In brief: The National Cryptologic Centre (CCN) publishes its own tools for working with the ENS (Spanish National Security Framework), and each one covers one phase of the cycle: PILAR calculates risk using the MAGERIT methodology, AMPARO guides the implementation of measures and generates the declaration of applicability, CLARA audits the hardening of your Windows and Linux systems, INES collects the annual security status report, and LUCIA manages incidents. Don't confuse these with the CPSTIC catalogue, which is a different thing entirely: qualified commercial products, not applications from the Centre itself. None of them is mandatory except INES; the rest are an excellent shortcut, especially if you're a local government body or an SME without a licensing budget.
The CCN's tools for the ENS (Spanish National Security Framework) are an ecosystem of free or access-regulated applications that cover the full compliance cycle: PILAR for risk analysis, AMPARO for adequacy and the declaration of applicability, CLARA for auditing technical configuration, and INES for reporting security status. Here I explain what each one does, which phase it fits into, and how to access it.
When an organisation sets out to comply with the ENS for the first time, I'm almost always asked the same question: "which software do I use for this?" The good news is that the CCN itself provides a set of tools, in many cases free of charge, that cover the entire compliance cycle from end to end. The bad news is that their names — PILAR, INES, CLARA, AMPARO, LUCIA — mean nothing to a newcomer, and it's easy to ask for the wrong one. This is the map I wish I'd had on day one.
What tools does the CCN offer for ENS compliance?
The CCN maintains an ecosystem of cybersecurity solutions, and part of it is designed specifically for the ENS compliance cycle. The five you'll actually use during adequacy and ongoing maintenance are:
- PILAR. Risk analysis and management using the MAGERIT methodology.
- AMPARO. Assistant for implementing security measures and generating the declaration of applicability.
- CLARA. Technical audit of your systems' security configuration.
- INES. Platform for reporting security status to the CCN, on an annual basis.
- LUCIA. Incident management and coordination with the government CERT.
One heads-up before we go further, because it's the most common source of confusion: these tools are not the CPSTIC catalogue maintained by the CCN. The CPSTIC is a list of commercial security products — firewalls, antivirus software, encryption devices — approved or qualified for use under the ENS. The tools covered in this article are applications from the Centre itself for managing your compliance, not products you buy and install in production. If you're choosing a certified product, that's a different path: I explain it in the difference between an approved and a qualified product.
PILAR: risk analysis and management with MAGERIT
PILAR is the CCN's veteran tool and probably the one you'll use the most. It automates MAGERIT risk analysis for the ENS: it starts from your assets, assigns them threats and safeguards from a predefined catalogue, maintains the dependency matrix, and calculates intrinsic and residual risk as you adjust values.
- What it does. It models the risk analysis and management of an information system following MAGERIT, the official methodology of the Spanish Public Administration. It's the fastest way to produce the formal risk analysis the ENS requires.
- Which phase of the ENS it fits into. At kick-off and at every review: risk analysis is the foundation on which you decide which measures to apply. You come back to it every time the system changes.
- Who can use it and how to access it. Free licences are available for the Spanish public sector, requested directly from the CCN, and paid licences exist for private or commercial use. There's a lightweight version, µPILAR, designed for small entities that don't need the full power of the complete version.
- The consultant's take. PILAR isn't mandatory. The ENS requires a formal risk analysis, not a specific tool; other well-documented equivalent methodologies are accepted. That said, for an SME tackling MAGERIT step by step for the first time, starting with PILAR saves weeks compared with building a spreadsheet from scratch.
INES: the national security status report
If PILAR is the one you'll use most, INES is the one you can't skip. It's the platform through which entities within the scope of the ENS report their compliance level and security indicators to the CCN, and the report is submitted annually.
- What it does. It collects the National Security Status Report: basic metrics, asset characterisation, degree of ENS compliance, and data on security organisation, incident management, and outsourced services. The CCN aggregates it to build a picture of the public sector's overall security posture.
- Which phase of the ENS it fits into. In ongoing monitoring and continuous improvement, once you're already compliant. It's a recurring commitment, not a one-off formality.
- Who can use it and how to access it. Entities within scope access the CCN platform with credentials within the annual data-submission window. It's supported by CCN-STIC guide 824.
- The consultant's take. For small local entities, INES is often the first real contact with the ENS. I cover this in the guide on self-assessment and INES for small municipalities, where reporting and basic-conformity self-assessment go hand in hand.
CLARA: auditing your systems' configuration
CLARA gets into the technical weeds. While PILAR and AMPARO work on documentation and management measures, CLARA checks how your systems are actually configured: it verifies hardening against the ENS's security templates.
- What it does. It audits the security configuration of Windows and Linux systems (there's a version for each) and measures the degree of compliance by applying the CCN-STIC hardening guides. It produces two reports: a technical one with the detail of controls and gaps, and an executive one for management.
- Which phase of the ENS it fits into. In technical verification and audit preparation. It tells you, before the auditor arrives, where you fall short at the configuration level.
- Who can use it and how to access it. It's one of the most open: it's downloaded from the CCN-CERT tools area and used by security officers at both public bodies and private companies. There's a version for the ENS and a version for classified systems.
- The consultant's take. CLARA is a thermometer, not a magic button: it flags the deviations, but fixing them is a job for your systems team, following the technical security instructions and CCN-STIC guides. Run it early, not the night before the audit, so there's time to remediate.
AMPARO: ENS adequacy and the declaration of applicability
AMPARO is the implementation assistant. It guides an organisation through the ENS adequacy process, and once you've finished implementing the measures, it helps you formalise conformity.
