When a Spanish public tender requires the Esquema Nacional de Seguridad (ENS), Spain's National Security Framework, the shortlist of tools narrows quickly. The large international compliance platforms do not carry ENS, so a company looking for ENS software ends up comparing the players built for the Spanish regime. Two names come up again and again: GlobalSuite and Complaion. This comparison sets out what each does well, what kind of company each is built for, who does each stage of the scheme with each option and how each differs from Qalea, with one principle: describe each option precisely and leave the decision to the reader.
What all three cover equally: ENS at every category
ENS is governed by Royal Decree 311/2022. It classifies each information system as Basic, Medium or High according to the impact an incident would have across five dimensions: confidentiality, integrity, availability, authenticity and traceability. The category decides which of the 73 measures in Annex II apply, and at what depth.
It also decides how conformity is demonstrated. The Basic category allows a self-assessed declaration. Medium and High require a certification issued by a body accredited by ENAC, Spain's national accreditation body, following an audit that article 31 requires at least every two years. Our guide to how an ENS audit works covers the process in detail.
GlobalSuite, Complaion and Qalea all work with ENS at all three categories. All three help categorise the system, build the documentation and prepare for the audit. None of them issues the certification, which only an accredited body can do. With coverage equal, the useful comparison lies elsewhere: in who does the work, and which part of ENS each one covers.
The three at a glance

GlobalSuite is broad GRC software operated by the organisation's own governance, risk or security team, backed by a consulting practice. Complaion is a certification platform paired with a Lead Auditor assigned to each client. Qalea combines a multi-framework compliance platform with an operated security function: SOC, EDR, vulnerability and attack-surface management, penetration testing and a vCISO.
GlobalSuite: the reference GRC software in Spain
What it does well
GlobalSuite Solutions is a Madrid firm with two decades of work in risk management, security, continuity and compliance, and the company states that more than 2,000 organisations use its solutions. Its ENS module covers the full cycle, from the initial categorisation of systems to the certification audit. As you categorise and run the risk analysis, the platform generates the Statement of Applicability and maps the relevant Annex II measures to each asset.
It also carries authority of its own within the scheme. GlobalSuite is itself certified to ENS at High category, with a scope covering its GRC platform and its other services. Its framework breadth is hard to match: the same software manages ISO 27001, ISO 22301, ISO 31000, ISO 20000, GDPR, criminal compliance and critical-infrastructure protection, among others.
Two further features matter to particular organisations. The licence is available as a subscription or a perpetual purchase, and deployment can be shared cloud, dedicated cloud or the customer's own infrastructure. And an in-house consulting and audit practice configures the system, loads the catalogues of measures and migrates existing information.
Who it is built for
With its breadth and deployment options, GlobalSuite fits naturally in mid-sized and large organisations that already have an established governance, risk or security function, and in public administrations managing several frameworks at once. That profile gets the most from a single system of record for every management system it runs.
What sits outside its scope
GlobalSuite is a governance system: it documents compliance, connects it and makes it traceable. The customer's own team runs it day to day, and the technical side of ENS, such as monitoring, vulnerability management and incident response, is operated with other tools or providers.
Complaion: a platform and a Lead Auditor for SMEs
What it does well
Complaion is an Italian company based in Milan that works with Italian and Spanish SMEs and runs a Spanish-language ENS practice covering all three levels. The company states that more than 500 businesses have chosen it. Its model is clear: by its own description, the platform automates up to 80% of the process and a dedicated Lead Auditor covers the remaining 20%.
The platform organises evidence, procedures, internal audits, risks, assets, suppliers and training, and includes a trust centre for sharing certifications with customers. The Lead Auditor designs the management system, drafts the procedures the customer approves and handles communication with the certification body. Of the three, it is the one that puts a named person most at the centre of the offer. Alongside ENS and ISO 27001, it covers quality, environmental and health-and-safety standards such as ISO 9001, 14001 and 45001.
