Consulting · Royal Decree 311/2022
Implementation and certification ENS
We align your systems with Spain's National Security Framework and support you all the way to certification of conformity.
The standard
What the ENS is and who it applies to
Spain's National Security Framework (ENS) sets the security requirements that information systems in the Spanish public sector must meet. It is regulated by Royal Decree 311/2022 and applies both to public authorities and to the companies that provide them with services or technology solutions.
Each system is classified as BASIC, MEDIUM or HIGH depending on the damage an incident would cause. That category determines which security measures must be applied and how compliance must be demonstrated.
For the BASIC category, a self-assessment is enough. MEDIUM and HIGH require a certification audit carried out by an accredited body.
Do you need it?
Tick everything that applies to your organization.
One foundation for several standards
What you implement for the ENS works for other standards too
They share many of the same security measures: a single system can cover both the ENS and ISO 27001.
ISO 27001 implementation → NIS2ENS measures help you meet NIS2 obligations on risk management and incident reporting.
NIS2 compliance → ISO 9001Documentation, internal audits and management review can be shared in an integrated system.
ISO 9001 implementation →Frequently asked questions
What people ask us before getting started
Those that provide services or supply solutions to public sector entities, when those services are part of the entities' activity. In practice, more and more public contracts and tenders require it.
The category depends on the damage an incident would cause to the information or services. The higher it is, the more security measures must be applied and the more demanding it is to demonstrate compliance.
No. It is issued by an accredited, independent certification body. Whoever helps you implement the standard cannot certify you, precisely to guarantee impartiality. We prepare you and support you throughout the audit.
Systems must undergo a regular audit at least every two years, and also whenever there are significant changes affecting their security.
Not automatically. They share many measures, but they are separate certifications and the ENS has its own requirements. That said, with ISO 27001 in place the path is much shorter.
Yes. The scope is defined at the start and can be limited to a service, a department or a site, as long as it is clearly defined.
Shall we talk about your certification?
Tell us where you stand and we'll explain how to get certified.
