ENS maintenance starts the day after you certify: conformity is not permanent. You must renew it through an audit at least every two years (or a self-assessment in the BASIC category), report once a year to INES, keep your risk analysis and Declaration of Applicability current, notify incidents, and recategorize the system whenever it changes substantially. Let any one of those pieces slip and you lose conformity.
I work with companies and public administrations throughout the entire ENS lifecycle, and the question I hear most often comes right after the seal goes up on the website: "now what?" Many SMEs certify to qualify for a tender, breathe a sigh of relief, and file the documentation away in a drawer. Eighteen months later they discover their conformity has lapsed, that nobody reported to INES, or that a cloud provider change left the scope out of date. This article is the map of that "day after": which recurring obligations apply to you, what they cost to keep up with, and which mistakes leave you out of scope.
Does ENS certification expire?
Yes. Neither the certificate of conformity nor the declaration of conformity lasts forever. The ENS is a continuous-improvement model, not a formality you complete once. If you've just finished the ENS certification process, here are the five things you now need to keep alive:
- Limited validity. The distinctive mark has a set validity period — two years as the general reference — set by the Technical Security Instruction on ENS conformity.
- Periodic renewal. Through an audit by an accredited body in the MEDIUM and HIGH categories, or through a self-assessment in the BASIC category.
- Annual report to INES. The National State of Security Report coordinated by the CCN.
- Ongoing maintenance. Risk analysis, Declaration of Applicability, measures and procedures reviewed regularly.
- Extraordinary audit. Whenever the system changes substantially before the scheduled review.
The rest of this article walks through each of these obligations and its real-world frequency.
Calendar of obligations after ENS certification
This is the table I hand a client the same day they get the seal. What changes by category is how conformity is evidenced; the rest of the obligations are common to all three.
| Obligation | Frequency | BASIC category | MEDIUM / HIGH category |
|---|---|---|---|
| Evidence conformity | At certification and at each renewal | Self-assessment → Declaration of conformity | Audit → Certificate of conformity |
| Ordinary security review | At least every 2 years | Self-assessment | Audit by an ENAC-accredited body |
| Extraordinary review | Upon substantial changes | Yes | Yes |
| INES report | Annual | Yes | Yes |
| Updated risk analysis | Ongoing / at least annual | Yes | Yes |
| Incident notification | Upon detection | Yes | Yes |
| Renewal of the distinctive mark | Before it expires (ref. 2 years) | Yes | Yes |
If you certified right at a deadline, also check the ENS adaptation deadlines: the renewal clock starts counting from the date on the distinctive mark, not from when you signed the contract.
ENS renewal audit: how often it's due and what it covers
The audit is the heart of maintenance in the MEDIUM and HIGH categories. It isn't a formality: if the auditor finds serious non-conformities, they won't renew it.
How often is the ENS certification renewed?
Royal Decree 311/2022 requires MEDIUM or HIGH category systems to be audited at least every two years. That's the ordinary renewal rhythm. In the BASIC category, no third-party audit is needed: a self-assessment is enough, though it's worth documenting it with the same rigour. I explain the full mechanism in my guide on how often ENS conformity is audited.
What does the auditor check at renewal?
It doesn't start from zero: it verifies that what you declared is still true and that you've kept the system maintained. Specifically, it looks at:
- The risk analysis. That it's up to date and reflects the real system, not the one from two years ago.
- The Declaration of Applicability. That the Annex II measures you declared are still in place and consistent with your category.
- Operational evidence. Incident logs, continuity tests, access reviews, staff training.
- Previous non-conformities. That the corrective actions from the prior audit were genuinely closed.
If you'd rather hand this review to someone who prepares and runs it with you, that's exactly what my ENS audit service is for.
Extraordinary audit: when the review moves up
The two-year period is the ordinary minimum, but a substantial change in the system requires an earlier audit: a cloud migration, a change of critical provider, a new technology site, or a change in how the security dimensions are valued. Treating those changes as if they didn't affect conformity is one of the costliest mistakes I see.
INES: the annual report you can't skip
INES — the National State of Security Report — is the obligation most often forgotten, because nobody chases it visibly… until they do. Entities within the scope of the ENS report their security indicators every year through the platform coordinated by the CCN, which aggregates that information into the national report. It's an annual pulse check on your system's state: maturity level, measures in place, incidents managed.
For an SME that certified for a tender, the key point to understand is that INES isn't optional within its scope, and filing it every year is part of maintenance, just like the audit. If you manage a small entity, my guide on self-assessment and the INES report, written for teams with limited resources, will be useful.
Ongoing maintenance: keeping risk, measures and documentation current
Between one audit and the next, the work doesn't stop. Conformity is demonstrated with evidence, and evidence is generated daily. These are the three threads you need to keep moving.
Risk analysis and the Declaration of Applicability
The risk analysis is a living document. Every new asset, every service you outsource and every emerging threat changes it. I recommend reviewing it at least once a year and whenever anything relevant changes, using a recognised methodology such as the MAGERIT risk analysis. The Declaration of Applicability must move in parallel: if you activate or withdraw an Annex II measure, it needs to be reflected there.
Incident management and notification
A conformant system isn't one that never suffers incidents — it's one that detects them, manages them and notifies them. You need to keep your ENS incident response procedure operational and notify CCN-CERT of the ones that require it, according to their severity level. A serious incident that goes unreported is, on top of being an operational failure, a direct cause of losing conformity.