Its offer comes in three plans, Essential, Full and Premium, all priced by quote. According to its plans page, policy writing, implementation and internal audit by the Lead Auditor begin at the Full plan, while third-party integrations and support during the external audit sit in Premium. Complaion states plainly that it is not a certification body: it coordinates the final stage with partner bodies.
Who it is built for
Complaion explicitly targets SMEs without an internal compliance function, in sectors such as manufacturing, IT and software, healthcare, construction, logistics and professional services. It suits companies that need several ISO certifications at once, for example quality, environment and security, and value a single expert point of contact for all of them.
What sits outside its scope
Complaion is built around certification: preparing the management system, maintaining it and taking it to audit. Operating the customer's security, such as monitoring its systems, scanning for vulnerabilities or running a penetration test, is not part of the offer it describes for customers. Its site does mention recurring penetration tests and threat monitoring, but in relation to the security of its own infrastructure.
GlobalSuite and Complaion: two different routes to ENS
Both cover ENS, and both are serious at what they do. The difference is who does the work.
GlobalSuite puts a very complete tool for governing compliance in the hands of an in-house team. Its value grows with that team's maturity: the more frameworks and systems it manages, the more it gains from the software's traceability and breadth. The typical buyer is a security, risk or compliance lead who already exists in the organisation.
Complaion puts an expert alongside a company that has no such team. Its value lies in the support: the Lead Auditor takes on much of the design and drafting, and the platform organises the rest. The typical buyer is the managing director or IT lead of an SME who has received the requirement and has nobody to hand it to.
Neither model is better in the abstract. They answer to different organisations.
Who does each stage of the ENS cycle
Reaching ENS conformity and keeping it involves very different stages: categorising the system, analysing risk and writing the Statement of Applicability, drafting policies and procedures, implementing and operating the technical measures, appointing the Security Officer, passing the internal audit and supporting the external one. Each option divides that work differently.

On the documentation side, all three cover the route, with different divisions of labour. With GlobalSuite, the platform automates the Statement of Applicability and the customer's team handles the rest, supported by its consulting practice. With Complaion, the Lead Auditor takes on design, drafting and internal audit from the Full plan. With Qalea, the platform generates and maintains the documentation and Qalea's team supports the customer according to the tier chosen.
The difference shows in the operational rows. Monitoring, incident response, vulnerability management and penetration testing sit with other tools or providers under GlobalSuite, and outside Complaion's customer offer. With Qalea they are part of the same service.
What ENS asks for beyond documentation
Those rows matter because part of ENS cannot be satisfied by any document on its own. The operational framework in Annex II includes measures that describe continuous activity: system monitoring (op.mon), including intrusion detection and surveillance, which since Royal Decree 311/2022 apply from the Basic category upwards; incident management (op.exp.7) and incident records (op.exp.9); protection against malicious code (op.exp.6); and security maintenance and updates (op.exp.4). Article 10 states it as a principle, continuous surveillance and periodic reassessment, and article 33 requires incidents affecting covered systems to be notified to the CCN-CERT, Spain's national government CERT.
Article 11 adds an organisational requirement that weighs heavily on a mid-sized company: responsibility for security must be separated from responsibility for operating the system. The obvious candidate for Security Officer, the head of IT, is precisely the person the article rules out.
In a Medium or High audit, the auditor does not stop at reading the policy. They sample logs from different months, incident trails and evidence that someone reviews what the monitoring produces. A documentation platform prepares the ground for that check; making sure the monitoring exists and someone watches it is operated work, whether the customer does it, a provider does it or the same company that runs the compliance does it. We cover the distinction in full in what a compliance platform does not do.
Where Qalea fits
Qalea is the third route to ENS: the compliance platform and the security function that operates the measures, delivered as one service. It is built so that ENS does not stop at documentation.
