Mexico - Interministerial ICT Commission (2023)

Decree creating the Interministerial Commission on ICT and Information Security

Decreto por el que se crea la Comisión Intersecretarial de Tecnologías de la Información y Comunicación y de la Seguridad de la Información (CITICSI)

Mexico

RAI-MX-NA-DPEQSXX-2023
Effective: January 11, 2023
In Force(In Force)
DecreeGovernance and OversightCybersecurity and Model SecurityAccountability and Documentation
Export PDF

This presidential Decree (published in the Diario Oficial de la Federación on 10 January 2023) creates the Interministerial Commission on Information and Communication Technologies and Information Security (CITICSI). The Commission, chaired by the Coordinación de Estrategia Digital Nacional, coordinates ICT and information-security policy across the Federal Public Administration, issues binding internal lineamientos, creates subcommissions and workgroups, and re-structures prior government-electronic coordination instruments.

Summary

The Decree creating the Comisión Intersecretarial de Tecnologías de la Información y Comunicación, y de la Seguridad de la Información (CITICSI) was published in the Diario Oficial de la Federación on 10 January 2023 and entered into force the following day. The Decree establishes a permanent intersecretarial commission directly dependent on the head of the Executive Branch to coordinate policy, strategy and operational action across the Federal Public Administration in matters of information and communication technologies (ICT) and information security. The Commission is presided by the head of the Coordinación de Estrategia Digital Nacional (CEDN) of the Office of the Presidency and is composed principally of the heads of the Units of Technologies of Information and Communication (UTIC) or equivalents of the specified central federal agencies (including the Presidency, Secretaría de Gobernación, Secretaría de Relaciones Exteriores, Secretaría de la Defensa Nacional, Secretaría de Marina, Secretaría de Seguridad y Protección Ciudadana, Secretaría de Hacienda y Crédito Público, Secretaría de Bienestar, Secretaría de Medio Ambiente y Recursos Naturales, Secretaría de Energía, Secretaría de Economía, Secretaría de Agricultura y Desarrollo Rural, Secretaría de Infraestructura, Comunicaciones y Transportes, Secretaría de la Función Pública, Secretaría de Educación Pública and others referenced in the text).

Key features: the Commission will serve as the coordinating body for implementation of federal ICT and information-security measures; it may issue organizational and operational lineamientos; it may create permanent subcommissions and ad hoc workgroups (including permanent subcommissions for Government Electronic Services & Interoperability, Advanced Electronic Signature, and Information Security); it can invite representatives from autonomous bodies, state/municipal authorities, the judiciary, Congress, academia, civil society and private sector to participate with voice but no vote; it establishes quorum rules, session frequency (at least three ordinary sessions per year), and rules for convening and minute-taking. The presiding officer (CEDN head) has specific powers including calling sessions, appointing the technical secretariat, coordinating follow-up to agreements, reporting periodically to the President, and proposing subcommissions.

Transitory provisions: the Decree expressly abrogates the 2005 intersecretarial Acuerdo that created the prior Intersecretarial Commission for Electronic Government (published 9 December 2005), while preserving pre-existing instruments/acts of that body to the extent they do not conflict and enabling their ratification, modification or repeal by the new Commission. The Commission must install itself within 15 business days of entry into force and must issue its internal lineamientos within 30 business days of installation. The Decree requires participating agencies to use existing budgetary resources for Commission activities so no additional appropriations are mandated. The Commission's lineamientos for integration, organization and functioning were subsequently issued and published as an Acuerdo providing operational detail on subcommissions, workgroups, secretariat functions, documentation standards and transparency responsibilities. The Decree has important governance and coordination implications for federal ICT policy, interoperability, cybersecurity and advanced electronic signature implementation and forms a legal institutional basis for consolidated federal action in these areas.

