Spain’s ENS: What It Is and Which Category Applies to Your Project
ENS is not a certificate a company buys, but a set of requirements for a particular information system. The volume of those requirements is set by the category, calculated from five dimensions — and everything else depends on that.
ENS is not a certificate a company buys, but a set of requirements for a particular information system. The volume of those requirements is set by the category, calculated from five dimensions — and everything else depends on that.
The tender specification arrives in Spanish, and in the technical part there is a paragraph which the translator renders literally and which therefore becomes even less clear: the bid must attach a “declaration of conformity or certificate in accordance with the ENS”. Nobody in the company has seen this abbreviation, and the first guess is usually that this is yet another certificate the company will have to buy — more or less like ISO 27001, only in Spanish, and that it can be commissioned the same way any other certificate is commissioned, if only one can find a body that issues it.
The guess is wrong in two places at once, and both are expensive. ENS is not a certificate a company obtains, but a nationally set security framework which applies to a particular information system, and the volume of its requirements is determined not by the buyer and not by the supplier, but by the system’s category, which is calculated according to a rule written into the law. This article explains how that category is read, why everything else depends on it, and where exactly the supplier sits in this story.
What ENS is and who created it
The full name is Esquema Nacional de Seguridad, that is, the National Security Framework (ENS), and it is Spain’s public-sector information-security framework. The most important thing to know about it at once is that it was not created by the decree everyone cites: the framework is established by Spain’s law on the legal regime of the public sector, whose article 156(2) provides that the purpose of the ENS is to determine the security policy in the use of electronic means and that it is made up of basic principles and minimum requirements.
How the framework works in practice is regulated by Royal Decree 311/2022, which entered into force in May 2022 and replaced the previous decree, twelve years older. Its consolidated text has an amendment from November 2024, but that only affected who approves the technical security instructions; the annexes themselves, which are the substance of this article, were left untouched. This history has one practical meaning: documents and consultants’ presentations that refer to the old decree are out of date, and certificates issued under the old decree are not valid.
There is also one name that is easy to confuse with this one. Spain has a separate Royal Decree that approves the national security framework for fifth-generation mobile networks, and that is an entirely different instrument with a different scope. Alongside it there is also the national interoperability framework, which is laid down in the first paragraph of article 156 of the same law and which is not about security. If the specification mentions “Esquema Nacional”, it is worth making sure which of the three is meant before anyone goes looking for a document.
There is also a deadline which has already passed and because of which older documents mislead. The transitional provision gave systems that already existed, including systems of private contractors, twenty-four months from the decree’s entry into force to reach full conformity and to evidence it. That means the transitional period ended in spring 2024, and for new systems the decree has to be applied from the moment of conception, not from handover. If a bid promises to reach conformity after go-live, that is a promise that does not match the text of the decree.
Who ENS applies to: the whole public sector
The first paragraph of article 2 of the decree is short: it applies to the whole public sector in the sense defined by article 2 of the law on the legal regime of the public sector. That reference is broader than it sounds, because in that article the public sector includes the General State Administration, the administrations of the autonomous communities, the local administrations and the institutional public sector, which in turn includes legal persons under private law that are linked to, or dependent on, the public administrations.
In the same place there is also a second paragraph which no specification highlights, but which changes the volume of requirements: the decree also applies to systems that process classified information, without prejudice to the separate statute on official secrets and other special rules. In practice that means that for such systems ENS is a minimum, not a maximum, and that above it additional requirements may come which are not listed in this decree at all, and that a bid which promises conformity only with the decree will not fully cover such a system.
The third layer concerns personal data. The decree itself states that the data-protection rules apply at the same time, and that if the results of the two risk analyses differ, the stricter of them is followed. Spain’s Organic Law 3/2018 on data protection, moreover, has a separate provision that requires ENS measures for personal-data processing carried out by the public sector, so requirements can arrive at one and the same system through two doors at once, and the answer to which of them is the stricter has to be known before the budget is planned.
