Search Client access
Burgos · Compliance & security · ENS

ENS Consultancy in Burgos

I am Ángel Ortega Castro, independent ENS consultant. I guide companies in Burgos and its province through compliance with the Esquema Nacional de Seguridad (ENS) — Spain's national information security framework established by RD 311/2022 — so they can bid for and deliver services to the local, provincial and regional public administration without regulatory compliance becoming an operational obstacle.

RD 311/2022
Applicable framework
3 levels
Basic · Medium · High
Burgos
Province · Castilla y León
The local context

Burgos's public sector and its suppliers.

The province of Burgos has a wide and diverse public sector. The Diputación de Burgos delivers digital services to the province's 371 municipalities — tax administration, electronic processing platforms, social services, rural development — and requires its technology suppliers to operate with auditable information security guarantees. The Ayuntamiento de Burgos, the provincial capital with around 175,000 inhabitants, runs citizen participation platforms, urban management systems and a continuously expanding electronic administration portal. The Universidad de Burgos (UBU), with campuses in Burgos city, Miranda de Ebro, Aranda de Duero and Palencia, regularly issues tenders for ICT equipment, cloud services and academic management solutions.

These bodies are joined by the provincial delegations of the Junta de Castilla y León and state agencies — the Subdelegación del Gobierno, the Agencia Tributaria, the Seguridad Social and the Servicio Público de Empleo — which also contract digital services from local companies. All of them are subject to the Esquema Nacional de Seguridad under Real Decreto 311/2022, of 3 May (BOE-A-2022-7191). And that obligation, by explicit provision of the regulation, extends to every company that provides services to them.

Diputación de Burgos

The supramunicipal body managing digital services for 371 municipalities. Its technology tenders include information security requirements aligned with the ENS.

Ayuntamiento de Burgos

The provincial capital with an electronic administration portal, digital tax management and online municipal services. ICT suppliers must demonstrate ENS conformity to access its contracts.

Universidad de Burgos (UBU)

A public university with four campuses and a growing commitment to digitalisation. It issues software, cloud and ICT infrastructure tenders subject to the ENS security requirements.

Who is required to comply

If your company works with the Burgos public administration, the ENS applies to you.

RD 311/2022 does not limit its scope to the public sector in the strict sense. Its additional provision one makes clear that private-sector entities providing services or solutions to the public sector must demonstrate ENS conformity within the relevant contractual relationship. This is not a recommendation: it is a condition that appears as a technical solvency requirement in public procurement documents.

This means that if your company — based in Burgos city, in the Aranda de Duero district, in Miranda de Ebro or anywhere else in the province — provides any of the following services to the Diputación de Burgos, the Ayuntamiento, the UBU or any body of the Junta de Castilla y León present in the province, the ENS is part of your contractual obligations:

The transitional period for adapting pre-existing systems ended on 5 May 2024. New contracts require conformity from day one. Companies unable to demonstrate it are excluded from public procurement and cannot submit a bid. The ENS consultancy for companies explains the full process; the ENS guide provides the regulatory background.

Legal basis: Real Decreto 311/2022, of 3 May, regulating the Esquema Nacional de Seguridad (BOE-A-2022-7191). Application guides from the CCN (Centro Criptológico Nacional). Certification bodies are accredited by ENAC under UNE-EN ISO/IEC 17065:2012.
Compliance levels

ENS categories: basic, medium and high.

Not every project requires the same level of rigour. The category of an information system is determined by assessing the impact a security incident would have across the five CIDAT dimensions — confidentiality, integrity, availability, authenticity and traceability. The dimension with the highest level sets the category for the whole system.

Basic category

Limited impact

Common for suppliers of management support services to municipal administrations or processing applications for small and medium local entities.

  • No dimension exceeds the low level
  • Conformity by self-assessed declaration
  • No mandatory external certification body
Medium category

Serious impact

Frequent for systems handling sensitive citizen data or critical processes of provincial bodies or universities.

  • At least one dimension reaches the medium level
  • Certification by an ENAC-accredited body
  • Biennial conformity audit
High category

Very serious impact

Applies to systems whose failure could cause irreparable consequences: critical infrastructure or essential public-sector services.

  • At least one dimension reaches the high level
  • Certification by an ENAC-accredited body
  • Mandatory biennial conformity audit

The two routes to conformity

Basic → self-assessed declaration of conformity

At the basic category, the organisation verifies its own compliance against the CCN-STIC guides and issues a declaration of conformity. No external certification body is required, but the documentation and evidence must be in order. I prepare the full documentary body so the declaration is solid and withstands scrutiny from any contracting authority.

