All articlesISO 27001

Running ISO 27001 and ENS as a single programme

Running ISO 27001 and ENS as a single programme

In short

  • One ISMS can serve both frameworks; the policy and procedure base is largely shared
  • ISO 27001 Annex A offers 93 controls selected by risk; ENS Anexo II assigns 73 measures by system category
  • ENS adds three things ISO does not: categorisation, segregated security role, CCN-CERT notification
  • ISO adds management system clauses 4 to 10, including internal audit and management review
  • The audits stay separate: different auditors, different cycles, different certificates

Can ISO 27001 and ENS be certified with one management system?

One management system can serve both, and most of the documentary base is shared. The differences are specific: ENS assigns measures by system category rather than by risk selection, requires a Security Officer segregated from system operation, and obliges incident notification to the CCN-CERT. Each framework is still audited and certified separately.

The pairing comes up constantly in Spain. A company holds ISO 27001 because an enterprise customer asked for it, then a public tender requires ENS conformity. Or the reverse. The instinct is to run two projects. That instinct is expensive and unnecessary.

Where the two genuinely overlap

Both frameworks want the same underlying things: a defined scope, an approved security policy, a risk assessment, documented procedures, access control, supplier management, business continuity, incident handling, staff awareness, and evidence that all of it happens.

In practice a single documentary base covers most of this. One access control policy can satisfy the relevant ISO 27001 Annex A control and the corresponding ENS measure, provided it is written to the stricter of the two and mapped explicitly to both. The same applies to supplier security, continuity planning, cryptography, logging, and staff training.

The mapping is where the leverage sits. A single document mapped to two frameworks, with traceability from requirement to document to evidence, is the difference between one programme and two. Maintained as separate folders, the same content diverges within a year and each audit finds a different version.

What ENS asks for that ISO 27001 does not

Three things, and each one changes how the programme is built.

Categorisation comes first, and it has no ISO equivalent. ENS requires the system to be categorised as básica, media or alta based on the harm that would follow if it were compromised, assessed across confidentiality, integrity, availability, authenticity and traceability. The category then determines which measures apply and at what depth. Nothing in ISO 27001 works this way.

Measures are assigned, not selected. This is the deepest structural difference. Annex A of ISO/IEC 27001:2022 lists 93 controls across four themes: organisational, people, physical and technological. It is explicitly a reference set. The organisation assesses risk, selects applicable controls, and justifies exclusions in the Statement of Applicability. Anexo II of Royal Decree 311/2022 lists 73 measures across three frameworks: marco organizativo, marco operacional and marco de protección. Applicability follows from the system's category rather than from the organisation's risk appetite.

The practical consequence: under ISO you can argue a control out. Under ENS, at a given category, you generally cannot. Teams accustomed to ISO frequently misjudge this and arrive at an ENS audit expecting to justify an omission the scheme does not permit.

Roles must be segregated. Article 11 of RD 311/2022 requires the Responsable de la Seguridad, who determines security requirements and approves measures, to be a different person from the Responsable del Sistema, who operates it. ISO 27001 expects defined responsibilities but does not mandate this specific split. For a mid-sized company the constraint bites, because the obvious candidate for the security role is the IT lead, and the IT lead is precisely who the article excludes.

Alongside these, ENS obliges notification of incidents affecting covered systems to the CCN-CERT, and the scheme has its own audit rhythm: certificates valid two years, ordinary audit at least every two years, extraordinary audit on substantial change.

What ISO 27001 asks for that ENS does not

ISO 27001 is a management system standard, and clauses 4 to 10 carry obligations that have no direct ENS counterpart.

Context of the organisation and interested parties. Leadership commitment evidenced at management level. A risk assessment and risk treatment methodology that is documented and repeatable, under clauses 6.1.2 and 6.1.3. Measurable information security objectives. Internal audit as a defined programme under clause 9.2. Management review under clause 9.3. Continual improvement, nonconformity handling and corrective action.

A company that built for ENS alone and then goes for ISO 27001 usually finds the measures largely in place and the management system machinery missing. The gap is not technical. It is the governance layer above the controls.

What one combined programme looks like

In sequence:

  1. Define one scope statement, or two that are deliberately aligned. If ENS covers only the system that serves a public contract and ISO covers the whole company, say so explicitly rather than leaving the boundary ambiguous.
  2. Categorise the ENS system first. The category drives measure depth, which drives everything downstream. Getting this wrong late is costly in both directions.
  3. Build one risk assessment that satisfies the ISO methodology requirement and feeds the ENS analysis.
  4. Write one document set, mapped to both. Each policy and procedure references the ISO Annex A controls and the ENS Anexo II measures it addresses.
  5. Produce two applicability statements from that mapping: the ISO Statement of Applicability with justified inclusions and exclusions, and the ENS Declaración de Aplicabilidad against the category's measures.
  6. Collect evidence once, use it twice. A single access review record can serve both audits if it is stored with the traceability to prove which requirements it satisfies.
  7. Designate the ENS roles properly, respecting article 11 segregation, and record the appointments formally.

Sequencing the two audits

The audits stay separate. Different accredited bodies, different scopes, different certificates, different cycles: ISO 27001 on annual surveillance with three-year recertification, ENS on its two-year rhythm.

Which to do first depends on commercial pressure rather than on methodology. If a tender deadline is driving the work, ENS leads. If an enterprise customer is driving it, ISO leads. Either way, build the combined documentary base before the first audit, not between them. Retrofitting the second framework onto a document set written for the first is where the duplicated effort reappears.

One internal audit programme can cover both, provided it tests against both requirement sets and the records show which.

What this costs if you have no security function

Most companies facing this pairing do not have a security team. Two frameworks, two audit cycles, a segregated security role, a risk methodology, an internal audit programme, and continuous monitoring obligations all land on someone who already has a job.

The realistic alternative is not a tool. It is a hire: a security lead who can hold the Responsable de la Seguridad role, own the ISMS, run the mapping and sit in front of two different auditors. That salary is the number worth comparing against, and an outsourced security function covering the same ground sits below it while arriving already staffed.

What no provider can do is issue either certificate. Those come from accredited certification bodies after audits. What a provider can do is build the single system both audits examine, and keep it accurate in the years between them.

The overlap between ISO 27001 and ENS is large enough that running them as two projects wastes most of the work. It is not large enough that one certificate implies the other. The distinction sits in three places: categorisation, assigned measures, and the segregated security role.

Map your existing documentation against both frameworks.

Frequently asked questions

Does ISO 27001 certification cover ENS requirements?

ISO 27001 certification does not satisfy ENS. The frameworks share most of their documentary base, but ENS adds system categorisation, assigns measures by category rather than by risk selection, requires a security role segregated from system operation, and obliges CCN-CERT incident notification. Separate audits and separate certificates apply.

How many controls and measures do the two frameworks contain?

Annex A of ISO/IEC 27001:2022 lists 93 controls in four themes and functions as a reference set from which applicable controls are selected by risk. Anexo II of Royal Decree 311/2022 lists 73 measures in three frameworks, with applicability determined by the system's category.

Can one internal audit cover both ISO 27001 and ENS?

A single internal audit programme can cover both frameworks provided it tests against both requirement sets and the records show which requirements each finding relates to. The external certification audits remain separate, carried out by different accredited bodies on different cycles.

Which framework should be certified first?

Sequencing follows commercial pressure rather than methodology. A tender deadline argues for ENS first; an enterprise customer requirement argues for ISO 27001 first. In either case the combined documentary base should be built before the first audit, since retrofitting the second framework afterwards recreates the duplicated effort.

More articles

All articles