Does ENS apply to your company, and at which level?

Does ENS apply to your company, and at which level?

The Esquema Nacional de Seguridad is governed by Royal Decree 311/2022, which replaced the earlier RD 3/2010. Most organisations meet it the same way: a tender document lands, someone reads the technical requirements, and a sentence about ENS conformity turns out to be a condition of bidding.

The scheme reaches suppliers, not only public bodies

Article 2 of RD 311/2022 sets the scope. Alongside state, regional and local administrations, it covers private-sector organisations that handle information or provide services to them. Nationality is not the qualifier: a provider established outside Spain that processes Spanish public-sector information falls inside the same scope as one established in Madrid.

This is how the requirement travels down a supply chain. A prime contractor holds the public contract; the subcontractor running part of the system inherits the obligation. Companies frequently discover this second-hand, from a customer rather than from a regulator.

The practical consequence is commercial. Where a tender specifies ENS conformity, a bidder who cannot evidence it is excluded from that procedure. Where a live contract requires a valid certificate, letting one lapse gives the contracting body grounds to terminate.

Three categories, decided by impact, not by company size

ENS categorises systems, not organisations. A twelve-person company can operate a system in categoría media, and a large organisation can hold several systems in different categories at once.

Categorisation works from the harm that would follow if the system were compromised, assessed across confidentiality, integrity, availability, authenticity and traceability:

  • Básica: limited impact
  • Media: significant harm to the organisation
  • Alta: serious harm

Two things follow from getting this wrong. Categorise too low and the certificate will not satisfy the tender. Categorise too high and you commit to controls, audits and cost the contract never asked for.

Declaration or certification: the distinction that changes everything

This is the part that most often surprises people, and it is worth being precise about.

For categoría básica, RD 311/2022 permits a declaración de conformidad: the organisation assesses itself and publishes the result. No external auditor is required.

For categoría media and alta, a certificación de conformidad is required, issued following an audit by a certification body accredited by ENAC.

Two different procedures, two different costs, two different timelines. A tender that says "ENS conformity" without naming a category is ambiguous, and the ambiguity is expensive in both directions. Read the technical specification for the category before scoping any work, and if the document is genuinely silent, ask the contracting body rather than guessing upwards.

What Annex II actually asks for

Annex II of RD 311/2022 sets out 73 security measures, grouped into three frameworks:

  • Marco organizativo: 4 measures covering the security policy, normative documents, procedures and authorisation processes
  • Marco operacional: 32 measures covering planning, access control, operations, protection of outsourced services, continuity and system monitoring
  • Marco de protección: 37 measures covering facilities, personnel, equipment, communications, media, applications, information and services

Each measure applies at a depth set by the system's category. Higher categories do not add entirely new measures so much as raise what each one demands. Continuous monitoring is a good example: present in a light form at básica, and a substantive operational requirement at alta.

That distinction matters when choosing how to comply. Documentation alone satisfies parts of the marco organizativo. It does not satisfy the operational monitoring measures, which require something to actually be watching.

The role you have to designate before anything else

Article 11 requires differentiated responsibilities. The Responsable de la Seguridad, the person who determines security requirements and approves the measures, must be a different person from the Responsable del Sistema, who operates it.

For a mid-sized company this is the awkward part. The obvious candidate is the IT lead, and the IT lead is precisely the person the article rules out, because they run the systems. Naming them anyway creates a finding an auditor will pick up.

The role is not ceremonial. Whoever holds it approves the security measures formally, produces the statement of applicability against the Annex II measures, supervises policy, coordinates training and manages incidents. In an organisation with no security function, it is a substantial job handed to someone who already has one.

What happens after the certificate

An ENS certificate is not a one-off. Certificates carry a validity of two years, and the scheme requires ordinary audits at least every two years, plus an extraordinary audit where the system changes substantially. Internal review continues in between.

That cadence is what tends to break document-led approaches. A folder of policies assembled for an audit drifts within months of the auditor leaving. Systems change, staff rotate, and the evidence that supported a measure last spring no longer describes what happens today. The next audit finds the gap.

Separately, RD 311/2022 obliges notification of incidents affecting covered systems to the CCN-CERT. That obligation is continuous, and it presumes the organisation can detect an incident in the first place.

What this means if you have no security function

Most companies that hit ENS for the first time do not have anyone whose job is security. The obligation still lands in full: a designated Security Officer segregated from IT operations, 73 measures scoped by category, an audit every two years, monitoring that runs continuously, and an incident notification duty.

The honest way to size that is against the alternative you would otherwise choose, which is not a tool: it is a hire. A security lead capable of holding the Responsable de la Seguridad role, running the Annex II programme and standing in front of an ENAC auditor is a salaried appointment, and the cost of that appointment is the benchmark worth comparing against. An outsourced security function that covers the same ground sits well below one salary, and it arrives already staffed.

What no provider can do is issue the certificate. That comes from an accredited certification body after an audit. What a provider can do is run the programme that survives the audit, and keep running it in the two years afterwards when nobody is watching.

If ENS is on your desk because of a tender, the first two decisions are the ones above: which category the specification requires, and whether that means a declaration or a certification. Get those right and the rest of the programme scopes itself.

Talk to our team about your ENS scope.