Full article

Read full text ↗

Overview

The Decree creating the Comisión Intersecretarial de Tecnologías de la Información y Comunicación, y de la Seguridad de la Información (CITICSI) was published in the Diario Oficial de la Federación on 10 January 2023 and entered into force the following day. The instrument establishes a permanent intersecretarial body, directly dependent on the head of the Executive Branch, to coordinate federal policy and actions on information and communication technologies (ICT) and information security across the Federal Public Administration. The Commission is presided by the Coordinación de Estrategia Digital Nacional (CEDN) of the Presidency and comprises heads of UTICs or their equivalents from specified federal departments. The full text of the Decree is available from the Mexican official registry: Diario Oficial de la Federación – Decree (10 Jan 2023).

Definitions

The Decree and subsequent operational lineamientos define key terms used for the Commission's work. "Technologies of Information and Communication" (TIC or ICT) is defined broadly to include hardware, software, printing devices, infrastructure and services used to store, process, protect, transmit, transfer and retrieve information (data, voice, images, video). "Security of the Information" (Seguridad de la Información) is defined in accordance with the lineamientos as the capacity to preserve confidentiality, integrity and availability, and attributes such as authenticity, reliability, traceability and non-repudiation. "UTIC" denotes the Unit of Technologies of the Information and Communication (or equivalent) within each federal dependency. "Subcommissions" and "Groups of Work" are specialist bodies formed by Commission agreement to handle technical or legal matters. These definitions are elaborated in the Commission's implementing lineamientos: Lineamientos for Integration, Organization and Functioning (Acuerdo).

Governance and Institutional Framework

The Commission operates as a collegiate coordinating body under the Presidency. It is presided by the CEDN (who designates a deputy in case of absence) and includes the UTIC heads of a list of federal secretariats (Presidency Office; Secretaría de Gobernación; Secretaría de Relaciones Exteriores; Secretaría de la Defensa Nacional; Secretaría de Marina; Secretaría de Seguridad y Protección Ciudadana; Secretaría de Hacienda y Crédito Público; Secretaría de Bienestar; Secretaría de Medio Ambiente y Recursos Naturales; Secretaría de Energía; Secretaría de Economía; Secretaría de Agricultura y Desarrollo Rural; Secretaría de Infraestructura, Comunicaciones y Transportes; Secretaría de la Función Pública; Secretaría de Educación Pública; among others identified in Article 3). Members have voice and vote; invited participants (other UTICs, autonomous bodies, state/municipal authorities, judiciary, legislative commissions, academia, civil society and private sector representatives) participate with voice but no vote. The presiding official appoints a technical secretariat (minimum level: director general) responsible for convocations, minute-taking, follow-up and archival functions. Commission powers and structure are detailed in the Decree and clarified in the subsequent lineamientos, which set rules for subcommissions, groups of work, transparency, archiving and technical staffing.

Key Focus Areas

The Commission's designated functions include: (i) acting as the principal instance for coordination of federal implementation and development of ICT and information-security actions; (ii) participating in the execution of interinstitutional strategies and actions for ICT use and information security; (iii) promoting and coordinating with public, private, academic and social sectors studies and activities to advance ICT and information security; (iv) issuing organizational and operational lineamientos for its own structure and for subcommissions and workgroups; (v) establishing permanent subcommissions and ad hoc groups of work to address specific technical or legal matters (the lineamientos create three permanent subcommissions by default: Government Electronic Services & Interoperability; Advanced Electronic Signature; and Information Security); (vi) requesting studies, projects, documents and normative proposals from subcommissions and groups of work; and (vii) receiving, analyzing and approving reports, agreements and documentation prepared by subcommissions and workgroups. These areas place emphasis on interoperability of systems, the modernization of public digital services, the adoption and standardization of advanced electronic signature processes, and a coordinated national approach to confidentiality, integrity and availability of public-sector information assets. The Commission therefore serves both as policy coordinator and operational standard-setting body across the federal administration.

