๐Ÿ“‹ GRC compliance for CMMC 2.0, CPCSC, CPA Canada, IIROCโ€ฆSaaS discovery for data governanceFree enriched web chat widget๐Ÿš€ Enriched remote support without your laptop

GRC · US local government

Compliance and GRC for US municipalities

Cities, counties, and agencies map a demanding stack, from NIST SP 800-53 and FBI CJIS to IRS Publication 1075, StateRAMP, and AWIA water-system cybersecurity, usually on a lean IT team. Lavawall® maps those obligations to concrete controls, runs and evidences them, and keeps you audit-ready year-round.

Start free, no credit cardTalk to our team

NIST SP 800-53 · FBI CJIS · IRS Pub 1075 (FTI) · StateRAMP · AWIA water · NIST CSF · CIS Controls

Local government carries federal-grade requirements

A single city can run police systems under CJIS, a tax or benefits program that receives IRS federal tax information, a water utility under AWIA, and cloud procurements that expect StateRAMP, all mapped back to NIST SP 800-53. That is a lot of overlapping control work for a team that is also keeping the lights on, and ransomware crews treat local government as a soft, high-impact target.

Lavawall® carries the mapping, the controls, and the evidence, so the same underlying work counts across every framework at once.

Your data stays in the US

US municipalities run on US-resident systems. On request, Lavawall® can host US local-government data on infrastructure located in the United States, so regulated information — criminal justice information (CJI) under CJIS and federal tax information (FTI) under IRS Publication 1075 — stays in-country, where those rules require it. Ask us about US-resident hosting when you get in touch.

How Lavawall GRC works for local government

Map once, satisfy many

Because CJIS, IRS 1075, and StateRAMP all lean on NIST SP 800-53, Lavawall maps your controls once and shows how they satisfy every framework in scope.

Close the gaps

Patch 7,400+ applications, harden Microsoft 365 and Google Workspace, watch for account takeover, run access reviews, and back up configuration, from one console.

Stay review-ready

Evidence is collected continuously and time-stamped for a CJIS audit, an IRS safeguard review, a StateRAMP continuous-monitoring cycle, or a cyber-insurance renewal.

See how Lavawall GRC works

North of the border?

Canadian municipalities map MFIPPA (Bill 194), Alberta’s Protection of Privacy Act, and Canadian baselines. See GRC for municipalities.

Frequently asked questions

What compliance frameworks do US municipalities need?

It depends on what the local government does, but the common set includes NIST SP 800-53 as a control baseline, the FBI CJIS Security Policy for any system that touches criminal justice information, IRS Publication 1075 where federal tax information is handled, StateRAMP for cloud services sold to state and local government, and AWIA cybersecurity requirements for community water systems. Most also align to NIST CSF and the CIS Controls. Lavawall maps each to the technical controls it runs and keeps the evidence current.

What is CJIS Security Policy compliance?

The FBI CJIS Security Policy sets the security requirements any agency or vendor must meet to access criminal justice information (CJI), covering areas like access control, encryption, auditing, incident response, and personnel screening, and it increasingly aligns with NIST SP 800-53. Police departments, and the IT teams and cloud vendors that support them, all fall in scope. Lavawall helps a municipality assess against CJIS and produce the evidence auditors ask for.

What is IRS Publication 1075 (federal tax information)?

IRS Publication 1075 sets the safeguards agencies must apply when they receive federal tax information (FTI), for example in tax, benefits, or collections programs. It draws heavily on NIST SP 800-53 controls plus specific handling, logging, and reporting rules. Lavawall maps Publication 1075 to the controls it monitors so an agency can show FTI is protected and stay ready for a safeguard review.

What is StateRAMP, and when does a municipality need it?

StateRAMP is a standardized security assessment and authorization program for cloud products sold to US state and local government, much like FedRAMP is for federal. Municipalities encounter it when they procure cloud services, and vendors need it to sell into that market. Lavawall helps a vendor or an in-house team map to the StateRAMP baseline and keep continuous evidence rather than a point-in-time snapshot.

What does AWIA require for water and wastewater systems?

America's Water Infrastructure Act requires community water systems to assess their risk and resilience, including cybersecurity, and to maintain emergency response plans. Many water and wastewater utilities are municipal, so this lands on local-government IT and operations. Lavawall maps the cybersecurity side to concrete controls, monitors them, and keeps the evidence a review will ask for.

Does NIST SP 800-53 apply to local government?

NIST SP 800-53 is the federal control catalog, but it is widely used as the baseline behind state and local requirements, CJIS, and IRS Publication 1075, and many municipalities adopt it directly. Lavawall supports NIST 800-53 at its baseline tiers (low, moderate, high) and maps the controls to what it already runs, so a city or county can assess and evidence against it from one console.

Do you also cover Canadian municipalities?

Yes. Canadian cities and towns map a different set, including Ontario MFIPPA (as amended by Bill 194), Alberta's Protection of Privacy Act, and Canadian security baselines. See our GRC for municipalities page for that stack.

Where is our data hosted, and does it stay in the US?

US-resident hosting is available on request for US municipalities, so your data can stay in the United States. That matters because frameworks like the CJIS Security Policy and IRS Publication 1075 restrict where regulated data (criminal justice information and federal tax information) can be stored and who can access it. Ask us about US-resident hosting when you get in touch and we will set it up for your organization.

Bring senior security to your city or county

Start free with no credit card, or talk to our CISSP/CISA team about mapping NIST 800-53, CJIS, IRS 1075, StateRAMP, and AWIA for your organization.

Start freeTalk to our team