Spain’s National Security Framework (Esquema Nacional de Seguridad, ENS) makes no distinction between a ministry and a local council serving 3,000 inhabitants: Law 40/2015 on the legal regime of the public sector (Ley 40/2015) and Royal Decree 311/2022 (Real Decreto 311/2022) oblige every public sector entity to bring its information systems into line with it. The difference lies in the resources available, and the legislation recognises this through specific compliance profiles: sets of measures tailored to a type of entity, which the National Cryptologic Centre (CCN) approves and publishes. There are three for local authorities, within the CCN-STIC 883 guide (CCN-STIC is the CCN’s series of security guides): 883A for councils with fewer than 5,000 inhabitants and limited resources, 883B for those with fewer than 20,000 and 883C for those with between 20,000 and 75,000. This guide explains what they are, how one is used to declare conformity, what role the provincial council (Diputación) plays and, above all, what a small council should require of its software and hosting suppliers, which is where most of its systems actually live.

Why a small council is bound too

Article 156 of Law 40/2015 establishes the ENS as the security framework for e-government across the whole public sector, and Royal Decree 311/2022 implements it with no exceptions based on size. A council’s systems (the e-office or sede electrónica, the document registry, the case management system, the register of residents or padrón, accounting, the transparency portal and email) process its residents’ personal data and support procedures with legal effect: that is why they are in scope. What the legislation adjusts is how to comply, through two tools: the categorisation of the system (basic, medium or high, according to the impact of an incident) and the specific compliance profiles of Article 30.

What is a specific compliance profile?

Article 30 of Royal Decree 311/2022 allows the CCN to approve specific compliance profiles for particular entities or sectors, comprising the set of security measures that, following the risk analysis, apply to a given security category. This is the principle of proportionality: a council with 4,000 inhabitants does not need to implement the same catalogue as a regional ministry (Consejería), but it does need a defined, complete and auditable catalogue suited to its circumstances.

The CCN-STIC 883 guide, on implementing the ENS in local authorities, includes in its annexes the profiles and sample compliance plans (planes de adecuación) for each population band:

ProfileApplies toWhat it provides
CCN-STIC 883ACouncils with fewer than 5,000 inhabitants and limited resourcesMinimum measures that are achievable with very limited staff and budget; support expected from the provincial council or competent body
CCN-STIC 883BCouncils with fewer than 20,000 inhabitantsA set of measures and a model compliance plan for the band that contains the largest number of Spanish municipalities
CCN-STIC 883CCouncils with 20,000 to 75,000 inhabitantsA profile for entities with their own IT department but limited resources

Applying the profile does not exempt a council from carrying out the risk analysis and producing the statement of applicability and the security policy; what it does is set out in advance which measures are expected, so that both the compliance work and the audit have a clear bar to meet.

The role of the provincial council

Law 7/1985 on the basic rules of local government (Ley 7/1985 de Bases del Régimen Local) entrusts provincial councils with providing e-government services to municipalities with fewer than 20,000 inhabitants, and the CCN’s profiles expressly provide for these councils to rely on the provincial council or competent body throughout the compliance plan. In practice, many small councils use the e-office, case management system, document registry and hosting that the provincial council provides, and in those cases:

  • The conformity of those systems is demonstrated by the provincial council (or its supplier) within its own ENS scope.
  • The local council remains responsible for its own systems (computer equipment, email if it runs its own, applications it has contracted directly) and for the organisational measures: security policy, designated roles, training and user management.
  • There must be a document that makes clear which systems the provincial council covers and which it does not, because the gap between the two is where incidents occur.

How conformity is declared in a small council

Once the system has been categorised and the profile applied, conformity is demonstrated in the same way as in any other entity:

  • Basic category: a declaration of conformity based on a self-assessment, signed by the person responsible for the system and reviewed at least every two years.
  • Medium and high categories: a certification of conformity following an audit by a certification body accredited by ENAC (Spain’s national accreditation body) for the ENS, likewise valid for two years.

In both cases, the conformity mark set out in the CCN-STIC 809 guide must be published on the website with a link to the document. Many municipal systems that handle the register of residents or case files containing sensitive data are categorised as medium, which requires certification – a declaration is not enough – and the profile does not change that rule. We explain how to check that an ENS certificate is current in expired ENS certificates: how to check your supplier’s.

