I am Ángel Ortega Castro, independent ENS consultant. I guide companies in Palencia and its province through compliance with the Esquema Nacional de Seguridad (ENS) — Spain's national framework for information security in the public sector, established by RD 311/2022 — so they can bid for and deliver services to the Diputación de Palencia, the Ayuntamiento and other public bodies without regulatory compliance becoming an obstacle.
Palencia province has a compact but active public sector whose demand for digital services has grown steadily over the past decade. The Diputación de Palencia provides technology cooperation services to the province's 191 municipalities — electronic administration platforms, tax management systems, document processing and citizen-facing services — and requires the private companies supplying those solutions to operate with verifiable information security standards. The Ayuntamiento de Palencia, with a city population of around 78,000, runs an expanding electronic administration portal, digital citizen participation channels and a network of internal management systems whose suppliers fall directly within the scope of the Esquema Nacional de Seguridad (ENS). The Complejo Asistencial Universitario de Palencia (CAUPA) — comprising Hospital General de Palencia and Hospital Río Carrión and managed by the regional health authority Sacyl — contracts information technology services for clinical records, laboratory systems and administrative platforms, all of which process sensitive health data subject to the ENS.
These bodies are joined by the Delegación Territorial de la Junta de Castilla y León en Palencia, which covers employment, education and social services for the province, and by public schools and other institutions that procure digital solutions from local and regional suppliers. All of them are subject to the ENS under Real Decreto 311/2022, of 3 May (BOE-A-2022-7191). That obligation, by explicit provision of the regulation, extends through the supply chain to every company providing them with technology services.
The provincial body providing digital services and electronic administration platforms to 191 municipalities. Its technology tenders include ENS-aligned information security requirements that suppliers must demonstrate.
The city administration managing its electronic headquarters, online tax services and citizen-facing digital platforms. ICT suppliers must demonstrate ENS conformity to access its contracts and maintain existing ones.
The university hospital complex (Sacyl), whose clinical and administrative systems involve sensitive health data. Technology companies supporting these systems must comply with the ENS at the appropriate security category.
RD 311/2022 does not limit its scope to public bodies themselves. Its additional provision one makes clear that private-sector companies providing services or solutions to the public sector must demonstrate ENS conformity within the relevant contractual relationship. This is not a recommendation: it is a technical solvency condition that appears explicitly in procurement documents once the contract scope involves information systems.
This means that if your company — based in Palencia city, in the Cerrato, Tierra de Campos or Montaña Palentina districts, or anywhere else in the province — provides any of the following services to the Diputación de Palencia, the Ayuntamiento, CAUPA, the Delegación Territorial de la Junta de Castilla y León in Palencia, or any public educational centre in the province, the ENS is part of your contractual obligations:
The transitional period for adapting pre-existing systems ended on 5 May 2024. New contracts require conformity from day one. Companies that cannot demonstrate it are excluded from public procurement before their offer is evaluated. The ENS consultancy for companies explains the full process; the ENS guide provides the regulatory background.
Not every system requires the same level of rigour. The category is determined by assessing the impact a security incident would have across the five CIDAT dimensions — confidentiality, integrity, availability, authenticity and traceability. The dimension with the highest level sets the category for the whole system. For a supplier to the Diputación or the Ayuntamiento de Palencia, this assessment is the first concrete step, and the category it produces determines the route to conformity.
Typical for SMEs supplying general management support, document digitisation or ICT maintenance to local municipal bodies in Palencia province.
Frequent for systems that manage sensitive citizen data or critical processes at the Diputación, the Ayuntamiento or the CAUPA health complex.
Applies to systems whose failure could cause irreparable harm: critical health infrastructure at CAUPA or essential public services where continuity is vital.
At the basic category, the organisation verifies its own compliance against the CCN-STIC guides and issues a declaration of conformity. No external certification body is required, but the documentation and evidence must be solid enough to withstand scrutiny from any Palencia contracting authority. I prepare the full documentary body so the declaration holds up.
At medium or high category, conformity requires certification by an ENAC-accredited body under UNE-EN ISO/IEC 17065:2012. I prepare your organisation to pass that audit with confidence; the seal is issued by the accredited body, not by the consultant. That distinction matters: be cautious of anyone who promises to guarantee certification.
The goal is not to produce paperwork: it is to ensure your company has the documentary and technical body that any auditor or Palencia public procurement document will request. Every deliverable follows the structure prescribed by the CCN-STIC guides and Annexes I–IV of RD 311/2022.
Yes. The Diputación de Palencia, as a local public body, is fully subject to the ENS under RD 311/2022. Through its local cooperation service it provides digital platforms and electronic administration tools to 191 municipalities, generating contracts with private ICT suppliers that inherit the same ENS obligations. If your company provides software, infrastructure, maintenance or technology consulting to the Diputación or to any municipality it supports digitally, the regulation applies and procurement documents will require you to demonstrate conformity at the appropriate security category.
The Ayuntamiento de Palencia, as a local administration managing its own electronic headquarters, online tax services and digital citizen services, is obliged to comply with the ENS in its own systems and to extend that requirement to suppliers whose services affect public information systems. In practice, contracts for systems maintenance, cloud services, cybersecurity, document management and electronic administration platforms typically include ENS conformity as a technical solvency requirement. Companies that cannot demonstrate it are excluded from the tender before their offer is assessed on price or quality.
Yes. The Complejo Asistencial Universitario de Palencia (CAUPA) — comprising Hospital General de Palencia and Hospital Río Carrión — is part of Sacyl, the regional health authority of the Junta de Castilla y León. Sacyl is a public-sector entity fully subject to the ENS. Its technology contracts — clinical information systems, laboratory platforms, radiology and imaging solutions, administrative management and electronic records — involve the processing of highly sensitive health data. Suppliers handling those systems must demonstrate ENS conformity, and the category is often medium or high given the sensitivity and criticality of the data involved. The initial diagnostic determines the exact scope and category applicable to each contract.
It depends on the nature of the service and the data processed. For many Palencia SMEs providing municipal management software, ICT support or document digitisation to the Diputación or to small municipalities, the basic category is the most common: the impact of an incident across the five CIDAT dimensions is limited and a self-assessed declaration of conformity suffices. For contracts involving sensitive citizen data, critical administrative processes or health-related systems at CAUPA, the category is often medium or high, requiring ENAC-accredited certification. The first step is always the diagnostic and categorisation exercise, which provides the reliable answer for your specific situation.
The transitional period of RD 311/2022 for adapting pre-existing systems ended on 5 May 2024. If you have active contracts and have not yet begun the compliance process, the situation is pressing: at the next contract renewal or in any pliego review, the contracting body may require proof of conformity. The most sensible course of action is to start immediately with a diagnostic that establishes the actual scope and category required, prioritise the measures that close the most significant risks, and have the documentary body ready before the contract comes up for renewal. Acting early avoids being in breach at the worst possible moment.
Yes. The ENS compliance process is fundamentally documentary and technical, and can be managed remotely with the right tools and communication. Diagnostic sessions, working meetings with your team, document reviews and training are routinely conducted by video conference. When a project requires an on-site visit — for example, to carry out a physical infrastructure review at your Palencia premises or to support an on-site audit session — I travel without any issue, as I work regularly across Castilla y León and cover the whole province of Palencia.
First call at no charge and with no commitment. We identify together which Palencia public bodies are your clients, which ENS category applies to your scope and what the most direct route to demonstrating conformity looks like. Even if we decide not to work together, you leave with a useful initial diagnostic and a clearer picture of where you stand.