Another boundary worth knowing before the conversation is that the public-sector definition here also includes public universities and legal persons under private law linked to the administration, that is, structures that from the outside do not look like an authority. For a supplier bidding from outside Spain that practically means that a partner who in a presentation calls themselves a foundation, an institute or an agency may, as far as scope is concerned, be public sector in exactly the same way, and that question is cheaper to ask before the bid than after the contract is signed.
And to you, if you are a supplier
This is the paragraph most readers opened this article for, and it has to be read precisely, because retellings of it tend to be both too wide and too narrow. The third paragraph of article 2 of the decree provides that the decree also applies to the information systems of private-sector entities, including the duty to draw up a security policy, when those entities, in accordance with the applicable rules and on the basis of a contractual relationship, provide services or supply solutions to public-sector entities so that those entities can exercise their competences and administrative powers.
In that sentence there are four boundaries, and each of them excludes something. First, it applies to information systems, not to the company as a legal person in general, so the question is always about a particular system, not about the whole company. Second, the basis is a contract, not general co-operation. Third, the service has to be connected with the exercise of the public entity’s competences and administrative powers. Fourth, the security policy in that case is approved by the highest executive body in the company itself, that is, the board or its chair, not the project manager or the IT department.
The decree then says how this requirement reaches you in practice: the administrative or technical specifications of public-sector entities’ contracts must include everything necessary to ensure ENS conformity of the information systems on which the contractor’s services rest, including the submission of the relevant declaration of conformity (ENS) or certificate. In the same place there is also a reservation about the supply chain: the requirement also applies to the contractor’s supply chain to the extent that is necessary and in accordance with the results of the risk analysis, so not automatically to every subcontractor.
One more thing worth knowing in conversation with the buyer: for outsourced services the decree provides that the contractor designates a security contact, but final responsibility remains with the public-sector entity that receives those services. The supplier is therefore not the one who is responsible for the system’s conformity as a whole, and is not the one who determines its category, but it is usually on the supplier’s side that all the evidence later used to substantiate that category in the audit sits, so the documentation is the supplier’s work from the first day.
One terminology point is worth fixing at once, because it saves half the misunderstandings in conversation with the buyer. The word “system” is defined widely in the decree and includes not only the application, but also the networks, the devices and the data themselves, together with everything needed to operate, use, protect and maintain them. That is why the question “does our product conform to the ENS” is usually the wrong question: conformity is assessed for a particular system in a particular environment, and one and the same product in two environments can fall into two different categories.
The five dimensions that measure information
The rest of the construction rests on five security dimensions, which the first annex of the decree marks with capital letters: confidentiality (confidencialidad), integrity (integridad), traceability (trazabilidad), authenticity (autenticidad) and availability (disponibilidad). They are not abstractions, because each of them has its own definition in the fourth annex of the decree, and it is by those definitions that each dimension is assigned a level, and that is exactly why an assessment carried out against some other list, or by habit from another industry, will not survive the first question in an audit.
Confidentiality means that information is not made available or disclosed to unauthorised persons, entities or processes. Integrity means that the information asset has not been modified without authorisation. Traceability means that an entity’s actions can be traced indisputably back to that same entity. Authenticity means that an entity is who it claims to be, or that the origin of the data is guaranteed. Availability means that authorised entities and processes have access to the information assets when they need it, and it is this last dimension that in public services most often turns out to be the highest, because an interruption there is visible at once and affects people, not only the authority.
The practical gain from this list is that it lets a conversation about security be turned from a general one into a specific one. The question is no longer “how secure is this system”, but five separate questions about how severe the consequences would be if this one property were lost. For a system that stores publicly available information, confidentiality may not be material at all, whereas traceability may be decisive, and it is exactly this asymmetry that the category calculation later uses.
It is also worth understanding why there are exactly five dimensions, not three. In the classic information-security triad there is confidentiality, integrity and availability, but public administration works with documents that have legal effects, so it additionally needs to know who did what and whether the origin of a document can be proved. That is why traceability and authenticity are separate dimensions here with their own levels, and they are the ones that most often turn out to be the highest in systems that from the outside look non-critical.