Implementation Framework

Implementation depends on institutional collaboration and on the UTICs (or equivalent) of the participating dependencies. The Decree requires the Commission to install itself within 15 business days after entry into force and to issue its internal lineamientos within 30 business days after installation. Session rules are established (at least three ordinary sessions per year; extraordinary sessions as needed) and quorum and voting rules are set (presence of half plus one; majority simple; chair's casting vote in event of tie). The technical secretariat organizes convocations, prepares agendas, circulates decisions and maintains the Commission's archives in accordance with the Law on Archives. The Decree specifies that no additional budgetary appropriations will be required: member dependencies must use existing approved human, material and financial resources for Commission operation. The Commission's lineamientos further specify the composition, mandates, deliverables and timelines for subcommissions and groups of work and require work product delivery and periodic reporting to the Commission and to the Office of the Presidency. For the authoritative legal text see the DOF publication: DOF (10 Jan 2023) and the implementing Acuerdo: Lineamientos (Acuerdo).

Monitoring and Evaluation

The Decree and the implementing lineamientos adopt a governance approach that requires reporting, minute-keeping and periodic reporting to the head of the Executive. Minutes of each session must be taken and approved in the subsequent ordinary session, and agreements are binding on Commission members. The technical secretariat coordinates follow-up to agreements and the monitoring of subcommissions and groups of work (including timelines and deliverables). The lineamientos explicitly require that outputs be archived and made public except where confidentiality or legal reserve applies. Monitoring thus relies on internal reporting channels, the secretariat's oversight and the binding nature of Commission agreements; external oversight may continue to arise from the Secretaría de la Función Pública and transparency/data protection institutions where applicable.

Penalties, Liability, and Appeals

The Decree does not create new penal sanctions; rather, it establishes an administrative coordination and standard-setting body whose agreements are binding on constituent agencies. Non-compliance by members with Commission agreements is subject to administrative follow-up through existing accountability mechanisms within the Administration (including internal control units, the Secretaría de la Función Pública, and applicable administrative responsibility rules). The Decree preserves the applicability of other legal instruments and does not alter criminal laws, administrative liability rules or protections under transparency and data-protection law. The lineamientos require archival and documentation practices consistent with the Law General of Archives and do not supplant judicial or administrative appeal rights that may be available under applicable statutes and the Ley Federal de Procedimiento Administrativo.

Relationship to Other Instruments

The Decree expressly abrogates the 2005 Acuerdo that created the earlier Intersecretarial Commission for the Development of Electronic Government (published 9 December 2005) but preserves prior instruments, acts and files of that body to the extent they do not conflict. It functions in conjunction with the Estrategia Digital Nacional (2021-2024) and the Plan Nacional de Desarrollo 2019-2024, and intersects with other administrative policies such as the 2022/2023 policies for ICT and information security adopted across federal dependencies. The Commission's remit interacts with specialized laws and instruments including the Ley Orgánica de la Administración Pública Federal, the Ley Federal de Procedimiento Administrativo, the Ley General de Archivos, and sectoral regulation on data protection and cybersecurity. The Commission's lineamientos supplement and operationalize these instruments by defining subcommissions, interoperability goals and standards and archiving and transparency rules. Primary legal texts are available at the official DOF and SIDOF portals: Decree (DOF) and Lineamientos (Acuerdo).

International Alignment

Although the Decree is internal to the Federal Public Administration, its objectives align with international norms and trends: promoting interoperability, modern digital government services, standardized electronic signatures and coordinated information-security approaches parallels OECD and other international guidance on digital government and cybersecurity. The Commission's structure enables federal alignment with international cooperation on cybersecurity, cross-border data and digital government best practices through participating agencies (e.g., Secretaría de Relaciones Exteriores and sectoral secretariats). The institutional framework supports participation in bilateral and multilateral fora and adoption of international technical standards for information security and trusted electronic identification and trust services.

