, services, dependencies and residual risk.
- Documents
- Inventory, methodology, risk matrix, treatment plan and roadmap.
- Measures
- Technical, operational and organizational controls with an owner, deadline and acceptance criterion.
- Evidence
- Configurations, records, test results, corrections, approvals and accepted residual risk.
Incidents and continuity
- Obligation
- Prevent, detect, handle, communicate and recover from incidents while maintaining service continuity.
- Documents
- Incident response, continuity and recovery plans, contacts, on-call arrangements and notification procedures.
- Measures
- Monitoring, triage, backups, recovery, alternative communications and exercises.
- Evidence
- Handled alerts, timelines, notifications, restoration tests, exercises and improvement actions.
Suppliers and ICT contracts
- Obligation
- Manage supply-chain risks and relationships with direct service providers.
- Documents
- Supplier assessment, security requirements, contract, SLA, exit plan and subcontracting provisions.
- Measures
- Least-privilege access, MFA, updates, logs, incident cooperation, audit and reversibility.
- Evidence
- Assessments, service reports, access records, corrections, tests, revocations and final handover.
Verifiable evidence
Demonstration requires more than storing files.
Useful evidence shows what was implemented, by whom, when, for which asset or service, and with what validation.
- 01Identified source, date, context and owner
- 02Connection between requirement, risk, measure and implementation
- 03Validation and integrity appropriate to the type of proof
- 04Defined updating and retention
- 05Documented gaps, exceptions and residual risk
Ten priority answers
Better decisions begin by removing false assumptions.
The following answers organize interpretation of the RJCS in local public administration. They provide information based on official sources and do not replace qualification by the competent authority, decisions by the entity's bodies or legal advice for a specific case.
01Is a municipality automatically an essential entity?
No. Municipal status places the entity within Public Administration, but does not in itself determine qualification as an essential entity.
Qualification follows Articles 6 to 8 of the RJCS. A municipality may be qualified as essential, important or a relevant public entity, depending on its responsibilities, digital integration, services, size, criticality and the competent authority's decision.
CautionDo not rely solely on the designation 'municipality' or population size to anticipate the outcome.
02Are parish councils covered by the RJCS?
Parishes form part of autonomous administration, which falls within the personal scope of the RJCS, but the specific framework should not be presumed without self-identification and qualification.
Size, services, shared dependencies and the criteria in Articles 6 and 7 shape the category and applicable measures. Small parishes should not be treated as though they automatically have the same framework as a municipality or an essential entity.
CautionPersonal scope, qualification and the level of measures are separate questions.
03Does a municipal company complete its own self-identification?
As a rule, yes, where it is an autonomous legal person, acts in its own name and has its own tax identity and representation.
The Regulation creates one provisional registration per entity, regardless of the number of sectors or subsectors. A municipality and municipal company should not be combined merely because of ownership, oversight or institutional dependence.
CautionAlways confirm legal personality, tax number, legal representation and which entity actually provides each service.
04Who can be the Cybersecurity Officer in a municipality?
Where the municipality is qualified as an essential or important entity, it must appoint a person who belongs to its management, executive or administrative bodies, or who reports organically and directly to them.
The appointed person must be able to propose measures, inform and support the competent bodies, ensure risk management and the annual report, and coordinate the Permanent Contact Point (PCP) where that role is held by someone else.
CautionAuthority to make the appointment and the reporting model must be confirmed against the local authority's organization and specific rules.
05Can the CISO or vCISO be external?
An external CISO or vCISO may support governance, risk and implementation, but should not be presented as automatically eligible to fulfill the statutory Cybersecurity Officer (RCS) role.
Article 31 requires the appointed person to be a member of a management, executive or administrative body, or to report organically and directly to it. The law does not expressly resolve every external-delivery model, so the contract, named appointment, reporting, autonomy, resources and conflicts of interest require specific validation.
CautionUntil there is unequivocal official guidance for the specific model, distinguish CISOaaS/vCISO services from statutory appointment as RCS.
06Do a municipality and its municipal services make a single submission?
It depends on whether there is one legal entity or separate entities. The operational rule is one registration per entity, not one registration per service or sector.
Municipal services without autonomous legal personality may be included in the municipality's self-identification, identifying the relevant sectors and services. A municipal company or other autonomous legal person should generally have its own registration.
CautionMap legal personality, tax number, representation, assets, workers and responsibility for service delivery before submitting.
