
The transposed NIS2 directive in French law changes the game for territorial information systems management. Local authorities no longer choose to invest in cybersecurity: they are legally obliged to do so, with penalties at stake. This regulatory framework redistributes the budgetary and technical priorities of the entire local public sector.
NIS2 Obligations and Cybersecurity of Local Authorities
The classification of local authorities into two levels of requirements constitutes the major structural change. Regions, departments, metropolitan areas, urban communities, and municipalities with more than 30,000 inhabitants are now classified as essential entities, subject to the strictest regime. Agglomeration communities, communities of communes, and certain SDIS fall under the status of important entities, with an intermediate level.
The obligations are not limited to a declaration of intent. Each concerned local authority must formalize an information systems security policy, conduct a documented risk analysis, and establish a business continuity plan for its critical digital services.
Notifying significant incidents to ANSSI within 24 hours, followed by a detailed report within 72 hours, transforms crisis management. Territorial IT departments that operated with informal procedures must now structure an on-call duty and operational escalation circuits. We observe that this time constraint pushes many local authorities to outsource all or part of their security supervision to shared security operations centers.
To delve deeper into the technical challenges that arise, IT on Collectivité Numérique details the architectures adapted to the constraints of the local public sector.

Governance of Territorial Data and Open Data
The fragmentation of information systems remains the main obstacle to coherent data governance in local authorities. Each business department (urban planning, civil status, finance, public works) has historically deployed its own tools, often without interoperability. Unifying data reference systems before discussing open data is a non-negotiable technical prerequisite.
The opening of public data also requires reconciling two conflicting legal frameworks. On one hand, the obligation to publish administrative documents and databases. On the other, the requirements of the GDPR regarding the protection of personal data. The CNIL reminds that local authorities must anonymize or pseudonymize datasets before publication, which requires skills and tools that many small intercommunalities do not possess internally.
- Map all business databases and identify duplicates, proprietary formats, and personal data to be processed before any opening
- Designate a data governance referent distinct from the DPO, responsible for overseeing the quality, updating, and interoperability of datasets
- Favor open formats and standardized APIs rather than one-off CSV exports, to enable real reuse by local stakeholders
Sovereign Cloud and SaaS Mode for Local Public Services
The migration to the cloud in SaaS mode is progressing rapidly in local authorities, driven by reduced infrastructure costs and simplified application maintenance. The question of digital sovereignty now structures the choice of providers. Hosting citizens’ data with a provider subject to extraterritorial legislation exposes the local authority to direct legal risk.
We recommend clearly distinguishing sensitive data (civil status, social assistance, local taxation) from routine operational data. The former require hosting qualified as SecNumCloud or equivalent. The latter can tolerate a lower level of certification, provided that the contract specifies the location of the data and the conditions for reversibility.
The classic trap of territorial SaaS lies in dependency on the provider. A local authority that migrates its financial management or HR tools to a proprietary platform without a clear reversibility clause finds itself captive. The requirement to export data in an open format, tested under real conditions before signing the contract, should be included in all specifications.

Artificial Intelligence and Responsible Digital Practices in Local Authorities
Artificial intelligence is entering local authorities through targeted use cases rather than massive deployments. Automated processing of incoming mail, classification of user requests, detection of anomalies in the energy consumption of public buildings: these applications generate measurable gains without requiring a complete overhaul of the information system.
The main barrier is not technological but organizational. Training agents in the use of tools augmented by AI, defining the cases where automated decisions must be validated by a human, documenting the algorithms used to meet transparency obligations: these projects require time and skills that the current staff of territorial IT departments struggle to allocate.
The aspect of responsible digital practices adds a layer of constraints. The REEN law requires local authorities with more than 50,000 inhabitants to implement a strategy to reduce the environmental footprint of digital technology. In practical terms, this translates into environmental criteria in public IT contracts, extending the lifespan of equipment, and rationalizing server infrastructures.
- Integrate environmental criteria in public IT contracts, in accordance with obligations arising from the Climate and Resilience law
- Measure the carbon footprint of the existing digital park before setting quantified reduction targets
- Encourage the reuse and refurbishment of workstations, in connection with local circular economy sectors
- Document the AI algorithms deployed to ensure transparency towards citizens and elected officials
The articulation between these four axes (regulatory cybersecurity, data governance, cloud sovereignty, responsible AI) outlines the real scope of territorial digital transformation for the coming years. Local authorities that address these issues in silos replicate the fragmentation errors that have made their information systems so difficult to evolve. Managing these projects in a transversal manner, under the authority of a digital management and not just a technical IT department, remains the condition for these investments to yield sustainable results.