The ENS in 5 key points
- What it is: a royal decree (Real Decreto 311/2022) that requires public information and services to be protected by a common minimum of cybersecurity measures.
- Who it applies to: the entire public sector and, by extension, the private companies that provide it with services or technology solutions.
- Three levels: basic, medium and high categories, depending on the impact an incident would have.
- Five dimensions: confidentiality, integrity, availability, authenticity and traceability (mnemonic C-I-D-A-T).
- How conformity is certified: the basic category is declared through self-assessment; medium and high require certification by a body accredited by ENAC.
What is the National Security Framework?
The ENS is the standard that harmonises cybersecurity across Spain's Public Administration. It originated with Real Decreto 3/2010 and was completely overhauled by Real Decreto 311/2022, of 3 May, which is the version currently in force. Its legal basis is article 156.2 of Ley 40/2015 (Spain's Legal Regime of the Public Sector Act).
In plain terms: whenever a public administration processes your taxes, manages your medical record or publishes a tender, it does so on IT systems that must be protected by a minimum level of security common to every administration. That "common minimum" is the ENS. It is not a recommendation — it is mandatory.
The declared purpose of the standard is to create the conditions of trust needed to use electronic means, protecting data and services against threats, whether accidental or deliberate. To do this, RD 311/2022 sets out basic principles, minimum requirements, a mechanism for categorising systems and a catalogue of security measures (its well-known Annex II).
A couple of nuances are worth keeping in mind, because they explain why the ENS matters more than it might seem. First, it is not something you sign once and forget: security is treated as a continuous process, with periodic risk analysis, monitoring and improvement. Second, the ENS distributes specific responsibilities within the organisation (information owner, service owner, security officer and system officer), so compliance does not fall only on the IT department — it also rests with senior management, which approves the security policy.
Who does the ENS apply to?
The scope of application is set out in article 2 of RD 311/2022 and is broader than many people think. It applies to two large groups:
- The entire public sector. Central government, the autonomous communities, local entities (town and provincial councils), public universities, autonomous bodies and public-law entities. If it delivers a public service electronically, it is covered.
- Private companies that serve the public sector. Article 2.3 extends the obligation to private-sector entities when they provide services or supply solutions to public-sector entities. This is the part that surprises tech SMEs the most: if you sell software, hosting, support or any ICT service to a public administration, the ENS reaches you through the supply chain.
That extension to suppliers shows up in procurement documents: more and more public tenders require bidders to submit the ENS Declaration or Certificate of Conformity as a condition of contracting. If your company wants to work with the public administration, it pays to plan ahead. We cover this in detail in the article on why the ENS is mandatory for businesses and suppliers.
The ENS does not exist in isolation, either: it coexists with GDPR obligations for businesses, the NIS2 directive's obligations and the DORA regulation. To place each rule in context, see the general map of cybersecurity regulation in Spain.
What are the ENS levels?
The ENS classifies every information system into one of three categories, depending on the harm a security incident would cause. The category determines how many security measures apply, and how demanding they are.
| Category | When it applies | Impact of an incident | Conformity |
|---|---|---|---|
| Basic | No dimension exceeds the LOW level | Limited | Self-assessment (declaration) |
| Medium | Any dimension reaches the MEDIUM level (and none reach HIGH) | Serious | Certification by an accredited body |
| High | Any dimension reaches the HIGH level | Very serious | Certification by an accredited body |
The golden rule is simple: the system's category is set by its most demanding dimension. It only takes one dimension reaching the high level for the whole system to be classified as high category, with the corresponding reinforcement of measures. This "the strongest link pulls the whole chain up" logic is key to understanding why a well-done classification saves effort — and money.
What are the security dimensions (C-I-D-A-T)?
To decide each system's level, the ENS does not look at "security" in the abstract — it looks at five specific properties of information and services. These are the security dimensions, summarised by the acronym C-I-D-A-T (from the Spanish Confidencialidad, Integridad, Disponibilidad, Autenticidad, Trazabilidad — Confidentiality, Integrity, Availability, Authenticity, Traceability). Each dimension is assessed separately at one of three levels: low, medium or high.
| Dimension | Question it answers | What it guarantees |
|---|---|---|
| C — Confidentiality | Who can see the information? | That only authorised people can access the data. |
| I — Integrity | Is the information intact? | That data is not altered or destroyed without authorisation. |
| D — Availability | Is it accessible when needed? | That the service and information are available when required. |
| A — Authenticity | Is it who it claims to be? | That the identity of users, equipment and data can be trusted. |
| T — Traceability | Who did what, and when? | That actions are logged and attributable to whoever performed them. |
The process is methodical: each dimension is assessed (for example, the availability of an electronic office at medium level, traceability at high level, and so on), and the highest level among the five sets the system's category. From there, Annex II of RD 311/2022 specifies which concrete measures must be implemented for each combination of dimension and level.
A simple example to fix the idea. Picture a town council's electronic office where citizens file applications. Availability is probably medium (the service going down for a few hours is annoying but tolerable), the integrity of records must be high (an altered document would have serious consequences), and traceability must also be high (it must be possible to prove who filed what, and when). Since at least one dimension reaches high, the entire system is classified as high category. That is why a rigorous assessment of each dimension — neither too low nor too high — is the step that most affects a project's cost and scope.
