HomeFrameworksNational Cyber & Cloud SchemesENS

Framework  National Cyber & Cloud Schemes

ENS

The Esquema Nacional de Seguridad (ENS, National Security Scheme) is Spain's mandatory security framework for public sector information systems and for the private providers whose services support them.

It is set by Royal Decree 311/2022 of May 3, 2022, which replaced the 2010 decree, and is operated by the Centro Criptológico Nacional (CCN) within the national intelligence center.

Each system is categorized as Básica, Media, or Alta according to the impact a breach would have on the services and information it handles, and the decree's Annex II lists the security measures required at each category across organizational, operational, and protective groups.

The CCN publishes the CCN-STIC guide series that explains how to implement and audit the measures; CCN-STIC 809 sets the conformity criteria and CCN-STIC 802 the audit method.

Conformity is demonstrated by a Declaración de Conformidad (self-declaration) for Básica systems and by a Certificación de Conformidad for Media and Alta systems, issued by a certification body accredited by ENAC after an audit. Certificates are renewed through a full audit at least every two years.

In writing, an organization needs the categorization decision and its rationale, a security policy approved by the governing body, the appointment of the security, information, service, and system roles, a risk analysis, the statement of applicability (declaración de aplicabilidad) mapping Annex II measures to controls, procedures for each measure, the security improvement plan, incident handling and CCN-CERT notification procedures, and the audit report.

Suppliers to Spanish public bodies must hold ENS certification for the services they provide, so ENS has become a common requirement in Spanish public procurement and for cloud providers serving the Spanish state.

AI-compiled
Share
Sponsored
ENS
help
Consultants  Assessors  Quotes
Matched3 quotesread by a human
The Shortlist is Yoursfrom this directory
Comply the Modern WayFind help with ENS
01
Verified listings first
Unverified ones follow, labeled
02
Published prices where they exist
“Quote only” where we confirmed it, “Not published” where we have not
03
Up to three quotes, one form
Firms don’t see you until you choose
House ad. This slot is open to firms listed for this page. Get help Advertise here

Who has to comply

All Spanish public sector entities (state, regional, and local administrations and their public bodies) and private sector organizations that provide services or solutions to them where the systems support public services or handle public sector information, to the extent set in the contract.

Category depends on the system's impact assessment, not on the size of the organization.

What the assessor asks to see

Categorization decision and rationale; security policy and normative framework; role appointments (responsable de seguridad, de la información, del servicio, del sistema); risk analysis and treatment; declaración de aplicabilidad; procedures for each Annex II measure; access control, logging, configuration, and change management evidence; incident register and CCN-CERT notifications; business continuity plans and tests; supplier contracts with ENS clauses; internal audit or prior conformity audit reports; security improvement plan; the certificate or declaration published on the entity's site.

Categories

Básica (self-declaration), Media, and Alta (certification by an ENAC-accredited body). The category follows from assessing the impact of a security incident on the confidentiality, integrity, availability, authenticity, and traceability of the system's information and services.

Assessors

Who assesses ENS

For Media and Alta categories, certification bodies accredited by ENAC under the ENS certification scheme perform the audit and issue the Certificación de Conformidad. For Básica, the organization issues a Declaración de Conformidad after a self-assessment (an external audit is optional).

Accredited by ENAC (Entidad Nacional de Acreditación), Spain's national accreditation body; the CCN publishes the list of accredited certification bodies.

Public register of assessors: https://ens.ccn.cni.es/es/certificacion/entidades-de-certificacion

AENOR CONFIAOn the public register
What they do
Assessor
Which standards
On the public register for ENS.
Standards
ENS
Pricing
Not published
Audertis Audit ServicesOn the public register
What they do
Assessor
Which standards
On the public register for ENS.
Standards
ENS
Pricing
Not published
BDO AuditoresOn the public register
What they do
Assessor
Which standards
On the public register for ENS.
Standards
ENS
Pricing
Not published
Bureau Veritas CertificaciónOn the public register
What they do
Assessor
Which standards
On the public register for ENS.
Standards
ENS
Pricing
Not published
LGAI Technological Center (Applus)On the public register
What they do
Assessor
Which standards
On the public register for ENS.
Standards
ENS
Pricing
Not published

Consultants

Who helps with ENS

A large Spanish consultancy market implements the ENS: gap analysis against Annex II, categorization, risk analysis (often with the CCN's PILAR tool), policy and procedure sets, and preparation for certification. Engagements run six to twelve months for a first Media or Alta certification.

Firms that name this framework in their own material. Listings we have not verified yet come from public filings and partner lists. Each firm can confirm its own.

No firm has claimed a ENS consultant listing yet. Claim yours →

Software

Tools for ENS

Tools that name this framework in their own material.

No firm has claimed a ENS tool listing yet. Claim yours →

Related reading

  1. Spain Esquema Nacional de Seguridad: high-level security measuresExplains the basic, medium and high categories and which of them require an ENAC-accredited audit rather than a self-declaration.Microsoft
  2. Esquema Nacional de Seguridad complianceSets out how a cloud provider is certified under the scheme and what a Spanish public-sector customer still has to do itself.Amazon Web Services

Independent third-party explainers, chosen by hand. Not affiliated with this site and not paid placements. All links are nofollow.

Need a hand implementing it?

Find a Consultant for ENS

Tell us what you need done and we will point you to firms that do this work. Your details go to a firm only when you choose it.

Not sure where to start?

Get Help with ENS

Tell us what you are trying to put in place. We will point you to the right tool, a consultant who can implement it, or both.

About this data

Pages on this site are compiled with AI from two or more linked sources, rewritten in our words, and reviewed by people in stages. Each record shows its stage and date. Nothing here is legal, audit or tax advice, and policyandcompliance.com accepts no responsibility for errors or for decisions made on it. Read the source, then decide.
How we compile and verify →

Think something is wrong?

corrections@policyandcompliance.com
Tell us the page and what you found. We check it against the source and fix it.
Corrections log →

Want to advertise here?

ads@policyandcompliance.com
A primary ad and a secondary placement, flat fee. Buying one changes nothing else on the page.