The pairing comes up constantly in Spain. A company holds ISO 27001 because an enterprise customer asked for it, then a public tender requires ENS conformity. Or the reverse. The instinct is to run two projects. That instinct is expensive and unnecessary.
Where the two genuinely overlap
Both frameworks want the same underlying things: a defined scope, an approved security policy, a risk assessment, documented procedures, access control, supplier management, business continuity, incident handling, staff awareness, and evidence that all of it happens.
In practice a single documentary base covers most of this. One access control policy can satisfy the relevant ISO 27001 Annex A control and the corresponding ENS measure, provided it is written to the stricter of the two and mapped explicitly to both. The same applies to supplier security, continuity planning, cryptography, logging, and staff training.
The mapping is where the leverage sits. A single document mapped to two frameworks, with traceability from requirement to document to evidence, is the difference between one programme and two. Maintained as separate folders, the same content diverges within a year and each audit finds a different version.
What ENS asks for that ISO 27001 does not
Three things, and each one changes how the programme is built.
Categorisation comes first, and it has no ISO equivalent. ENS requires the system to be categorised as básica, media or alta based on the harm that would follow if it were compromised, assessed across confidentiality, integrity, availability, authenticity and traceability. The category then determines which measures apply and at what depth. Nothing in ISO 27001 works this way.
Measures are assigned, not selected. This is the deepest structural difference. Annex A of ISO/IEC 27001:2022 lists 93 controls across four themes: organisational, people, physical and technological. It is explicitly a reference set. The organisation assesses risk, selects applicable controls, and justifies exclusions in the Statement of Applicability. Anexo II of Royal Decree 311/2022 lists 73 measures across three frameworks: marco organizativo, marco operacional and marco de protección. Applicability follows from the system's category rather than from the organisation's risk appetite.
The practical consequence: under ISO you can argue a control out. Under ENS, at a given category, you generally cannot. Teams accustomed to ISO frequently misjudge this and arrive at an ENS audit expecting to justify an omission the scheme does not permit.
Roles must be segregated. Article 11 of RD 311/2022 requires the Responsable de la Seguridad, who determines security requirements and approves measures, to be a different person from the Responsable del Sistema, who operates it. ISO 27001 expects defined responsibilities but does not mandate this specific split. For a mid-sized company the constraint bites, because the obvious candidate for the security role is the IT lead, and the IT lead is precisely who the article excludes.
Alongside these, ENS obliges notification of incidents affecting covered systems to the CCN-CERT, and the scheme has its own audit rhythm: certificates valid two years, ordinary audit at least every two years, extraordinary audit on substantial change.
What ISO 27001 asks for that ENS does not
ISO 27001 is a management system standard, and clauses 4 to 10 carry obligations that have no direct ENS counterpart.
Context of the organisation and interested parties. Leadership commitment evidenced at management level. A risk assessment and risk treatment methodology that is documented and repeatable, under clauses 6.1.2 and 6.1.3. Measurable information security objectives. Internal audit as a defined programme under clause 9.2. Management review under clause 9.3. Continual improvement, nonconformity handling and corrective action.
A company that built for ENS alone and then goes for ISO 27001 usually finds the measures largely in place and the management system machinery missing. The gap is not technical. It is the governance layer above the controls.
What one combined programme looks like
In sequence:
- Define one scope statement, or two that are deliberately aligned. If ENS covers only the system that serves a public contract and ISO covers the whole company, say so explicitly rather than leaving the boundary ambiguous.
- Categorise the ENS system first. The category drives measure depth, which drives everything downstream. Getting this wrong late is costly in both directions.
- Build one risk assessment that satisfies the ISO methodology requirement and feeds the ENS analysis.
- Write one document set, mapped to both. Each policy and procedure references the ISO Annex A controls and the ENS Anexo II measures it addresses.
- Produce two applicability statements from that mapping: the ISO Statement of Applicability with justified inclusions and exclusions, and the ENS Declaración de Aplicabilidad against the category's measures.
- Collect evidence once, use it twice. A single access review record can serve both audits if it is stored with the traceability to prove which requirements it satisfies.
- Designate the ENS roles properly, respecting article 11 segregation, and record the appointments formally.
Sequencing the two audits
The audits stay separate. Different accredited bodies, different scopes, different certificates, different cycles: ISO 27001 on annual surveillance with three-year recertification, ENS on its two-year rhythm.
Which to do first depends on commercial pressure rather than on methodology. If a tender deadline is driving the work, ENS leads. If an enterprise customer is driving it, ISO leads. Either way, build the combined documentary base before the first audit, not between them. Retrofitting the second framework onto a document set written for the first is where the duplicated effort reappears.
One internal audit programme can cover both, provided it tests against both requirement sets and the records show which.
What this costs if you have no security function
Most companies facing this pairing do not have a security team. Two frameworks, two audit cycles, a segregated security role, a risk methodology, an internal audit programme, and continuous monitoring obligations all land on someone who already has a job.
The realistic alternative is not a tool. It is a hire: a security lead who can hold the Responsable de la Seguridad role, own the ISMS, run the mapping and sit in front of two different auditors. That salary is the number worth comparing against, and an outsourced security function covering the same ground sits below it while arriving already staffed.
What no provider can do is issue either certificate. Those come from accredited certification bodies after audits. What a provider can do is build the single system both audits examine, and keep it accurate in the years between them.
The overlap between ISO 27001 and ENS is large enough that running them as two projects wastes most of the work. It is not large enough that one certificate implies the other. The distinction sits in three places: categorisation, assigned measures, and the segregated security role.
Map your existing documentation against both frameworks.








