Local Public Administration · RCS

Cybersecurity Officer in local authorities: appointment must create capability.

Where applicable under the confirmed framework, the Cybersecurity Officer (RCS) should be connected to governance, receive information and resources, and be able to oversee risks, measures, incidents and improvement.

Role and governance

The role extends beyond the appointment instrument.

The formal act should be supported by organizational and operational conditions. The solution depends on the entity's category, structure and applicable interpretation; it should not be copied mechanically between entities.

  • Reporting and access to competent bodies
  • Access to information and responsible people
  • Resources and availability appropriate to risk
  • Documented coordination with the PCP, teams and providers

Govern before delegating

Clear responsibility, specialist support and effective reporting.

Governance connects decisions, risk, resources and oversight. It must not exist only in an organization chart or an isolated document.

Competent bodies

Retain the applicable responsibilities for approval, oversight, decisions and provision of resources.

Cybersecurity Officer (RCS)

Coordinates and oversees risk management and the functions established in the applicable model, with effective reporting and verifiable records.

Permanent Contact Point (PCP)

Ensures permanent availability and operational coordination. It may coordinate with the RCS, but is a distinct role and should be treated accordingly.

Services and dependencies

A role connected to decisions, risk and implementation.

The appointment should correspond to an actual ability to report, access information, coordinate and oversee.

Mandate

  • Appointment instrument
  • Responsibilities and boundaries
  • Direct reporting
  • Substitution and continuity

Access and resources

  • Risk information
  • Internal contacts
  • Tools and support
  • Training and updating

Coordination

  • ICT and security teams
  • PCP and incident response
  • Suppliers and shared services
  • Data protection and continuity

Demonstration

  • Reports and decisions
  • Risk register
  • Monitored measures
  • Reviews and improvement

Municipal implementation

From the initial assessment to continuous improvement.

Each stage should produce a decision, verifiable implementation or evidence that allows progress to be monitored.

  1. 01

    Confirm

    Validate the framework and requirements applying to the entity.

  2. 02

    Design

    Define mandate, reporting, resources, contacts and coordination.

  3. 03

    Appoint

    Formally appoint the natural person and record the elements required by the applicable model.

  4. 04

    Perform

    Oversee risks, measures, incidents, evidence and decisions.

  5. 05

    Review

    Assess capability, conflicts, availability, outcomes and the need for change.

Usable outcomes

Deliverables that support decision-making and implementation.

The role requires a mandate, resources, information and records that demonstrate its effective performance.

  1. 01Proposed mandate and appointment instrument
  2. 02Reporting, information and contact matrix
  3. 03Role activity plan
  4. 04Register of risks, decisions and monitored measures
  5. 05Coordination model with the PCP and incident response
  6. 06Periodic report and review record

Effective performance

Three perspectives that corroborate one another.

Formal

Documented appointment, acceptance, mandate, reporting and substitution.

Functional

Demonstrable access, meetings, decisions, coordination and interventions.

Evolving

Reviews, training, improvement and adaptation of the role to risk.

First steps

Begin with enough information to make better decisions.

The first decision is not choosing an acronym. It is confirming the framework, understanding the structure and ensuring the appointed person can perform the role.

Open the RJCS Checker
  1. 01Confirm whether and how the role applies to the entity
  2. 02Identify the reporting line and decision-makers
  3. 03Assess availability, competencies and conflicts
  4. 04Define coordination with the PCP, ICT, suppliers and data protection
  5. 05Document the mandate, resources and expected evidence

Frequently asked questions

Provide guidance without anticipating official decisions.

Must every local authority appoint an RCS?

The same answer should not be generalized to every entity. First confirm the framework, category and rules applying to the specific entity.

Does the RCS replace the governing bodies' responsibility?

No. The role supports coordination and oversight without removing the decision and supervision duties assigned to competent bodies.

Are the RCS and PCP the same role?

No. The Cybersecurity Officer (RCS) and Permanent Contact Point (PCP) have different purposes, although the organization may provide for coordination between them.

Can an external person be the RCS?

The admissibility of an external model depends on the interpretation and requirements applying to the specific case. Cyberprotech awaits specific CNCS guidance and does not present this possibility as an automatic conclusion.

Primary sources

Always confirm against the official source.

Information published on . This information supports initial guidance and should be confirmed against the applicable framework and official instructions for each entity.

Next step

Structure the role before formalising the appointment.

Clarify reporting, resources, availability, coordination and boundaries according to the specific entity.