Three levels for each dimension
Each affected dimension is assigned one of three levels, namely low, medium or high (BAJO, MEDIO, ALTO), and it is determined not by how likely an incident is, but by how severe the harm would be if it happened, which is an important difference from ordinary risk analysis. A low level means limited harm: a noticeable reduction of the organisation’s capacities in which functions are nevertheless performed, slight harm to assets, a formal and remediable breach of the law, or slight harm to a person that is easily compensated.
A medium level means serious harm: a substantial reduction of capacities in which functions are still performed, substantial harm to assets, a material or irreversible formal breach of the law, or substantial harm to a person that is hard to compensate. A high level means very serious harm: the effective destruction of the organisation’s capacities, very serious or irreversible harm to assets, a serious breach of the law, or serious harm to a person that is hard or impossible to compensate.
Two details at this point decide the result. The first is that a dimension which in the particular system is not affected at all does not receive a level, and that is not the same as a low level — it means that the measures attached to that dimension are not applied at all. The second is that if the system processes different information and provides different services, then in each dimension the system’s level is the highest of all those determined in it, not the average and not the most frequent.
In practice the assessment is done not by feel, but by a question asked about each dimension separately and always in the same way: what would happen to the organisation, to its assets, to compliance with the law and to a particular person, if this very property were lost. The discipline of that question is what distinguishes an ENS assessment from a general risk register, and it is also the reason why the result is defensible in conversation with an auditor — each level has a rationale, not a mark.
How the dimensions produce the system’s category
The category is determined by one rule, and it is short. A system is in category ALTA if even one of its dimensions reaches the high level. It is in category MEDIA if even one dimension reaches the medium level and none reaches higher. It is in category BÁSICA if even one dimension reaches the low level and none reaches higher. In other words, the highest dimension wins, and the others do not affect the result, so the whole conversation about category is in practice a conversation about that one dimension which turns out to be the highest.
This is also the place where retellings go wrong most often, so it is worth saying separately: determining the category does not raise the level of those dimensions that did not decide the category. A system in which availability is high but confidentiality is low is in category ALTA, but the measures attached specifically to confidentiality are still applied to it in the volume of the low level. That is a logical but counter-intuitive result, and it is also the reason why a simplified table of “category against number of requirements” misleads.
Another requirement that tends to be omitted is that the assessment is not a one-off. The annex requires it to be reviewed once a year, or more often if the criteria against which it was carried out change materially. In practice that means that new functionality, a new type of data or a new set of users can change the level of a dimension and with it the category of the whole system, so conformity is not a state you reach once and then put on a shelf, but an annual rhythm which has to be planned into the maintenance contract in the same way as updates and backup checks.
There is also one possibility of departure which the decree allows directly. Measures may be replaced by documented compensatory measures which provide equivalent or better protection, and the chosen set is drawn up in a Statement of Applicability (ENS), the Declaración de Aplicabilidad, which is signed by the Security Officer. In practice that means that conformity is not a tick-list in which each row has to match exactly as written — but also that each departure has to be justified in writing and will be read in the audit, so a compensatory measure invented in the week of the audit costs more time than the one that was planned in the project.
What each category requires
The measures are in the second annex of the decree, and they are divided into three groups: the organisational framework, the operational framework and the protection measures. Altogether there are more than seventy separate measures with their own designations, and they are chosen in a set order — first the types of asset are determined, then the applicable dimensions, then the level of each dimension, then the system’s category, and only then the measures themselves are chosen, together with the reinforcements that apply in the particular category or at the particular dimension level.
The volume of requirements between categories grows in two ways at once, and that is why a single number does not describe it. First, in a higher category measures become applicable which in the lower one are not applicable at all — for example, requirements about outsourcing and about the supply chain appear only in the higher categories. Second, the measures that are already applicable acquire named reinforcements: a risk analysis in category BÁSICA may be informal, in category MEDIA it is already partially formal, and in category ALTA — formal and with an internationally recognised mathematical basis.
