The Esquema Nacional de Seguridad (National Security Framework, ENS) is the framework that sets the minimum security requirements for public-sector information systems in Spain. It is currently governed by Real Decreto 311/2022, de 3 de mayo, which repealed the earlier Real Decreto 3/2010 and updated both the basic principles and the catalogue of measures. If you want to understand the full framework before going further, I wrote a complete guide to the Esquema Nacional de Seguridad where I break it down in more detail.

The obligation covers a wider universe than many people think. On one hand, it applies to public administrations in the strict sense: the Administración General del Estado (central government), the autonomous communities and local authorities, plus their public-law bodies and entities. Local councils have particularities of size and resources that I cover separately in this analysis on the ENS in local government.

On the other hand — and this is what gets forgotten most often — the ENS also applies to private companies that provide services to those administrations when those services involve handling public-sector information or systems. A software provider, a hosting company that stores a local council's data, or a company that manages an electronic government office all fall squarely within scope. In practice, more and more public procurement tenders require ENS conformity as a condition for bidding.

Security categories: BÁSICA, MEDIA and ALTA

The ENS does not apply the same level of demand to every system. Each system is classified into one of three categories: BÁSICA (Basic), MEDIA (Medium) or ALTA (High). That category determines which security measures are mandatory and how rigorously they must be applied. The higher the category, the more measures and the greater the rigour.

The category isn't picked arbitrarily. It is calculated by assessing the impact an incident would have across five security dimensions: confidentiality, integrity, traceability, authenticity and availability. Each dimension is assigned a BAJO (Low), MEDIO (Medium) or ALTO (High) level depending on the harm its loss would cause. The system's category is set by the highest level reached by any of its dimensions, subject to the nuances detailed in the royal decree's own annex.

An example clarifies the logic. An information portal that only publishes content with no sensitive personal data will probably fall into BÁSICA. A system that manages the local population register or case files with health data, where a leak would have serious consequences, easily scales up to MEDIA or ALTA. Getting the categorisation right is the foundation of the whole project: overshoot it and you overspend; undershoot it and you fail to comply.

CategoryWhen it applies (incident impact)Requirement level
BÁSICANo dimension exceeds the BAJO (Low) levelMinimum set of protective measures
MEDIASome dimension reaches the MEDIO (Medium) levelReinforced management, control and monitoring measures
ALTASome dimension reaches the ALTO (High) levelMaximum-demand measures and additional controls

What ENS consulting includes

When I talk about ENS consulting, I don't just mean delivering a report. I mean supporting the organisation from the initial diagnosis through to the point where an external auditor can certify conformity. The typical scope covers these blocks of work.

Gap analysis

This is the starting snapshot. We compare what the organisation does today against what the ENS requires for its category, and produce the list of gaps. Without this analysis it's impossible to plan realistically, because you don't know how much ground you still have to cover.

Categorising the systems

We classify each system as BÁSICA, MEDIA or ALTA using the method described above, documenting the decisions so they can be defended before the auditor.

Declaration of applicability

This is the document that states, measure by measure, which ones apply to the system, to what extent, and why. When a measure doesn't apply, it has to be justified with proper reasoning. The declaration of applicability is one of the deliverables the auditor scrutinises most closely.

Adequacy plan

This turns the gaps identified in the gap analysis into an action plan with owners, priorities and deadlines. This is where you decide what gets fixed first, usually whatever reduces risk the most for the least effort.

Implementing the measures

This is the execution stage: policies, procedures, technical controls, access management, activity logging, backups and everything else the catalogue requires. Without real implementation there is no possible certification; paperwork alone isn't enough.

Preparing for the audit

Before calling in the certification body, it's worth doing an internal review that simulates the audit and catches the loose ends. It's far cheaper to fix a non-conformity before the official auditor finds it.

This scope is, in essence, regulatory compliance consulting applied to a specific framework, with the difference that the ENS ends in a certification that a third party can verify.

The project phases step by step

Every organisation has its own pace, but a well-ordered ENS project usually goes through these phases. I present them in the order I execute them, because skipping steps costs you later.

