The ENS in 5 key points

  1. What it is: a royal decree (Real Decreto 311/2022) that requires public information and services to be protected by a common minimum of cybersecurity measures.
  2. Who it applies to: the entire public sector and, by extension, the private companies that provide it with services or technology solutions.
  3. Three levels: basic, medium and high categories, depending on the impact an incident would have.
  4. Five dimensions: confidentiality, integrity, availability, authenticity and traceability (mnemonic C-I-D-A-T).
  5. How conformity is certified: the basic category is declared through self-assessment; medium and high require certification by a body accredited by ENAC.

What is the National Security Framework?

The ENS is the standard that harmonises cybersecurity across Spain's Public Administration. It originated with Real Decreto 3/2010 and was completely overhauled by Real Decreto 311/2022, of 3 May, which is the version currently in force. Its legal basis is article 156.2 of Ley 40/2015 (Spain's Legal Regime of the Public Sector Act).

In plain terms: whenever a public administration processes your taxes, manages your medical record or publishes a tender, it does so on IT systems that must be protected by a minimum level of security common to every administration. That "common minimum" is the ENS. It is not a recommendation — it is mandatory.

The declared purpose of the standard is to create the conditions of trust needed to use electronic means, protecting data and services against threats, whether accidental or deliberate. To do this, RD 311/2022 sets out basic principles, minimum requirements, a mechanism for categorising systems and a catalogue of security measures (its well-known Annex II).

A couple of nuances are worth keeping in mind, because they explain why the ENS matters more than it might seem. First, it is not something you sign once and forget: security is treated as a continuous process, with periodic risk analysis, monitoring and improvement. Second, the ENS distributes specific responsibilities within the organisation (information owner, service owner, security officer and system officer), so compliance does not fall only on the IT department — it also rests with senior management, which approves the security policy.

Who does the ENS apply to?

The scope of application is set out in article 2 of RD 311/2022 and is broader than many people think. It applies to two large groups:

That extension to suppliers shows up in procurement documents: more and more public tenders require bidders to submit the ENS Declaration or Certificate of Conformity as a condition of contracting. If your company wants to work with the public administration, it pays to plan ahead. We cover this in detail in the article on why the ENS is mandatory for businesses and suppliers.

The ENS does not exist in isolation, either: it coexists with GDPR obligations for businesses, the NIS2 directive's obligations and the DORA regulation. To place each rule in context, see the general map of cybersecurity regulation in Spain.

What are the ENS levels?

The ENS classifies every information system into one of three categories, depending on the harm a security incident would cause. The category determines how many security measures apply, and how demanding they are.

Table 1. The ENS's three categories under RD 311/2022 (Annex I)
CategoryWhen it appliesImpact of an incidentConformity
BasicNo dimension exceeds the LOW levelLimitedSelf-assessment (declaration)
MediumAny dimension reaches the MEDIUM level (and none reach HIGH)SeriousCertification by an accredited body
HighAny dimension reaches the HIGH levelVery seriousCertification by an accredited body

The golden rule is simple: the system's category is set by its most demanding dimension. It only takes one dimension reaching the high level for the whole system to be classified as high category, with the corresponding reinforcement of measures. This "the strongest link pulls the whole chain up" logic is key to understanding why a well-done classification saves effort — and money.

What are the security dimensions (C-I-D-A-T)?

To decide each system's level, the ENS does not look at "security" in the abstract — it looks at five specific properties of information and services. These are the security dimensions, summarised by the acronym C-I-D-A-T (from the Spanish Confidencialidad, Integridad, Disponibilidad, Autenticidad, Trazabilidad — Confidentiality, Integrity, Availability, Authenticity, Traceability). Each dimension is assessed separately at one of three levels: low, medium or high.

Table 2. The ENS's five security dimensions (C-I-D-A-T)
DimensionQuestion it answersWhat it guarantees
C — ConfidentialityWho can see the information?That only authorised people can access the data.
I — IntegrityIs the information intact?That data is not altered or destroyed without authorisation.
D — AvailabilityIs it accessible when needed?That the service and information are available when required.
A — AuthenticityIs it who it claims to be?That the identity of users, equipment and data can be trusted.
T — TraceabilityWho did what, and when?That actions are logged and attributable to whoever performed them.

