I am Ángel Ortega Castro, independent ENS consultant. I guide companies in Burgos and its province through compliance with the Esquema Nacional de Seguridad (ENS) — Spain's national information security framework established by RD 311/2022 — so they can bid for and deliver services to the local, provincial and regional public administration without regulatory compliance becoming an operational obstacle.
The province of Burgos has a wide and diverse public sector. The Diputación de Burgos delivers digital services to the province's 371 municipalities — tax administration, electronic processing platforms, social services, rural development — and requires its technology suppliers to operate with auditable information security guarantees. The Ayuntamiento de Burgos, the provincial capital with around 175,000 inhabitants, runs citizen participation platforms, urban management systems and a continuously expanding electronic administration portal. The Universidad de Burgos (UBU), with campuses in Burgos city, Miranda de Ebro, Aranda de Duero and Palencia, regularly issues tenders for ICT equipment, cloud services and academic management solutions.
These bodies are joined by the provincial delegations of the Junta de Castilla y León and state agencies — the Subdelegación del Gobierno, the Agencia Tributaria, the Seguridad Social and the Servicio Público de Empleo — which also contract digital services from local companies. All of them are subject to the Esquema Nacional de Seguridad under Real Decreto 311/2022, of 3 May (BOE-A-2022-7191). And that obligation, by explicit provision of the regulation, extends to every company that provides services to them.
The supramunicipal body managing digital services for 371 municipalities. Its technology tenders include information security requirements aligned with the ENS.
The provincial capital with an electronic administration portal, digital tax management and online municipal services. ICT suppliers must demonstrate ENS conformity to access its contracts.
A public university with four campuses and a growing commitment to digitalisation. It issues software, cloud and ICT infrastructure tenders subject to the ENS security requirements.
RD 311/2022 does not limit its scope to the public sector in the strict sense. Its additional provision one makes clear that private-sector entities providing services or solutions to the public sector must demonstrate ENS conformity within the relevant contractual relationship. This is not a recommendation: it is a condition that appears as a technical solvency requirement in public procurement documents.
This means that if your company — based in Burgos city, in the Aranda de Duero district, in Miranda de Ebro or anywhere else in the province — provides any of the following services to the Diputación de Burgos, the Ayuntamiento, the UBU or any body of the Junta de Castilla y León present in the province, the ENS is part of your contractual obligations:
The transitional period for adapting pre-existing systems ended on 5 May 2024. New contracts require conformity from day one. Companies unable to demonstrate it are excluded from public procurement and cannot submit a bid. The ENS consultancy for companies explains the full process; the ENS guide provides the regulatory background.
Not every project requires the same level of rigour. The category of an information system is determined by assessing the impact a security incident would have across the five CIDAT dimensions — confidentiality, integrity, availability, authenticity and traceability. The dimension with the highest level sets the category for the whole system.
Common for suppliers of management support services to municipal administrations or processing applications for small and medium local entities.
Frequent for systems handling sensitive citizen data or critical processes of provincial bodies or universities.
Applies to systems whose failure could cause irreparable consequences: critical infrastructure or essential public-sector services.
At the basic category, the organisation verifies its own compliance against the CCN-STIC guides and issues a declaration of conformity. No external certification body is required, but the documentation and evidence must be in order. I prepare the full documentary body so the declaration is solid and withstands scrutiny from any contracting authority.
At medium or high category, conformity requires certification by an ENAC-accredited body under UNE-EN ISO/IEC 17065:2012. I prepare your organisation to pass that audit; the seal is issued by the accredited body, not by the consultant. This distinction matters: be wary of anyone who promises to guarantee certification.
The goal is not to produce paperwork: it is to ensure your company has the documentary and technical body that any auditor or Burgos procurement document will request.
Yes. The Diputación de Burgos, as a public-sector entity, is subject to the ENS under RD 311/2022. That obligation extends, through the supply chain, to suppliers and contractors that manage information systems. If your company provides ICT services, management software or digital infrastructure to the Diputación, the ENS applies to you directly and the procurement documents may require you to demonstrate conformity.
The Ayuntamiento de Burgos, as a local administration, is obliged to comply with the ENS and to pass that requirement on to its digital service providers. In practice, the technical specifications of software, systems maintenance, cloud or cybersecurity contracts incorporate ENS conformity as a technical solvency requirement. Companies unable to demonstrate it cannot bid for those contracts.
Yes. The Universidad de Burgos is a public-sector entity subject to the ENS, and its technology contracts — equipment, cloud, academic management applications, e-learning platforms — involve the processing of student, staff and research data. Suppliers managing those systems must demonstrate ENS conformity at the category corresponding to the system's impact level.
It depends on the type of service and the data processed. For many Burgos SMEs providing municipal management software, ICT maintenance or technical support to local bodies, the basic category is the most common, since the impact of an incident across the five CIDAT dimensions is typically limited. In that case, a self-assessed declaration of conformity suffices, with no external certification body required. However, if the system handles sensitive citizen data or critical processes, the category may be medium or high, requiring ENAC-accredited certification. The first step is always the diagnostic and categorisation exercise.
Yes. The Junta de Castilla y León is a regional administration fully subject to the ENS. Its territorial delegations in Burgos — covering employment, health and education services — contract digital services from local companies. If your company provides any technology service to the Junta in the province, RD 311/2022 obliges you to demonstrate ENS conformity within the scope of that contract.
Yes. The ENS compliance process is largely documentary and technical, and can be managed remotely with the right tools. Diagnostic meetings, working sessions with your team and document reviews are routinely conducted by video conference. When a project requires an on-site visit — for example, to audit physical infrastructure at Burgos premises — I travel without any issue, as I work regularly across Castilla y León.
First call at no charge and with no commitment. We assess together which Burgos or regional bodies are your clients, which ENS category applies to your scope and what is the most direct route to demonstrating conformity. If we are not the right fit, you still walk away with a useful initial diagnostic.