Implementation Timeline

EventDate / Deadline
Publication in Diario Oficial de la Federación10 January 2023
Entry into force (day after publication)11 January 2023
Commission installation (Transitory Fifth; actual installation)Within 15 business days after entry; installed 30 January 2023 (session)
Lineamientos issuance (Transitory Sixth)Within 30 business days from installation; lineamientos approved 8 March 2023
Ordinary sessions (recurrence)At least 3 times per year (ongoing)

Sources and References

SourceType
Decree creating the Commission (Diario Oficial de la Federación, 10 Jan 2023)Primary Source
Lineamientos for Integration, Organization and Functioning (Acuerdo)Primary Source
Coordinación de Estrategia Digital Nacional (CEDN) — official pagePrimary Source

Requirements for a company

What an organisation has to do under Mexico - Interministerial ICT Commission (2023), at a glance. Not legal advice — the table below gives the provision and deadline for each item.

Must do

12
  • Comply with all binding agreements made by the Commission.Members of the Interministerial Commission (CITICSI).
  • Install the Interministerial Commission.The Interministerial Commission (CITICSI).
  • Issue internal operational lineamientos.The Interministerial Commission (CITICSI).
  • Appoint a technical secretariat at director general level or higher.The presiding official of the Commission (CEDN).
  • Hold at least three ordinary sessions annually.The Interministerial Commission (CITICSI).
  • Ensure sessions meet quorum and follow voting rules.The Interministerial Commission (CITICSI) and its members.
  • +6 more in the table below

Must not do

0

Nothing in this category.

Should do

0

Nothing in this category.

Should not do

0

Nothing in this category.

Who must do what

The obligations under Mexico - Interministerial ICT Commission (2023), most serious first. Not legal advice — verify against the official text before relying on it.

#WhoRequirementBy whenWhereSeverity
1Members of the Interministerial Commission (CITICSI).Comply with all binding agreements made by the Commission.
agreements are binding on Commission members.
OngoingCritical
2The Interministerial Commission (CITICSI).Install the Interministerial Commission.
The Decree requires the Commission to install itself within 15 business days after entry into force.
Jan 30, 2023Transitory FifthCritical
3The Interministerial Commission (CITICSI).Issue internal operational lineamientos.
The Decree requires... to issue its internal lineamientos within 30 business days after installation.
Mar 8, 2023Transitory SixthCritical
4The presiding official of the Commission (CEDN).Appoint a technical secretariat at director general level or higher.
The presiding official appoints a technical secretariat (minimum level: director general).
Before first sessionImportant
5The Interministerial Commission (CITICSI).Hold at least three ordinary sessions annually.
Session rules are established (at least three ordinary sessions per year; extraordinary sessions as needed).
OngoingImportant
6The Interministerial Commission (CITICSI) and its members.Ensure sessions meet quorum and follow voting rules.
quorum and voting rules are set (presence of half plus one; majority simple; chair's casting vote in event of tie).
OngoingImportant
7The Technical Secretariat of the Commission.Organize convocations, prepare agendas, circulate decisions, and maintain archives.
The technical secretariat organizes convocations, prepares agendas, circulates decisions and maintains the Commission's archives.
OngoingImportant
8The Technical Secretariat and the Commission.Take minutes of each session and approve them in the subsequent session.
Minutes of each session must be taken and approved in the subsequent ordinary session.
OngoingImportant
9The Technical Secretariat of the Commission.Coordinate follow-up to agreements and monitor subcommissions and work groups.
The technical secretariat coordinates follow-up to agreements and the monitoring of subcommissions and groups of work.
OngoingImportant
10The Commission and its Technical Secretariat.Archive outputs and make them public, unless confidentiality or legal reserve applies.
The lineamientos explicitly require that outputs be archived and made public except where confidentiality or legal reserve applies.
OngoingImportant
11The Interministerial Commission (CITICSI).Establish permanent subcommissions and ad hoc groups of work as needed.
establishing permanent subcommissions and ad hoc groups of work to address specific technical or legal matters.
OngoingImportant
12Member dependencies of the Commission.Use existing approved human, material, and financial resources for Commission operation.
member dependencies must use existing approved human, material and financial resources for Commission operation.
OngoingImportant

© Regulations.AI · updated on 13-Jun-2026