Search Client login
Compliance and security · ENS · Salamanca

ENS Consultancy in Salamanca

I am Ángel Ortega Castro, independent ENS consultant. I help companies that want to tender or work as suppliers to the Ayuntamiento de Salamanca, the Diputación de Salamanca or the Universidad de Salamanca (USAL) align with the Esquema Nacional de Seguridad (ENS) — Spain's National Security Framework (RD 311/2022): gap assessment, alignment plan and conformity preparation, without guarantees of certification.

RD 311/2022
Current framework
3 categories
Basic · Medium · High
1 to 1
Real accompaniment
Salamanca's public sector

A demanding and diverse public procurement ecosystem.

Salamanca concentrates, for its size, an unusually broad public sector: a university with eight centuries of history, a provincial council covering more than three hundred municipalities across the province, and a city council that has driven significant digital transformation in recent years. Three institutions with different procurement profiles, yet with one growing common denominator: the requirement that their technology suppliers demonstrate conformity with the Esquema Nacional de Seguridad (ENS).

Ayuntamiento de Salamanca

The city council manages its electronic office, citizen-facing processing platforms, and urban planning and social services systems. Any company providing technology services to the Ayuntamiento falls within the ENS perimeter as part of its supply chain.

Diputación de Salamanca

The Diputación provides shared e-administration and technology services to the province's municipalities. Its contracts for software, infrastructure and cloud services increasingly require suppliers to demonstrate ENS conformity as a condition of technical standing.

Universidad de Salamanca (USAL)

The USAL, as a public institution founded in 1218 and subject to Spain's Organic Law on the University System, is directly bound by ENS and extends that obligation to its entire supply chain. Companies providing learning management systems, academic administration software, research tools or cloud services must demonstrate ENS conformity before signing the contract or, in many cases, at the tender specification stage.

The obligation is already in force

RD 311/2022 removed any ambiguity: suppliers and contractors working with the public sector must align with ENS. The transitional period for pre-existing systems expired on 5 May 2024. Salamanca's tender documents, like those across Spain, now incorporate this requirement as a technical standing condition. This is not a future trend: it is the current landscape.

If your company provides or wants to provide technology services to any of these institutions, ENS consultancy is the path to demonstrating that you manage information security with the rigour the standard demands. The ENS guide is the best starting point if you are still assessing whether it applies to you.

Obligated parties

Who does the ENS apply to in Salamanca?

The ENS applies directly to the Ayuntamiento de Salamanca, the Diputación de Salamanca and the Universidad de Salamanca (USAL), as to every public-sector body. But its reach does not stop there: Real Decreto 311/2022 extends the obligation to private companies that provide services or solutions to the public sector under a contractual relationship — that is, to the entire supply chain. ICT suppliers, systems integrators, SaaS companies, cloud service providers, software consultancies: if your commercial activity includes working with these administrations, ENS applies to you.

The sole transitional provision of RD 311/2022 set 24 months to align pre-existing systems; that deadline expired on 5 May 2024. New systems or systems with significant changes must comply from day one. ENS certification is renewed every two years for medium and high categories.

Legal basis: Real Decreto 311/2022, of 3 May, regulating the Esquema Nacional de Seguridad (BOE-A-2022-7191). Application guides from the CCN (Centro Criptológico Nacional). Independent verification is carried out by entities accredited by ENAC.
How we work

Phases of the ENS alignment service.

The ENS alignment plan follows the order set out in the CCN-STIC guides. Nothing is improvised: each phase produces a deliverable that builds on the previous one. This is the complete roadmap, from the initial gap assessment to audit preparation.