Third, the required maturity level changes. Category BÁSICA corresponds to a level at which the process is repeatable but intuitive, category MEDIA — a defined process, and category ALTA — a process that is managed and measurable, that is, one about which there are data, not only a description. That means that one and the same measure designation in a higher category is not the same volume of work, and that is why the claim that a given category requires a given number of measures cannot be read out of this annex at all.
For the supplier a practical conclusion about price follows from all of this. Between category BÁSICA and category MEDIA the difference is not in percentages, but in the fact that in one case a self-assessment is enough, which can be done by the team that administers the system anyway, while in the other an external audit is needed, with its own timetable and its own price. That is why the first question worth asking the buyer in a tender is not about the list of requirements, but about what the system’s category is and who determined it.
Declaration or certification: the difference you must not mix up
This is the place where a wrong answer costs the most, so it is taken straight from article 38 of the decree. Systems in categories MEDIA and ALTA need an audit for certification of conformity (ENS), whereas for systems in category BÁSICA a self-assessment for a declaration of conformity (ENS) is enough — and that does not prevent those too from going through a certification audit voluntarily. Mixing these two sides up is the most common error that exists on this subject at all, and it costs either an unnecessary audit or a missed bid, depending on which direction the error was made in.
The self-assessment, as the third annex provides, can be carried out by the same staff who administer the system, or by someone to whom it has been entrusted, and the result has to be documented measure by measure with evidence. In categories MEDIA and ALTA the result is a formal audit report on the degree of conformity, with findings of conformity and non-conformity, and that is a document prepared by an external assessor, not by the team itself. In addition the decree requires a regular compliance audit at least once every two years, and an extraordinary audit if material changes have taken place in the system.
The result is public. The decree provides that declarations of conformity (ENS) and certificates are published on the relevant internet portals or on the authorities’ official websites, and they have their own visual form — a distinctive mark, which in the case of a declaration is signed by the responsible entity itself, but in the case of certification by the certification body that assessed the systems. Who exactly may carry out a certification audit is not laid down in the decree and is left to the technical security instructions; we have written separately about what such requirements usually look like in a tender specification.
Another practical detail concerns deadlines. A certification audit is not a one-off event, because the decree requires a regular compliance audit at least once every two years, and that means that the contract for maintaining the system also has to be clear about who organises this audit, who pays for it and who prepares the evidence. In projects where that has not been written down, the second audit usually arrives as a surprise just when the team has already moved on to other work.
How it differs from other frameworks you already know
A reader coming from outside Spain will find ENS easier to understand through the differences than through the similarities. The national cyber-security statutes we have written about separately start with the question of whether the organisation is even in scope, and only then talk about measures. ENS starts from the other end: the scope is broad and almost self-evident, because it is the whole public sector, but the volume of requirements is decided by the category of each particular system, so in Spain the question “does this apply to us” is much less interesting than the question “what category is this system”.
The second difference is the object of the assessment. Under those statutes the talk is of the entity — that is, the organisation — and the measures apply to its activity as a whole. ENS assesses a system, and in one authority a system in category BÁSICA and a system in category ALTA can stand next to each other with an entirely different volume of requirements. For the supplier that is convenient, because the requirements scale to the particular job, but it also means that a reference to earlier conformity on another project proves nothing.
The third difference is publicity. A supplier from outside Spain cannot look up a client’s in-scope status from a public register the way they can look up an ENS declaration; in Spain the declarations of conformity (ENS) and the certificates are published, and they have their own recognisable mark. In practice that means that before submitting a bid you can look at what the buyer has already published about its systems, and that is information the specification usually does not write down, but which is more useful in preparing the bid than half the specification’s text.
The fourth difference is the method. Those statutes set their measures at the level of the entity, and they are the same list for every entity in a given category; in Spain the set of measures is chosen for each system, following the decree’s annex and documenting any substitution. For the supplier the Spanish approach is heavier in documents, but more predictable in money, because the volume of requirements is known as soon as the category is known.
