Free ISO 27001 Assessment

ENS

A Spanish tender names the ENS. Here is how the system gets certified.

Categorisation, declaration of applicability, the Annex II measures of Royal Decree 311/2022 in place and the documentation an ENS auditor expects, delivered in Spanish, inside the platform that keeps the evidence current.

Declaración de aplicabilidadExample, categoría MEDIA

73 Annex II measures: 61 applicable, 12 not applicable with justification

Marco organizativo [org]
4 measures
4 / 4
Marco operacional [op]
31 measures, 5 not applicable
26 / 26
Medidas de protección [mp]
38 measures, 7 not applicable
31 / 31
Risk analysis
MAGERIT method, 5 dimensions valued
Done
Approved by the responsable de seguridad, week 9Export · DOCX, PDF

Who this is for

Private companies that serve the Spanish public sector.

  • A fit

    • A SaaS company that has won, or is bidding for, a contract with a Spanish ministry, regional government, university or city council.
    • A cloud or IT services provider whose public sector customer has asked for an ENS conformity certificate at renewal.
    • A subcontractor of a company that holds a public sector contract and must pass the ENS requirement down the supply chain.
  • Also a fit

    • A company that already holds ISO 27001 and needs the ENS added; many Annex II measures map and the CCN publishes the correspondence.
    • A company with a BASIC category system that needs the self-assessment and conformity declaration done properly.
    • A non-Spanish company entering Spanish public procurement for the first time.
  • Not a fit

    • Organisations that need the ENS certification audit itself for MEDIUM and HIGH systems. We prepare you; an accredited certification body audits and certifies.
    • HIGH category systems with owned infrastructure. Quoted after the assessment, with an on-site partner named.
    • Teams that want the certificate without appointing the roles. The ENS requires a responsable de seguridad; we help you appoint one, we do not take the role.

What you walk away with

What the ENS auditor expects, written in Spanish.

Every deliverable is editable and yours, inside the platform or exported as DOCX, CSV and PDF.

ENS compliance

10 deliverables, 8 to 10 weeks
  • System categorisation with valuation of the five dimensions

    Availability, authenticity, integrity, confidentiality, traceability

    • DOCX
    • PDF
  • Declaration of applicability of Annex II measures

    Applicable or not, with justification and status, per group

    • CSV
    • PDF
  • Information security policy approved by management

    Formally adopted, as the ENS requires

    • DOCX
    • PDF
  • Risk analysis in the MAGERIT method or an equivalent

    Assets, threats, safeguards, residual risk

    • CSV
    • PDF
  • Procedures of the organisational and operational framework

    Roles, access, change, incident, continuity, monitoring

    • Procedure
  • Role appointments and responsibilities

    Responsable de la información, del servicio, de seguridad, del sistema

    • DOCX
  • Evidence pack for each applicable measure

    From connected cloud, code and identity systems where possible; uploaded where not

    • Platform
  • Conformity self-assessment (BASIC) or audit preparation file (MEDIUM, HIGH)

    Per Annex III and the CCN-STIC 809 profiles

    • DOCX
    • PDF
  • Certification body shortlist and audit plan

    For MEDIUM and HIGH, booked around your contract date

    • DOCX
  • Recorded hand-over and readiness sign-off, in Spanish or English

    With whoever owns the system afterwards

    • Video
    • PDF

How it works

Ten weeks to hand-over. Then the auditor, then every two years.

For a single system of BASIC or MEDIUM category. HIGH category systems are quoted after the assessment.

  • GRCTrail
  • Hand-over
  • Without us
  1. Week 0

    Scoping call

    The contract or tender, the systems that serve it, what exists. Written fixed price within 3 business days.

  2. Weeks 1 to 2

    Assessment

    System scope, provisional categorisation, gap analysis against Annex II for that category, audit route confirmed. Implementation price confirmed.

  3. Weeks 3 to 9

    Implementation

    Categorisation, applicability statement, policy, risk analysis, procedures, role appointments, evidence linked to each measure. Two review sittings with your team.

  4. Week 10

    Hand-over

    Self-assessment or audit file complete, recorded hand-over in Spanish or English, readiness sign-off.

  5. Your auditor

    Certification audit

    For MEDIUM and HIGH, with the accredited body you contract. We join the calls and fix findings against our work. BASIC files the conformity declaration.

  6. Every two years

    Re-audit

    And whenever the system changes substantially. The measures keep operating and the evidence keeps collecting, in GRCTrail or in your export.

How we price

What moves the price

Three things we ask about on the call.

  • Category and number of systems.

    BASIC is the base case; MEDIUM adds measures to evidence; each additional system adds scope.

  • What already exists.

    An ISO 27001 certificate shortens the work considerably; the CCN correspondence guide maps most measures.

  • How much of the stack is cloud.

    Measures on cloud, code and identity systems are evidenced automatically; owned infrastructure is not.

Never in our price, named in the quote so you can budget

  • The ENS certification audit for MEDIUM and HIGH systems, performed by an accredited certification body that you contract directly
  • Acting as your responsable de seguridad after hand-over; we help you appoint the roles the ENS requires
  • Penetration testing
  • Formal legal opinions

Questions before the call

Does a private company need ENS certification?

A private company must comply with the ENS for the systems it uses to serve Spanish public bodies. Certification by an accredited body is required for MEDIUM and HIGH category systems. BASIC systems use a self-assessment and conformity declaration.

Can we reuse ISO 27001 for the ENS?

Partly. Many Annex II measures overlap with ISO/IEC 27001 Annex A controls, and the CCN publishes a correspondence guide. The ENS adds categorisation, Spanish-specific measures and its own audit, so an ISO 27001 company still needs an ENS implementation, but a shorter one.

Is the work delivered in Spanish?

Yes. Documentation is produced in Spanish for the auditor and the public body, with English versions where your team needs them. Calls run in whichever language your team prefers.

How often is an ENS audit repeated?

Every two years for MEDIUM and HIGH systems, and whenever the system changes substantially. The self-assessment for BASIC systems follows the same cycle.

What if the auditor raises a nonconformity?

If it is against work we delivered, we fix it at no extra charge; that is stated in the quote. If it concerns something outside the agreed scope, we tell you what it would take and you decide.

Tell us about the tender and the systems that serve it.

You leave the call with a scope and an indicative range. The written fixed price follows within 3 business days.