The Spanish National Security Framework (ENS) is the mandatory security framework for the Spanish public sector and, increasingly, the requirement that public bodies pass on to their private providers. These are the questions we are asked most often.
Guidance prepared by Jaquers Ciberseguridad from Royal Decree 311/2022 and the CCN-STIC guides. It is not legal advice; for your specific case consult the text in force and, where appropriate, your certification body.
1. What is the ENS?
The Spanish National Security Framework, now regulated by Royal Decree 311/2022 of 3 May, sets the security policy that Spanish public sector entities must apply when using electronic means: basic principles, minimum requirements and a catalogue of security measures proportionate to the risk. It replaces Royal Decree 3/2010 and is supported by the CCN-STIC technical guides of the National Cryptologic Centre.
2. Who does it bind?
The entire public sector (national government, regional governments, local authorities, public universities and dependent bodies and companies) and also the private entities that provide services or solutions to public entities, to the extent that those services are affected: software developers, cloud and hosting providers, platform operators, consultancies and managed services. The requirement normally arrives through public procurement specifications.
3. What are the basic, medium and high categories?
Each system is categorised according to the impact an incident would have on five dimensions: confidentiality, integrity, availability, authenticity and traceability. The highest level reached in any of them determines the system’s category (BASIC, MEDIUM or HIGH) and, with it, the set of required measures.
4. Certification or self-assessment?
MEDIUM and HIGH category systems must obtain a certificate of conformity issued by a certification body accredited by ENAC, after a formal audit. BASIC category systems may opt for a self-assessment with a declaration of conformity, although many organisations get certified anyway at their customers’ request. Certification is valid for two years.
5. What measures does it require?
Annex II lists more than seventy measures grouped into three blocks: organisational framework (policy, rules, procedures and authorisation process), operational framework (planning, access control, operations, external resources, cloud services, continuity and monitoring) and protective measures (facilities, personnel, equipment, communications, media, applications, information and services). Which measures apply, and how strictly, depends on the system’s category and is documented in the statement of applicability. The CCN also publishes specific compliance profiles for cases such as small municipalities or cloud services.
6. How often must you audit?
MEDIUM or HIGH category systems undergo a regular ordinary audit at least every two years, and an extraordinary one when there are substantial changes that may affect the security measures. BASIC category systems carry out a self-assessment with the same frequency. The audit report is the basis for certification.
7. How does it relate to ISO 27001?
They share many controls and the same risk management logic, and the CCN publishes mapping tables. But they are not interchangeable: an ISO 27001 certificate does not replace ENS conformity, although it makes it much easier to achieve. Private providers typically maintain both, with a common management system.
8. And with NIS2?
Public administration is one of NIS2’s high-criticality sectors, and the ENS is the instrument through which Spain already requires security measures in that area. For a private provider, ENS conformity is also a solid way to demonstrate to customers subject to NIS2 the guarantees they must require from their supply chain.
9. How does pentesting fit into the ENS?
Several measures require or presuppose it: the risk analysis [op.pl.1] needs to be checked against reality, monitoring [op.mon.3] and the protection of web services and applications [mp.s.2] require verifying actual exposure, and the auditor will ask for evidence that vulnerabilities are detected and fixed. A periodic pentest with findings tracked to their fix is the most direct evidence.
10. What about incidents?
The ENS requires an incident management process [op.exp.7] and its logging [op.exp.9], and public sector entities must report incidents to CCN-CERT according to the established procedure, in addition to complying with the GDPR when personal data is involved. A private provider must have an equivalent procedure and a contractual obligation to notify its public sector customer.
How Jaquers helps
We provide the technical evidence the ENS auditor asks for and prepare private providers for procurement requirements: external and internal pentesting, secure configuration of the cloud and Microsoft 365, measurable awareness and incident response with full documentation.
If you are preparing for certification or responding to a tender with ENS requirements, request an initial assessment: a 30-minute conversation to understand your systems and what worries you.