ENS certification in Spain: who needs it and how to obtain it

1. Why a company outside Spain ends up needing the ENS
Most organisations discover the Esquema Nacional de Seguridad the hard way: a tender document lands on the desk, and somewhere in the technical requirements there is a line demanding ENS conformity at a given category. By then the deadline is usually weeks away, and conformity is not something you obtain in weeks.
The ENS is Spain’s national security framework, currently governed by Royal Decree 311/2022, which replaced the 2010 original. It binds the whole Spanish public sector. And, critically for foreign suppliers, it reaches the private companies that provide services to that public sector. If your software, your hosting or your managed service touches a Spanish public administration’s information systems, the requirement lands on you.
This is not a certification you can substitute with another one. ISO 27001 helps enormously as a starting point, but it is not equivalent and it is not accepted in its place.
2. Who exactly is bound
Three groups, in practice:
- Spanish public sector bodies, at state, regional and local level.
- Private suppliers that provide services or solutions to those bodies, when the service affects the systems in scope.
- Cloud and technology providers whose platforms underpin those services. This is why the large cloud vendors publish their own ENS conformity statements.
A useful test: if a Spanish public body could not run the service without you, assume the requirement will reach you.
3. The first decision: the category
Everything downstream depends on one judgement made at the start, and it is the step where most projects go wrong.
The system is rated across five security dimensions: confidentiality, integrity, traceability, authenticity and availability. Each is assessed for the impact that a security breach would have, on a scale of low, medium or high. The system’s overall category — BASIC, MEDIUM or HIGH — follows from the highest rating among those dimensions.
Two consequences people underestimate:
- A single dimension drags the whole system up. One “high” on availability makes the system HIGH, with every obligation that entails.
- Over-categorising is expensive, under-categorising is fatal. Rate too high and you commit to controls you did not need; rate too low and the auditor will reject the whole exercise.
The categorisation must be documented and reasoned, not asserted. An auditor will ask why availability is medium and not high, and “because that is what we decided” is not an answer.
4. What conformity actually looks like
This is where the two routes separate:
4.1. BASIC category
Conformity is accredited through a declaration of conformity. The organisation assesses itself against the applicable measures and declares its compliance. Lighter, faster, and it still requires the underlying work to be real: the declaration is a statement you sign, with the responsibility that carries.
4.2. MEDIUM and HIGH categories
These require a certification of conformity, issued after an audit by a certification body accredited for the purpose. You cannot self-declare your way to MEDIUM. The audit is repeated periodically, and also whenever substantial changes are made to the system.
In both cases the outcome is published and can be displayed, which is what the tender document is asking you to evidence.
5. The measures you will have to implement
Annex II of the Royal Decree organises the security measures into three blocks:
- Organisational framework: security policy, normative framework, procedures and the authorisation process. This is governance, and it is usually the part technical teams underestimate.
- Operational framework: planning, access control, exploitation, external services, continuity and monitoring.
- Protection measures: facilities, personnel, equipment, communications, information media, applications, information itself and services.
Which measures apply, and at what intensity, depends on the category. That is why the categorisation is not paperwork: it is the decision that sets the size of the entire project.
6. Risk analysis is not optional
The framework requires a formal risk analysis, and in the Spanish context the expected methodology is MAGERIT, frequently supported by the PILAR tool. Foreign organisations often arrive with a risk register built to a different standard and assume it will transfer. It rarely does without rework, because the auditor expects the assets, threats and safeguards to be expressed in terms the framework recognises.
The CCN, Spain’s National Cryptologic Centre, publishes the CCN-STIC guides that develop all of this. They are the reference an auditor will work from, and several are available in English.
7. How long it really takes
An honest range, assuming you start from a functioning ISO 27001-style management system:
- BASIC: three to five months to a defensible declaration.
- MEDIUM: six to nine months including the certification audit.
- HIGH: nine months and up, and the remediation work is genuinely heavy.
Starting from nothing, add three to four months. The bottleneck is almost never the technology: it is producing the documentary body — policy, normative framework, procedures, evidence of operation — and being able to demonstrate that the controls have actually been running, not just that they exist on paper.
The practical implication: if the tender closes in two months, you will not be certified in time. What you can sometimes do is present a formally approved compliance plan with dates, if the tender permits it. That is a conversation to have with the contracting body, not a technicality to hide.
8. The five mistakes we see most
- Starting with the controls instead of the categorisation. Teams begin hardening systems before knowing which category applies, and half the work turns out to be misaimed.
- Assuming ISO 27001 is enough. It is a strong foundation and it saves real time, but it does not substitute for ENS conformity.
- Defining the scope too broadly. Pulling the entire corporate infrastructure into scope when only one service touches the administration multiplies the cost for nothing.
- Treating it as a documentation exercise. The audit tests whether controls operate, and asks for evidence over a period. A policy written last week does not evidence a year of operation.
- Leaving the supply chain out. Your own providers are part of your system. If they are not addressed, the gap is yours.
9. Where to start
If the requirement has just landed on you, the first three steps are always the same: define the scope precisely, categorise the system with documented reasoning, and run a gap assessment against the measures for that category. Those three deliverables tell you what the project actually costs. Everything before them is guesswork.
More in this series: ENS security categories: BASIC, MEDIUM and HIGH explained · Selling to the Spanish public sector: the security requirements
Do you need to comply with the ENS?
At Jaymon Security we take organisations through the whole ENS process from Spain: system categorisation, risk analysis, gap assessment, remediation and preparation for the conformity audit.
See our ENS compliance service or get in touch to discuss your case.

