ENS audit: compliance with Spain's National Security Framework (ENS)
The National Security Framework (ENS) is mandatory for Spanish public administrations and their technology providers. We help you understand which system category applies to you, which measures are required and how to obtain certification.
Who must comply with the ENS?
Royal Decree 311/2022, which regulates the ENS, makes it mandatory for Spanish Public Administrations and for any private company that provides technology services to the public sector or processes citizens' information on behalf of the Administration. If you've won a public contract with a technology component, you probably have (or will soon have) the obligation to certify under the ENS.
What ENS compliance involves
- System classification: BASIC, MEDIUM or HIGH category based on the data and impact of the service
- Risk analysis using the MAGERIT methodology
- Selection and application of the security measures required by category
- Statement of Applicability (SoA)
- Compliance plan and follow-up
- Support in the audit and certification process
Compliance process
- System classification: We determine the security category (BASIC, MEDIUM or HIGH) based on the security dimensions of the information processed.
- MAGERIT risk analysis: We identify assets, threats, vulnerabilities and impact to underpin the measures to be implemented.
- Measure selection: We define the applicable security measures by category and draft the Statement of Applicability.
- Compliance plan: We plan the implementation of the pending measures with deadlines and resources.
- Audit preparation: We support the preparation of documentation and controls for the formal certification audit.
Deliverables
- System classification report with justification
- Documented risk analysis (MAGERIT)
- Statement of Applicability (SoA)
- Compliance plan with the status of each measure
- Evidence and documentation for the certification audit
Who typically requests it?
- Technology companies that have won or want to win public contracts
- Cloud, hosting and SaaS providers with public sector clients
- Public Administrations that must renew or start their compliance
- Local entities (city councils) with e-government systems
- Education, healthcare or justice organizations with critical IT systems
Frequently asked questions about ENS
What's the difference between an ENS declaration of conformity and certification?
The declaration of conformity is an internal document the entity itself issues stating that it complies with the ENS. Certification is issued by a certification body accredited by ENAC after a formal audit. Some public contracts require certification, others accept the declaration.
How often must ENS certification be renewed?
ENS certification is valid for 2 years, with annual follow-up audits.
What if the systems are BASIC category?
BASIC category systems have a less demanding but equally mandatory set of measures. Conformity can be demonstrated through a properly documented internal audit.
Can I hire QuantumSec for the ENS audit, or does it have to be an official body?
Formal ENS certification must be issued by an ENAC-accredited certification body. Our service is the preparatory consulting: gap analysis, system classification, implementing controls and preparing all documentation so the certification audit passes on the first attempt.