The process is methodical: each dimension is assessed (for example, the availability of an electronic office at medium level, traceability at high level, and so on), and the highest level among the five sets the system's category. From there, Annex II of RD 311/2022 specifies which concrete measures must be implemented for each combination of dimension and level.

A simple example to fix the idea. Picture a town council's electronic office where citizens file applications. Availability is probably medium (the service going down for a few hours is annoying but tolerable), the integrity of records must be high (an altered document would have serious consequences), and traceability must also be high (it must be possible to prove who filed what, and when). Since at least one dimension reaches high, the entire system is classified as high category. That is why a rigorous assessment of each dimension — neither too low nor too high — is the step that most affects a project's cost and scope.

How is conformity with the ENS certified?

Complying with the ENS is not enough — you need to be able to prove it. The mechanism depends on the system's category and is described in guide CCN-STIC 809 from Spain's National Cryptologic Centre (CCN).

Table 3. ENS conformity mechanisms by category
CategoryMechanismWho carries it outResult
BasicSelf-assessmentThe system's own staff, or whoever they delegate toDeclaration of Conformity
MediumCertification auditENAC-accredited certification bodyCertificate of Conformity
HighCertification auditENAC-accredited certification bodyCertificate of Conformity

In practice, the difference is significant. The basic category allows for a self-assessment: the organisation verifies internally that it complies and issues a Declaration of Conformity, without needing an external auditor. The medium and high categories, by contrast, require a formal audit carried out by an ENAC-accredited certification body, which culminates in a Certificate of Conformity. Conformity must be reviewed at least every two years.

Both the declaration and the certificate entitle the organisation to display the corresponding ENS conformity mark, the seal public administrations typically ask for in tenders. Reaching that point requires a prior compliance project: risk analysis, security policy, implementation of measures and audit. If your organisation is on that path, we can help — both with ENS implementation consulting and with preparing for the conformity audit.

Where can you download the ENS in PDF?

The official, free text of the ENS is published in Spain's Official State Gazette (BOE). These are the primary sources worth keeping:

A practical tip: always download the consolidated version from the BOE, not the original May 2022 publication, because the consolidated version incorporates later corrections and reflects the standard's current state.

Summary: the ENS at a glance

If you had to keep just one idea, it would be this: the ENS is the Spanish public sector's "mandatory cybersecurity minimum," which also applies to its private-sector suppliers, is measured across three levels and five dimensions, and is demonstrated through self-assessment (basic) or external certification (medium and high).

And above all, remember that this is the summary. When you need to go deeper — how to classify a specific system, which Annex II measures apply to you, what the compliance deadlines are, or how to approach the audit — the natural next step is the complete ENS guide.

Frequently asked questions about the ENS

What is the National Security Framework, in a nutshell?
It is Spain's legal framework, regulated by Real Decreto 311/2022, that sets the minimum cybersecurity requirements that public-sector information systems — and the private companies that provide services to them — must meet. It defines three levels of requirement (basic, medium and high) and five security dimensions to protect public electronic data and services.
Who does the ENS apply to?
It applies to the entire Spanish public sector (central government, the autonomous communities, local entities, public universities and dependent bodies) and, by extension, to private companies that provide it with services or technology solutions. That is why many public tenders require contractors to submit an ENS Declaration or Certificate of Conformity.
What are the ENS levels?
The ENS defines three security categories: basic, medium and high. The category is assigned according to the impact an incident would have and is set by the system's most demanding dimension: if just one of the five dimensions reaches the high level, the whole system moves to high category. The category determines the applicable set of security measures.
Where can you download the ENS in PDF?
The official, free text is published in Spain's Official State Gazette (BOE). The recommended option is the consolidated text of Real Decreto 311/2022 (reference BOE-A-2022-7191), available in HTML and PDF at boe.es. The CCN's portal (ens.ccn.cni.es) complements the standard with CCN-STIC guides, templates and frequently asked questions.

Five minutes are enough to understand it, not to solve it. If you would rather have someone else solve it for you, that is how I approach ENS certification.

Sources

Is your organisation a public administration or a public-sector supplier in Castilla y León that needs to comply with the ENS? We cover the region from our base in Castilla y León, supporting the whole project from risk analysis through to obtaining the conformity mark.

Reference information for general guidance; it does not replace professional advice or the official text of the regulation.