What to require of the software and hosting supplier

Article 31 of Royal Decree 311/2022 requires private sector operators that provide services to public entities to comply with the ENS within the scope of those services. For a small council, almost all of whose systems are contracted out, this puts the supplier at the centre. What to ask for, and write into the tender specifications:

  1. A current ENS certificate or declaration of conformity, under RD 311/2022, less than two years old and with a scope that explicitly includes the contracted service (a hosting certificate does not cover development work, or vice versa).
  2. A category equal to or higher than that of the municipal system: if the case management system is medium category, the supplier must be certified at medium or high.
  3. Data location and processing: where the data is hosted, who has access, under what controls, and a commitment to process it in accordance with the GDPR as data processor.
  4. Activity logging and traceability: who did what in each case file, exportable for audit purposes.
  5. Incident management: deadlines for notifying the council and, where applicable, CCN-CERT (the CCN’s incident response team).
  6. Backups and continuity: frequency, restore tests and recovery time.
  7. Updates and vulnerability management for the software delivered, with a schedule.
  8. Authentication in line with the profile (two-factor for administrators and for external access).
  9. Contract exit: handover of the data in a reusable format and certified deletion.
  10. Interoperability: compliance with the National Interoperability Framework (ENI) and its technical standards, as we set out in what a custom case management system must comply with.

And a rule of thumb: if the supplier cannot show you the certificate and its scope at the first meeting, it does not have one. Our guide to writing these requirements so that they are checked automatically is in how to prepare technical specifications for software with ENS requirements.

An eight-step compliance plan for a small council

  1. Inventory of systems: the council’s own, the provincial council’s and contracted ones, with a named person responsible for each.
  2. Categorisation of each system according to the impact on the five dimensions (availability, authenticity, integrity, confidentiality and traceability).
  3. Choose the profile that matches the council’s population and adopt it formally.
  4. Security policy approved by the full council (Pleno) or the mayor’s office (Alcaldía), designating the information officer, the service manager, the security officer and the system manager.
  5. Risk analysis tailored to the profile and statement of applicability.
  6. Division of responsibilities with the provincial council and the suppliers: which measures each one covers, in writing.
  7. Implementation of the council’s own organisational measures: users, training, procedures, backups and incidents.
  8. Declaration or certification depending on the category, publication of the conformity mark and a schedule for the two-yearly review.

What will change with NIS2

As at 16 September 2026, Spain’s transposition of the NIS2 Directive has still not been published in the BOE (Boletín Oficial del Estado, the official state gazette), but the draft bill covers local authorities above a certain size and their essential suppliers, and refers to the ENS as the basis for the measures. A council that has adopted its compliance profile today will already have done the work by the time it arrives; we explain this in NIS2 in Spain: what it will require of public sector suppliers and how it fits with the ENS.

How CEDESA does it

CEDESA develops case management systems, e-offices and custom systems for the public sector, with clients such as the Diputaciones de Badajoz, Toledo and Ourense, the provincial councils that provide e-government services to the local councils in their provinces. Our medium-category ENS certification, issued under Royal Decree 311/2022, covers those services, and we maintain it alongside ISO 27001. For a small council, that means the software it receives through its provincial council already sits within a verifiable ENS scope, and that the division of measures between supplier, provincial council and local council is documented from the start of the project.

Frequently asked questions about the ENS in small councils

Does a council with fewer than 5,000 inhabitants have to comply with the ENS?

Yes. Law 40/2015 and Royal Decree 311/2022 bind every public sector entity, with no exception based on size. What the legislation does allow is the use of a specific compliance profile, such as CCN-STIC 883A for councils with fewer than 5,000 inhabitants and limited resources, which tailors the measures to those circumstances.

What are the CCN-STIC 883A, 883B and 883C profiles?

They are specific ENS compliance profiles for local authorities, published by the National Cryptologic Centre as annexes to the CCN-STIC 883 guide: 883A for councils with fewer than 5,000 inhabitants, 883B for those with fewer than 20,000 and 883C for those with between 20,000 and 75,000. They set out the measures that apply and include sample compliance plans.

Can the provincial council comply with the ENS on the local council’s behalf?

In part. The provincial council demonstrates the conformity of the systems it provides (e-office, document registry, case management system, hosting) within its scope, and the profiles provide for councils with fewer than 20,000 inhabitants to rely on it. But the local council remains responsible for its own systems and its organisational measures, and what each one covers must be set down in writing.

Is a declaration of conformity enough, or is certification needed?

It depends on the category of the system, not on the size of the municipality. In the basic category, a declaration of conformity is enough; in medium and high, certification by an ENAC-accredited body is needed. A case management system holding sensitive data is usually categorised as medium.

What should I require of my council’s software supplier as regards the ENS?

A current certificate or declaration of conformity under RD 311/2022, less than two years old, with a scope that includes the contracted service and a category equal to or higher than that of the system; plus data location, traceability, incident management, backups and continuity, updates, strong authentication and contract exit terms.

Conclusion

The ENS binds every local council, but the CCN-STIC 883A, 883B and 883C profiles make it possible to comply with the resources of a small municipality, by relying on the provincial council and requiring each supplier to hold a current certificate with the right scope. The key is to set down in writing who covers each system and to leave no gaps. If you would like to see what that division looks like in a specific case, tell us which systems your council has today and who provides them.