ENS
A Spanish tender names the ENS. Here is how the system gets certified.
Categorisation, declaration of applicability, the Annex II measures of Royal Decree 311/2022 in place and the documentation an ENS auditor expects, delivered in Spanish, inside the platform that keeps the evidence current.
73 Annex II measures: 61 applicable, 12 not applicable with justification
- Marco organizativo [org]
- 4 measures
- 4 / 4
- Marco operacional [op]
- 31 measures, 5 not applicable
- 26 / 26
- Medidas de protección [mp]
- 38 measures, 7 not applicable
- 31 / 31
- Risk analysis
- MAGERIT method, 5 dimensions valued
- Done
Who this is for
Private companies that serve the Spanish public sector.
A fit
- A SaaS company that has won, or is bidding for, a contract with a Spanish ministry, regional government, university or city council.
- A cloud or IT services provider whose public sector customer has asked for an ENS conformity certificate at renewal.
- A subcontractor of a company that holds a public sector contract and must pass the ENS requirement down the supply chain.
Also a fit
- A company that already holds ISO 27001 and needs the ENS added; many Annex II measures map and the CCN publishes the correspondence.
- A company with a BASIC category system that needs the self-assessment and conformity declaration done properly.
- A non-Spanish company entering Spanish public procurement for the first time.
Not a fit
- Organisations that need the ENS certification audit itself for MEDIUM and HIGH systems. We prepare you; an accredited certification body audits and certifies.
- HIGH category systems with owned infrastructure. Quoted after the assessment, with an on-site partner named.
- Teams that want the certificate without appointing the roles. The ENS requires a responsable de seguridad; we help you appoint one, we do not take the role.
What you walk away with
What the ENS auditor expects, written in Spanish.
Every deliverable is editable and yours, inside the platform or exported as DOCX, CSV and PDF.
ENS compliance
10 deliverables, 8 to 10 weeksSystem categorisation with valuation of the five dimensions
Availability, authenticity, integrity, confidentiality, traceability
- DOCX
Declaration of applicability of Annex II measures
Applicable or not, with justification and status, per group
- CSV
Information security policy approved by management
Formally adopted, as the ENS requires
- DOCX
Risk analysis in the MAGERIT method or an equivalent
Assets, threats, safeguards, residual risk
- CSV
Procedures of the organisational and operational framework
Roles, access, change, incident, continuity, monitoring
- Procedure
Role appointments and responsibilities
Responsable de la información, del servicio, de seguridad, del sistema
- DOCX
Evidence pack for each applicable measure
From connected cloud, code and identity systems where possible; uploaded where not
- Platform
Conformity self-assessment (BASIC) or audit preparation file (MEDIUM, HIGH)
Per Annex III and the CCN-STIC 809 profiles
- DOCX
Certification body shortlist and audit plan
For MEDIUM and HIGH, booked around your contract date
- DOCX
Recorded hand-over and readiness sign-off, in Spanish or English
With whoever owns the system afterwards
- Video
How it works
Ten weeks to hand-over. Then the auditor, then every two years.
For a single system of BASIC or MEDIUM category. HIGH category systems are quoted after the assessment.
- GRCTrail
- Hand-over
- Without us
Week 0
Scoping call
The contract or tender, the systems that serve it, what exists. Written fixed price within 3 business days.
Weeks 1 to 2
Assessment
System scope, provisional categorisation, gap analysis against Annex II for that category, audit route confirmed. Implementation price confirmed.
Weeks 3 to 9
Implementation
Categorisation, applicability statement, policy, risk analysis, procedures, role appointments, evidence linked to each measure. Two review sittings with your team.
Week 10
Hand-over
Self-assessment or audit file complete, recorded hand-over in Spanish or English, readiness sign-off.
Your auditor
Certification audit
For MEDIUM and HIGH, with the accredited body you contract. We join the calls and fix findings against our work. BASIC files the conformity declaration.
Every two years
Re-audit
And whenever the system changes substantially. The measures keep operating and the evidence keeps collecting, in GRCTrail or in your export.
How we price
What moves the price
Three things we ask about on the call.
Category and number of systems.
BASIC is the base case; MEDIUM adds measures to evidence; each additional system adds scope.
What already exists.
An ISO 27001 certificate shortens the work considerably; the CCN correspondence guide maps most measures.
How much of the stack is cloud.
Measures on cloud, code and identity systems are evidenced automatically; owned infrastructure is not.
Never in our price, named in the quote so you can budget
- The ENS certification audit for MEDIUM and HIGH systems, performed by an accredited certification body that you contract directly
- Acting as your responsable de seguridad after hand-over; we help you appoint the roles the ENS requires
- Penetration testing
- Formal legal opinions
Questions before the call
Does a private company need ENS certification?
A private company must comply with the ENS for the systems it uses to serve Spanish public bodies. Certification by an accredited body is required for MEDIUM and HIGH category systems. BASIC systems use a self-assessment and conformity declaration.
Can we reuse ISO 27001 for the ENS?
Partly. Many Annex II measures overlap with ISO/IEC 27001 Annex A controls, and the CCN publishes a correspondence guide. The ENS adds categorisation, Spanish-specific measures and its own audit, so an ISO 27001 company still needs an ENS implementation, but a shorter one.
Is the work delivered in Spanish?
Yes. Documentation is produced in Spanish for the auditor and the public body, with English versions where your team needs them. Calls run in whichever language your team prefers.
How often is an ENS audit repeated?
Every two years for MEDIUM and HIGH systems, and whenever the system changes substantially. The self-assessment for BASIC systems follows the same cycle.
What if the auditor raises a nonconformity?
If it is against work we delivered, we fix it at no extra charge; that is stated in the quote. If it concerns something outside the agreed scope, we tell you what it would take and you decide.
Last reviewed: October 2026
Tell us about the tender and the systems that serve it.
You leave the call with a scope and an indicative range. The written fixed price follows within 3 business days.