In brief: CCN-CERT is the incident response team for Spain's public sector, part of the National Cryptologic Centre (CCN). If your organisation falls within the scope of the ENS (Spanish National Security Framework) you have a legal duty — Articles 33 and 34 of Royal Decree 311/2022 — to report incidents with significant impact. Danger level and impact are classified under the CCN-STIC 817 guide into five levels, and reports are channelled through the LUCIA tool. Private companies outside the ENS go to INCIBE-CERT; national defence systems go to ESPDEF-CERT.

CCN-CERT is Spain's government CERT: the security incident response capability of the National Cryptologic Centre (CCN), attached to the CNI. It is the body that entities within the scope of the ENS must notify of cyberincidents with significant impact, through the LUCIA tool and in accordance with Royal Decree 311/2022.

When I help a public body — or a private company that provides services to the public sector — align with the ENS, incident reporting is the part that raises the most questions. People confuse which CERT to contact, aren't sure when reporting is actually mandatory, and mix up the internal incident log with the official report to the State. Here I clarify what CCN-CERT is, what role it plays within the ENS and, above all, when and how you need to report a cyberincident to it.

What is CCN-CERT (quick answer)

CCN-CERT is the security incident response capability of the National Cryptologic Centre. Put simply: it's Spain's national government CERT, the public team that helps the Administration prevent, detect and respond to cyberattacks. Three ideas to place it:

  • It's a team, not a law. "CERT" stands for Computer Emergency Response Team: a technical team that responds to computer emergencies. CCN-CERT is the State's team for the public sector.
  • It reports to the CCN, which in turn reports to the CNI. It is part of the National Cryptologic Centre, attached to the National Intelligence Centre. That's why its natural remit is the Administration and its systems.
  • It has a specific regulatory role under the ENS. Royal Decree 311/2022 designates it as the point to which entities within the scope of the ENS report incidents with significant impact.

CNI, CCN and CCN-CERT: who's who

The names look alike and are easy to mix up, so it's worth separating them:

  • CNI — National Intelligence Centre. Spain's state intelligence service.
  • CCN — National Cryptologic Centre. Attached to the CNI, it is the body responsible for information technology security across the Administration. It is the one that produces the CCN-STIC guides and the ENS framework.
  • CCN-CERT — the CCN's incident response capability. It's the operational arm that manages alerts, coordinates the response and receives incident reports from the public sector.

In practice: the CCN sets the rules (the ENS, the guides); CCN-CERT is who you call when something happens. I cover what each article requires in more detail in my summary of Royal Decree 311/2022.

CCN-CERT or INCIBE-CERT: which one applies to you

Spain doesn't have a single CERT — it has several reference teams depending on the type of entity. Picking the wrong point of contact slows down the response, so here is the assignment set out in Royal Decree 311/2022 itself:

Entity profileReference CERTBasis
Public administration (state, regional, local) and its bodiesCCN-CERTRD 311/2022 (ENS), art. 33
Private company providing services to the public sector (within ENS scope)INCIBE-CERT, coordinating with CCN-CERTRD 311/2022, art. 33
Private company, citizen or operator outside ENS scopeINCIBE-CERTINCIBE
Systems linked to National DefenceESPDEF-CERT (Joint Cyberspace Command)Ministry of Defence

The general rule is simple: public sector → CCN-CERT; private sector → INCIBE-CERT; defence → ESPDEF-CERT. The important nuance is in row two: if you are a private company certified under the ENS because you provide services to the Administration, your report is channelled through INCIBE-CERT, which coordinates with CCN-CERT. All three teams share information with each other, so you are not reporting "twice": you pick the contact that applies to you, and they escalate whatever is needed.

When is it mandatory to report an incident under the ENS

Not every incident is reported to the State. The obligation arises when the incident has a significant impact on the security of the systems affected. That is set out in the two articles of Royal Decree 311/2022 that cover this matter:

  • Article 33 (Incident response capability). The CCN organises the response through CCN-CERT and establishes that public entities will report incidents with significant impact to it, coordinating with ESPDEF-CERT for defence matters and with INCIBE-CERT for private-sector providers of public services.
  • Article 34 (Provision of incident response services to public-sector entities). It defines the services CCN-CERT provides: support and coordination in the face of vulnerabilities and incidents, investigation, dissemination of good practice, training and threat intelligence.

The key question, then, isn't "did I have an incident?" but "what impact does it have?" Answering that requires classifying it — which is exactly what the reference technical guide standardises.

How the severity of a cyberincident is classified

The reference is the CCN-STIC 817 guide ("National Security Framework. Cyberincident Management"), which sorts classification along two independent axes, each with five levels (CRITICAL, VERY HIGH, HIGH, MEDIUM and LOW):

  • Danger level. The technical severity of the threat itself (for example, active ransomware versus an isolated phishing email). The guide uses a taxonomy of nine incident classes and 36 subtypes.
  • Impact. The real consequences for your organisation (information compromised, services affected, scope). This is the axis that triggers the reporting obligation.

The table below summarises, as a guide, when notification to the CCN is triggered depending on the impact level:

Impact levelReport to CCN-CERT?Guide's indicative deadline
CRITICALYes, with maximum urgencyImmediate (reference: max. 24h)
VERY HIGHYesImmediate (reference: max. 24h)
HIGHYesImmediate (reference: max. 24h)
MEDIUMAt the guide's discretionReference: 72h
LOWInternal logging and monitoringReference: 5 days

The exact thresholds and deadlines are set by the current version of CCN-STIC 817, which is updated periodically: confirm them against the current guide and the rest of the ENS technical security instructions and CCN-STIC guides before applying them. The underlying idea doesn't change: the greater the impact, the sooner you need to report it.

