Consulting. ENS.
We guide public administrations and their suppliers through categorizing and adapting their systems to the Spanish National Security Framework, and into the certification audit fully prepared. A framework that protects what matters: public services and citizens' data.
What the ENS is and where it comes from.
Approved on May 3, 2022, it regulates the Spanish National Security Framework. It replaces and modernizes the earlier RD 3/2010, aligning it with today's threat landscape and European regulation.
The Public Sector Legal Regime Act establishes in article 156 that the Spanish National Security Framework is mandatory for all public administrations.
The National Cryptologic Centre publishes the 800-series STIC guides, which develop each control in detail: categorization, adaptation plan, measures, audit and indicators.
Who is required to comply with the ENS?
Every Spanish public administration and every supplier providing services to the administration. It is not optional, it is not a recommendation: it is a legal obligation backed by a sanctions regime.
Why it matters more than ever.
The pressure on public sector infrastructure is real and growing. The ENS is not bureaucracy: it is the line of defense that keeps an attack from turning a public service into a headline.
Five dimensions, three categories.
The ENS assesses every system across five security dimensions. From there, the applicable category is derived and, with it, the minimum required measures.
Systems where the impact of an incident is limited. Measures proportionate to low risk.
Systems with serious impact on the organization or citizens. Higher technical and organizational requirements.
Critical systems. An incident can severely affect rights, freedoms or essential functions.
How we do it.
Five phases that take an organization from the first assessment to the certification audit with its evidence in order. No empty promises, no recycled templates.
Request consulting.
Free initial assessment. We tell you where you stand and what realistic work lies ahead. We respond in < 24h on business days.
Content on ENS Consulting
Quién está obligado al ENS y a qué categoría: administraciones y empresas
Quién debe cumplir el ENS: administraciones públicas, organismos y empresas privadas proveedoras, y cómo se asigna la categoría Básica, Media o Alta.
ENS vs ISO 27001: diferencias, equivalencias y cuál necesita tu empresa
Guía comparativa del Esquema Nacional de Seguridad (ENS) y la ISO 27001: diferencias clave, solapes y cómo decidir cuál necesita tu organización.
Auditoría ENS: en qué consiste, plazos y cómo superarla sin sobresaltos
Qué es la auditoría del Esquema Nacional de Seguridad, cada cuánto es obligatoria, fases, documentación y cómo superarla. Guía actualizada 2026.