Who takes the decisions, and what ENS does not mean
Decisions are taken by two distinct roles, and the supplier is neither of them. The assessment of information and services, that is, determining the level of each dimension, is the competence of the Information Officer or the Service Officer, whereas determining the system’s category is the competence of the Security Officer. Both of these roles sit on the public-sector side, so the supplier can prepare evidence and a rationale, but cannot decide the category.
The methodology is published by the National Cryptologic Centre, which sits inside Spain’s National Intelligence Centre and which also has charge of the national incident-response body. It issues the 800-series guides, and for determining the category there is a numbered guide of its own on assessing systems, which also contains worked examples with a notation in which each of the five dimensions is shown separately. If a project in Spain is real, that is the guide to read immediately after the decree itself, because that is where the notation is written in which the result of determining the category is submitted, and the examples against which it can be checked.
What ENS does not mean is at least two things. A certificate to the ISO 27001 standard is not ENS conformity: the Centre’s own guide on the relationship between the two frameworks writes that compatibility must not be treated as an arithmetic relation of equivalence, and that the existence of an ISO certificate does not automatically imply equivalence with other frameworks. Nor is ENS a substitute for NIS2. The Centre published a specific compliance profile in 2024 linking the two regimes for organisations already in ENS scope, but in March 2025 it announced that this guide had been removed from the portal and had lost its applicability, and that a new edition is being prepared.
Finally, one thing about us. We do not certify anyone in Spain and we are not a certification body; this article is an explanation, not a service offer. What we do is public-sector systems development to the requirements of a tender specification, and if you have a specification with an ENS requirement and a question about what it means for the particular system, write to us — the answer to that starts with the five dimensions, not with the price of a certificate.
Frequently asked questions.
What is ENS?
Esquema Nacional de Seguridad is Spain’s public-sector information-security framework, established by the law on the legal regime of the public sector and regulated in its operation by Royal Decree 311/2022, in force since May 2022. It is not a certificate a company obtains, but a set of requirements that applies to a particular information system. The volume of requirements is determined by the system’s category, namely BÁSICA, MEDIA or ALTA, which is calculated from five security dimensions and the levels assigned to them.
Does ENS apply to a supplier from outside Spain?
It applies to that supplier’s information systems, not to the company as such. The third paragraph of article 2 of the decree provides that it applies to the information systems of private-sector entities when they, on the basis of a contractual relationship, provide services or supply solutions to public-sector entities for the exercise of those entities’ competences and administrative powers. The requirement reaches the supplier through the tender specification, which must include the submission of a declaration of conformity (ENS) or a certificate; it applies to subcontractors in accordance with the risk analysis, not automatically.
How is the system’s category determined?
By the highest of the five dimensions. Each of confidentiality, integrity, traceability, authenticity and availability is assigned a low, medium or high level according to how severe the harm would be in the event of an incident; a dimension which is not affected in the system does not receive a level at all. Then the category follows that highest dimension: ALTA if even one is high; MEDIA if even one is medium and none higher; BÁSICA if even one is low and none higher. The assessment has to be reviewed once a year.
How does a declaration of conformity differ from certification?
By who verifies it, and that is determined by the category, not by a choice. For systems in category BÁSICA a self-assessment is enough, which can be carried out by the system’s own administrative staff and whose result is a declaration of conformity (ENS); in categories MEDIA and ALTA an audit is needed, whose result is a certificate of conformity (ENS). A BÁSICA system may go through a certification audit voluntarily. Mixing these two directions up is the most common error on this subject, and it costs either an unnecessary audit or a missed bid.
Does an ISO 27001 certificate replace ENS conformity?
No, and Spain’s own authority writes that. The National Cryptologic Centre’s guide on the relationship between the two frameworks writes that compatibility must not be treated as an arithmetic relation of equivalence and that the existence of an ISO certificate does not automatically imply equivalence with other frameworks — each framework has its own conformity process. Nor is ENS a substitute for NIS2. The Centre published a specific compliance profile linking the two regimes in 2024, but in March 2025 it removed it from the portal and is preparing a new edition.
Latvian public institutions since 2010. SSO, official e-delivery, WCAG 2.1 AA and GDPR — we handle the specification and procurement requirements.