ENS alignment plan · phases and deliverables
Phase What we do Reference and deliverable
Phase 01
Gap assessment
Differential analysis between your current position and ENS requirements. Scope definition and identification of affected information systems. Gap assessment report showing the real distance to compliance.
Phase 02
Categorisation
Assessment of systems across the five security dimensions (CIDAT) and assignment of the category: basic, medium or high. Annex I of ENS. Determines the applicable basic, medium or high category.
Phase 03
Risk analysis
Identification of assets, threats and safeguards using MAGERIT methodology (supported by tools such as PILAR). MAGERIT risk analysis report and risk treatment plan.
Phase 04
Alignment plan + DdA
Security policy, measure selection and drafting of the Declaration of Applicability (DdA), justifying each applicable control. CCN-STIC 806 guide. Alignment plan and declaration of conformity.
Phase 05
Implementation
Deployment of selected measures: organisational, operational and protection framework. Team accompaniment throughout. Implementation of Annex II measures with supporting evidence.
Phase 06
Audit / certification
Preparation and pre-audit review. For medium or high category, accompaniment during the accredited entity's audit. Annex III. I prepare you for the ENS audit; the conformity audit is conducted by an accredited third party.

Want to know how long each phase takes? I break it down in the ENS alignment timelines. And if your system is already running, I can take charge of the ENS implementation and alignment directly.

Request your gap assessment →

Security categories

ENS categories: basic, medium and high.

A system's category is not a rough "low/medium/high" estimate: it is determined by assessing the impact of an incident across the five security dimensionsconfidentiality, integrity, availability, authenticity and traceability (CIDAT). The dimension with the highest level determines the system's overall category.

Basic category

Limited impact

When an incident would cause limited harm to the organisation's functions, assets or individuals.

  • No dimension exceeds the low level
  • Conformity through self-assessed declaration
  • A proportionate and achievable set of measures
Medium category

Serious impact

When an incident would cause serious harm: at least one dimension reaches the medium level.

  • At least one dimension at medium level
  • Conformity through accredited certification
  • Biennial conformity audit
High category

Very serious impact

When an incident would cause very serious, or even irreversible, harm: at least one dimension reaches the high level.

  • At least one dimension at high level
  • Conformity through accredited certification
  • Biennial conformity audit

Choosing the right category is key to avoiding over-investment without falling short. I help you decide in the ENS levels guide and how to choose your category, and to understand the role of the five security dimensions (CIDAT).

The two conformity paths

Basic → declaration of conformity

In the basic category, conformity is demonstrated through a self-assessed declaration of conformity: the organisation itself verifies compliance against the CCN-STIC guides. I prepare the documentation and evidence so that your declaration is solid and can withstand any subsequent audit.

Medium / high → accredited certification

In the medium or high category, conformity requires certification by an entity accredited by ENAC under standard UNE-EN ISO/IEC 17065:2012. I prepare you for the audit; the certification is issued by the accredited entity, never by the consultant.

If you are unsure which framework you need, compare ENS or ISO 27001 for public-sector tendering; and for the complete certification process, review the ENS certification process.

What you take away

Documentation ready to demonstrate conformity.

You do not walk away with a PDF that nobody opens again. I deliver the documentary and technical body that supports conformity and that the auditor — or the procurement authority at the USAL, the Diputación or the Ayuntamiento — needs to see.

Ángel Ortega Castro, independent ENS consultant
Why work with me

An ENS consultant who stands behind their work.

I am Ángel Ortega Castro, an independent consultant specialising in regulatory compliance and information security. I accompany public administrations, ICT suppliers and companies tendering with the public sector in their alignment with the Esquema Nacional de Seguridad (ENS).

My approach is one of real, person-to-person accompaniment: I do not hand you a manual and disappear. I work alongside you at every phase, translating the standard into concrete decisions and leaving your team equipped to maintain conformity once the engagement ends.

I am honest about what I can and cannot promise: I prepare and align your organisation for conformity; certification is issued by an ENAC-accredited entity. That transparency, combined with rigorous application of the current standard (RD 311/2022, Annexes I–IV and CCN-STIC guides), is what sets me apart from anonymous consulting firms.

Independent ENS consultant RD 311/2022 · Annexes I–IV CCN-STIC guides MAGERIT · risk analysis Castilla y León · Canarias · Spain
Profiles I support in Salamanca

Three common situations in the Salamanca environment.

USAL supplier

Companies supplying technology to the Universidad de Salamanca.

Learning platforms, academic administration systems, research software or cloud services that the USAL procures through public tender. ENS conformity appears in the specifications as a technical standing requirement; alignment is the entry point to the contract.

Diputación contractor

ICT suppliers of provincial and municipal services.

