DEFENSEEnter the division
service · ENS consulting

Consulting. ENS.

We guide public administrations and their suppliers through categorizing and adapting their systems to the Spanish National Security Framework, and into the certification audit fully prepared. A framework that protects what matters: public services and citizens' data.

current regulation
RD 311/2022
technical guides
CCN-STIC 800
categories
Basic · Medium · High
dimensions
D · A · I · C · T
· regulatory framework · §01

What the ENS is and where it comes from.

rd.311-2022
in force
current regulation
Royal Decree 311/2022

Approved on May 3, 2022, it regulates the Spanish National Security Framework. It replaces and modernizes the earlier RD 3/2010, aligning it with today's threat landscape and European regulation.

ley.40-2015
art. 156
legal basis
Law 40/2015

The Public Sector Legal Regime Act establishes in article 156 that the Spanish National Security Framework is mandatory for all public administrations.

ccn-stic.800
technical guides
how it is applied
CCN-STIC 800 series

The National Cryptologic Centre publishes the 800-series STIC guides, which develop each control in detail: categorization, adaptation plan, measures, audit and indicators.

· legal obligation · §02

Who is required to comply with the ENS?

Every Spanish public administration and every supplier providing services to the administration. It is not optional, it is not a recommendation: it is a legal obligation backed by a sanctions regime.

age
General State Administration
All public bodies and agencies of the AGE.
ccaa
Autonomous Communities
Regional governments and their dependent public-law entities.
eell
Local Entities
City councils, provincial councils, island councils and municipal associations.
sp
Institutional Public Sector
Autonomous bodies, agencies, foundations and public-sector companies.
univ
Public universities
The public university system and its affiliated bodies.
prov
Public sector suppliers
Any company providing services to the administration must demonstrate equivalent compliance.
· current context · §03

Why it matters more than ever.

The pressure on public sector infrastructure is real and growing. The ENS is not bureaucracy: it is the line of defense that keeps an attack from turning a public service into a headline.

Ransomware against public administrations
Targeted attacks on city councils, public healthcare and state agencies number in the dozens every year in Spain.
Impersonation and targeted phishing
Campaigns that mimic official bodies to harvest credentials with access to internal systems.
Personal data exposure
Breaches affecting citizens' rights, with AEPD sanctions and severe reputational damage.
Continuity of essential services
An outage in critical systems can paralyze administrative services, healthcare or public safety for weeks.
// why the ENS works
The ENS requires you to categorize, to measure risk, to document measures and to audit that those measures truly exist. It is a demanding common baseline that has proven to drastically reduce the attack surface in organizations that take it seriously.
· categorization · §04

Five dimensions, three categories.

The ENS assesses every system across five security dimensions. From there, the applicable category is derived and, with it, the minimum required measures.

D
Availability
The system remains accessible when it is needed.
A
Authenticity
The identities involved can be proven.
I
Integrity
Information has not been altered without authorization.
C
Confidentiality
Information is only accessible to those who should access it.
T
Traceability
Every action is logged and attributable.
category
BASIC

Systems where the impact of an incident is limited. Measures proportionate to low risk.

E.g. Backup information systems, non-critical internal records.
category
MEDIUM

Systems with serious impact on the organization or citizens. Higher technical and organizational requirements.

E.g. Citizen portals, electronic government offices, case file management.
category
HIGH

Critical systems. An incident can severely affect rights, freedoms or essential functions.

E.g. Law enforcement systems, critical public healthcare, essential infrastructure.
· nexus methodology · §05

How we do it.

Five phases that take an organization from the first assessment to the certification audit with its evidence in order. No empty promises, no recycled templates.

01
Categorization
We assess the five dimensions (D-A-I-C-T) and derive the applicable category.
02
Risk analysis
We identify threats, vulnerabilities and the real impact on the organization.
03
Adaptation plan
A prioritized roadmap with owners, deadlines and verifiable deliverables.
04
Implementation
Deployment of the technical and organizational measures, aligned with CCN-STIC 800.
05
Audit support
We prepare the evidence and stand by you during the audit. Verification is performed by an independent certification body.
· consulting request · §06

Request consulting.

Free initial assessment. We tell you where you stand and what realistic work lies ahead. We respond in < 24h on business days.

contact.consultoria
POST /api/contact · channel=CONSULTORIA
type of service *
type of organization *
No-obligation initial assessment · response < 24h on business days