Watching new technical instructions and CCN-STIC guides
The ENS isn't a frozen text. The National Cryptologic Centre (CCN) publishes and updates Technical Security Instructions (ITS) and CCN-STIC guides that spell out how to apply the measures. Keeping the ENS current means watching for those updates and adopting them before the auditor asks you about them. It's the least visible part of maintenance, and the one that separates those who comply on paper from those who comply for real.
What to do when the system or scope changes (and when to recategorize)
Systems change: services get added, more sensitive information moves to the cloud, the number of users grows. When a change affects the valuation of the security dimensions — confidentiality, integrity, traceability, authenticity and availability — you need to redo the categorization, and the result can move up from BASIC to MEDIUM, or from MEDIUM to HIGH.
Recategorizing has immediate practical consequences: if the system moves from BASIC to MEDIUM, self-assessment stops being enough and you need a certification audit. That's why it's worth evaluating every relevant change before you make it, not after. The three triggers I always check for:
- Change of scope. New services or systems that fall under the ENS umbrella.
- Substantial technology change. Cloud migration, a new data centre, or a new critical provider.
- Change in the valuation of information. Data that becomes more sensitive and raises the system's category.
Any one of the three can require an extraordinary audit ahead of the ordinary renewal. Reporting it in time is maintenance; hiding it is putting conformity at risk.
How much it costs to maintain the ENS (and how much it costs to let it lapse)
Maintaining conformity costs considerably less than certifying from scratch, and far less than recovering it after letting it expire. I won't give you a fixed figure, because it depends on the category, the size of the system, and how much your team handles internally; for the ranges involved in initial certification, see my article on the ENS certification process and costs. What I can break down is what makes up the annual maintenance spend:
- The renewal audit. Concentrated every two years; in the BASIC category it's replaced by self-assessment and the external cost drops substantially.
- Documentation update hours. Risk analysis, Declaration of Applicability, procedures and evidence.
- Internal team time. Day-to-day operation of the measures: backups, access, logs, training.
- External support, where used. Many SMEs outsource ongoing monitoring and keep operations in-house.
The cost of "letting it lapse" rarely shows up in the spreadsheet, and it's the highest one: being shut out of a tender that requires current conformity, redoing much of the project to recertify, and losing your competitive edge against providers who did keep it up. Maintaining is always cheaper than rescuing.
Mistakes that make you lose ENS conformity
Almost every loss of conformity I've seen comes down to the same oversights. None of them are technical; all of them are managerial:
- Letting the distinctive mark expire. Nobody noted the renewal date, and the certificate expired without an audit. The most common mistake and the most avoidable.
- Changing the system without reporting it. A cloud migration or a new service that isn't reflected in the scope and doesn't trigger the extraordinary audit.
- Not filing INES. The annual report gets forgotten because no reminder arrives, and its absence is on record.
- Fossilized documentation. Risk analysis and Declaration of Applicability identical to the ones from certification day, when the system no longer is.
- Unreported incidents. Handled quietly, without the record or the notification to CCN-CERT that the framework requires.
- Ignoring new ITS. The auditor asks about a technical instruction published months ago that nobody had read.
Conclusion: the ENS is a state, not a formality
Certification is a snapshot; conformity is the film. Maintaining the ENS means auditing or self-assessing on schedule, reporting to INES every year, keeping the risk analysis and Declaration of Applicability current, notifying incidents and recategorizing when the system calls for it. None of that is complex on its own; the hard part is not losing sight of any piece over two straight years. If you want to place this phase within the full cycle, see my ENS guide for companies and public administrations.
If you certified for a tender and aren't sure what applies to you now, or your renewal is approaching and you want to get there without surprises, tell me about your case and we'll review it together, no obligation.
Need help keeping conformity alive year after year? Learn about my ENS consultancy service for companies that have already certified and don't want to lose the seal.
Frequently asked questions
Does ENS certification expire?
Yes. Neither the certificate of conformity nor the declaration of conformity lasts forever. The reference validity period is two years, set by the Technical Security Instruction on ENS conformity, after which you must renew through an audit (MEDIUM/HIGH category) or a self-assessment (BASIC category).
How often is the ENS certification renewed?
Royal Decree 311/2022 requires MEDIUM or HIGH category systems to be audited at least every two years. BASIC category systems do not need a third-party audit — a well-documented self-assessment is enough.
What does the auditor check when renewing an ENS certificate?
The auditor checks that your risk analysis is up to date, that the measures listed in your Declaration of Applicability are still in place and consistent with your category, that you have operational evidence (incident logs, continuity tests, access reviews, staff training), and that corrective actions from the previous audit were genuinely closed.
What is the INES report and is it mandatory?
INES (Informe Nacional del Estado de Seguridad — the National State of Security Report) is the annual set of security indicators that ENS-scoped entities must report through the platform coordinated by the National Cryptologic Centre (CCN). It is not optional within the ENS scope.
When do you need to recategorize an ENS system?
Whenever a change affects the valuation of the security dimensions — confidentiality, integrity, traceability, authenticity and availability — such as a change in scope, a substantial technology change (cloud migration, new data centre, new critical provider) or information becoming more sensitive. If the category rises, self-assessment stops being enough and a certification audit becomes necessary.
What mistakes make an organisation lose ENS conformity?
The most common are: letting the certificate expire without scheduling renewal, changing the system without reporting it, failing to file the annual INES report, leaving the risk analysis and Declaration of Applicability frozen since certification day, not notifying incidents to CCN-CERT, and ignoring new Technical Security Instructions (ITS).
Content prepared by Ángel Ortega Castro for angelortegacastro.com. Informational content; for any legal obligation, consult the current text of Royal Decree 311/2022 in the BOE.