Medium / high → ENAC-accredited certification

At medium or high category, conformity requires certification by an ENAC-accredited body under UNE-EN ISO/IEC 17065:2012. I prepare your organisation to pass that audit; the seal is issued by the accredited body, not by the consultant. This distinction matters: be wary of anyone who promises to guarantee certification.

What you get

Documentation that underpins conformity.

The goal is not to produce paperwork: it is to ensure your company has the documentary and technical body that any auditor or Burgos procurement document will request.

Ángel Ortega Castro, independent ENS consultant in Burgos
Who is behind this service

An ENS consultant who genuinely supports you.

I am Ángel Ortega Castro, an independent consultant specialising in regulatory compliance and information security. I work with companies in Castilla y León — including those in Burgos and its province — that need to achieve ENS conformity in order to bid for and operate with the public administration.

My approach is one of genuine accompaniment: I do not hand you a manual and disappear. I work alongside you at every stage of the process, translate the regulation into concrete decisions for your context and leave your team with the capacity to maintain conformity autonomously once the project is complete.

I am transparent about what I can and cannot do: I prepare and bring your organisation to conformity; the certificate is issued by an ENAC-accredited body. That transparency, combined with rigorous application of RD 311/2022 and the CCN-STIC guides, is what distinguishes this consultancy from generic proposals with no knowledge of the local administrative landscape.

Independent ENS consultant RD 311/2022 · Annexes I–IV CCN-STIC guides MAGERIT · risk analysis Burgos · Castilla y León · Spain
Frequently asked questions

Common questions from Burgos companies about the ENS.

Do companies supplying services to the Diputación de Burgos need to comply with the ENS?

Yes. The Diputación de Burgos, as a public-sector entity, is subject to the ENS under RD 311/2022. That obligation extends, through the supply chain, to suppliers and contractors that manage information systems. If your company provides ICT services, management software or digital infrastructure to the Diputación, the ENS applies to you directly and the procurement documents may require you to demonstrate conformity.

Does the Ayuntamiento de Burgos require ENS compliance in its technology tenders?

The Ayuntamiento de Burgos, as a local administration, is obliged to comply with the ENS and to pass that requirement on to its digital service providers. In practice, the technical specifications of software, systems maintenance, cloud or cybersecurity contracts incorporate ENS conformity as a technical solvency requirement. Companies unable to demonstrate it cannot bid for those contracts.

Does the Universidad de Burgos (UBU) require ENS compliance from its ICT suppliers?

Yes. The Universidad de Burgos is a public-sector entity subject to the ENS, and its technology contracts — equipment, cloud, academic management applications, e-learning platforms — involve the processing of student, staff and research data. Suppliers managing those systems must demonstrate ENS conformity at the category corresponding to the system's impact level.

What ENS category typically applies to a Burgos SME supplying the local administration?

It depends on the type of service and the data processed. For many Burgos SMEs providing municipal management software, ICT maintenance or technical support to local bodies, the basic category is the most common, since the impact of an incident across the five CIDAT dimensions is typically limited. In that case, a self-assessed declaration of conformity suffices, with no external certification body required. However, if the system handles sensitive citizen data or critical processes, the category may be medium or high, requiring ENAC-accredited certification. The first step is always the diagnostic and categorisation exercise.

My client is the Junta de Castilla y León in Burgos: do I need the ENS?

Yes. The Junta de Castilla y León is a regional administration fully subject to the ENS. Its territorial delegations in Burgos — covering employment, health and education services — contract digital services from local companies. If your company provides any technology service to the Junta in the province, RD 311/2022 obliges you to demonstrate ENS conformity within the scope of that contract.

Can I manage the full ENS compliance process without travelling to Burgos in person?

Yes. The ENS compliance process is largely documentary and technical, and can be managed remotely with the right tools. Diagnostic meetings, working sessions with your team and document reviews are routinely conducted by video conference. When a project requires an on-site visit — for example, to audit physical infrastructure at Burgos premises — I travel without any issue, as I work regularly across Castilla y León.

Keep exploring

ENS service across the region and key guides.

Next step

Shall we talk about your ENS compliance in Burgos?

First call at no charge and with no commitment. We assess together which Burgos or regional bodies are your clients, which ENS category applies to your scope and what is the most direct route to demonstrating conformity. If we are not the right fit, you still walk away with a useful initial diagnostic.