I am Ángel Ortega Castro, independent ENS consultant. I guide companies seeking to work with the Diputación de León, the Ayuntamiento de León and the Universidad de León (ULE) through their compliance with the Esquema Nacional de Seguridad (ENS) — Spain's national information security framework, governed by RD 311/2022. No shortcuts, no empty jargon: from gap assessment to conformity.
León contracts with companies. Those companies must comply.
León has three major public institutions that generate a significant volume of technology procurement: the Diputación Provincial de León, which provides digital and management services to more than 200 municipalities across the province and promotes tourism and rural development through its own ICT infrastructure; the Ayuntamiento de León, which operates its Electronic Office (Sede Electrónica), handles online administrative procedures and has made meaningful progress on its digital-city agenda; and the Universidad de León (ULE), a public university with more than 10,000 students that manages high-value academic, research and personnel data and procures software, hosting and technical support services on a regular basis. All three bodies act as public administrations in every sense of Real Decreto 311/2022 (BOE-A-2022-7191), of 3 May, which regulates the Esquema Nacional de Seguridad.
The key for companies is not merely meeting the standard directly: it is understanding that ENS reaches the supply chain. RD 311/2022 extends the ENS conformity obligation to private organisations that provide services or solutions to the public sector under contract. A software development company serving the Diputación de León, a managed cybersecurity services provider to the Ayuntamiento, or a systems integrator for the ULE are just as much subject to this framework as the administrations themselves.
Access to Diputación tenders
The Diputación de León publishes ICT service, document management and digital transformation contracts. ENS conformity is increasingly listed as a technical solvency requirement in its procurement specifications.
Ayuntamiento de León Electronic Office
The Ayuntamiento de León processes sensitive citizen procedures through its electronic administration. Its platform and support providers must demonstrate security measures proportional to the risk involved.
ICT providers for the ULE
The Universidad de León (ULE) handles research data, academic records and personnel files protected by the GDPR. Companies offering technology services to the ULE must demonstrate a level of security equivalent to that required by ENS.
Obligation fully in force
The transitional period under RD 311/2022 for pre-existing systems ended on 5 May 2024. There is no grace period left: the obligation is enforceable today in any public tender in León.
Legal basis: Real Decreto 311/2022, of 3 May, regulating the Esquema Nacional de Seguridad in the field of Electronic Administration (BOE-A-2022-7191). Technical coordination by the Centro Criptológico Nacional (CCN). Conformity certification in medium and high categories issued by bodies accredited by ENAC.
Why comply with ENS in León
Public tendering with security in order.
Companies based in León, or those operating in the province and seeking contracts with local government, face a reality in which information security has ceased to be an optional criterion. Procurement specifications from the Diputación de León, the Ayuntamiento de León and the ULE increasingly include ENS conformity as an access condition or as a technical scoring criterion. Failing to demonstrate that conformity means being eliminated from the selection process before any bids are opened.
Compliance, moreover, is not only useful for tendering. It signals to any client — public or private — that your organisation manages information rigorously and that the data entrusted to you is governed by a recognised security framework. That is a differentiating argument that goes well beyond strict regulatory compliance. The ENS consultancy I offer covers the full process: from the initial gap assessment to the delivery of evidence ready for the auditor. For a broader overview of the regulatory framework, the ENS guide is the best starting point.
ENS categories
Basic, medium or high: which level applies to you?
The system category is not chosen: it is calculated by assessing the impact that a security incident would have across the five CIDAT dimensions — confidentiality, integrity, availability, authenticity and traceability. The dimension with the highest level determines the category of the whole. For suppliers to León's administrations, the basic category is the most common when the data handled has limited impact; systems processing more sensitive information may reach medium level.
Basic category
Limited impact
An incident would cause limited harm to the organisation's functions, assets or the individuals concerned.
No dimension exceeds the low level
Conformity through self-assessed declaration
Proportionate, achievable measures for SMEs
Medium category
Serious impact
At least one dimension reaches medium level: an incident would cause serious harm to the organisation or the individuals affected.
At least one dimension at medium level
Conformity through accredited certification
Biennial audit by ENAC-accredited body
High category
Very serious impact
An incident would cause very serious or irreparable harm: at least one dimension reaches the high level.
At least one dimension at high level
Conformity through accredited certification
Biennial audit by ENAC-accredited body
The two conformity routes
Basic → conformity declaration
In the basic category, conformity is demonstrated through a self-assessed declaration of conformity. The organisation verifies compliance against the CCN-STIC guides and formalises the declaration. I prepare all the documentation and evidence so that the declaration is robust and withstands scrutiny from the León public buyer.
Medium / high → accredited certification
In medium or high categories, conformity requires certification by a body accredited by ENAC under standard UNE-EN ISO/IEC 17065:2012. I prepare your organisation to pass the audit; the certification itself is issued by the accredited body, which is independent of the consultant.
What I deliver
Documentation that underpins conformity.
The work does not end with a generic report. Each deliverable addresses a specific requirement of RD 311/2022 and its Annexes, and is designed to withstand review by the public buyer or the certification body.
GAP assessment showing the real distance between your current situation and the ENS requirements applicable to your scope.
System categorisation across the five CIDAT dimensions and the resulting level, justified in accordance with Annex I of RD 311/2022.
MAGERIT risk analysis: identification of assets, threats and safeguards, with residual risk treatment.
Information security policy and derived security rules, adapted to your organisation's actual reality.