  1. Scope and kick-off. We define which systems enter the project, who is responsible for security, and how we're going to work. A poorly defined scope is the most common cause of projects that drag on forever.
  2. Categorisation. We assess the five dimensions of each system and set its category. This determines the level of demand for everything else.
  3. Gap analysis. We measure the distance between the current situation and what's required. The result is the prioritised list of gaps.
  4. Risk analysis. We identify threats and assess risk to decide what to tackle first. The ENS requires it, and it also gives meaning to the plan's priorities.
  5. Declaration of applicability and adequacy plan. We document which measures apply and map out the roadmap for closing the gaps.
  6. Implementation. We execute the plan: policies, procedures and technical controls. This is the longest phase and the one that depends most on internal resources.
  7. Internal review. We check that the evidence exists and is consistent before the external audit.
  8. Certification audit. An accredited body verifies conformity and, if everything checks out, issues the certification.

I'm deliberately not giving you fixed timelines. The total time depends on the category, the number of systems, and above all on your starting point. An organisation that already has security policies in place moves much faster than one starting from zero.

The ENS conformity certification audit

Conformity with the ENS is accredited through an audit carried out by a certification body accredited for that purpose. An internal self-assessment doesn't count when you're seeking formal certification: the value lies precisely in an independent third party verifying that the measures exist and actually work.

The auditor reviews the documentation (categorisation, declaration of applicability, risk analysis, policies) and checks on the ground that the declared measures are actually implemented and operational. If deviations are found, they are classified by severity and the organisation must correct them. Once the non-conformities are resolved, the ENS conformity certificate is issued; it has a set period of validity and requires follow-up.

It's worth separating two concepts that are sometimes confused. There's the declaration of conformity, lighter and typical for the BÁSICA category, and certification of conformity through audit, required for higher categories. Which one applies depends on the system's category. If you want the full detail of the journey and what influences its cost, I cover it in this article on ENS certification.

Maintenance: conformity doesn't expire on audit day

The most expensive mistake I see is treating the ENS as a project with an end date. Conformity has to be kept alive. Measures degrade, systems change, new threats appear, and the certificate requires periodic follow-up audits to remain valid.

Healthy maintenance includes reviewing the categorisation whenever a system changes significantly, updating the risk analysis, managing security incidents, and preparing each follow-up audit well in advance. In organisations that also handle systems with artificial-intelligence components, that maintenance is best coordinated with the rest of their obligations — something that connects with AI regulatory compliance when those systems fall within scope.

Conclusion

A well-designed ENS consulting engagement for public administrations isn't paperwork: it's putting the security of your systems in order using a method an auditor can verify. Categorise with judgement, document the applicability, implement real measures, and reach the audit without surprises. And then maintain it, because conformity is preserved, not conquered once and for all.

If your administration or company needs to certify ENS conformity, or if a tender is asking for it and you don't know where to start, tell me about your case and let's look at the scope together. I work from Valladolid and Las Palmas de Gran Canaria, and the first conversation is to understand your starting point, with no obligation.

If you'd like to see this scope applied to your specific organisation, with its own phases and timelines, that's how I work on ENS certification for companies.

Need professional support for your ENS adequacy process? Learn about my ENS consulting service for companies that want to bid for or become suppliers to the public administration.

Frequently asked questions

What regulation currently governs the ENS?
The Esquema Nacional de Seguridad is governed by Real Decreto 311/2022, de 3 de mayo, which repealed the earlier Real Decreto 3/2010 and updated the basic principles and the catalogue of security measures.
Do private companies have to comply with the ENS?
Yes, when they provide services to public administrations that involve handling public-sector information or systems. It's common for procurement tenders to require ENS conformity as a condition for bidding.
How is the BÁSICA, MEDIA or ALTA category decided?
It's based on assessing the impact of a possible incident across five security dimensions (confidentiality, integrity, traceability, authenticity and availability) at BAJO, MEDIO or ALTO levels. The system's category is set by the highest level reached by any of its dimensions.
Who can certify ENS conformity?
Certification of conformity is obtained through an audit carried out by a certification body accredited for that purpose. An internal self-assessment doesn't replace that audit when you're seeking formal certification.
How long does an ENS adequacy project take?
It depends on the category, the number of systems in scope, and the starting point. An organisation with security policies already in place moves considerably faster than one starting from scratch, which is why it's best to avoid fixed timelines before the gap analysis.

Looking for support certifying ENS conformity for your organisation? Let's talk for a free diagnostic of your scope. Presence across Castilla y León and the Canary Islands.