How is conformity with the ENS certified?
Complying with the ENS is not enough — you need to be able to prove it. The mechanism depends on the system's category and is described in guide CCN-STIC 809 from Spain's National Cryptologic Centre (CCN).
| Category | Mechanism | Who carries it out | Result |
|---|---|---|---|
| Basic | Self-assessment | The system's own staff, or whoever they delegate to | Declaration of Conformity |
| Medium | Certification audit | ENAC-accredited certification body | Certificate of Conformity |
| High | Certification audit | ENAC-accredited certification body | Certificate of Conformity |
In practice, the difference is significant. The basic category allows for a self-assessment: the organisation verifies internally that it complies and issues a Declaration of Conformity, without needing an external auditor. The medium and high categories, by contrast, require a formal audit carried out by an ENAC-accredited certification body, which culminates in a Certificate of Conformity. Conformity must be reviewed at least every two years.
Both the declaration and the certificate entitle the organisation to display the corresponding ENS conformity mark, the seal public administrations typically ask for in tenders. Reaching that point requires a prior compliance project: risk analysis, security policy, implementation of measures and audit. If your organisation is on that path, we can help — both with ENS implementation consulting and with preparing for the conformity audit.
Where can you download the ENS in PDF?
The official, free text of the ENS is published in Spain's Official State Gazette (BOE). These are the primary sources worth keeping:
- Consolidated text (recommended): includes all corrections and amendments. Available in HTML and as a downloadable PDF at BOE-A-2022-7191.
- Direct PDF of the consolidated text: BOE-A-2022-7191-consolidado.pdf.
- Supporting guides and tools: the CCN's official portal, ens.ccn.cni.es, gathers the CCN-STIC 800-series guides, templates and frequently asked questions.
A practical tip: always download the consolidated version from the BOE, not the original May 2022 publication, because the consolidated version incorporates later corrections and reflects the standard's current state.
Summary: the ENS at a glance
If you had to keep just one idea, it would be this: the ENS is the Spanish public sector's "mandatory cybersecurity minimum," which also applies to its private-sector suppliers, is measured across three levels and five dimensions, and is demonstrated through self-assessment (basic) or external certification (medium and high).
- Regulation: Real Decreto 311/2022, of 3 May (repeals RD 3/2010).
- Legal basis: Ley 40/2015, article 156.
- Structure: 41 articles, 3 additional provisions and 4 annexes.
- Categories: basic, medium, high.
- Dimensions: confidentiality, integrity, availability, authenticity and traceability.
- Conformity: declaration (basic) or ENAC certification (medium and high), reviewable every two years.
And above all, remember that this is the summary. When you need to go deeper — how to classify a specific system, which Annex II measures apply to you, what the compliance deadlines are, or how to approach the audit — the natural next step is the complete ENS guide.
Frequently asked questions about the ENS
- What is the National Security Framework, in a nutshell?
- It is Spain's legal framework, regulated by Real Decreto 311/2022, that sets the minimum cybersecurity requirements that public-sector information systems — and the private companies that provide services to them — must meet. It defines three levels of requirement (basic, medium and high) and five security dimensions to protect public electronic data and services.
- Who does the ENS apply to?
- It applies to the entire Spanish public sector (central government, the autonomous communities, local entities, public universities and dependent bodies) and, by extension, to private companies that provide it with services or technology solutions. That is why many public tenders require contractors to submit an ENS Declaration or Certificate of Conformity.
- What are the ENS levels?
- The ENS defines three security categories: basic, medium and high. The category is assigned according to the impact an incident would have and is set by the system's most demanding dimension: if just one of the five dimensions reaches the high level, the whole system moves to high category. The category determines the applicable set of security measures.
- Where can you download the ENS in PDF?
- The official, free text is published in Spain's Official State Gazette (BOE). The recommended option is the consolidated text of Real Decreto 311/2022 (reference BOE-A-2022-7191), available in HTML and PDF at boe.es. The CCN's portal (ens.ccn.cni.es) complements the standard with CCN-STIC guides, templates and frequently asked questions.
Five minutes are enough to understand it, not to solve it. If you would rather have someone else solve it for you, that is how I approach ENS certification.
Sources
- Real Decreto 311/2022, of 3 May, regulating the National Security Framework (consolidated text) — BOE
- RD 311/2022 — consolidated PDF from the BOE
- Ley 40/2015, on the Legal Regime of the Public Sector (legal basis of the ENS, art. 156) — BOE
- National Security Framework portal — National Cryptologic Centre (CCN)
- CCN-STIC 809 Guide: Declaration and Certificate of Conformity with the ENS — CCN-CERT
Is your organisation a public administration or a public-sector supplier in Castilla y León that needs to comply with the ENS? We cover the region from our base in Castilla y León, supporting the whole project from risk analysis through to obtaining the conformity mark.
Reference information for general guidance; it does not replace professional advice or the official text of the regulation.