An ENS certificate shows what an auditor verified on specific dates. Renewal depends on what happens next: for the following two years, the system has to keep meeting the measures of the Esquema Nacional de Seguridad, and the next audit will check that against the records from that period.
This guide explains what has to keep running to maintain ENS certification, what the auditor will review, and which changes force an earlier audit.
How long ENS certification lasts and what renews it
Article 31.1 of Royal Decree 311/2022 requires systems within the scope of the ENS to pass an ordinary audit at least every two years. The CCN's frequently asked questions state that a certificate of conformity has an effective validity of two calendar years from the date it is granted, and that the renewal date can never exceed that.
Three details matter for planning:
- An extraordinary audit restarts the count. If one is carried out because of a substantial change, its date becomes the starting point for the next two years.
- The deadline only moves for force majeure. Article 31.1 allows a three month extension when there are force majeure impediments not attributable to the organisation. It is not an extension for preparing documents.
- The Basic category has a cycle too. It is covered by a self assessment and a declaration of conformity, repeated on the same cycle.
The ENS does not follow the three year cycle with surveillance audits that ISO 27001 holders know. Some certification bodies add intermediate reviews in their own procedure, so check the procedure of the body that issued your certificate. If you run both standards, see running ISO 27001 and ENS as a single programme. How the audit itself works is covered in the ENS audit: how it works and what the auditor reviews.
Which ENS measures have to run every day
Royal Decree 311/2022 rests on two principles that define the period between audits: continuous monitoring and periodic reassessment (article 10), and risk management as a continuous, permanently updated activity (article 7). In Annex II, those principles mostly take shape in the operational framework. These measures leave a trace every week, not every two years.
Detection and monitoring (op.mon.1, op.mon.3)
Intrusion detection and monitoring apply from the Basic category, with further reinforcements at Medium and High. Monitoring (vigilancia) is a new measure in the 2022 decree. In practice, someone collects and reviews system events and acts on alerts. A tool that nobody reviews will struggle to show monitoring to an auditor.
Maintenance and vulnerabilities (op.exp.4)
The maintenance and security updates measure requires tracking the defects that vendors announce and deciding when to apply each update according to risk. Article 21 adds that permanent evaluation and monitoring must adapt the security posture to the vulnerabilities identified. What gets audited is the judgement applied and its record, including on the external attack surface.
Incidents and their register (op.exp.7, op.exp.9)
Both measures apply in every category. Article 25 calls for detection mechanisms, classification criteria, resolution procedures and a record of actions taken. For a private supplier to the public sector, article 33.7 adds reporting to INCIBE-CERT any incidents that affect it. An empty register after two years tends to raise questions at the audit.
Metrics, category and risk (op.mon.2, op.pl.1)
The metrics system measures how far the measures are implemented. The risk analysis has to stay current, and Annex I requires the system category to be reassessed every year or whenever the criteria behind it change significantly.
People (mp.per.3, mp.per.4)
Awareness and training apply in every category. Staff change over two years, and new joiners need them too. We cover this in security awareness for ISO 27001.
What the auditor will review from the two years
Under article 31.4, the audit report gives a verdict on the degree of compliance and includes the data, facts and observations its conclusions rest on. In a system that has been certified for two years, those facts sit in the operational records. This is the evidence of operation that goes with each measure:
- op.mon.1, op.mon.3: alerts raised, reviewed and closed.
- op.exp.4: vulnerabilities found, the decision on each update and the date applied.
- op.exp.7, op.exp.9: incident register with classification, resolution and notifications.
- op.exp.8: user activity logs, retained and protected.
- op.pl.1: risk analysis reviewed and approved.
- mp.per.3, mp.per.4: attendance at awareness and training, including new joiners.
- Article 31.5: corrective measures from the previous audit, applied and closed.
The exact list depends on the system category and its Statement of Applicability. We go into more detail in what a certification audit actually tests.
Which changes trigger an extraordinary audit
Article 31.1 requires an extraordinary audit whenever there are substantial changes to information systems that could affect the required security measures. The decree gives no closed list, so the decision sits with the system owner and the security officer. Some changes worth assessing against that test:
- Moving services within the scope to the cloud.
- Publishing a new service within the scope to the internet.
- Integrating the network or systems of an acquired company.
- Changing the provider that hosts or operates the system.
Recording why a change was or was not judged substantial is also useful evidence for the next audit.
Where compliance slips after certification
When compliance erodes between audits, the cause is usually organisational rather than technical. These patterns are common:
- The team that prepared the certification finishes its work. If a consultancy ran the project, its engagement often ends with the certificate, and nobody takes over day to day operation.
- Responsibilities change hands. Article 13 requires the security officer to be a different person from the system owner. If one of them leaves, that separation of duties can break without anyone noticing.
- The documentation stands still. Policies remain approved but describe a system that has since changed.
- Tools stay installed, but nobody attends to them. There is EDR and there are logs, but no alert review and no recorded decisions.
- The records have gaps. Months with no entries in the incident or update registers, which then have to be rebuilt before the audit.
A maintenance calendar for the two years
Royal Decree 311/2022 sets only some frequencies, such as the audit and the annual category reassessment. The rest comes from each organisation's Statement of Applicability and procedures. This calendar is a practical reference:
- Continuously: intrusion detection, event monitoring and alert response (op.mon.1, op.mon.3, op.exp.7).
- Every month: vulnerability review and decisions on updates (op.exp.4).
- Every quarter: implementation metrics, access rights review and incident register review (op.mon.2, op.acc.4, op.exp.9).
- Every year: category reassessment, risk analysis review, awareness for all staff and internal audit (Annex I, op.pl.1, mp.per.3).
- At every change: assess whether it is substantial and requires an extraordinary audit (article 31.1).
- Before the audit: review of evidence for the period and closure of outstanding corrective measures (article 31.5).
Who runs security between audits
There are three common ways to cover this period, and all three have to deliver the same measures.
- An internal team. This works when the company can dedicate people to monitoring, updates and incidents on a continuous basis, and keep the security officer and system owner roles separate.
- A consultancy on a maintenance engagement. It brings document review and audit preparation. Confirm who runs the measures in the operational framework, because that work often falls outside a documentation scope.
- An operated security service. A third party runs part of the measures. The contract should make clear who answers for each one and who the security contact for the service is.
Qalea works in this third model. The compliance platform keeps the risk analysis, evidence and metrics current between audits, and the Qalea team runs the technical layer: SIEM and SOC for detection and monitoring, EDR on laptops and servers, internal vulnerability management, external attack surface and cloud, and awareness training with phishing simulations for staff. We explain the difference between documenting and operating in compliance platform vs security. Qalea prepares and maintains the system; the certificate is issued by an independent accredited body.