07How should evidence be prepared for MyCiber?
Organize proof through the connection between requirement, risk, measure, implementation and validation, rather than accumulating files without context.
For each item of evidence, identify the entity, asset or service, owner, source, date, period, approval, integrity and review status. Combine documents with operational records, configurations, test results, minutes, reports, tickets and proof of correction appropriate to the control.
CautionDo not submit sensitive information indiscriminately: confirm the request, classification, channel, necessity and minimization before communicating it.
08Which decisions require approval by the competent bodies?
In essential and important entities, management, executive and administrative bodies approve risk-management measures and oversee their implementation.
Decisions on policies, responsibilities, accepted risk, priorities, resources, measures, exceptions, continuity, incident response, critical procurement and oversight should be formalised under the applicable internal powers. Role appointments and powers of representation must also have a valid basis.
CautionArticle 25 does not allow the bodies' responsibility to be transferred to a consultant; authority for each decision must be confirmed within the entity's organizational framework.
09How should the RJCS, GDPR and RGPC be coordinated?
Treat the three frameworks as coordinated layers of governance while preserving their own purposes, owners, decisions and evidence.
The RJCS addresses risks to networks and systems and service continuity; the GDPR protects personal data and data-subject rights; the RGPC organizes corruption prevention, integrity, training, risk and whistleblowing. An incident, supplier or process may activate all three without one assessment or notification replacing the others.
CautionUse a common matrix of processes, assets, data, risks, controls, owners and obligations while keeping legal bases, deadlines and competent authorities separate.
10Which cybersecurity requirements should be included in ICT contracts?
Requirements should reflect the risk, service and access granted to the supplier, with verifiable obligations throughout the contract lifecycle and at exit.
As appropriate, include scope and assets, responsibilities, access control and MFA, data location and protection, logs, vulnerabilities and updates, subcontracting, incident notification and cooperation, continuity and recovery, service levels, testing, audit, evidence, return or deletion of information, and transition at contract end.
CautionAvoid generic clauses: define acceptance criteria, deadlines, evidence, oversight and consequences, aligned with the procurement procedure and validated by legal, technical, data-protection and compliance functions.
The answers reflect the official sources available. Qualification and instructions applying to the specific entity remain the responsibility of the competent cybersecurity authority.
From framework to action
Continue along the pathway that matches the entity's current position.
Each link addresses a different need: explore the framework, prepare MyCiber, obtain practical instruments, understand implementation capabilities or begin supported work.
MyCiber Assessment
Organize the starting point, gaps and priorities before using the official platform.
Prepare MyCiber →KnowledgeKnowledge Center
Explore the RJCS, Regulation No. 756/2026, MyCiber, roles, obligations and evidence.
Explore knowledge →ResourcesResource Library
Use versioned guides, checklists, templates and instruments to support implementation.
Open resources →ImplementationSolutions
Connect governance, technical implementation, operations, continuity, training, SOC and CSIRT.
Explore capabilities →SupportSupported process
Understand the stages, data protection, human review and limits of supported RJCS work.
Understand the process →Frequently asked questions
Answers without shortcuts.
Are all local authorities automatically covered by the RJCS?
An outcome should not be presumed solely from the entity's designation. Its type, services, applicable criteria and the self-identification and qualification procedure must be confirmed.
Can a municipality, municipal company and municipal service use the same analysis?
They may share context and dependencies, but legal personality, activity, governance, assets and evidence must be assessed for each entity and service.
Is documentation sufficient to demonstrate compliance?
No. Documentation must correspond to implemented and maintained measures, supported by records, configurations, tests, decisions and other appropriate evidence.
What is the difference between an essential, important and relevant public entity?
Essential and important entities are qualified under Article 6 of the RJCS. A relevant public entity is a public entity not qualified as essential or important and placed in one of the groups established in Article 7, with measures determined by the CNCS under Article 33.
Are management responsibilities the same across all three categories?
They should not be generalized. Article 25 establishes specific duties for management, executive and administrative bodies of essential and important entities. Relevant public entities implement measures determined by the CNCS for their group, and the specific framework must be confirmed.
Does Cyberprotech replace the competent authority's decision?
No. Cyberprotech organizes information, identifies uncertainty and supports preparation and implementation. Official qualification belongs to the competent authority.
Primary sources
Always confirm against the official source.
Informational content. It is not an official qualification, legal opinion or substitute for the powers of the entity and the competent authority.
