If you work in public administration, or for a company that provides services to public bodies, you have probably heard of the ENS, Spain’s National Security Framework. Yet many procurement officers are unsure exactly what it involves, when they are obliged to require it of a software supplier and, above all, how to check that a certification is genuine and still valid. This guide explains it in practical terms.
What is the ENS (National Security Framework)?
The National Security Framework (Esquema Nacional de Seguridad, ENS) is the cybersecurity reference framework for the information systems of Spain’s public authorities. It is governed by Royal Decree 311/2022 (Real Decreto 311/2022), which repealed and updated the previous ENS of 2010.
Put simply, the ENS defines which technical, organisational and management security controls an information system – and its supplier – must have in place so that the public sector can entrust it with processing its data and running its processes.
It is not a voluntary certification. It is a legal requirement for:
- The information systems of all Spanish public authorities
- Private suppliers that provide services to the public sector, where those services involve processing public data or accessing public sector systems
The ENS is administered and supervised by the National Cryptologic Centre (CCN), a body attached to Spain’s National Intelligence Centre (CNI).
Three ENS levels: basic, medium and high
The ENS categorises systems according to the impact a security incident would have:
| Category | Description | Examples |
|---|---|---|
| Basic | Incident with limited impact | Informational websites, contact forms, newsletters |
| Medium | Incident with significant impact | Most municipal management, HR and accounting systems |
| High | Incident with serious or very serious impact | Public safety systems, critical infrastructure, health data |
For each category, the ENS defines a set of security measures that must be implemented. The category is determined by the public body that owns the system, not by the supplier.
Who the ENS applies to
Bodies required to comply
All bodies in the Spanish public sector are required to comply with the ENS:
- Central government (Administración General del Estado, AGE)
- Autonomous communities (regions)
- Local authorities: local councils (ayuntamientos), provincial councils (diputaciones) and island councils (cabildos)
- Public universities
- Publicly owned companies and public-law entities
- Public sector foundations
Private suppliers
A private supplier is required to comply with the ENS when it:
- Provides systems administration services to a public body
- Develops or maintains software that processes public sector data
- Offers cloud or SaaS services in which public data is stored
- Provides support services with access to the public sector’s production systems
If your company provides any of these services without ENS certification, you are in breach of contract and, depending on the tender specifications, you may be exposed to financial penalties or termination of the contract.
How ENS certification works
There are two ways to demonstrate compliance with the ENS:
ENS declaration of conformity
This is issued by the supplier itself after a documented self-assessment process. It is sufficient for systems in the basic category. It carries less legal weight than certification because it is not audited by an independent third party.
ENS certification
This is issued by a certification body accredited by ENAC (Spain’s national accreditation body), such as AENOR, Bureau Veritas, BSI Group, SGS or Dekra. It includes a technical audit of the supplier’s system and processes. It is mandatory for systems in the medium and high categories, and is increasingly required in tender specifications even where the law does not make it mandatory.
Certification is valid for two years, after which it must be renewed by means of a follow-up audit. The CCN publishes a public register of certified entities where you can verify any certification.
How to check whether your supplier’s ENS certification is valid
This is the step most often skipped in procurement processes. Asking for ENS certification is not enough: you have to verify that it is genuine and still valid.
Step 1: Go to the CCN’s ENS portal or ask the supplier for the certificate number and the issuing body.
Step 2: Check on the ENAC website that the issuing body is accredited for ENS certification.
Step 3: Check the issue date and the expiry date. An expired ENS certification is not valid.
Step 4: Check that the scope of the certification includes the service you are going to procure. A company may hold ENS certification for one specific product and not for another.
As a benchmark for what any supplier should be able to show, CEDESA publishes its current certifications – ENS, ISO 27001, ISO 9001 and ISO 56001 – with the issuing body and scope of each on its certifications page.
The risks of procuring software without ENS compliance
Many public bodies still procure software without requiring ENS compliance, either through lack of awareness or because their usual supplier “has always worked out fine”. The risks are tangible:
Legal risk: Non-compliance with Royal Decree 311/2022, with the possibility of penalties and personal liability for the public body’s security officer.
Audit risk: Projects financed with Next Generation EU funds are audited by Spain’s Court of Auditors (Tribunal de Cuentas) and by the IGAE (Intervención General, the General State Comptroller). If the supplier does not comply with the ENS when the funding requires it, the public body may have to repay the funding.
Incident risk: A supplier without ENS certification lacks the audited security controls that reduce the likelihood and impact of a cyberattack. In the event of a security breach, the Spanish Data Protection Agency (AEPD) can impose GDPR fines on the public body, not only on the supplier.
Continuity risk: If, during the life of the contract, the public body is audited by the CCN and the system does not comply with the ENS, it may be forced to suspend the service or change supplier at very short notice.
The ENS also matters when you are choosing what kind of supplier to work with: a large integrator and a certified mid-sized company do not demonstrate it with the same scope or with the same team. We explore this in Large integrator or mid-sized company? How to choose a supplier.
ENS vs ISO 27001: are they the same thing?
A common source of confusion. They are not the same, but they are complementary:
| ENS | ISO 27001 | |
|---|---|---|
| Geographical scope | Spain (mandatory for the Spanish public sector) | International (voluntary) |
| Regulated by | Royal Decree 311/2022 (CCN) | ISO/IEC 27001 standard (ISO) |
| Obligation | Legally required for the Spanish public sector | Voluntary |
| Approach | Specific technical and organisational measures for central government (the AGE) | Information security management system |
| Recognition | Essential for public contracts in Spain | Internationally recognised |
Having ISO 27001 does not exempt you from the ENS. Having ENS certification without ISO 27001 is enough for Spanish public contracts, but leaves you less competitive in the international market. Ideally, you should have both.
Frequently asked questions about the ENS
Does the ENS apply to systems in the cloud?
Yes. When a public body uses a cloud service (SaaS, IaaS, PaaS), the cloud provider must comply with the ENS for the infrastructure, and the application supplier must do so for the software. The CCN-STIC-823 guide (CCN-STIC is the CCN’s series of security guides) deals specifically with the use of cloud services in the public sector.
Can the ENS be required in contracts with private companies outside the public sector?
It is not a legal requirement for private companies that do not contract with the public sector. But many private companies in regulated sectors (utilities, critical infrastructure, banking) voluntarily require it of their suppliers as a sign of cybersecurity maturity.
How much does it cost a software supplier to obtain ENS certification?
The cost varies with the size of the company and the initial maturity of its security controls. As a rough guide: between €15,000 and €50,000 in consultancy and implementation, plus the certification body’s fees (between €5,000 and €15,000). The whole process usually takes between 6 and 18 months.
What happens if the supplier loses its ENS certification during the contract?
The supplier is obliged to notify the contracting authority. Depending on the tender specifications, this may lead to suspension of the service or termination of the contract. This is one more reason to include in the specifications a clause requiring the certification to be maintained throughout the life of the contract.
If what you are preparing is a set of tender specifications, the ENS is one of eight criteria worth pinning down in writing. The rest – and the documentary evidence that backs them up – are set out in what to require of a public sector software supplier.