- What they do
- Assessor
- Which standards
- On the public register for ENS.
- Standards
- Pricing
- Not published
Framework National Cyber & Cloud Schemes
ENS
The Esquema Nacional de Seguridad (ENS, National Security Scheme) is Spain's mandatory security framework for public sector information systems and for the private providers whose services support them.
It is set by Royal Decree 311/2022 of May 3, 2022, which replaced the 2010 decree, and is operated by the Centro Criptológico Nacional (CCN) within the national intelligence center.
Each system is categorized as Básica, Media, or Alta according to the impact a breach would have on the services and information it handles, and the decree's Annex II lists the security measures required at each category across organizational, operational, and protective groups.
The CCN publishes the CCN-STIC guide series that explains how to implement and audit the measures; CCN-STIC 809 sets the conformity criteria and CCN-STIC 802 the audit method.
Conformity is demonstrated by a Declaración de Conformidad (self-declaration) for Básica systems and by a Certificación de Conformidad for Media and Alta systems, issued by a certification body accredited by ENAC after an audit. Certificates are renewed through a full audit at least every two years.
In writing, an organization needs the categorization decision and its rationale, a security policy approved by the governing body, the appointment of the security, information, service, and system roles, a risk analysis, the statement of applicability (declaración de aplicabilidad) mapping Annex II measures to controls, procedures for each measure, the security improvement plan, incident handling and CCN-CERT notification procedures, and the audit report.
Suppliers to Spanish public bodies must hold ENS certification for the services they provide, so ENS has become a common requirement in Spanish public procurement and for cloud providers serving the Spanish state.
help
Who has to comply
All Spanish public sector entities (state, regional, and local administrations and their public bodies) and private sector organizations that provide services or solutions to them where the systems support public services or handle public sector information, to the extent set in the contract.
Category depends on the system's impact assessment, not on the size of the organization.
What the assessor asks to see
Categorization decision and rationale; security policy and normative framework; role appointments (responsable de seguridad, de la información, del servicio, del sistema); risk analysis and treatment; declaración de aplicabilidad; procedures for each Annex II measure; access control, logging, configuration, and change management evidence; incident register and CCN-CERT notifications; business continuity plans and tests; supplier contracts with ENS clauses; internal audit or prior conformity audit reports; security improvement plan; the certificate or declaration published on the entity's site.
Categories
Básica (self-declaration), Media, and Alta (certification by an ENAC-accredited body). The category follows from assessing the impact of a security incident on the confidentiality, integrity, availability, authenticity, and traceability of the system's information and services.
Assessors
Who assesses ENS
For Media and Alta categories, certification bodies accredited by ENAC under the ENS certification scheme perform the audit and issue the Certificación de Conformidad. For Básica, the organization issues a Declaración de Conformidad after a self-assessment (an external audit is optional).
Accredited by ENAC (Entidad Nacional de Acreditación), Spain's national accreditation body; the CCN publishes the list of accredited certification bodies.
Public register of assessors: https://ens.ccn.cni.es/es/certificacion/entidades-de-certificacion
- What they do
- Assessor
- Which standards
- On the public register for ENS.
- Standards
- Pricing
- Not published
- What they do
- Assessor
- Which standards
- On the public register for ENS.
- Standards
- Pricing
- Not published
- What they do
- Assessor
- Which standards
- On the public register for ENS.
- Standards
- Pricing
- Not published
- What they do
- Assessor
- Which standards
- On the public register for ENS.
- Standards
- Pricing
- Not published
Consultants
Who helps with ENS
A large Spanish consultancy market implements the ENS: gap analysis against Annex II, categorization, risk analysis (often with the CCN's PILAR tool), policy and procedure sets, and preparation for certification. Engagements run six to twelve months for a first Media or Alta certification.
Firms that name this framework in their own material. Listings we have not verified yet come from public filings and partner lists. Each firm can confirm its own.
No firm has claimed a ENS consultant listing yet. Claim yours →
Software
Tools for ENS
Tools that name this framework in their own material.
No firm has claimed a ENS tool listing yet. Claim yours →
Related reading
- Spain Esquema Nacional de Seguridad: high-level security measuresExplains the basic, medium and high categories and which of them require an ENAC-accredited audit rather than a self-declaration.Microsoft
- Esquema Nacional de Seguridad complianceSets out how a cloud provider is certified under the scheme and what a Spanish public-sector customer still has to do itself.Amazon Web Services
Independent third-party explainers, chosen by hand. Not affiliated with this site and not paid placements. All links are nofollow.
Need a hand implementing it?
Find a Consultant for ENS
Tell us what you need done and we will point you to firms that do this work. Your details go to a firm only when you choose it.
Not sure where to start?
Get Help with ENS
Tell us what you are trying to put in place. We will point you to the right tool, a consultant who can implement it, or both.