Compliance plan (CCN-STIC 806) with responsible parties, timelines and prioritisation by impact.
Statement of Applicability (SoA) with the selection and justification of measures from Annex II.
Implementation evidence for the organisational, operational and protective measures selected.
Audit preparation: pre-audit review, checklist and accompaniment throughout the conformity process with the accredited body.
Ángel Ortega Castro ENS consultant · León
Why work with me
A consultant who puts his name to the work and knows the territory.
I am Ángel Ortega Castro, an independent consultant specialising in regulatory compliance and information security. I guide companies seeking to provide services to public administrations — including the Diputación de León, the Ayuntamiento de León and the Universidad de León — through their compliance with the Esquema Nacional de Seguridad (RD 311/2022).
My work is one of genuine accompaniment: I understand your business before opening any Annex, I translate the standard into concrete decisions and I leave your team equipped to maintain conformity independently once the project ends. I do not disappear after the first delivery.
I am transparent about what I can and cannot promise: I prepare and align your organisation; certification is issued by a body accredited by ENAC. That honesty, combined with rigorous application of RD 311/2022 and the CCN-STIC guides, is what distinguishes this service from consultancies that sell a stamp without accompanying the process.
Three situations a León-based company may face with ENS.
ICT provider to the Diputación
Company providing digital support to the León municipal network.
Integrators and ICT consultancies providing electronic administration, document management or infrastructure services to the Diputación Provincial de León and the municipalities it covers. ENS conformity is the key that unlocks these contracts.
Ayuntamiento de León supplier
Software or cybersecurity company serving the city.
Companies offering processing platforms, digital identity solutions or managed security services to the León city council. The Ayuntamiento demands security assurances from anyone accessing its systems and the personal data of its citizens.
Technology supplier to the ULE
Company managing academic or research data.
Software, hosting or data analytics firms contracted by the Universidad de León (ULE). The ULE processes sensitive information about students, researchers and staff, and passes its security obligations on to the technology providers it works with.
Indicative investment
How much does it cost to comply with ENS in León?
There is no single figure valid without knowing your case. The investment depends on the system scope, the resulting category (basic, medium or high), your baseline security maturity and whether conformity requires only a declaration or also accredited certification.
Fixed quote after the gap assessmentNo surprises · tailored to your scope and category
In medium or high categories, the consultancy fee is supplemented by the cost of the ENAC-accredited certification body, which is independent of my fees and invoiced by the third party conducting the conformity audit.
In our first call we jointly assess your scope and category, and I provide a fixed proposal. No commitment required and no figures that cannot be justified: honest guidance from the first minute.
Frequently asked questions
Common questions about ENS in León.
Which León bodies require ENS compliance from their suppliers?+
Bodies acting as public administrations — including the Diputación Provincial de León, the Ayuntamiento de León and the Universidad de León (ULE) — are obliged to apply ENS and, by extension, to require conformity with ENS from private companies that provide them with technology services or solutions. This extension to the supply chain is explicit in RD 311/2022 and affects every contract involving the processing of information or access to the administration's systems.
Does my company need ENS compliance to tender with the Ayuntamiento de León?+
Yes, if the service involves access to or processing of information from the Ayuntamiento's systems. The Ayuntamiento de León operates its Electronic Office and numerous digital services under the umbrella of RD 311/2022; its technology procurement specifications increasingly include ENS conformity as a technical solvency requirement. If you submit a bid without being able to demonstrate that conformity, you may be excluded before the bids are even evaluated. I can assist with all the ENS consultancy needed to be ready.
Does the Universidad de León (ULE) require ENS compliance from its ICT suppliers?+
The ULE is a public institution and, as such, is subject to ENS in its own systems. That obligation is passed on contractually to its technology suppliers when the service involves access to university systems or the processing of university data. Providers of e-learning platforms, academic management software, cloud hosting or infrastructure technical support fall within the scope of this requirement. ENS conformity — and the documentation backing it up — is the way to demonstrate that you meet that standard.
What ENS category typically applies to León administration suppliers?+
It depends on the specific data and services your company handles. For the majority of León local administration suppliers — support services, document management or processing platforms with limited impact — the basic category is the most common. The medium category applies when the impact of an incident would be serious, for example in systems processing sensitive personal data or supporting essential services. The high category is less frequent in the local administration supplier context. The first step is always a gap assessment, which determines the category using objective criteria.
Is a conformity declaration sufficient to tender in León?+
In the basic category, yes: conformity is demonstrated through a self-assessed declaration of conformity, without the need for a third-party audit. In medium or high categories, the declaration is not sufficient; certification by a body accredited by ENAC under standard UNE-EN ISO/IEC 17065:2012 is required. The category is determined by the system assessment, not at the supplier's own discretion. I prepare the declaration of conformity with all supporting documentation, so that it can withstand scrutiny from any reviewer.
How long does it take to achieve ENS compliance for tendering with the Diputación de León or the Ayuntamiento?+
The timeline depends on the system category and the organisation's starting maturity. A basic category process for a company that already has documented controls can be completed in a matter of weeks. A medium category project involving several systems and accredited certification may take several months. I assess this during the initial gap assessment, which is the first step of any project and from which you will gain useful information even if you decide not to proceed further.
A first call at no cost and with no commitment. We assess your scope, determine the category that applies to you and, if we are a good fit, I provide a fixed proposal. If not, you leave with at least an initial assessment that is already useful for starting to comply.