LUCIA and the step-by-step reporting procedure

Reporting isn't a stray email: it's done through LUCIA (Unified Incident and Threat Coordination Listing), the CCN-CERT tool for managing and coordinating public-sector cyberincidents. LUCIA provides a common language for danger level and classification, maintains the incident's traceability and meets the requirements of the ENS and guide 817. In practice, the flow is:

  1. Detect and log the incident internally. This part is governed by your own ENS incident management protocol, covering detection, containment and eradication; I don't go into it here.
  2. Classify the danger level and impact in line with CCN-STIC 817. Whether there is an obligation to report, and how urgently, depends on that classification.
  3. Report to CCN-CERT by opening the case in LUCIA once the impact reaches the threshold, with the minimum content: what happened, systems and services affected, and measures already taken.
  4. Contain and eradicate in parallel, updating the incident's status in the tool as the response progresses.
  5. Coordinate with CCN-CERT on analysis and, where relevant, specialist support. The tool is designed for that joint work.
  6. Close the incident in LUCIA once the threat is eradicated, documenting the lessons learned.

If you want the detail of the internal response cycle — the steps before the report — I cover it in my guide to incident response under the ENS. This article covers the other half: the mandatory external report.

What other services CCN-CERT offers beyond incident management

Reducing CCN-CERT to "where you report incidents" sells it short. Under Article 34 of Royal Decree 311/2022, it provides a catalogue of services worth using before you have a problem:

  • Alerts and advisories on emerging vulnerabilities and threats.
  • Threat intelligence reports and good-practice guidance, with useful intelligence for staying ahead.
  • Support tools, such as LUCIA itself, to give capabilities to bodies that don't already have them.
  • Specialist training (courses and technical sessions) for public-sector security teams.
  • CCN-STIC guides, the 800 series dedicated to the ENS, which spell out the "how" for each measure.

For a security officer, CCN-CERT is both a preventive resource and a point of contact in a crisis. The sooner you build it into your operations, the less you'll be improvising on the day of the incident.

Incident reporting and NIS2: what's coming

Until now, mandatory incident reporting has been almost unique to the public sector. That is changing with the NIS2 directive, which extends the duty to report to essential and important entities across many more sectors — energy, health, transport, banking, digital infrastructure — with their own strict deadlines: an early warning within the first 24 hours, a notification within 72, and a final report afterwards, to whichever CSIRT applies.

The consequence is that many organisations will fall under two frameworks at once: the ENS, if they operate in the public sector, and NIS2, if they belong to a covered sector. The two aren't incompatible — they share the same logic of classifying, reporting and coordinating — but they do require clarity on which team gets notified of each incident and within what deadline. Designing the procedure once, covering both, avoids duplicating work and getting the contact wrong.

Conclusion: reporting is part of compliance, not a penalty against it

CCN-CERT isn't an adversary you hide problems from: it's the public team that exists precisely to help you when you have an incident. Reporting on time, correctly classifying danger and impact, and using LUCIA the way the rules require doesn't cost you points on your ENS conformity — it adds to it, because it shows your management system works. What does compromise conformity is the opposite: staying quiet about a significant incident.

If you are bringing a public body or a service provider into line with the ENS and aren't sure when and how to report, or how this fits with the ENS compliance guide, tell me about your situation and we'll go through it together.

Frequently asked questions about CCN-CERT

What is CCN-CERT?

It's the security incident response capability of the National Cryptologic Centre (CCN), attached to the CNI: Spain's government CERT. It helps the public sector prevent, detect and respond to cyberattacks and coordinates incident reporting within the scope of the ENS (Spanish National Security Framework).

Who is required to report incidents to CCN-CERT?

Entities within the scope of the ENS — the public sector — when they suffer incidents with significant impact, under Article 33 of Royal Decree 311/2022. Private companies that provide services to the public sector channel their report through INCIBE-CERT, coordinating with CCN-CERT, and those outside ENS scope generally go to INCIBE-CERT.

What is LUCIA?

LUCIA (Unified Incident and Threat Coordination Listing) is the CCN-CERT tool for managing and reporting public-sector cyberincidents. It standardises the incident lifecycle, provides a common language for danger level and classification, and maintains traceability and coordination with CCN-CERT.

What is the deadline for reporting an incident?

It depends on the incident's impact under the CCN-STIC 817 guide: high, very high or critical impact incidents are reported immediately (as a reference, within a maximum of 24 hours), medium impact around 72 hours, and low impact incidents are logged with less urgency. Confirm the exact thresholds and deadlines against the current version of the guide.

Does reporting an incident count against my ENS certification?

No: what compromises conformity is not reporting. Detecting, managing and reporting incidents are measures required by the ENS itself and are reviewed during the conformity audit. Reporting on time shows that your management system works.

Is reporting to CCN-CERT the same as reporting a breach to the AEPD?

No. They are separate obligations that can coincide in the same incident. Reporting to CCN-CERT responds to the ENS and the security of public-sector systems; reporting to the Spanish Data Protection Agency (AEPD) responds to the GDPR and only applies when personal data is affected, with its own 72-hour deadline. A cyberattack involving data theft can require both.

Sources

Content written by Ángel Ortega Castro for angelortegacastro.com. Informational content; for any legal obligation, consult the current text of RD 311/2022 on the BOE.