- What it does. It guides the implementation of security measures and lets you evaluate the system's status. For the BASIC category, it automatically produces the declaration of applicability — the document that sets out which measures apply according to the system's category. It also acts as a meeting point between the organisation, certification bodies, and auditors.
- Which phase of the ENS it fits into. In adequacy and implementation, between the risk analysis and the conformity audit. It's the bridge that organises everything that came before into a presentable file.
- Who can use it and how to access it. It's aimed at entities within the scope of the ENS and integrates with INES within the CCN's governance environment. Access is managed through its portals, with prior registration.
- The consultant's take. Automatically generating the declaration of applicability is very convenient for the basic category, but it doesn't replace judgement: in the MEDIUM and HIGH categories you have to justify exclusions and reinforcements. If you're planning to self-assess, this pairs with the ENS declaration of conformity at basic level.
Other tools in the CCN-CERT ecosystem: LUCIA, ANA and more
The CCN's catalogue goes well beyond adequacy. These tools show up once you move into day-to-day operations, although not all of them are needed to get certified:
- LUCIA. Cyber-incident management and coordination. This is the tool entities within the scope of the ENS use to notify and track their incidents centrally and coordinate with the government CERT, using taxonomies aligned with ENISA. It's the operational piece of incident management under the ENS.
- ANA. Audit automation and standardisation, geared towards centralised, continuous vulnerability management.
- SOC and detection. Tools such as CARMEN (advanced threat detection in network traffic), GLORIA (event and incident management), and REYES (cyber-threat information sharing) are geared towards running a security operations centre. They're powerful, but they go beyond what a basic- or medium-category ENS adequacy needs: don't worry about them at the start.
The practical rule: PILAR, AMPARO, CLARA and INES are enough to reach adequacy; LUCIA and the rest come into play once you move into running security operations.
Which CCN tool to use in each phase of the ENS
This is the table I use to place each tool at its point in the cycle, along with a market alternative in case the CCN's own tool doesn't apply in your case.
| ENS phase | CCN tool | What it solves | Market alternative |
|---|---|---|---|
| Risk analysis and management | PILAR / µPILAR | Intrinsic and residual risk with MAGERIT | Commercial GRC platforms |
| Adequacy and declaration of applicability | AMPARO | Implementing measures and formalising conformity | Consultancy + GRC tools |
| Technical configuration audit | CLARA | Windows and Linux hardening against CCN-STIC | Compliance scanners (Nessus, OpenVAS) |
| Security status reporting | INES | Annual indicator report to the CCN | No alternative: it's the official platform |
| Incident management | LUCIA | Notification and coordination with the CERT | Ticketing or SOAR platforms |
| Continuous vulnerability management | ANA | Vulnerability detection and tracking | Tenable, Qualys, Rapid7 |
CCN tool or commercial solution? How to decide
There's no single answer. These are the criteria I apply when recommending one or the other:
- Budget and scope. If you're in the public sector, the CCN's tools are free or access-regulated and are aligned to the letter with the regulation: the default starting point. If you're a private company outside the scope of a public tender, some licences are paid, and a commercial GRC platform may pay off.
- Team maturity. The CCN's tools assume someone on your team understands MAGERIT, hardening, and conformity. A commercial solution with support and automation can perform better for a small team without a dedicated technical profile.
- Integration. If you already run a SOC or a GRC platform, keeping everything in one environment avoids silos. If you're starting from scratch, the CCN's tools give you a complete cycle at no licensing cost.
- Mandatory status. INES isn't negotiable: it's the official reporting channel and has no substitute. The rest are means to an end, and there you do have a choice.
Which tools to prioritise depending on your organisation
Small municipality or local entity
Start with the minimum viable set: µPILAR for risk analysis, AMPARO for basic conformity, and INES for annual reporting. Add CLARA once you have someone who can interpret the technical report. This is the scenario where the CCN's free tools shine brightest, because there's no budget for licences.
SME looking to become a public-sector supplier
You need to demonstrate conformity in order to bid, so the core is PILAR plus AMPARO, with CLARA thrown in so the audit doesn't spring configuration surprises on you. If the tender specifies particular products, that's where the CPSTIC comes in, not these tools. When the case gets complicated, that's the moment to lean on ENS consultancy.
Medium-sized body with its own team
Here the CCN's full cycle makes sense, along with adding the operational layer: LUCIA for incidents and ANA for vulnerabilities, on top of PILAR, AMPARO, CLARA and INES. If you're preparing for certification, it's worth mapping out the ENS certification process first and fitting each tool to its milestone.
Conclusion: the tool is the means, not the end
The CCN's tools remove a lot of friction, but they don't comply with the ENS for you. PILAR calculates the risk, but you're the one who decides which measures to apply; CLARA detects the deviation, but fixing it is a job for your systems team; AMPARO organises the file, but conformity rests on your judgement. Used well, they save you months and a fair amount of money in licences. Misunderstood, they create the false impression that filling in the template equals compliance.
If you're not sure where to start, which tool to use, or in what order, tell me about your case and we'll figure it out together, with no obligation.
Does your company need to achieve ENS adequacy or certification in order to bid for or become a supplier to the Administration? Find out about my ENS consultancy service, and I'll support you through the whole cycle.
Frequently asked questions
What tools does the CCN offer for ENS compliance?
The CCN maintains an ecosystem of cybersecurity solutions, and part of it is designed specifically for the ENS compliance cycle. The five you'll actually use during adequacy and ongoing maintenance are: