📋 GRC compliance for CMMC 2.0, CPCSC, CPA Canada, IIROC…SaaS discovery for data governanceFree enriched web chat widget🚀 Enriched remote support without your laptop

Governance, risk & compliance

Municipal compliance, assessed for your actual jurisdiction

Five jurisdiction-specific municipal assessments · United States, Alberta, Ontario, British Columbia, and other Canadian provinces

A city in Iowa and a town in Alberta do not share a rulebook, so they should not share a checklist. Lavawall ships five municipal assessments, each tuned to the statutes and programs that actually govern local government where you are. They share a common core of 62 questions and differ in the 11 that carry the local law, so you are measured against the rules that apply to you, not a generic average of everyone’s.

Assess your municipalitySee the five

Five assessments, one for each rulebook

Each row is a distinct assessment in the product. The shared core is the same; the column on the right is the local obligation that assessment adds.

JurisdictionGoverning regimeWhat its local questions add
United StatesNIST SP 800-53, FBI CJIS, IRS Pub 1075, AWIA water, GovRAMPFIPS 199 impact categorization and Federal Tax Information handling under IRS 1075
AlbertaProtection of Privacy Act & Access to Information ActThe privacy management program required in place by June 11, 2026
OntarioMFIPPA (Municipal Freedom of Information and Protection of Privacy Act)Municipal records and privacy duties specific to MFIPPA
British ColumbiaFIPPA (Freedom of Information and Protection of Privacy Act)FIPPA’s privacy-impact and protection-of-privacy duties for local government
Canada — other provincesThe shared Canadian municipal baselineThe common municipal security and privacy obligations where no province-specific municipal statute governs

Most competitors offer one municipal checklist and call it coverage. The reason a US Local Agency Security Officer and an Alberta records manager can both use Lavawall is that neither is handed the other’s questions.

62 shared, 11 local: why that split matters

Good municipal security is largely universal. Access control, backups, incident response, logging, patching, and evidence look the same in Ontario as in Iowa. That universal part is the 62-question shared core.

What changes by jurisdiction is the legal hook: which breach statute applies, which records law shields your security documentation, whether you categorize systems under FIPS 199, whether you have to stand up a privacy management program. That is the 11. Keeping the two separate is what lets Lavawall be both broad and precise: the shared core is answered once and carried across every jurisdiction you operate in, while the local questions make each assessment genuinely specific instead of a lowest-common-denominator list.

Operate in more than one jurisdiction? The shared core does not get re-answered. Finishing the United States assessment leaves an Ontario or Alberta assessment mostly complete, with only its 11 local questions outstanding.

The United States difference

A US municipality categorizes its information systems under FIPS 199 (low, moderate, or high impact), and any body that receives Federal Tax Information inherits the full IRS Publication 1075 safeguard set. Those are the questions the US assessment adds on top of the shared core, alongside the CJIS, AWIA, and NIST SP 800-53 obligations a US city already carries. See GRC for US municipalities.

The Alberta difference

Alberta’s Protection of Privacy Act requires public bodies, municipalities included, to have a privacy management program in place by June 11, 2026. That is a program a city has to build and be able to evidence, not a box to check, and it is exactly the kind of local obligation a generic checklist misses. See GRC for Canadian municipalities.

How Lavawall® runs it

Pick your jurisdiction and Lavawall gives you the right assessment: the 62-question shared core plus the 11 that carry your local law. It maps each answer to the technical controls it runs across Windows, macOS, Linux, and Microsoft 365 / Google Workspace, keeps the evidence current, and lets a second jurisdiction reuse everything the first already answered.

  • Assess against the assessment built for your province or state, not a generic municipal list.
  • Reuse the shared core across every jurisdiction you operate in, so multi-jurisdiction coverage is not multi-jurisdiction rework.
  • Evidence each obligation with timestamped records that hold up to the auditor or records request you actually face.

Related

Last verified August 27, 2026.

Frequently asked questions

Do you have a municipal assessment for my jurisdiction?

Lavawall ships five jurisdiction-specific municipal assessments: United States, Alberta, Ontario, British Columbia, and other Canadian provinces. Each is tuned to the statutes and programs that actually govern a city, county, or municipality there.

How different are the five assessments?

They share a common core. 62 of the questions are identical across all five, because good municipal security is largely the same everywhere; 11 change by jurisdiction to capture the local legal obligations. You answer the shared core once and layer the local questions on top.

What does the United States municipal assessment add?

The US-specific questions include FIPS 199 impact categorization for information systems and the handling of Federal Tax Information under IRS Publication 1075, alongside the CJIS, AWIA water, and NIST SP 800-53 obligations a US city typically carries.

What does the Alberta municipal assessment add?

Alberta's local questions include the privacy management program that the Protection of Privacy Act now requires public bodies to have in place by June 11, 2026, which a city has to be able to evidence rather than just assert.

Which law governs the Ontario and British Columbia assessments?

Ontario municipalities fall under MFIPPA, the Municipal Freedom of Information and Protection of Privacy Act. British Columbia municipalities fall under FIPPA, the Freedom of Information and Protection of Privacy Act. Each assessment carries the questions specific to its statute.

We operate across two jurisdictions. Do we answer everything twice?

No. The 62-question shared core is answered once and reused; only the 11 jurisdiction-specific questions differ. Running a second jurisdiction is mostly already done the moment you finish the first.