Companies that provide or want to provide e-administration, infrastructure or software services to the Diputación de Salamanca for its network of municipalities. The Diputación's provincial reach — covering over three hundred local councils — makes these contracts a highly relevant entry point into Salamanca's public-sector ecosystem.

Ayuntamiento tender

Companies seeking to enter Salamanca City Council procurement.

From electronic processing solutions to urban planning or social services management systems: more and more of the Ayuntamiento de Salamanca's tenders require ENS conformity as a technical standing condition. Aligning before submitting is the difference between competing on merit and being left out of the process entirely.

Indicative investment

How much does ENS alignment cost?

There is no single figure, and you should be wary of anyone who gives you one without knowing your case. The investment depends on the scope (how many systems), the category (basic, medium or high), your starting maturity and whether you need accredited certification or a self-assessed declaration is sufficient.

Fixed quote after the gap assessmentNo surprises · tailored to your scope and category

On top of the consultancy investment, medium and high category work also requires paying for the accredited certification entity, which is independent of my fees and is invoiced by the third party carrying out the audit.

In the first call we assess your scope and category and I give you a fixed proposal. No commitment and no inflated figures: honest guidance from minute one.
Frequently asked questions

Common questions from Salamanca companies about ENS.

Do companies tendering with the Ayuntamiento de Salamanca need to align with ENS?

Yes, when the contractual relationship involves the company providing technology services or solutions to the city council. RD 311/2022 extends the obligation to comply with ENS to public-sector suppliers and contractors: the Ayuntamiento de Salamanca, as a local authority, is part of that public sector. If the tender specifications require it — and increasingly they do, as a technical standing requirement — the company must demonstrate ENS conformity before the contract is awarded.

Does the Universidad de Salamanca (USAL) require ENS from its ICT suppliers?

The USAL is a public university subject to Spain's Organic Law on the University System and is therefore directly bound by ENS. This obligation passes on to its suppliers when the contract involves processing data or using the university's information systems. Learning platforms, academic administration systems, research tools and cloud services sit within the typical perimeter. The specific requirement depends on each tender's specifications, but the trend is clear: the USAL is incorporating ENS conformity as a technical standing criterion in its technology contracts.

What ENS category does a supplier to the Diputación de Salamanca need?

The category — basic, medium or high — is not set by the supplying company; it is determined by assessing the impact of a security incident across the five dimensions (CIDAT) of the specific system to be operated or supplied. Many ICT services delivered to local authorities through the Diputación de Salamanca fall into the basic category, which allows conformity to be demonstrated through a self-assessed declaration without the need for accredited certification. Others, if they involve sensitive data or critical administrative functions, may require the medium or high category and the corresponding certification from an ENAC-accredited entity. The first call is where we make that assessment, at no commitment.

What is the difference between a declaration of conformity and accredited certification?

In the basic category, the organisation conducts a self-assessment against the CCN-STIC guides and issues its own declaration of conformity: no third party is involved in validating it. In the medium or high category, conformity must be accredited by an independent entity accredited by ENAC under standard UNE-EN ISO/IEC 17065:2012; it is that entity that issues the seal or certificate, not the consultant. My work in both cases is to prepare you so that documentation and evidence are solid: in the basic category, so that the declaration can withstand scrutiny; in medium and high, so that the accredited entity's audit finds everything in order. I explain it in full in the ENS guide.

Can I submit tenders to Salamanca public bodies if I do not yet have ENS conformity?

It depends on whether the tender specifies conformity as an admission requirement or as an evaluation criterion. When it is an admission requirement, failing to demonstrate it means exclusion from the process. When it is an evaluation criterion, you may submit, but your score will be lower. In either case, starting the alignment process before submitting is the safest strategy: the initial gap assessment makes it clear how long and how much effort is needed to achieve conformity, and in many basic-category projects the timeline fits comfortably within a tender's calendar.

Keep reading

ENS cluster guides and nearby cities.

Next step

Shall we talk about your ENS alignment in Salamanca?

First call at no cost and no commitment. We assess your scope, the category that applies to you and the realistic timeline for submitting tenders to the Ayuntamiento, the Diputación or the USAL with conformity accredited.