One management system for ENS and every other framework
Qalea's platform is a digital ISMS. When you select ENS, it sets the category from the five dimensions, maps the relevant CCN-STIC measures to each system, generates the policies and procedures, and maintains the register of risks, exceptions and non-conformities. Evidence is collected automatically from the tools the company already uses, such as Google Workspace, Microsoft 365, AWS, GCP, Azure, GitHub, GitLab, Bitbucket and Slack, and the conformity pack for the external audit is produced in a single step.
The same system runs ISO 27001, NIS2, DORA, SOC 2, ISO 42001 and ISO 9001, reusing controls and evidence across frameworks, so adding a certification does not mean starting again or duplicating documentation. For a regulated company that already has a compliance function and keeps adding obligations, that reuse is what prevents one project per standard: the internal team governs the programme, and Qalea takes on the collecting, mapping and operating. We explain how ENS and ISO 27001 share one system in running ISO 27001 and ENS as a single programme. The platform also manages suppliers, customer security questionnaires and identities, and includes a Trust Center for sharing compliance status.
The security ENS measures assume
Underneath the platform, Qalea operates the security described in Annex II's operational framework:
- Monitoring and incident response (op.mon, op.exp.7, op.exp.9): a SIEM that centralises events, EDR across Windows, macOS and Linux laptops and servers, and a SOC that triages alerts and responds to incidents, leaving the trail an auditor samples.
- Malicious code, patching and vulnerabilities (op.exp.6, op.exp.4): EDR with hardening, and management of internal vulnerabilities across servers and hosts.
- External surface and cloud: external attack-surface management covering exposed assets, expired certificates and leaked credentials, and misconfiguration detection across AWS, GCP and Azure.
- Applications: SAST, DAST, SCA, secrets scanning and SBOM from commit to runtime, plus a manual penetration test.
- People (mp.per.3, mp.per.4): continuous awareness and training with real phishing simulations, device management and a password manager.
All of it runs under one monitoring layer. When the auditor asks for logs from different months, those logs exist because someone has been producing and reviewing them.
A Security Officer, and the level of support each company needs
Article 11 requires security to be separated from system operation. At Qalea, a vCISO provides that Security Officer function, together with senior judgement on architecture, due diligence and the security questionnaires customers send.
Support is sized to each company's team. At the Supported tier, Qalea provides onboarding and unlimited support. Guided adds the internal audit. At Fully Managed, Qalea absorbs the operational load of the programme, including support during the external audit, and the customer's team steps in only when it is needed.
Who it is built for
Qalea is built for Spanish companies of 10 to 250 people in three situations: a company that receives a tender requiring ENS and has nobody to take on either the Security Officer role or the operation; a regulated company with its own compliance function that is adding ENS, NIS2, DORA or SOC 2 and wants one system with the security operated; and a company whose certification project has stalled with a consultancy or a tool.
Qalea is itself certified to ENS at High category. It works with more than 80 clients won in two years, with churn below 1%, and was selected for the 2025 cohort of Google for Startups Growth Academy: AI for Cybersecurity, one of 16 startups worldwide. Like GlobalSuite and Complaion, it does not issue certificates and is not a certification body: it gets the organisation audit-ready and runs the security function that keeps the certificate valid between one audit and the next.
What to compare when you evaluate ENS software
With ENS coverage equal, these are the criteria that genuinely separate the options:
- Who operates the platform day to day: the organisation's own team, an expert from the provider, or a combination of both.
- Who takes on the Security Officer role, and how the separation required by article 11 is respected.
- What watches the systems between audits, and who responds when an alert fires.
- Which other frameworks need managing in the same place, and whether controls and evidence are reused across them.
- Which licensing and deployment model the organisation requires, cloud or its own infrastructure.
Three questions work on any demo, Qalea's included: who will do the work the platform assigns? What produces the logs and alerts the auditor will sample? Who will be our Security Officer, and who do they report to?
The full market map, including the international platforms and the Spanish security providers, is in Best Compliance Automation Platforms for Spain in 2026. Every guide to the scheme is collected on our ENS hub.








